Public Cloud Security Is A Conundrum

Ten years ago this week, Gartner released Assessing the Security Risks of Cloud Computing. Although several research notes in 2007 discussing SaaS security, the 2008 note co-authored by Jay Heiser and Mark Nicolett was Gartner’s first research using the term ‘Cloud Security’.

Unsurprisingly for a new domain, we had more to say about the hypothetical risks associated with the public cloud than we had to say about the specifics of managing those risks.

Most of the advice was generic, including bromides such as “Organisations that have IT risk assessment capabilities and controls for externally sourced services should apply them to the appropriate aspects of cloud computing.”

Captain Obvious couldn’t have said it better. That lack of specificity was representative of the conundrum that continues to frustrate the IT world: the cloud is just like traditional forms of computing, except that everything is different.

Our 2008 research highlighted 4 key findings that have remained significant considerations for the use of public cloud computing:

Finding 1: The most practical way to evaluate the risks associated with using a service in the cloud is to get a third party to do it.

Formal 3rd party evaluations (ISO 27001, SOC2, FedRAMP) are the only scalable way to provide a useful level of assurance on cloud provider security. Unfortunately, it still remains the case that only a small percentage of cloud service providers have undergone one. ‘How do we evaluate the security of CSPs’ remains my most frequent inquiry topic.

Finding 2: Cloud-computing IT risks in areas such as data segregation, data privacy, privileged user access, service provider viability, availability and recovery should be assessed like any other externally provided service.

In practice, the segregation of data between customers has not proven to be a significant problem, but the relative lack of transparency around the associated CSP technical and process controls remains a typical area of customer concern. There have been a number of small CSPs that have gone bankrupt, so vendor business viability remains a uniquely difficult aspect of cloud risk management, but in most cases, the providers have been so small that their loss was barely noticed by the enterprise. CSP incidents resulting in permanent data loss do occur, but are relatively infrequent.

Finding 3: Location independence and the possibility of service provider “subcontracting” result in IT risks, legal issues and compliance issues that are unique to cloud computing. Increasingly strict privacy regimes, and the dominance of the cloud services market by US-owned CSPs, has made data location a growing concern.

Today, new global norms for privacy or government data discovery look less likely than ever. The ‘chain of service provider’ model continues to grow in significance. The risks have mostly been sustainable, but it remains an area of ambiguity that would benefit from greater formalization on risk assessment and shared responsibility.

Finding 4: If your business managers are making unauthorized use of external computing services, then they are circumventing corporate security policies and creating unrecognised and unmanaged information-related risks. At one point, a significant minority of Gartner clients had policies that banned the use of unapproved external services.

The rapid shift in software delivery from a licensing to a servicing model made this unsustainable, and many IT leaders flip flopped, seemingly totally washing their hands of any responsibility for the implications of shadow IT. The number and significance of cloud services, especially SaaS, has exploded over the last 10 years.

Several Cloud Application Security Broker (CASB) vendors provide reliable evidence that most organisations improperly expose large amounts of sensitive data in the public cloud, not because the cloud services are ‘insecure’, but because they are being used insecurely.

CSPs normally do not emphasise the boring and unglamorous aspects of digital operations (indeed, a strong case can be made that most cloud services are marketed as a way to circumvent the IT department). Most cloud use scenarios remain a tacit agreement between the provider and customer to avoid awkward questions about user activity and responsibility.

As public cloud increasingly becomes the default model for software vendor delivery, and hosts a growing share of whatever computing is still left ‘in house’, it remains a marvelously ambiguous topic.

In the previous decade, recognizing the inherent difficulty in definitely pronouncing a cloud service provider as being ‘secure’, we began speculating on a philosophical question: if public cloud experiences relatively few failures, will people eventually come to trust the delivery model, even if they don’t have causal evidence?

Under what circumstances would the default assumption flip to ‘secure’. It took us until 2015 to declare “Clouds Are Secure”, subtitling that research ‘are you using them securely?’ The caveat about ‘secure use’ remains our most important finding.

Awkwardly, organisations that undertake heroic levels of CSP risk assessment effort fail to demonstrate a significant difference in experience in comparison to organizations that barely bother.

This is not saying that you can always take CSP security for granted, but it is difficult to escape the conclusion that many enterprises would be better served by spending more time on the things they can control, instead of trying to manage the things they cannot.

Most cloud security incidents involve avoidable customer misuse of the cloud service. Likewise, cloud service providers do a relatively good job of meeting their Service Level Agreements, but their customers often fail to take full advantage of configurable or optional resiliency mechanisms.

The best practice for safe use of cloud computing is not the crafting of the ultimate questionnaire, it’s the knowing how to use it appropriately.

This is the message - that responsibility is shared between provider and customer.

Ten years of focused research has reinforced Gartner’s observation that while public cloud is very much like traditional computing in the abstract, countless practices have changed in significance and form.

It has proven a secure and reliable starting place for computing, with overall low levels of failure. Keeping it that way requires the will to do so, though, and the IT community continues to refine its understanding of ‘how to use it appropriately.’

Information-Management:

You Might Also Read: 

How Cloud Computing Changes Data Governance Strategies:

The Cloud Is A Key To Cyber Defence:

 

« Social Media Giants Under Caution In Vietnam
Healthcare Cyber-Attacks Still Going Up »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

CyberDefenses

CyberDefenses

CyberDefenses services combine best-in-class cybersecurity oversight, managed services and training to help our clients truly address their cybersecurity challenges.

Zentek Digital Investigations

Zentek Digital Investigations

Zentek has been providing digital forensics services to the public and private sector for computers and mobile devices since 2004.

Radisys

Radisys

Radisys offers software, products, integrated systems, and professional services for communication service providers and telecom solution vendors.

Centrify

Centrify

Centrify’s Next-Gen Access is an identity & access management solution that uniquely converges Identity-as-a-Service, enterprise mobility management and privileged access management.

ATSEC Information Security

ATSEC Information Security

ATSEC is an independent, privately-owned company that focuses on providing laboratory and consulting services for information security.

Wolfpack Information Risk

Wolfpack Information Risk

Wolfpack specialise in information and cyber threat management covering the full spectrum of prevention, detection, incident response and business resilience capabilities.

Blake, Cassels & Graydon (Blakes)

Blake, Cassels & Graydon (Blakes)

Blakes is one of Canada’s top business law firms serving national and international clients in specialist areas including cyber security.

Zen360Consult

Zen360Consult

Zen360Consult provides Advisory and Training services in the field of Cyber Resilience, which includes Cyber Security /ISMS and Business Continuity.

Secure Code Warrior

Secure Code Warrior

Secure your code from the start with gamified, scalable online secure coding training for software developers.

VIQU Recruitment

VIQU Recruitment

VIQU Recruitment was formed with the primary focus of providing 'Smarter People Solutions' to the UK’s professional IT & Cyber Security markets.

HunCERT

HunCERT

HunCERT's mission is to assist Hungarian Internet Service Providers in applying appropriate procedures to address the risks of computer network incidents and to respond to such incidents.

Redhorse

Redhorse

Redhorse provides top-tier consulting to help clients address mission-critical government problems in National Security, Networking Technology, Energy and the Environment.

Quad9 Foundation

Quad9 Foundation

Quad9 is a free security solution that uses DNS to protect your system against the most common cyber threats. It improves your system's performance, plus, it preserves and protects your privacy.

Virtual Infosec Africa (VIA)

Virtual Infosec Africa (VIA)

Virtual InfoSec Africa (VIA) is a wholly-owned Ghanaian company specializing in information security and cybersecurity solutions and services.

Mitigo Group

Mitigo Group

Mitigo offers a well considered and effective approach to keeping businesses completely secure from any digital attacks.

Ever Nimble

Ever Nimble

Ever Nimble are award-winning experts in IT support, cybersecurity, and cloud technology. Our proactive approach will enhance your security and protect you from cyber security threats.