Top Banner
14

Managing Risk and S ecurity in the cloud.

Jan 14, 2016

Download

Documents

Jacqui

Managing Risk and S ecurity in the cloud. Stuart Strathdee / Chief Security Advisor. Session outline. - PowerPoint PPT Presentation
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Managing Risk and  S ecurity in the cloud.
Page 2: Managing Risk and  S ecurity in the cloud.

Managing Risk and Security in the cloud.

Stuart Strathdee / Chief Security Advisor

Page 3: Managing Risk and  S ecurity in the cloud.

Session outline

No cloud strategy is complete without a comprehensive risk management plan. In this session, you can learn more about how Microsoft addresses security, regulatory compliance, the potential for data to cross borders, and interoperability to prevent 'Cloud Lock'.

Page 4: Managing Risk and  S ecurity in the cloud.

If this is how you do Threat Analysis, then this presentation is not for you.

Translating the Threat relation[[ trs av −! dt ]] := [[ trs ]] [[ av ]] of [[ dt ]] attacking the system[[ trs av −! v ]] := [[ trs ]] [[ av ]] of [[ v ]] being exploited[[ trs av −! ts(l ) ]] := [[ trs ]] [[ av ]] of [[ ts(l ) ]] being initiated

To illustrate how a diagram is translated we will use the threat diagram in Fig. 5

Fig. 5. Threat diagram

Page 5: Managing Risk and  S ecurity in the cloud.

AUSTRAC provides help: http://www.austrac.gov.au/files/risk_management_tool.pdf

Page 7: Managing Risk and  S ecurity in the cloud.

Get your head in the cloud.

Page 8: Managing Risk and  S ecurity in the cloud.

Why where doesn’t matter.

Page 9: Managing Risk and  S ecurity in the cloud.

On premise

Off premise

Page 10: Managing Risk and  S ecurity in the cloud.

Why cloud represents greater profitability for partners.

• Allows transitioning of resources from low margin business to high margin business.

• Provides the customer with service levels which would have been prohibitively expensive on an individual scale. Think standards compliance.

• Reduces the exposure for customers and partners.

Page 11: Managing Risk and  S ecurity in the cloud.

Case Study time.

Page 12: Managing Risk and  S ecurity in the cloud.

Starting today, you can….• Focus more of your

resources on high profit aspects of your business.

• Deliver competitive advantages to your customers.

• Have Microsoft be the foundation for both you and your customers in transforming your businesses.

Page 13: Managing Risk and  S ecurity in the cloud.

Acknowledgements:• International Standards Organisation: http://www.iso.org• AUSTRAC• SourceForge.net for the CORAS Security Risk Modelling

Language.• Bsi Group. Http://www.bsigroup.com• http://am3218.k12.sd.us/Event/Wall.htm• http://photosdie.typepad.com• http://www.jhartfound.org• http://www.fashion-res.com• http://www.jodixonjeweller.co.uk/

Page 14: Managing Risk and  S ecurity in the cloud.