data security for cloud computingcdn.ttgtmedia.com › rms › editorial › rich mogull_data...

37
events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC @rmogull Data Security for Cloud Computing

Upload: others

Post on 04-Jul-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

events.techtarget.com

Rich Mogull, Analyst & CEO, Securosis, LLC

@rmogull

Data Security for

Cloud Computing

Page 2: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

To Steal a Data Center

Old School Cloud School

Page 3: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC
Page 4: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

How

Clouds

Store Data

Page 5: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Cloud Data Architectures

Abstraction/Management

Compute Instances

IaaS

PaaS

SaaS

Page 6: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Cloud vs. Trad

● Pooled physical storage

● Management by API

● Slower read/write, faster

snapshot/migration

● Multitenancy

Page 7: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Data

Dispersion

Photo by richiejarvisuk - http://flic.kr/p/7azb6u

Page 8: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

The

Pragmatic

Process

Page 9: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC
Page 10: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Assess

Page 11: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC
Page 12: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Manage

Cloud

Migrations

Page 13: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC
Page 14: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Secure

Transfers

Page 15: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Encryption

● Link/Network

● Client/Application

● Proxy

Photo by mbrand - http://flic.kr/p/61DP51

Page 16: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Encrypt

Page 17: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Encryption Matrix

Components Locations

Page 18: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Encryption Layers

Page 19: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Instance-Managed

Instance

Key Management

Encryption Engine Storage Volume

Page 20: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

External Key Management

Key Mgmt Server

Storage Instance

Crypto

Client

HSM, SECaaS, VM, or Server

Public/Private Cloud (IaaS)

Page 21: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Proxy

(Proxy)

Page 22: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

How to Choose

● Instance is easiest. Built into most operating systems.

● External more secure/flexible; easy to tie to existing

infrastructure. Go with agent-based.

● Proxy for databases and more-complex storage

situations.

Page 23: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Encrypting Object Storage

• File/Folder

• Client/Application

• Proxy

Page 24: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Object Storage Controllers

Container Container Container

Cloud Storage Gateway

Datacenter

Cloud

Server/Workst

ation

Server/Workst

ation

API

API

Page 25: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

How to Choose

● Try to find storage services that support encryption in the

client.

● Use file/folder for public cloud object storage (e.g.

DropBox, box.net, S3), or when extra protection needed

in private cloud.

● Consider proxy for server-to-object sync.

Page 26: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Encrypting PaaS/SaaS

SaaS

PaaS

Page 27: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Tokenization

Page 28: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

How to Choose

● PaaS is freaking hard to get right. Code into your

application if you can. Use a proxy if you can’t. Watch the

key management.

● Prefer a SaaS provider you trust.

● Proxy (encryption or tokenization) for SaaS if you have to,

but keep it simple.

Page 29: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Application Encryption Architecture

Page 30: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Monitor

Page 31: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Content Discovery

● DLP

● DAM

● Cloud awareness and

limitations

Photo by ...-Wink-... - http://flic.kr/p/6hTHYH

Page 32: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Data Loss Prevention

● Agent or hypervisor-based for

private cloud.

● Good for content discovery, less

good for in-cloud monitoring.

● SaaS for discovery should be

available soon.

Page 33: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Database Activity Monitoring

● Must be agent based.

● Physical server okay for

private, not good for

public.

● Virtual appliance for

public.

● Watch that performance.

Page 34: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Digital Rights Management?

● Maybe for consumer.

● Enterprise DRM complex beyond

workgroups, never mind cloud.

● It will happen... maybe in 5-10

years.

Page 35: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

What We Skipped

● Hardening the management plane.

● Internal segregations for private cloud.

● Authentication and Authorization.

● All the little details- encrypting an IaaS volume is

easy; encrypting a distributed cloud application is

hard.

● The future.

Page 36: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

What to Do

● Control data migrations with DLP, DAM, and FAM.

● Use the lifecycle to define your controls.

● Spend most of your cloud data security time on getting

encryption right.

Page 37: Data Security for Cloud Computingcdn.ttgtmedia.com › rms › editorial › Rich Mogull_Data Decurity for Cl… · events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC

Thank You!

●Rich Mogull

●Analyst/CEO

●nexus.securosis.com

[email protected]

●@rmogull