{"id":35525,"date":"2019-06-12T14:12:08","date_gmt":"2019-06-12T06:12:08","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=35525"},"modified":"2019-06-12T14:12:08","modified_gmt":"2019-06-12T06:12:08","slug":"who-is-responsible-for-cloud-security","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/06\/12\/who-is-responsible-for-cloud-security\/","title":{"rendered":"Who is responsible for cloud security?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em><strong>By Lionel Snell<br>Editor, NetEvents<\/strong><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>It must be a sign of the times. The world is growing so weary of all those malware massacres in the Internet Wild West, that security is beginning to feel quite sexy. <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The recent NetEvents EMEA Press Spotlight discussion \u2013 <em>Enterprise Security Considerations for the\nCloud \u2013 Containers, Perimeters, and Access Controls <\/em>\u2013 added greater\nintelligence to the mix. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/ovum.informa.com\/\">Ovum<\/a> Principle Analyst, Rik\nTurner, discussed the challenges, and beginning with Cloud Security, he\nintroduced the Shared Responsibility Model \u2013 chart below \u2013 and was surprised\nhow few people in the audience had been aware of it.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"620\" height=\"445\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud1.jpg\" alt=\"\" class=\"wp-image-35526\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud1.jpg 620w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud1-300x215.jpg 300w\" sizes=\"auto, (max-width: 620px) 100vw, 620px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">His\ndiagram showed three different delivery mechanisms, or ways of consuming cloud services:\nInfrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software\nas a Service (SaaS). So, what is the security\nresponsibility for the customer and what for the cloud service provider?\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In\nIaaS for example: Amazon Web Services (AWS) take care of all the grey bits, from Virtualization down\nto Networking. But above that it\u2019s the customers\u2019 responsibility. \u201cYou are not going\nto get any money back from them if you are breached because you didn\u2019t secure those layers\nabove.\u201d Similarly, for PaaS you are responsible for security in the top two\nlayers. \u201cIf anything goes wrong\nwith any of that,\nAWS would have to refund some money, or whatever\u201d. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The\nshared security model is clearly very important for any enterprise migrating to\nthe cloud: the enterprise will have to take care of security in all the red\nbits. So these are the very parts provided for by security vendors to the\nenterprise. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The\njoy, and the temptation, of SaaS is that it was so easy to sign up for \u2013 the IT\ndepartment does not even need to know about\nit \u2013 hence the whole notion of shadow IT and the rise of Cloud Access Security\nBrokers (CASB) that sit between the users and their services \u2013 Fig 2. CASB was\nthe first security response as it were to cloud adoption but: \u201cA lot of the\nCASB guys have been acquired by somebody else and are now disappeared into the\nbelly of much larger security companies with big broad portfolios\u201d.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"620\" height=\"445\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud2.jpg\" alt=\"\" class=\"wp-image-35527\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud2.jpg 620w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud2-300x215.jpg 300w\" sizes=\"auto, (max-width: 620px) 100vw, 620px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">IaaS\nand PaaS are more complicated, because the enterprise customer has broader\nresponsibility for security. What\u2019s more, it is no longer just a question of\nspinning up Virtual Machines (VMs) because of increasing use of Containers,\nMicroservices, or Serverless services &#8211; each with their own format. It\u2019s a\nprogression: VMs remove the dependence on physical servers; containers spare\nthe spinning up of new VMs, and Serverless means you can forget these and just\nspecify the functions to be supported \u2013 with a 70-80 percent saving in\ninfrastructure costs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So\npeople are now talking more about Cloud Workload Protection Platforms \u2013 blocking\nand remediating attacks, and restarting the workload somewhere\nelse \u2013 and Cloud Security Posture Management (CSPM), see the chart below.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CSPM\nis essentially a compliance function.\nIt\u2019s so easy now to spin up another instance either in the developer community\nor the actual production environment, that all of a sudden\nyou\u2019ve got another\n50 VMs that security didn\u2019t know about. So CSPM technology monitors and manages the spread of VMs to ensure\ncompliance with company policies.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"620\" height=\"445\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud3.jpg\" alt=\"\" class=\"wp-image-35528\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud3.jpg 620w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud3-300x215.jpg 300w\" sizes=\"auto, (max-width: 620px) 100vw, 620px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Rik\nTurner suggested: \u201cI personally think\nthat these two worlds will ultimately converge, because CSPM is itself\nstarting to move in the direction of actually doing the remediation rather than\njust alerting. So, those two will become\none&#8230; It gets a little bit more difficult with containers, in as much\nas you are starting to see smaller packages of code.\u201d And with serverless:\n\u201cthings become more ephemeral\u2026 the life of a piece of code that\u2019s running in a\nserverless environment may be a matter of milliseconds. How do I secure it?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The theory is that we are moving towards\na DevSecOps world, where the developers become responsible for embedding the security: \u201cnot a traditional developer concern, but\nwe\u2019re starting to see that\u201d.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"620\" height=\"445\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud4.jpg\" alt=\"\" class=\"wp-image-35529\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud4.jpg 620w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud4-300x215.jpg 300w\" sizes=\"auto, (max-width: 620px) 100vw, 620px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Moving\nto discuss perimeters and access control \u2013 Rik said: \u201cthe reason I want to make\nthese separate is because this is the traditional world of virtual private\nnetworks\u2026 all very old-world stuff.\nNow, not only are your applications moving into all kinds of other environments,\nbut fundamentally, your users have gone everywhere\u2026 So, I\u2019m seeing a lot more\ncomplexity in terms of the actual access issue and the access control than\nthere had been previously.\u201d <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"620\" height=\"445\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud5.jpg\" alt=\"\" class=\"wp-image-35530\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud5.jpg 620w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2019\/06\/cloud5-300x215.jpg 300w\" sizes=\"auto, (max-width: 620px) 100vw, 620px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">After this very clear introduction, Rik opened up the\ndiscussion with his panel from Hotshot Technologies, nCipher Security,\nNetFoundry, Versa Networks and BA TestLabs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Atchison\nFrazer, Worldwide Head of Marketing, Versa Networks, explained: \u201cVersa is an\ninnovator in the SD-WAN or WAN edge infrastructure space\u2026 one of the few vendors\nthat from the beginning actually\nbuilt a full-blown next-gen firewall UTM and web security into the same platform as the SD-WAN\nfunctionality. The issue for our clients isn\u2019t so much the on-premise\ntraffic; all SD-WAN vendors encrypt traffic on-premise at the highest\nstandards.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Philip\nGriffiths, Head of EMEA Partnerships, NetFoundry: \u201cWe are changing how the world connects their applications.\u201d Referring to Rik\u2019s examples\nhe added: \u201cSo a DevOps developer could create connectivity between their\nbranches, devices, containers, virtual machine environment \u2013 anything anywhere\n\u2013 using the public internet only\u2026 in minutes using APIs in a fully cloud-native approach.\u201d Delivering the security,\nperformance and reliability of fibre, over the public Internet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Peter Galvin, Chief Strategy and Marketing Officer, nCipher\nSecurity \u2013 a company offering a hardware security module for protecting\nbusiness critical applications and data for \u201cthings like digital payments, lift and shift\nto the cloud, encrypting information and protecting the\nkeys and hardware \u2013 allowing a very high level\nof assurance.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Aaron\nTurner, CEO &amp; Co-Founder, Hotshot Technologies: \u201ca security company that\nprovides the best security to protect the least sophisticated customers from\nthe most sophisticated attackers. We take the power of very high entropy\nencryption, combine it with the location services that are available, and help\npeople shift to a true zero trust model for messaging, collaboration and identity.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">&nbsp;<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">Jan Guldentops, Director, BA Test\nLabs: \u201cI have been playing around with security for 20 years, sometimes as a journalist, sometimes as a neutral consultant. What I would like to do today is take all these cool ideas,\nall the terminology and see what can be real and what are the problems\u201d.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Rik noted that the panel had four non-competing vendors, all\nwith different approaches. Of these, only nCipher would he classify as a \u201ctrue\nsecurity company\u201d because \u201cthe reason it exists is in order to secure stuff.\u201d The\nsame analyst\u2019s eye would describe Hotshot as \u201can application provider who\nhappens to provide secure applications, but it is in the business of certainly\nselling applications with security wrapped into them.\u201d Whereas \u201cNetFoundry is\nan application networking company which can, if it needs to, sell alongside an\nSD-WAN, but it can also sell independently as an alternative to SD-WAN\u201d. Then:\n\u201cYou could say that Versa are really wrapping security in from the outset into\nSD-WAN offerings. So, it\u2019s a little bit of a different thing. But they\u2019ve still\ngot &#8211; each got their own take on what are the great issues around cloud\nsecurity and equally, around network access and access control\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Starting with Jan Guldentops, who pointed out how people who\ncould not manage security used the cloud as an excuse: \u201cWe\u2019re going to\noutsource to the cloud as it\u2019s all secure and all the problems are gone. That\u2019s\nthe first misconception I see all the time. We are going to the cloud just to\nbe able to secure\u201d. He also reiterated Rik\u2019s point about the need for\ndesigned-in, rather than bolted on, security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Peter Galvin did not agree. For him the cloud driver was\nagility and reducing spending on data centers. But what was overlooked was the\ntop layer in Rik\u2019s Shared Responsibility: the need to protect one\u2019s own data.\nGuldentops reminded us that this protection was also a legal requirement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Phillip Griffiths pointed out that people were rushing to a\nfast-evolving cloud with legacy thinking: \u201cwhat we now see as wrong used to be\nbest practice.\u201d He criticized over-use of the term zero trust: \u201cyou can\u2019t be\nzero trust if you trust the network or the perimeter\u201d. Aaron Turner agreed\nabout dated ideas of a perimeter, then referred to the very recent <em>Verizon Data Breach Investigation Report<\/em>\nthat reported a doubling of the number of nation-state level attacks against\nsmall business: \u201chow\u2019s the average small business going to defend themselves\nagainst a nation-state adversary?\u201d Hence his company\u2019s emphasis on: \u201ca new\nsolution that helps those least sophisticated people protect themselves from\nthe most sophisticated adversaries\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The conversation moved to false expectations of perimeter\nfirewalls in a world where every single cloud connected device is now a\npotentially vulnerable endpoint. Again, a tendency to trust security to the\ncloud, the latest add-on, rather than seeing the need to design it in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Griffiths\nshifted the emphasis from trust to verify with: \u201cwe work with a three-letter\ngovernment agency\u2026 to access applications on the cloud,\nthey have to show five points of trust. They have to have a client on their laptop, they\nenter a password onto that laptop, they are wearing a watch with unspoofable\nhardware, they put their thumb on that watch to give biometric proof of trust\nand that watch also measures their EKG, so it can\u2019t all be done under duress.\u201d <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As\nthe team recovered form this paranoid bombshell, Guldentops reminded us: \u201cIf\nthe prize is big enough \u2013 I mean if the prize on the end of the hack is big\nenough \u2013 somebody will come up with something\u201d. Griffiths hit back with: \u201cIf\nyou\u2019re harder and more expensive to hack, people find another victim. It\u2019s\nabout having better shoes to run faster than other people when the bear comes along.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Time\nfor questions from the floor, beginning with Steve Broadhead \u2013 another long\nesteemed NetEvents gadfly. He could have been speaking for a world population\nof frustrated IT users \u2013 or should we say \u201csufferers\u201d \u2013 when he began: \u201cthe fundamental problem there is IT is supposed to make\nlife more simple and you\u2019re just painting this amazingly complex picture. I\u2019m just imagining my mother\nattempting to do what you\u2019ve just described!\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Griffiths\nwas quick to reassure us: \u201cBut at the other end of the scale, you can literally go on to our website, download a couple of\nendpoints, deploy into your cloud and, in five minutes, create a network. One of our customers connected\nseven AWS data centres in two hours the other day, while doing another job that implements multiple layers of security by design. So that\nyou take away many of these threat\nvectors such as DDos, man-in-the-middle et cetera\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hotshot\nmakes a point of securing the least sophisticated customers, so it was no\nsurprise that Turner came next with: \u201cWe try to make it so that a family or a\nsmall business can deploy nation-state level protections in 30 seconds or less\u2026\nso easy to use and so intuitive that you get that protection built in\u201d. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before\nNetFoundry and Versa could get their word in, Broadhead acknowledged their\nofferings, adding: \u201cWhat you\u2019re doing is fine; the problem is when it gets to\nthe customer, they often make a mockery of what you\u2019re trying to do by adding\nbells and whistles. Like having a beautiful car designed for minimum wind\nresistance, and people put a roof rack on it, right?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Frazer\nfor Versa saw this as a key challenge, and distilled from it a definitive case\nfor automation: \u201cCapital One has a thousand sites. They use digital labour\ndelivered by Versa. It\u2019s all automated. We have the NSS labs, we\u2019re the only\nSD-WAN vendor that scored in the top vector of NSS labs rating. At some point,\nyou have to automate as many of these functions as you can, be able to reprogram as needed and set those\npolicies and have complete visibility on-premise through the cloud and back.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Griffiths\nhad an interesting example of a new cloud-native bank working towards an\nautomated blockchain trust mechanism: \u201cso that this electronic transaction with almost no humans involved\nin has legal bearing.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For\nthe final question: Antony Savvas, \u201cIT Europa and Data Economy, among others\u201d,\nlead to the room a very large elephant, namely \u201cThe US Cloud Act.\u201d He\nsuggested: \u201cWe might as well all\ngive up because,\nat the end of the day,\nif a US agency wants your data in Europe controlled by an\nAmerican company, it can have it. What are the security companies saying about this? I\u2019ve heard that companies should\nsimply encrypt their data and control the encryption keys. So, if a US vendor has to comply with the US Cloud Act, all it can do is potentially hand over encrypted data. What\ndoes the panel feel about this?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This\ngenerated quite a buzz of \u201cover-speaking\u201d from which Galvin from nCipher stood\nout with: \u201cMost of our customers are concerned about it. One of the reasons\nthey are encrypting data and managing the keys themselves is to protect\nthemselves from any subpoena activity. Not only the US government, but other\ngovernments have the right to ask for information and never even tell the\nperson that data is being taken. The only way you can really protect yourself\nfrom that is if you are encrypting the data and maintaining ownership of the keys.\nThey\u2019ll get encrypted\ndata, but they won\u2019t be able\nto read it.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Turner\nadded: \u201cThe first question\nwe ask to the General Counsel is, which laws do you\nwant to comply with\u2026 because you\ncan\u2019t comply with them all. You can\u2019t comply with US Cloud Act and GDPR and the\nChinese data encryption law and UK encryption law. You have to do the risk\nanalysis to trickle-down: so I\u2019m willing to run the risk of not complying with\nthe Chinese encryption law and I\u2019ll run the risk of not complying with UK, and\nso on\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Just\nin case there was anyone left still feeling secure, Guldentops cut in with:\n\u201cThere is one thing worse than not using encryption \u2013 using bad encryption \u2013\nI\u2019ve seen that quite a lot. There\u2019s another problem: what is unbreakable encryption today will not be\nunbreakable in five years. In a cloud perspective that\u2019s potentially the worst: because\nyour data stays there potentially and could be decrypted\nwithin two, three, four years.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The\naudience came to discover security. They went away with the wisdom of\nexperience as distilled by Guldentops: \u201cPeople will stay stupid. I mean it\u2019s\nthe same thing with DevOps; am I the only guy who\u2019s scared giving software\nengineers control over infrastructure? I used to coin the phrase \u2018it\u2019s not\nDevOps, it\u2019s DevFlops\u2019. It\u2019s scary. It\u2019s a brave new world and we\u2019ll have to\nlearn to live with it.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"text-align:center\"><em>The <\/em><a href=\"https:\/\/www.netevents.org\/wp-content\/uploads\/2019\/01\/Debate-III-Enterprise-Security-Considerations-for-the-Cloud-Ovum-final.pdf\"><em>full transcript of this session<\/em><\/a><em> is available now.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The world is growing so weary of all those malware massacres in the Internet Wild West, that security is beginning to feel quite sexy. <\/p>\n","protected":false},"author":7,"featured_media":35531,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[107,148,1923,857,1130],"class_list":["post-35525","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions","tag-cloud","tag-cloud-computing","tag-cloud-security","tag-cloud-services","tag-cloud-technology"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/35525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=35525"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/35525\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/35531"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=35525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=35525"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=35525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}