Would-be and existing customers must understand that security isn't set-and-forget just because it resides in the cloud.
September 23, 2016
By now, the pitch for cloud-based services is familiar to anyone in IT: They're cheaper, more efficient, and will free up in-house infosec professionals for more value-added tasks (yes, everyone's really going to miss reviewing log management data).
The promises of highly automated functionality and trouble-free operations may be slightly overstated, at least where cloud-based security is concerned. But most infosec professionals are already masters of due diligence, and cloud is like any other external service provider: seasoned security pros know to ask a lot of questions, perform their own testing and audits, and get customer references for the real skinny on how cloud-based security goes.
Smart, reputable cloud service providers will encourage/require customers to undertake many of these steps we outline here, and then some. But it should be noted any time a provider balks at being transparent or at providing greater levels of access and discovery. The partnership nature of cloud is inherent when it's essentially an outsourced service; for something as strategic as security, customers are going to want lots of disclosure and trust upfront.
Whether you're entertaining cloud security or are already a customer, here are some basic ways that these third-party services change the ways infosec professionals have traditionally conducted themselves. The list is by no means exhaustive. And if we've missed something egregious, leave us a note in the comments section below! Let's make this a multi-party dialog.
About the Author(s)
You May Also Like
Guarding the Cloud: Top 5 Cloud Security Hacks and How You Can Avoid Them
April 4, 2024Cybersecurity Strategies for Small and Med Sized Businesses
April 11, 2024Defending Against Today's Threat Landscape with MDR
April 18, 2024Securing Code in the Age of AI
April 24, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024Black Hat Asia - April 16-19 - Learn More
April 16, 2024