TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
News Archive

Risk In The Cloud

by Msecadm4921

Mike Small, pictured, a member of London Chapter ISACA Security Advisory Group, writes of managing risk in the Cloud. Adopting Cloud computing may save money, but how does it change risk?

The Cloud allows the procurement of IT services from both internal and external suppliers to be optimised because the services are delivered through the Internet in a standard way. The Cloud is not a single model, but covers a wide spectrum from applications shared between multiple tenants to virtual servers used by one customer and hosted internally.

The key benefit of a Cloud approach is one of scale; the Cloud provider can potentially offer a better service at a lower cost because the scale of their operation means they can afford the skilled people and technology necessary to deliver a secure service. In general, a large Cloud provider is likely to provide a better and more secure IT service at a lower cost than a small to medium sized enterprise could provide itself.

While the public Cloud offers applications shared by multiple customers, the private Cloud provides applications and infrastructure that are dedicated to a particular organisation. It allows organisations to out-source the management of their IT infrastructure while retaining tighter control over the location and management of the resources. The price to pay for this is that the costs are likely to be higher than for a public Cloud because there is less potential for economy of scale, and resilience may be lower because of the limit on service resources available.

The information security risk associated with Cloud computing depend on both the service model and the delivery model adopted. The specific risks depend on the organisation and their individual requirements. The common security concerns across this spectrum are ensuring the confidentiality, integrity and availability of the services and data delivered through the Cloud.

The approach to managing risks from the perspective of the Cloud service user is one of due diligence?ensuring that the requirements are clearly understood, the risks are assessed, the right questions are asked and the appropriate controls are included in the service level agreements.
The principal information security related issues that organisations adopting Cloud computing need to address are summarised below. Because of the wide spectrum covered by the Cloud, their priority will depend on the Cloud model adopted and the individual circumstances:

โ€ขEase of Purchase: Anyone can buy access using a credit card. Your organisation may already be using a Cloud service without a proper assessment of the risk.
โ€ขService Contracts: Those offered by Cloud providers are often โ€œtake it or leave itโ€ and may contain less onerous obligations on the provider than a normal SLA. Key issues include: who owns the data, and how difficult would it be for you to get it back?
โ€ขCompliance: Identify the business requirements for compliance with laws and regulations and ensure that the Cloud provider is able to answer how they will meet these needs.
โ€ขService Location: Identify the legal issues that relate to the jurisdiction of the geographic location of the Cloud provider, the service and the data, and ensure that service contracts address these issues.
โ€ขData Security: Identify and classify the business data that is involved and specify the security requirements for this data in terms of confidentiality, integrity and availability.
โ€ขAvailability: Identify the service availability requirements and assure that the provider is capable of meeting these.
โ€ขIdentity and Access Management: Specify the business needs for identity management and access control and assure that it will be delivered securely.
โ€ขInsider Abuse of Privilege: Confirm that the Cloud service provider has processes and technology to properly control privileged access.
โ€ขInternet Threats: Determine the level of protection needed against Internet-based threats and ensure they the steps to be taken both by the Cloud provider and internally are adequate.
โ€ขMonitor: Within the Cloud service, meet the business and legal requirements of the client while separating the data relating to different clients.
Taking a good governance approach, such as COBIT , is the key to safely embracing the Cloud and the benefits that it provides. COBIT provides guidance to:
โ€ขIdentify the business requirements for the Cloud-based solution. This seems obvious but many organisations are using the Cloud without knowing it.
โ€ขDetermine if the functionality is currently provided by an existing internal service. If so what are the options?
โ€ขDetermine the governance needs based on the business requirements. Some applications will be more business critical than others.
โ€ขDevelop scenarios to understand the security threats and weaknesses. Use these to determine the risk response in terms of requirements for controls and questions to be answered. Risk IT: Based on COBIT provides an ideal framework for this.
โ€ขUnderstand what the accreditations and audit reports offered by the Cloud provider mean and actually cover.
Cloud computing can reduce costs by providing alternative models for the procurement and delivery of IT services. Many organizations have already adopted an outsourcing approach to internal functions that are not core and this approach naturally extends to IT. However, they need to consider the risks involved in a move to the Cloud and good governance provides a way for this. For more information, visit www.isaca.org/cloud for the free ISACA white paper on cloud.

About the author

Mike Small is a member of London Chapter ISACA Security Advisory Group and a Fellow of the BCS and a Senior Analyst at KuppingerCole. Until 2009, Small worked for CA where he developed CAโ€™s identity and access management product strategy. He is a speaker at IT security events around EMEA, including ISACAโ€™s Information Security and Risk Management (ISRM) Conference in Barcelona, Spain, in November, where he will lead a Cloud Security Workshop. E-mail: Mike.Small@kuppingercole.com