Top Banner
www.cloudsec.com | #CLOUDSEC Enabling Cloud Security It’s more than just ticking a box
17

Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

Jul 27, 2018

Download

Documents

LyMinh
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

www.cloudsec.com | #CLOUDSEC

Enabling Cloud Security

– It’s more than just ticking a box

Page 2: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

#CLOUDSEC

The c

loud landscape

Source: https://steveblank.files.wordpress.com/2011/02/bessemercloudscape.jpg

Page 3: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

Side Activities at Venue

“Opportunities and Challenges”

Page 4: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

#CLOUDSEC

Clo

ud

op

po

rtun

itie

s Flexibility

On-demand Services

Rapid Deployment

Automation Scalability

Availability

Lower TCO

Page 5: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

#CLOUDSEC

C

lou

d c

halle

nges

Talent & Expertise

Security

Managing Multiple Services

Compliance Cost

Management

Governance and Control

Integration

Page 6: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

“Why cloud hurts”

Page 7: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

#CLOUDSEC

Th

e c

lassic

co

ntr

acts

Requirements

Evaluations

Selection

Deployment Adoption

Optimisation

Renewal

Page 8: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

#CLOUDSEC

Standalone services

SLA based services

model

Business workflow

integration

Legacy infrastructure

integration

Data protection and

management

Source: https://www.simple-talk.com/iwritefor/articlefiles/cloud/2011/11/cloud-service-model.png

Page 9: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

#CLOUDSEC

CSA shared responsibility model

Page 10: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

#CLOUDSEC

Organisational implications • Clarity around scope and the primary motivation of moving to the cloud

• Changes to governance models and decision making

• Knowledge of cloud architecture, virtualization, multiple technology

platforms

• Challenge of standardised processes supporting seamless integration across multiple systems

• Changing skillset from technology management to vendor management

• Upskilling on effective cloud-based systems management

Page 11: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

#CLOUDSEC

http://cloudacademy.com/blog/wp-content/uploads/2014/07/CMS-in-VPC.jpg

Page 12: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

#CLOUDSEC

Controls and Questions

295 Supporting Questions

133 Control Areas

16 Control

Domains

• Model for enabling active governance

• Enables cloud architecture discussions for business outputs

• Moves cloud decisions from audit assessment to a risk based outcomes

Page 13: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

“A tale of three instances”

Page 14: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

#CLOUDSEC

Three cloud projects

• IaaS contracts • PaaS contracts • SaaS Contracts

• Finance • HR Services • Collaboration • CRM • Business Intelligence

Global Bank Healthcare Provider Government Department

Complete Set

295 Questions

133 Areas

16 Domains

295 Questions

133 Areas

16 Domains

• IaaS contracts • PaaS contracts • SaaS Contracts

• Finance • HR Services • Collaboration • Document Mgmt. • CRM

• GovCloud • SaaS Contracts

• Document Mgmt. • Collaboration • CRM

Page 15: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department
Page 16: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

#CLOUDSEC

T

he T

we

lve

Data

Breaches

Access Management

Account Hijacking

System Vulnerabilities

Insufficient Due Diligence

Insecure Interface

Malicious Insider

Advanced Persistent

Threat

Tech Vulnerabilities

Data Loss

Services Abuse

Denial of Service

Page 17: Enabling Cloud Security · • Upskilling on effective cloud-based systems management . ... • CRM • Business Intelligence Global Bank Healthcare Provider Government Department

Puneet Kukreja

Partner, Cyber Advisory

Deloitte, Australia

@iPuneetKukreja