Cloud Cybersecurity Governance

Controlling Cloud Security Through Continuous Visibility

Cloud providers only go so far in sharing the responsibility of keeping your information assets secure. The onus of protecting data and managing threats in the cloud still lies with you. But, if you can’t see what’s going on across your entire cloud infrastructure at all times, how do you detect and respond to threats, cut vulnerabilities, and ensure ongoing compliance? What are the steps to gaining continuous visibility into the cloud environment and using it to control related security?

Contributor

    • Tim Woods, Vice President, Technology Alliances, FireMon

Transcript

Sanjog Aul [00:00:00]:
Welcome listeners. This is Sanjog Aul your host and the topic for conversation is Controlling Cloud Security Through Continuous vVisibility. Joining me is Tim Woods. Tim is the Vice President, Technology Alliances with FireMon, a cybersecurity management company. Hello Tim, thank you for joining us.

Tim Woods [00:00:18]:
Thank you very much. Happy to be here today.

Sanjog Aul [00:00:21]:
Thanks once again. So there is no doubt that cloud offers great business value, but keeping it secure has turned out to be a serious challenge, and so much so that the term cloud security sometimes seems like an oxymoron. So Tim, what holds us back from fully controlling security in a cloud environment and what all have we tried to address those challenges and where have we reached so far in this journey?

Tim Woods [00:00:50]:
It’s a great question. Cloud adoption is obviously taking hold. You can literally swipe a credit card, you have cloud access or you have a space to provide your application and it’s been a little bit of a challenge for security professionals to secure. The native controls have not, I won’t say that they haven’t been sufficient. I think maybe understanding the native controls is really whether it’s the question of whether they’re sufficient or not getting their transport security by whatever means by the CASB or by the native vendor itself, you can’t rely on that because once you get there, there’s a lot of moving parts. I think we’re also seeing a rise, or I’m seeing a rise here at Pharma. We’re seeing a rise third party security controls that are now being adopted by cloud owners and where we’re seeing service insertions and things of that nature, much like what we’ve enjoyed on premise, but now only virtualized as an instance in the cloud itself.

Tim Woods [00:01:44]:
and so I think you’ll also continue to see that trend, but in the near future it’s still something that I don’t think we fully have our arms around yet and a lot of it links back to the topic today, which is visibility. Do you have visibility of the behavior of your enforcement technologies in the cloud or not?

Sanjog Aul [00:02:00]:
Now, how does an organization determine acceptable levels of vulnerabilities and compliance and threat management in the context of the cloud before starting the journey to establish security measures?

Tim Woods [00:02:15]:
The cloud presents an environment that can change rapidly. For this reason, we have to monitor and test continually our security controls because it can vary continuously and if you’re not constantly monitoring and testing your security controls and you don’t really know if they’re providing the value that you expect a simple static security policy in the cloud and in today’s world is just not going to cut it. Security policy have to be dynamic, they have to be adaptive in response to this varying change that’s occurring. It’s like a boy sticking his fingers in the dam to plug a link, a leak. As soon as you run out of fingers, then what? How do you plug up the other links and how do you see those other links? I’ve also heard it described as a whack a mole game. As soon as one security thing pops up, another one and you put it down, then another one pops up but too often we also encounter resource constraints which causes us to compromise our position as well

Tim Woods [00:03:14]:
and it’s not that there’s a lack of knowledge. I think even in the security space there’s a knowledge of what we have to do but it’s having the time and people and resources and the education which to accomplish that and a lot of the security, what we’ve seen is a lot of the security has been adopted by the actual application and or the business owners that may not be as well grounded in the security control as they could and somehow we have to get security back into the mix and I think that’s why we see you hear the term. We hear DevOps all the time, but now we’re hearing the term SecDevOps or DevSecOps where we’re moving security back into that but the cloud is no different.

Tim Woods [00:03:52]:
We got to get security back into the middle of the cloud security gang.

Sanjog Aul [00:03:56]:
So the claim is that if we could have continuous visibility in a cloud environment, controlling security will be a non issue. Do you agree and whatever that your answer is going to be, what else do you think would we need besides just having visibility?

Tim Woods [00:04:17]:
Visibility is part of the answer, right but it goes beyond just visibility. We also need, as I said earlier, we need dynamic, a dynamic security policy that can adapt as the things we’re protecting change or as the environment around those things that we’re protecting changes. Look, change happens constantly, completely aware of that but the real question is how are we evaluating that change as it occurs? Did the change introduce new risk? Did the change cause a drift in our compliance posture? Did the change impact our business in some way? Basically what the change was a good change or was it bad change? Was it expected or was it unexpected? I think the bottom line is if we expect to control security, then we have to evaluate change as it happened in the cloud. So it has to be adaptable, has to be dynamic.

Sanjog Aul [00:05:10]:
And what you are just mentioning here in terms of controlling security and having visibility and you gave some other factors. What has been the result so far by suppose an organization got the visibility and has these other factors, are we confident that the security was controlled or you were able to get to where you wanted to?

Tim Woods [00:05:34]:
Yes, I think you can definitely improve your security posture if you have the ability to evaluate change as it takes place within the security environment, within the security infrastructure. If you have the ability to evaluate that change real time, it doesn’t do us a lot of good to evaluate it hours after or days after we have to evaluate it as it happened, then that definitely has a significant impact on our security postures. It’s a positive thing. We work with companies all the time that who really enjoy having a centralized view of what their security behavior and what the policy behavior looks like by having that centralized view across their enforcement technologies in real time. So as change happens, that’s reflected on a dashboard that gives us an indication at any given point in time holistically where we sat from a security perspective.

Sanjog Aul [00:06:27]:
Let’s take a quick break, listeners. We’ll be right back after these messages and talk about the compliance management issue. Can continuous visibility lead to continuous compliance? Let’s explore. Please stay tuned. We’ll be right back.

Sanjog Aul [00:07:29]:
Welcome back. So Tim, let’s talk about compliance management. Can continuous visibility lead to continuous compliance? Is it that slam dunk of an outcome we can expect?

Tim Woods [00:07:45]:
It can, I believe that it can lead to continuous or can continuous visibility lead to continuous compliance management? I think it can if that visibility leads into actionable remediation. In other words, a control failure can’t simply turn a light red and then we go on about our business. We have to make sure that when we acknowledge a compliance failure, we’re alerted to a compliance failure, that somebody is assigned corrective action, somebody is assigned remediation to correct that compliance failure and or whitelist that compliant alert to say hey, this is okay temporarily we’ve evaluated this and this is okay, or hey, this compliance failure is definitely not acceptable and we need to take immediate action on that. So complaint people embrace compliance in a couple of different ways either embrace it to make their security infrastructure better, or they view it as an evil necessity. I think as we go forward in the future, and especially as we think about how it applies to the cloud and some of the new regulatory compliance initiatives that we see coming about, compliance have to be viewed in a manner that’s used to ensure we have security by design and default. If I look at the new GDPR regulatory compliance initiative, it definitely puts security at the forefront. Security has to be.

Tim Woods [00:09:11]:
It can’t be an afterthought, it has to be a forethought in our application deployment and our support of our environment and so compliance has to be one of these things. It’s the guide rail. It’s the things that keeps us in alignment with our security policies. So in answer to the question, absolutely, visibility can relate, it can lead into continuous compliant if we have actionable remediation control around that.

Sanjog Aul [00:09:37]:
So what do you believe is the road to effective risk management in a cloud environment, assuming we do achieve continuous visibility?

Tim Woods [00:09:48]:
I really believe the future. As I look down the road and I look at how we’re adopting, what we’re adopting today, and what different companies, I get the unique pleasure of talking to companies across almost every market sector, both large and small but I believe the future is security intent. Moreover, security intent orchestration, where the guide rails that I talked about, the guide rails of security, become dynamic and adaptable. It’s where potential risk related to change is constantly evaluated. Our focus shifts from rules on an enforcement point, virtual or otherwise, to the intent of what security should look like, or our workload, our application, or any of our other critical resources. Our written security policy becomes technically sustainable, if that makes sense. We remove doubt and uncertainty as to whether or not our installed security controls are an actual reflection of our security intent.

Tim Woods [00:10:46]:
I cannot tell you how many times that I’ve been in front of audiences where I’m speaking to them and I ask them to give me a show of hand. If they have confident, they’re not absolute confident, maybe medium confident, that their written security policies or their security guidelines are a reflection of their actual security implementation or their compensating controls. I can tell you very few hands get raised and we have to make sure that our security intent is truly a reflection of our actual written security policies.

Sanjog Aul [00:11:15]:
And besides technology tools, what people and process changes must be made to control cloud security? Leveraging continuous visibility.

Tim Woods [00:11:28]:
You can have the best technology in the world, but if it’s not managed or used effectively, we will fail to see the returns that we anticipate. So while having a centralized, continuous view is critical to the success of our security implementations, you also need to ensure that the security technology itself is easily consumed and it promotes collaboration across the different lines of business. Security must be there by design and default, as I said, but it also has to involve all those parties, the stakeholders, the business owners, the application owners, all those parties to maintain that common security goal. I also think that there will be a growing awareness of what a particular vendor’s API stack looks like. DevOps is definitely generating a need for more complete APIs that promote better interoperability and information exchange change across a company’s existing security investment in order to raise that overall security value of a given cybersecurity framework but for those vendors who choose not to focus on a solid API offering, I think may find themselves cast into dimmer light by comparison, say, to some other company that has placed a strong impact on their API offering. Synergy across what It Is if I’m a CIO, if I’m going to be looking for that synergy across the tools that I’m using to achieve my security goal.

Sanjog Aul [00:12:54]:
Once again, thank you Tim, for sharing your thoughts and insights about how organizations can control cloud security through continuous visibility.

Tim Woods [00:13:03]:
Absolutely, It’s been my pleasure. Thank you very much.

Sanjog Aul [00:13:05]:
And listeners, I invite you to find related conversations on our website@ciotalknetwork.com.

Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More

Contributors

Tim Woods

Tim Woods, Vice President, Technology Alliances, FireMon

Tim Woods brings more than 20 years of security experience to his role as the FireMon’s technical alliance lead. His global engagements have given him great insights across virtually every market sector and enterprises of all sizes. Ti... More   View all posts
Add Comment
Click here to post a comment

Exclusive Sponsor

FireMon-3 Steps to Gain Control of Cloud Security 300X250
Tim Woods