Traditionally, cloud has been seen as having major security vulnerabilities. Is it now possible to ensure that corporate and customer data is protected when used over public and private cloud services? What new security policies and architectures actually take advantage of cloud delivery in order to increase the levels of security?
Contributor
Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Summary
The value proposition of cloud is becoming too great for organizations to ignore, and rather than continually having CISOs sit on their hands and complain about security challenges related to cloud, practitioners must figure out a way to take advantage of cloud’s capabilities.
Traditional controls and old security measures are no longer effective in the present security environment, be it within an internal infrastructure or on the cloud. This requires prioritizing where new risks lie and what needs to be protected. Second, the difference between external and internal environments doesn’t exist any longer.
Considering these items, the issue revolves not around security but around risk. The benefits of the cloud must be weighed against the risk of putting certain data into a cloud environment. Start with the risk profile of the workload you’re trying to move, then decide what is the most effective destination.
An internal cloud, a hybrid cloud or a public cloud, each comes with their own benefits and trade-offs, and a large enough company can conceivably find use cases to operate in all three. In some cases, placing data in a public cloud may be just as safe as hosting internally. The ideal middle ground however may be a virtual private cloud, one that allows you to control the ingress and egress points back into your environment.
Performing this due diligence will cause many CISOs to rethink their approaches to security and may even result in some traditional principles to become outdated. But this new cloud-based security model has room for growth yet, including APT protection and receiving more control and solutions from cloud vendors overall.
Explore More
-
- Cloud Security as a Shared Responsibility
- Controlling Cloud Security Through Continuous Visibility
- Cloud Security Wish List
- Cloud Suitability and Transformation
- Roundup: Cyber Security Month
- Stronger Security with Big Data
- ‘Cloud Reimagined’ : Exploring New Ideas Behind Cloud Computing
- Part 3 Cloud Computing Service Level Agreements (SLA)
Transcript
Sanjog Aul:
Welcome listeners. This is Sanjog all, your host and the topic for today’s conversation is Cloud Enabled Security and I have with me Larry Biagini. Larry is the Chief Technology and Security Officer for GE. Good morning Larry, how are you?
Larry Biagini:
Good, how are you? Very good.
Sanjog Aul:
Thank you for joining us. Now there have been a lot of complaints and fears about the security of cloud, but for the purpose of this segment we wanted to turn that idea on its head and find out what it would require to take advantage of cloud delivery and so that we could actually increase our enterprise security. So to that, the first question I have for you, Larry, is that there must be some common denominators when we look at when we try to explore securing an on premise infrastructure and or applications compared to their cloud. So what are those?
Larry Biagini:
First of all, I think you’re to ask the question to turn it on its head because there are some common denominators. The first and most important I think is that things that we’ve done in the past for security, both internally and externally or in this case cloud, don’t work in this environment and haven’t worked for a while. So the common denominators really are you need to prioritize where your risks are, understand who would like to exploit those risks, understand what you can do to mitigate or lower the probability of those risks being exploited, and then deploy the correct controls depending on the environment that you’re in, because none of the general controls for the most part that we’ve used in the past at the network perimeter, for instance, are really effective in this environment, either for internal infrastructure or for cloud infrastructure. So we have to get very specific about what is it you’re trying to protect, why are you trying to protect it, who’s interested in it, and then put the controls around it, make that data or that information or that process as protected as it needs to be, but also put in good infinite response, put in good tape detection capability and good communications policies when things go wrong, if in fact they do go wrong.
Sanjog Aul:
And I’m sure that when you go about living your role and many others in the industry, they always try to see everything remaining equal. Which environment is inherently better equipped to track vulnerabilities, perhaps manage point of failure, handle breaches, and perform all other measures expected of a secure infrastructure. So where are you seeing the trend going? Do you think that cloud is becoming a favorite because it is new and it is basically breaking the old molds of how you used to handle things earlier?
Larry Biagini:
I think cloud is gaining traction because Just the value proposition of using cloud computing is too much to ignore. So the struggle or the thing that our security organizations have to do is figure out a way to take advantage of that. When you think about what’s more secure, internal or external, I actually don’t think that’s the question because there really isn’t a lot of difference between internal and external anymore, at least for large companies, because they have a connected supply chain, they’re connected to their customers. I think one big difference is on internal network versus cloud, you do have the capability, if you exploit it, to get better visibility, because you understand the infrastructure, you understand the administrative processes that are used, and you just get a better look at it, because where all the pieces are, at least where most of the pieces are in the cloud, you have to depend on process for that. You have to depend on cloud providers to provide you with logs and things like that. You may have to do a deeper level of analysis than you would in your own environment.
Sanjog Aul:
So would you say that in the new cloud environment you’re becoming just more cautious, more vigilant on what you’re doing and since you’re running it by process and not just hoping that one of your employees of your company who’s handling security or handling any of these infrastructure assets are going to work properly or not, do you think in that sense, do you think the cloud infrastructure inherently is pointing you towards becoming more secure and be more vigilant and be more responsible?
Larry Biagini:
I don’t think it’s a matter of degrees whether it’s more secure or not. I think it’s, again, I go back to, it’s a matter of risk. The benefits that you get from the cloud have to be weighed against the risk that you take for having that data exposed to that process exposed in a multi tenant environment or in a single tenant environment, you have some other options, but how you deploy in the cloud is really going to be dependent upon what your risk appetite is for the given workload that you’re talking about. Not all things we even we would think about putting in the cloud because if you think of our most important intellectual property or something that we really believe to be a competitive advantage, we probably would put very strong controls around that, or we have put very strong controls around that and keep that internal just because it’s something that we think that we can protect better and that we have an obligation to protect better because it’s so important to us. Other things that may not be as important or that we don’t need, that we can’t afford to protect at that level. We would just make a risk based decision on where’s the best place to run the workload in the cloud or internally.
Sanjog Aul:
So even if you take the different flavors of clouds that exist, which could be virtual private cloud or public cloud or a totally private cloud, do you think you could actually draw a comparison across these multiple environments and say a particular environment is better suited because of a specific type of risk mitigation it offers?
Larry Biagini:
Yes, I think that’s actually the way to look at it. I think it’s, you start with the risk profile of the workload that you’re trying to move, then you decide what’s the most effective destination for it, be it an internal cloud, be it a hybrid cloud or be it a public cloud, all of which come with different benefits, but also which come from all, all which have their own downside as well. So I sorry, go ahead.
Sanjog Aul:
So the question basically is that you mentioned like about across all three environments that we have. So would you say because when people talk about public cloud they just say my god, this is something which is not as secure. I mean that’s somehow it has been labeled over the years. When you talk about private, that means you’re going to carry too much baggage, too much capital outlay in terms of just building a private cloud. Do you think then the virtual private cloud becomes the best of both worlds?
Larry Biagini:
I think there’s a place even for a company like GE to operate in all three models of that cloud. For instance, if you think about the way that you do web based or customer based applications, putting them in a public cloud is probably not any less dangerous than putting them in our own DMZs. When you think about reach back into our environment, you may not want to put that in a public cloud, but you certainly could put it into a virtual private cloud because you can control the ingress points back into our environment. When you’re thinking about the data itself, you may not want to put that in a public cloud in a multi tenant environment, but you may want to very tightly control how the application that may exist in a public cloud reaches back into the internal enterprise to get the data that it needs to present for the given task that it’s trying to run.
Sanjog Aul:
Do you think that since we have actually explored some new horizons with this cloud as a computing paradigm, that when it’s arrived and over next number of years we have become a little more mature in understanding how it works, where all are its limitations? Do you think you can see, look at the hindsight being 2020 say that this journey has actually allowed us to build our overall enterprise to become more secure by leveraging whatever new innov. New ideas and thoughts that have been put into making cloud more secure has also kind of percolated into the on premise infrastructure and made Dax secure as well. So overall you can say you’re net positive.
Larry Biagini:
I think it’s caused us to think about security in a different manner where as before we used to think about security as long as it’s inside our four walls or inside our network, it’s relatively safe and things on the outside are relatively unsafe. When we started to understand cloud and we started to understand what the possibilities were, it caused us to relook at our own thinking and say what? There is very little network perimeter anymore. So any security model based on an inside versus outside perspective is probably invalid. So we started to rethink about it, and when we started to rethink about it, there are technologies that help us in both areas. There’s technologies around encryption, there’s technologies around key management, there’s also new technologies around identity management which is extremely important not only externally but internally, and if we start to base our security on those types of models or those types of technologies which don’t exist yet either for the enterprise or for the cloud, I think we’re going to be more secure.
Sanjog Aul:
Let’s take a quick break listeners. We’ll be back and explore what else is on the drawing board and what’s left to be desired towards the end goal of making the cloud more secure on premise or maybe leveraging whatever we have learned from cloud to implement an on premise, and all of this has to be looked at because while we have made great progress, but of course the CIS or the chief information security officers have a job and they’re very busy. So what are they busy doing? What are they trying to do in terms of helping become the people who are going to be catalysts to making the enterprise more secure? Please stay tuned. We’ll be back.
Larry Biagini:
HP is proud to sponsor this program.
Sanjog Aul:
Tap into our expertise, innovation and services
Larry Biagini:
to bring your most important workloads to the cloud. You are listening to CIO Talk Radio Viewpoint.
Sanjog Aul:
Welcome back. So Larry, what do you think is on the drawing board now that we have at least taken care of the basic infrastructure elements, how we are securing them and also what’s left to be desired, what’s not fully done yet. That’s why you’re not able to have your eight hour sleep every day.
Larry Biagini:
Good Question. I think the cloud providers have made a very good have made very good strides in differentiating themselves in different areas. Some of the public ones around orchestrating workloads, some of the private ones around visibility and building things like APT protection into their cloud offerings. I think they’ve done a pretty decent job of taking the existing technologies that are out there and then figuring out how to plug them into their own infrastructures. I think that’s what’s missing, and I know some folks are working on it, but I actually believe the enterprise has to have the ability to move workloads between clouds and there needs to be a layer that sort of is an abstraction layer to different cloud providers and we get to move workload around pretty much at will based on the differentiation in those backend clouds. I also think that there needs to be a much stronger identity management structure in place that supersedes any individual cloud provider because an enterprise can’t be expected to use its facebook id, for instance to log into our cloud provider applications, and then thirdly, I think encryption both at rest and in flight, needs to be strengthened, and by that, not the encryption algorithms themselves, but the control and the application usage of encrypted data.
Larry Biagini:
How much does the enterprise control? How much control does it have to give up to the cloud provider? Because if it has to give up all control of encrypted data to cloud providers, then we’re at the mercy of the processes within the cloud itself and we do lose some visibility.
Sanjog Aul:
Do you think that you raised some interesting points around the limitation where you cannot build bridge between the two cloud providers and being able to use the same authentication mechanism, et cetera, that you just mentioned? Do you think this is more of a competitive marketplace issue or people issue or policy issue versus a technology issue?
Larry Biagini:
I think it’s mostly a business issue, not a technology issue and, but it has to be. Somehow or another, we have to solve it because the current technologies like SAML and ping federated just don’t scale to the level that we need to scale. So somehow or another identity has got to be solved because it’s a tenet for security going forward. Once we lost the network parameter, identity became the new parameter, and if we, once you get that, we’re going to have a hell of a time trying to figure out what’s actually going on in the cloud environment.
Sanjog Aul:
Now, what do you think you’d like to see happen as evolution in the cloud infrastructure? No matter which flavor we are talking about virtual private, cloud private or public, which will allow you to make sure that you can say now we are at a point where we can take cloud as a role model or cloud security as a role model to elevate the overall security of an enterprise.
Larry Biagini:
I think one of the biggest things that we would like to see is the way that admin processes are handled within a cloud environment. The thought that nobody has the escalate privileges without a customer, for instance, agreeing that those privileges should be escalated because the fear of cloud is that there’s an insider threat within the cloud itself in addition to external threats, and so the more control the we have over who has access to what and visibility into when that access is used, the better we’ll feel that our information and our processes are secured.
Sanjog Aul:
Now, when you say that you want to as a CISO, always want to be able to stay confident as people come to you to say I want to put a solution in there for a business purpose and you want to be able to say with specific data points that this is why you have cloud as a better option to go with or you should take the on premise, do you think with the way the whole traditional model where it is, and I’m sure there’s some evolution that’s been done on the on premise as well, and then also cloud is going in its own direction, maybe at a much faster rate of evolution. Are you thinking that there’s going to be more clarity or it’s going to become even a difficult or a delicate decision to see which route you go?
Larry Biagini:
I think there’ll be more clarity. I actually think as we get more experience, as we understand what the workloads that we’re trying to move and the real risk versus the perceived risk, there’ll be more clarity, and again, I think it’s an education around the belief that being inside is more secure than being outside. That not being true for the most part. I think that education and just pure experience with moving applications out to the cloud will give us more clarity and it’ll become much more of a decision tree. If then else I can move to the cloud. If then else it depends. It should stay inside just because we don’t have appropriate mitigants in place for the risk.
Sanjog Aul:
So other fellow technology leaders and chief information security officers, what is your message or appeal to them? So that while we are still in this evolution phase and we are still trying to see how far we can take the security for both on premise and or cloud and how they can interplay what they should do in the interim so that the cloud still remains secure and they’re able to maximize whatever is available.
Larry Biagini:
I actually think that you have to. My recommendation would be think openly about it. There’s no way to prevent what’s happening in this space because the value proposition is just too great and the velocity of the improvements is just too great. So rather than say no to everything, understand again what is possible with today’s technology, what the technology is building in in the future and get your feet wet but just put your toe in the water, put some applications out there, understand what’s going on. Understanding that you may have to give up a little bit of control but that doesn’t mean that you have to give up a lot of security.
Sanjog Aul:
Once again thank you Larry for sharing your thoughts and insights in our viewpoint segment.
Larry Biagini:
Great. Thank you for having me.
Sanjog Aul:
Thank you and listeners. I invite you to find more conversations about cloud as part of the cloud reimagine series at www.ciotalkradio.com/cloudreimagine.


