Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud Security

12/26/2017
08:55 AM
Curtis Franklin
Curtis Franklin
Curt Franklin
50%
50%

Cloud Security Is a Shared Responsibility

In the answer to a question from a recent webinar, editor Curtis Franklin looks at who's responsible for data security in the cloud.

Here at Security Now, webinars are interactive affairs. In our most recent webinar, we had some great questions, including a couple that we couldn't answer in the time allowed. Here's the first of the questions along with our answer for everyone in the community to see.

In our Look Forward to CyberSecurity in 2018, Gary asked:

If we are going to move more critical applications and the data accessed, produced and stored -- will encryption capabilities become critical? And would anyone really outsource this function to AWS? Many people think AWS and Azure are taking responsibility for your apps and data when you move them to the cloud -- are they really going to "add this" via their service offerings?

The question of who takes responsibility for your applications and data is a critical issue when moving to a cloud infrastructure. Cloud providers have tried to bring some discipline to the question of who's responsible for what through the shared responsibility model of security. Stated most succinctly, this states that the cloud provider is responsible for the security of the cloud infrastructure (including the services and applications they're contracted to provide) while the customer is responsible for the security of the data that runs through the infrastructure.

Amazon was the first major cloud provider to publish a formal statement of their policy on AWS. Their language draws a distinction between the security of the cloud and the security of what's in the cloud. It's a useful distinction that helps clarify the pieces that fall under each definition.

Image: Amazon AWS
Image: Amazon AWS

Of course, Amazon has not been alone in drawing the distinction: Microsoft has also released information on the shared security model as applied to Azure. Google also has a paper explaining their security model, though it goes into more detail on the tools they provide to help customers with their responsibilities.

When you strip away all the explanations and jargon, the lesson to be learned in all of these papers and posts is that going to the cloud doesn't mean that you can forget about security. No cloud provider is stepping up to assume responsibility for your data's security -- that's still your job.

The fact that it's your job means that you may need to bring new tools and strategies to bear on data that no longer lives within the cozy confines of your network boundary. These tools, which range from micro-segmentation to CASB, should be deployed in consultation with your cloud provider so that you're certain neither of you is stepping on the other's toes in the name of security.

If you're interested in the other questions and answers from the webinar, as well as the editors' takes on the stories we're likely to be talking about in 2018, it's not too late to listen to the webinar. You've got time to ask your own questions, too -- just leave them as comments to this article or the next article answering questions from the event. And keep your eyes open for our next editorial webinar, coming to Security Now in January 2018!

Related posts:

— Curtis Franklin is the editor of SecurityNow.com. Follow him on Twitter @kg4gwa.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Edge-DRsplash-10-edge-articles
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
News
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Commentary
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-33033
PUBLISHED: 2021-05-14
The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled, aka CID-ad5d07f4a9cd. This leads to writing an arbitrary value.
CVE-2021-33034
PUBLISHED: 2021-05-14
In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.
CVE-2019-25044
PUBLISHED: 2021-05-14
The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs and blk_cleanup_queue.
CVE-2020-24119
PUBLISHED: 2021-05-14
A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
CVE-2020-27833
PUBLISHED: 2021-05-14
A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw container image (.tar file) which contains symbolic links. The vulnerability is limited to the command `oc image extract`. If a symbolic link is first c...