{"id":2468,"date":"2016-12-19T00:00:00","date_gmt":"2016-12-19T00:00:00","guid":{"rendered":""},"modified":"2017-06-01T14:03:59","modified_gmt":"2017-06-01T14:03:59","slug":"what-does-cloud-mean-enterprise-security-perimeters","status":"publish","type":"post","link":"https:\/\/cazenasite.com\/?p=2468","title":{"rendered":"What does the cloud mean for enterprise security perimeters?"},"content":{"rendered":"<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2016\/12\/security blog.jpg\" style=\"float: right; max-width: 320px; margin-left: 10px;\"\/><\/p>\n<p>In the past, protecting and securing enterprise data was simpler\u2014handled mainly through the use of basic perimeter-based devices like firewalls and intrusion protection services. As more and more enterprises now look to migrate or augment their big data clusters with the cloud, the amount of access points to their data continues to exponentially increase. For the modern enterprise, perimeters are almost gone. Thorough security and compliance measures for this newly distributed data are now a top priority for CISOs and security teams, well-covered in several recent articles around the web. Here are the common themes, along with some tips on how enterprises can adapt quickly to enable public cloud benefits while minimizing corporate risk.<\/p>\n<p><strong>Cloud\u2019s Faulty Security Reputation<\/strong><br \/>\nAlong with the public cloud\u2019s benefits and potential risks comes concern about security vulnerabilities. Our 2014 cloud survey with <u><a href=\"https:\/\/gigaom.com\/report\/how-enterprises-will-use-the-cloud-for-big-data-analytics\/\" target=\"_blank\">GigaOm found<\/a><\/u> that 63% of companies were most concerned with security and breaches as barriers to cloud usage. This concern was understandable, with the multitude of potentially disastrous data breaches being exposed in recent years. Yet the blame for these vulnerabilities is often wrongly placed on the cloud providers\u2014lending to the flawed reputation of inadequate cloud security. <u><a href=\"http:\/\/www.gartner.com\/newsroom\/id\/3143718\" target=\"_blank\">Gartner investigated<\/a><\/u> this misplaced blame among cloud security incidents, and found that a small percentage of them were actually the cloud provider\u2019s fault. The study predicts that through 2020, 95% of cloud security failures will be the fault of the customers \u2013 not cloud providers.&nbsp;<\/p>\n<p><strong>Confidence in Public Cloud Grows<\/strong><br \/>\nIn Prat Moghe\u2019s TNW article <u><a href=\"http:\/\/thenextweb.com\/insider\/2016\/04\/12\/6-challenges-cloud-overcome\/#gref\" target=\"_blank\">6 hidden challenges of using the cloud for big data<\/a><\/u> he dives deeper into the idea of human mismanagement in cloud, affirming that experts agree on cloud providers being the most secure they ever have been\u2014more secure than on-premises data centers with cloud offerings like AWS and Azure. Even the most security-conscious industries like financial services and healthcare have begun utilizing the public cloud. A 2016 <u><a href=\"https:\/\/www.rightscale.com\/lp\/state-of-the-cloud\" target=\"_blank\">RightScale survey<\/a><\/u> found a divergence, or perhaps evolution, in cloud opinion from our 2014 GigaOm study, showing that a \u2018lack of resources\/expertise\u2019 had replaced security as the biggest challenge with cloud. The modern cloud climate lends itself to the notion that issues with cloud security can often be chalked up to results of inconsistent use or poorly-defined policies.<\/p>\n<p><strong>The Next Challenge: Integrating the Enterprise Cloud<\/strong><br \/>\nAnother new challenge that enterprises must address, along with secure user management, is the integration of cloud resources with existing on-premises data infrastructure. Integration is important to avoid data silos\u2014where stand-alone repositories of data become isolated and create barriers for enterprise agility and decision-making. At Equifax, for example, CISO Susan Mauldin and her team treat the cloud as another enterprise asset to be secured. This means that up-to-date patches and compliance certifications must be maintained, and vulnerability assessments and penetration tests should be regular.<\/p>\n<p><strong>Enterprise Cloud Checklist<\/strong><br \/>\nIn observing how enterprises have approached these challenges, a few common tips emerge for locking down the cloud:&nbsp;<\/p>\n<p class=\"rteindent1\">\u2022&nbsp;&nbsp; &nbsp;Data should be encrypted both at-rest, through an HSM-based key management \u2013and in-motion, with either IPSEC or SSL depending on the enterprise\u2019s firewall configuration.<br \/>\n\u2022&nbsp;&nbsp; &nbsp;A security gateway or dedicated VPN tunnel should be in place to block all external cloud access from outside of the enterprise.<br \/>\n\u2022&nbsp;&nbsp; &nbsp;Role-based access controls should be layered on the cloud to define authentication and restrict any unauthorized activity or access.<br \/>\n\u2022&nbsp;&nbsp; &nbsp;A mobile data management plan should be in place and account for emergency situations of theft or loss.<br \/>\n\u2022&nbsp;&nbsp; &nbsp;Finally, all data in the cloud should be logged, audited and tracked to allow for organized inventory and security monitoring and alerting. The logs should be normalized across data services, and all events should integrate with the SIEM environment.&nbsp;<\/p>\n<p><strong>Your Enterprise\u2019s Path to Success<\/strong><br \/>\nTo establish and implement these policies is a large feat for enterprises. It may become necessary to invest in resources or new skills to bridge the security gap, and more intelligently wield the wide array of security tools that cloud providers offer. But with careful assessment, your IT security team can conquer these challenges and safely leverage cloud platforms.<\/p>\n<p>For more information on the comprehensive security provided by Cazena\u2019s managed Big Data as a Service, please <a href=\"mailto:testdrive@cazena.com\" target=\"_blank\"><u>contact us<\/u><\/a> today.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the past, protecting and securing enterprise data was simpler\u2014handled mainly through the use of basic perimeter-based devices like firewalls and intrusion protection services. As more and more enterprises now look to migrate or augment their big data clusters with the cloud, the amount of access points to their data continues to exponentially increase. For [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[46],"class_list":["post-2468","post","type-post","status-publish","format-standard","hentry","category-blog","tag-technical"],"_links":{"self":[{"href":"https:\/\/cazenasite.com\/index.php?rest_route=\/wp\/v2\/posts\/2468","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cazenasite.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cazenasite.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cazenasite.com\/index.php?rest_route=\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/cazenasite.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2468"}],"version-history":[{"count":0,"href":"https:\/\/cazenasite.com\/index.php?rest_route=\/wp\/v2\/posts\/2468\/revisions"}],"wp:attachment":[{"href":"https:\/\/cazenasite.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2468"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cazenasite.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2468"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cazenasite.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2468"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}