Three security issues loom large over the future of Cloud Computing:
-
- Will corporate IT security policies still apply to the applications and services delivered via the cloud?
- How will a CIO prove to management and clients that the company’s applications and services are as secure as before the cloud and meeting all SLAs?
- Will security be robust enough to pass any compliance audits required?
Only when each of these 3 concerns can be answered with a resounding “YES!”, will cloud computing be finally considered secure. Meanwhile, what will IT leaders and vendors have to consider, change, revamp, or manage differently in order to achieve this end goal?
Contributors
Transcript
Sanjog Aul [00:00:00]:
Good morning and welcome to CIO Talk Radio. To learn more about the show, please visit www.ciotalkradio.com. Today’s topic is How To Enable Secure Cloud Computing and our guests for today’s show are Elayne Starkey, who is the Chief Security Officer with the Department of Technology and Information with Delaware. Good morning, Elayne. How are you?
Elayne Starkey [00:00:23]:
I’m good, Sanjog thanks for having me.
Sanjog Aul [00:00:26]:
So how is life and work both?
Elayne Starkey [00:00:29]:
Life is good all the way around.
Sanjog Aul [00:00:33]:
All right, good. So you did not say how good is business? So that’s a question mark. All right, so we also have Dan Lohrmann, who’s the Chief Security Officer with Michigan Department of Technology Management and Budget ,which State of Michigan. Good morning, Dan. How are you doing?
Dan Lohrmann [00:00:46]:
Good morning, Sanjog. I’m doing fantastic, thank you.
Sanjog Aul [00:00:50]:
Now let me ask you this. With your title, you’ve got technology, got management and budget. Is there anything else that’s left in the company, in the department?
Dan Lohrmann [00:00:57]:
Just. Well, we’re a centralized IT organization. We’ve actually, we have enterprise wide focus. So really I am, I do play the role as Chief Security Officer for the State of Michigan Government. So we are, we are pretty all inclusive.
Sanjog Aul [00:01:12]:
Great. Now the topic that we picked up today and the premise of this is where whenever we people talk about cloud computing, yes, there are some first adopters and people are using it as a mainstream paradigm for getting their computing needs taken care of. However, everybody, whenever they talk about cloud computing, they also talk about security and that being the weakest link in or it is putting a damper on what we could otherwise achieve with this new paradigm. With that said, we can keep talking about what cannot work or introduce paranoia or introduce skepticism in how a technology paradigm would not be successful. How about taking a little more positive approach to it to say, guess what? Yes, anything which is a problem, which there should be a solution out there and perhaps we don’t have an actual solution right now. Everything totally every I dotted, every T crossed but we should be able to lay out a roadmap and say this is what we’ve accomplished and this is what we want to accomplish.
Sanjog Aul [00:02:10]:
With that said, when we are looking at cloud security or cloud computing related security. Dan, I’ll start with you. Do you think it is just a state of mind and is it being overstated and bloated versus what truly is the issue?
Dan Lohrmann [00:02:27]:
Yeah, I mean, I guess I would say, Sanjog, I do think to some extent security is a state of mind but the way people will feel more comfortable with any vague concept is to break that down into smaller parts. I mean, cloud to cloud computing, we think of the Internet, we think it’s so broad. So someone asks you if you feel safe or secure on your city or something, you may think not so, but maybe I feel secure in my neighborhood, in my subdivision, which you may know better, that kind of a thing. So in cloud, from a cloud computing perspective, I would say we need to break it down into smaller parts and define those smaller parts, whether we’re talking software as a service, infrastructure as a service. Are you talking about a private cloud, a public cloud? We need to get that level of comfort and the field secure. I think we need to break it down into its component part and answer specific questions and the more we can do that, the more trust we can build in cloud security.
Sanjog Aul [00:03:23]:
With that said, Elayne, we have people who will take everything, as we say about security and how we can address it, but they will always have a bug like a double quotes buck. This is not going to really make me feel comfortable. So what is it that people are after when it comes to security in reference to cloud computing?
Elayne Starkey [00:03:44]:
Well, yeah, definitely. There’s some sheet components that we’ve addressed here in Delaware and we’ve tried to capture them in our published terms and proposed terms and conditions. We vetted it through our attorney general’s office and we’ve offered that up to our agencies used for any type of negotiation. I think it’s important that we start talking about security very early in the engagements, not wait until you’re ready to sign the deal but what’s important is that we’re here to protect sensitive data and as soon as you think about turning that over, turning over infrastructure, turning over data to a third party, it certainly reduces control and introduces risks that people sense that in Dan and I see, that’s what we’re all about. That’s what we’re charged to do, is to try to mitigate those risks.
Elayne Starkey [00:04:39]:
So as a starting point, I would suggest kind of talk about start talking about the security early in the engagement and make sure the contractual language there’s safeguards in the contractual language if you decide to move forward with an engagement with a cloud provider.
Sanjog Aul [00:04:57]:
Now, whatever we do with respect to engaging a client provider, is the onus of you making people comfortable and warm and fuzzy. Does the onus lie on a third party that how secure are they or perhaps we could be the weakest link where we might leave a password exposed to an enterprise application which sits somewhere else and guess what somebody from a coffee shop could actually be connecting to your most mission databases and pull things out which you definitely find as a breach. So where is the weakest link? Is it truly can we blame for everything that could happen or has happened to a provider?
Elayne Starkey [00:05:42]:
I don’t think so. I think there’s equal accountability. I think it would be wrong to just simply hope that the vendor is going to do the right thing is not a strategy that I would recommend, but certainly the standards, the security standards on the shoring, the vendors have gotten better at implementing stronger security controls. So it’s definitely maturing as we go along but there’s a lot of responsibility that the organization has. Ultimately we are accountable and responsible for the protection of our data so there’s a lot of responsibility that falls on our shoulders.
Sanjog Aul [00:06:18]:
Then a question comes to mind is that when we did not have cloud, that is a pre cloud era, whatever you defined as an environment in which security was established and you called finally after putting all the checks and balances in place, you called it secure. Do you think is it the same field in which we are playing? Is it the same level at which we are playing? So what has changed in terms of the very benchmarks and standards with respect to what security should be?
Dan Lohrmann [00:06:46]:
Yeah, that’s a great question, Sanjog. I think the premise of your question is exactly right. I mean knowing for somebody to put something in the cloud, what’s secure today, is it encrypted, is it what protections are in place, what logging is in place, what are you doing today to determine that you’re compliant, that you’re meeting PGI compliance, looking at those specific deliverable and saying, okay, we know it’s been audited. XYZ is being done today. Now you’re saying, okay, what changes when you put it in the cloud? I think some of those components, it really depends obviously on the environment. Is it a public cloud, is it a private cloud? In Michigan we’ve actually built what we call our my cloud, our private cloud or government cloud, internal that we can do some of the same things. Provisioning, rapid provisioning, much quicker standup time for a lower cost, maybe that’s a lower set of risks. Whereas if somebody’s going into a public cloud that they don’t know where the data is, so maybe it crosses the level of international boundaries, there might be legal issues involved.
Dan Lohrmann [00:07:49]:
So it really kind of depends on you’re going from A to B, what is the context of that and so for us in Michigan, we started with a private cloud and built that in an environment that was still in our data centers and still in our government networks with some of our vendor partners. But as we built that out, we had some of the protections. We knew the data was in Michigan. We didn’t have some of the legal issues of going over international borders and those kinds of things.
Sanjog Aul [00:08:15]:
Now would you call your private cloud is nothing else but a data center on steroids, which is offering utility model.
Dan Lohrmann [00:08:24]:
Using some new technologies that are available from naming vendors. But I mean there’s a lot of different vendors that have it. Whether you’re talking the original response was HP, but HP, EMC, VMware, just a long list of ManTech that have new sets of tool sets that allow you to do day by day meeting maybe you build differently. It is kind of a data center on steroids. It is using new technologies that allow us to to do for example, we’re offering storage at 1:10 the price that we were offering storage before. More self service, more ability to do things on your own, more options for our customers that may not need all the different.
Dan Lohrmann [00:09:01]:
Maybe they don’t need replicated data, maybe they’ll need the same level of uptime, maybe they do. I mean, so depending on what you’re looking at as far as redundancy and those kinds of things, or are we just talking about the test environment or development environment that may not need the same level of logging because you wipe the data every day or that kind of a thing. So I think our private cloud has brought more flexibility, more options to our customers at a lower price and so in some extent it is a data center on steroids.
Sanjog Aul [00:09:32]:
Elayne, would you say that if an organization wants to feel secure, at least till date, the only option that they have is to go after the private cloud, which does not allow you to fully exploit the on demand infrastructure, the scalable or a utility model, because you are putting fixed cost, which is coming out of your own budget in some form or fashion. It’s just a different wrapper. So are we constrained to just calling secure cloud computing anything else but a private cloud implementation?
Elayne Starkey [00:10:04]:
Well, I think step one, it’s just to kind of look at the data first, the data that potentially may be moved to the cloud and think about the classifications, think about the sensitivity of it. If it is protected data, for example, health data or criminal justice data or something like that. I would say at this point that those are not good candidates to move to the cloud today but there are a lot of public, what we call in Delaware is public of public classification of that data that is very suitable for the public cloud application and there’s lots of examples out there movements to the cloud even that movement I believe I contend still needs to be very protected. We need to get heavy involvement in it. Vendors would like nothing more than for us to just kind of hand over everything to them and drop them And as I mentioned before, that’s not really a solid strategy.
Elayne Starkey [00:11:03]:
We need to understand exactly what data it is that may be leaving our environment and what’s this, what we are testing and what we want to hold the vendors accountable for in terms of the protection of that data.
Dan Lohrmann [00:11:15]:
Yeah, I just add to that. I mean even in Michigan we’re moving towards a hybrid cloud. I mean our, my cloud, private cloud offering, our government cloud in Michigan has been about two years old now. We’ve been you know, working, growing IT using, adding more and the different services to it. We are looking at a hybrid offering and we do have some, just like Elayne just mentioned, we do have some services like our HR applications or our recruiting which is software as a service is, is a cloud offering. So we do have some public cloud out there that we do use in Michigan but currently not for that most sensitive data as Elayne mentioned.
Sanjog Aul [00:11:51]:
Let’s take a quick break listeners. We’ll be right back. And let’s touch the topic of trust. So trust is kind of a two way street. So the cloud providers need to provide you with some visibility and or allow you to see under the hood to see what’s going on, where is my data residing. Whereas they also expect or they requested for you to trust them. Because this is again a state of mind to some extent and only then this can be tried to a degree that if you are given the immunity by the government and or your respective executive management and also are allowed to try what you want to try in order to see really is it that bad out there in the public world in five years what would you have changed in terms of your checks and balances or whatever, your policies and procedures where the way people use your cloud computing infrastructure to ensure sure that you basically start saying you know what, really I don’t need a private cloud. I can very well go to public cloud and still be compliant with all the regulation and feel warm and fuzzy.
Sanjog Aul [00:12:51]:
So what would it take? How will you instill trust? How will you make it a two way street? Please stay tuned. We’ll be right back.
Sanjog Aul [00:14:48]:
Welcome back. So Elaine, let’s start with you. This is about trust and it’s a two way street and you want to both parties want to make this happen and make it to a point where you do not really look at private out as the last resort or as the only resort that you have. Instead you say you know what, in five years I would rather have a list of pre compliant vendors. We should have a checklist of things and just provision ideas as many of the private sector companies are already trying and being successful. And it’s not the state government versus federal versus private sector question. There are many industries who are still not able to go beyond the private cloud infrastructure. So what is it that has to happen in the next few years that would allow all of you to, without fear, jump onto this public cloud infrastructure?
Elayne Starkey [00:15:39]:
The key part of that question is without fear I guess and that’s tricky for us as of us in the security business always are. It’s our nature to be cautious so a no fear kind of an approach. Wow. I’d love to get there and I’ve actually seen some progress in getting there and as we’ve discussed before. I think there’s the progress needs to happen on both sides of the table.
Elayne Starkey [00:16:04]:
The security of this space is improving. The vendors are improving the strength of their security offering. People like us are becoming more knowledgeable through programs like this and other material to make sure that we are entering into the discussion with the vendors at the appropriate level, at the appropriate time, talking about the important things on protection. So yeah, I hope so. I mean, I think what people in our business, it is a death sentence for us to say no all the time and this is a perfect example, Sanjog, of the there’s too many benefits that go along with this new face out here, this whole new paradigm. It’s the cost savings are incredible. The potential cost savings are incredible.
Elayne Starkey [00:16:52]:
The scalability that it brings you, the agility that it brings an organization being able to rapidly deliver solutions. It’s just too compelling of an argument for us to think that we can’t get to that place that you just described. We will get there.
Sanjog Aul [00:17:09]:
So, Elayne, the fact is that the benefits that you listed out are the ones that we want to realize. And for that, if we are saying let’s take the premise of you were given what you want to do, suppose they lift off the pressure that you have to be thinking, like always, a state government, think like a business, run your government like a business and want to get there. What is it that you would do differently going forward so that you can truly say we are going to remain secure even though we go to public cloud? So what should happen? Not it’s not all your responsibility. What do you want to the rest of the world to do, whether it’s vendor world, the compliance world, the consulting world, whichever is involved in it. What has to change?
Elayne Starkey [00:17:55]:
Very good question, and I think I answer it two ways. In the medium term or the short term. My preference would be all QWIL terms and conditions that we have defined which talk about protection of the data, the fact that the state retains ownership of the data, the fact that the data is not allowed to reside offshore, they’re not allowed to use any subcontractors that have any criminal history, negative criminal history. They’ve got to encrypt it as it’s moving. I’m just summarizing some of the important terms and conditions that we require for any new cloud engagements. Medium term, short term would be that our vendors accept that without dispute, without negotiation, longer firm. I would accept, maybe not even have that conversation with them, that they would come to the table with all of those in mind and understanding that they need to come to the table and represent their offerings in a way that satisfies the security requirements of my organization.
Dan Lohrmann [00:19:01]:
Yes, I just add to that William was just saying. I mean I think of private sector we try and do run our state government like a business and we have compliance requirements. Private sector has SOC sovereignty, we have TCI compliance. We as a state government use credit cards all the time. So we have credit card data. We have. We have PCI compliance as a central need just like the private sector does. So you know those things would be built in as Elayne mentioned as part of not negotiations not.
Dan Lohrmann [00:19:30]:
The more one person I heard I really enjoyed listening to about cloud computing said the more exceptions, the more specialization, the more terms and conditions we have to add, the less it is like cloud computing because you want it to be like signing up for Gmail. It just work and when you just at home I’m talking about. So I mean it’s going on a personal account just and everybody wants that efficiency and that cost saving. But are those features built in that you need the compliancy the specific controls and to say one other answer. I’ve heard that I think we are heading in that direction. Is the FedRAMP program FedRAMP? Your listeners can go and google that and and look at FedRAMP. There’s a lot of great articles out there but it’s a federal program looking at states as well and how we could have kind of pre approved certified cloud providers that have those things built in to make it part of the way we do business each and every.
Sanjog Aul [00:20:24]:
Dan now do you think in order for us to all reach there and yes, we have our own respective needs. Are there some standards and benchmarks that are created across private or public sector organizations so that we can say this is one roadmap and we at some point intersect anyway. So suppose you have a compliance need and you’re using a private sector company to meet that need who in turn might be using cloud to meet that need and or perhaps you’re using something. So this is like a mesh at the end of the day. So is there one benchmark and definition et cetera that has been defined to say these three things or these five items when and I can check out these is what I will call as this particular cloud implementation to be secure?
Dan Lohrmann [00:21:08]:
Yeah. I don’t know that there’s one. I mean one of the difficulties is like in state government is we really are many different businesses and I just rattled off a few of the compliancy topics DCI compliance, we have HIPAA compliance, health information compliance, we have different and within government there are different business areas. So in many ways we are hundreds of different businesses under one umbrella. In state government we do taxes, we do roads, we do education, we do renewal, driver’s licenses. And different areas have different requirements in the same way, different businesses have different requirements. I think there’s going to be if you get this all sensitive data but just as we regulate things differently for smart grid or different parts of government are regulated differently, different industries.
Dan Lohrmann [00:21:54]:
Credit cards might be different than other types of data. I don’t know of any one. I think there are several really good roadmaps out there. Another one I’m working with, Tech America has a commission on the cloud. Again you can, people can go to those websites, the Tech America foundation website, they have a fair federal government did a really good white paper that’s available out on the net that you can look at that lays out the basic core component that people need to be considering and laying out that roadmap. And again I said fedramp is another one. There’s a number of really good ones out there that, that are, that are trying to work on this topic. I don’t know that we’re ever going to get to one specific answer, but be nice.
Dan Lohrmann [00:22:36]:
My gut is it’s going to as I mentioned when we started the program that you’re going to have specializations, you’re going to have certain as we have certain zones in our network today for a higher zone for certain types of data. We have different levels of classifications in the federal government, state government, even even the Defense Department, contractors, top secret, different types of data. I think we’re going to see probably different types of cloud for different types of scenarios, but I think we can get to a few. I don’t know that we’re ever going to get to one.
Sanjog Aul [00:23:09]:
If you do not get to one question for you is that three or four or five years from now would you say that I can kick back and relax and let the cloud computing run my IT and I’ll feel warm and fuzzy about it even though whatever that you pick up or is it still going to be the same conversation that it’s a moving target? What does your crystal ball say?
Elayne Starkey [00:23:32]:
Warm and fuzzy. I would love to say that I could get to a warm and fuzzy state. I’m not there yet but there’s, some great work being done. I, I think that if we continue on this track we’re going to be able to realize the savings we’re going to be able to satisfy those people in our space wearing the security hat to try to mitigate some of these risks. I don’t know, Dan, warm and fuzzy. Do you think we can get the warm?
Dan Lohrmann [00:23:59]:
I don’t know.I mean, I think you mentioned something earlier that I really think is really important that every in the listener think about and every CIO is that you can outsource the work but not the responsibility. So if somebody gets hacked, it’s still going to come back to the politician or the government employee or the person overseeing the contract with your cloud provider saying, how did you lose my credit card data? How did you lose this data? And they’re looking for somebody in government to be accountable for that and so I think to that point, my, I think that you’re always going to have, it is going to be a moving target in this sense Sanjog, is that you’re always going to have bad guys. We haven’t grown out of people robbing banks. I mean it was happening back in Jesse James and everything else and they’re still robbing banks today. So there’s going to be people who are still going to be going after that data five years from now. I think we’re going to move, but I also think it’s going to be a moving target because those that are attacking us, that are going after that financial gain, quite frankly, criminal conduct are also going to improve. So while we’re improving, they’re improving as well.
Dan Lohrmann [00:25:03]:
So it is somewhat of a moving target. However, I do think more and more government and private sectors will decide is this a core function that I want to be doing? Do I want to necessarily be doing storage? Do I want to necessarily be standing up servers as infrastructure? Do I even want to be managing this software? Do I want to offer the software as a service? I think you’re going to see more and more movement in that way. But I also think you’re still going to have concerns. I think five years from now if you invite us back, we’re not going to say, yeah, we solved all the cybersecurity problems.
Sanjog Aul [00:25:34]:
Let’s take a quick break, listeners. We’ll be right back and look at specifically what is your expectation from the providers because any new feature, functionality and or provisioning that they will do, that’ll of course keep maturing. But what is it that you expect them to put as the very basic standard that they follow so that it’s a no brainer? And in fact you do not have to as security champions have to look as closely on the cloud related implementations because you’ve got enough other battles to fight already. So if you are handling the business side or the government side and the technology provider that is a cloud provider handling the technology portion, what is it that you expect? What is where is the onus? What all are they expected to do and deliver to you when it comes to cloud computing? Please stay tuned. We’ll be right back and discuss.
Sanjog Aul [00:28:15]:
Welcome back. So given the very technology paradigm and or the way it gets provisioned a lot of responsibility or from the technology implementation standpoint and safeguarding what is being provisioned is lying with the provider. So in a way it looks like the reason we do not feel secure that either we have lack of visibility or we feel that it is too immature or we perhaps have some latent or unsaid expectations from the providers and which are not seemingly met is what’s causing us to say you know what? I cannot go to that full blown public cloud infrastructure. So if you could inventory those, I guess that would be a great start. So Dan, please help us inventory some of those or at least anything that you have on your Network.
Dan Lohrmann [00:29:03]:
I mean, I think we talk a couple of quick things. Encryption is, is the data encrypted at rest? Is the data is encrypted? Obviously in motion, separation of duties, logging of data. Who touched the data? Who saw the data? Can you prove that no one else saw it? How do I know that your system administrators were looking at those sensitive records? What tools and procedures can we put in place around logging? Really? It’s the same list that you have when you get audited today. I mean what are the audit findings you’re having in your organization today? What are the good, the bad and the ugly around security controls that you have today? So some of the basic things that everyone of course wants is malware protection, intrusion prevention, those kind of things that are expected around. Are you, are you being penetrated? Are your systems being penetrated by whether it be corn, governments or criminal organizations? And how do you know? I mean, how can you don’t know what you don’t know. So I think you said visibility into their operation. Knowing when somebody saw data has the data at a very basic level. It’s CIA.
Dan Lohrmann [00:30:06]:
It’s confidentiality, integrity and availability of the data. So at a most basic point is the data being changed, is it confidential? Obviously you don’t want identity theft and those things. But also is it somebody adding a zero? Is the integrity of the data there and is the data available when I need it? 724365 at the right speed? So if it’s going to be somewhere else in the country and I need a certain level of functionality and availability when my customers need it.
Elayne Starkey [00:30:37]:
Because of that, we do want that glimpse into the organization. But then the whole reason we’re getting involved in this is because we don’t have, want to have to weed through a lot of the details. And I agree with the inventory look that Jan Zan just went through. But I think what’s important is that we, we get enough information about those details and more. There’s additional items as well. But to comfort us to know that they are paying attention, as much attention to these issues as we would if we were hosting it here in our data center. So to build up that confidence, I think, Sanjay, it’s so important to, to get to the level and it is about relationship building and building partnerships with trusted vendors to get to that point where we have enough information, we’ve gathered enough detail to get to that level of confidence that we know they’re going to protest it as sanely as we would protect it ourselves.
Sanjog Aul [00:31:36]:
So two things come to mind. Number One is that they are not willing and another is when they are willing and you did go through the so called audit or looking under the hood to see what’s going on. You did not find what was missing. You did find something which is missing and you told them, but you don’t have confidence that they will fix it. Which one is it more prevalent and or what’s happening in the minds of people who are safeguarding security for any of the organization, maybe government, private or public sector. What do you think?
Dan Lohrmann [00:32:09]:
Great example of what you’re saying. Give me give you an example of how that’s working in real life and then answer your question. Michigan.gov is being hosted in Boulder, Colorado right now. I mean we actually have a contract with IBM. We actually started that back about a decade ago. Long story short, how we did that. But there’s, it’s a long fixed contract, I don’t know, 60, 70 pages of terms and conditions, work through a whole bunch of things. We do have that level of comfort.
Dan Lohrmann [00:32:35]:
This is the high level webpages. Now the front page is the pictures, not the detailed sensitive data. A lot of the internal systems with credit card and sensitive data is within the state of Michigan. That is within Michigan but I do have that level of comfort that Elaine just talked about that they are doing what they need to do to make sure we don’t get hacked, to make sure they don’t grow mustache on the governor’s face. All those kinds of things that you worry about for web portal. We trust that they’re doing it, but it’s for a lot of negotiation. It took many took a very large, complex contract in place with lots of terms and conditions and lawyers on both sides and everything else put that in place.
Dan Lohrmann [00:33:14]:
It’s a very successful contract and I do have a lot of peace of mind that our web portal won’t have, for example a denial of service attack or if it does that they’re going to be able to take care of it. The challenge, to answer your question, then become, yeah, I mean if I knew that the auditors were happy with what that provider was offering me and I could just get the annual report and say yeah, everything’s in place, you have no audit findings, everything is yada, yada, yada, that would be great. I just don’t think that’s the best current state right now. I don’t. I think that when you say well wait a minute, you’re not going to have separation of duties for this or you’re not going to have this type of Logging that I need for PCI compliant where you’re not but going to meet all the new PCI standards that just came out that are different than last year’s or if you’re going to do that, you’re going to double my price. Those kinds of things will scare people off because otherwise everything has change order.
Sanjog Aul [00:34:07]:
So lack of cooperation, lack of capability, lack of intent. Elayne, is it all three? Is it one of those three or two of those three? Which ones are the ones which is holding us back?
Elayne Starkey [00:34:21]:
Well, I don’t think it’s lack of cooperation because we’ve had our terms and conditions on trial now for about five months and we’ve experienced some. Some very willing participants come to the table and read through our terms and conditions and gladly agree to abide by them. Now granted there’s some of the smaller vendors that don’t have heavy duty legal team. We’ve not experienced that as much with the bigger vendors. And I’ll leave name out of for now. But. But certainly there’s a willingness I at least it’s not been my experience to to see that there’s an unwillingness to cooperate and to try to find the common ground. I think that I’m pleased with what I’m seeing in that area.
Sanjog Aul [00:35:08]:
Now coming to the lack of capability or lack of intent, Elayne, what do you think is the one which is true here? Because these three arc in combination is what instills trust. If none of them is true, that means you should be trusting them.
Elayne Starkey [00:35:25]:
Yeah, I think capability and the intent discussions I think are dependent on the vendor that you’re talking to. I mean are there certain. This is a hot area right now. It’s an emerging product safe and lots of. There’s lots of new players in the field that see a financial opportunity to move into this space. The there’s also. So it’s a financial gain and kind of the focus and the primary intent. Often what we see on the back end is not a lot of attention to the details about the loss.
Elayne Starkey [00:36:00]:
All those things that Dan just went through. It’s like a quick fuss. Find some unsubstecting customer that just simply wants to unload the responsibility and they’re out there. There’s lots of lots of engagements that are being set up like that with a lot of regrets afterward. I shouldn’t generalize and say that’s the case for all vendors. There’s a lot of vendors that are very familiar with this base that certainly are learning as they go as are we and want to do the right things and want to protest the beta. That’s the challenge, I guess for us DSOs is to find those partners, to find the ones that we can’t cross. As you say, have the capability and the willingness to go along with it.
Sanjog Aul [00:36:44]:
So what do you think, Dan, if I were to ask the same thing where if I did get you a vendor or a provider who has the capability, wants to cooperate, let you see under the hood and has shown intent of doing whatever best possible to safeguard your interests, is it just a matter of time before you will find your respective partners and life will be good and you can focus on something else?
Dan Lohrmann [00:37:12]:
I do think we’re heading towards a lot more adoption of cloud computing. Depends fundamental question. I do think I agree with Elayne that I mean, I think we have a ways to go on the capability side. I do think they, they want you all the major. Everyone I come in and comes in and talks to me when I was CTO and often now I’m a CSO. I mean, everybody wants to talk about their cloud program, Everybody wants to spatial cloud.
Dan Lohrmann [00:37:37]:
I mean that’s where they’re going when they want to tell you as a service infrastructure, as a service software, as a service platform, as a service. I mean, it’s, it’s rampant and everyone’s got a cloud program. I think what, I’m not hearing the heater is, well, we’re FISMA compliant or we’re this, we have this capability. We have this capability. But I see still things that caused distrust out there. I think all the vendors are heading in the right direction. I agree with Elaine. We’re moving in there.
Dan Lohrmann [00:38:04]:
They all want to do the right thing. They want to head there. I still see people. Well, I could give you one or two examples where people, you know, will go around the IT team straight to a business team. I mean, this generally doesn’t happen, but it does happen sometimes and they show they, they don’t want you to ask the tough questions. They just want to sell you on price or they want to sell, we can do this for half the price of what you’re currently paying but they don’t want you to ask the audit questions.
Dan Lohrmann [00:38:29]:
They don’t want you to ask the separation of duty questions. They don’t want you to ask the compliance questions because as soon as you say that they may even have that offering, oh, you want to be PCI compliant. Oh, okay, that’s worth as much and that doesn’t. So try.
Sanjog Aul [00:38:44]:
It’s about selling. Is that what you’re saying that they’re selling versus trying to come in with an intent to add true value and be straightforward and honest with you, I think. Is that what you’re saying?
Elayne Starkey [00:38:55]:
Right. I agree with that. When you what put people like Dan and I in a really bad spot is when that sale pitch goes to the business leaders of the organization at a meeting or at a conference or even our management chain as well, you know that someone will come back, stay for another department, all excited about that very low cost cloud offering and you come to us and we start asking the compliance questions and all of the other things and suddenly we look like we’re throwing up barriers. We’re trying to find ways not to move forward with this wonderful opportunity that makes it, say discovery.
Sanjog Aul [00:39:33]:
All right, so let’s take a quick break. We’ll definitely be coming back and exploring this more in terms of what is it that has to be done. So here what we are finding is that perhaps some people way too aggressive in terms of what they’re offering and they’re not allowing or diverting attention from the fine print. And if they were to really look at it themselves and try to work on the areas where they feel it is not up to the mark or perhaps the price sensitivity that we have here, that’s not being met, that expectation is not being met. That’s why we are not seeing a lot more adoption. So we’ll talk more about this when we come back. So please stay tuned.
Sanjog Aul [00:41:59]:
Welcome back. So based on the responses that we got, it looks like the undercurrent here is that people are trying to go and try to do anything and commit anything in order to get the business because it looks like a gold mine. So in a way we are saying that the folks are coming in to sell versus create value. So that’s one concern and secondly, we do not know what they can provide for a given price. So your pricing structures as and or the offering combinations with the fine print not been exposed as well. So that’s where the trust is not getting built. They’re starting on the wrong footing.
Sanjog Aul [00:42:37]:
So with that said, suppose we fix that. Let’s take a premise. Let’s see if you can get a vendor who fixes it. Then what’s your concern? Dan?
Dan Lohrmann [00:42:46]:
Yeah, I mean, I think you mentioned it. I want to have an ongoing relationship and repeat again. I think Fedramp is heading in that direction as an example, which is the federal Risk and Authorization Management program, which actually looks at standard approaches to assessing and authorizing cloud computing services and products and you know, that people understand from like from a catalog perspective, from a service catalog perspective, what are the options, what are the price? I think that we’re heading in that direction. I think equalizing, helping people understand almost like a checklist or a chart, these vendors offer these services at these price points and it does include compliance, it does include the different security features that you’re looking for. I also think another challenge in the trust area is getting out of the cloud. So I’ve heard different people say it’s easy to get in, hard to get out.
Dan Lohrmann [00:43:35]:
So what happens in three years if you have to rebid it? Many governments, Elayne and I work for state government. We have to, we have provisions where we have to competitively bid. So do we have to relook at moving the data from one cloud provider to another cloud provider three years from now or whenever? So and so those are some of the provisions that I think to build that relationship but just as we bid things out to look at, do we go with Microsoft or Google or do we go with Apple? Or whatever the product is and then we rebid that in regular terms over multiple years. Is the data portable? Is it, are the interfaces there, is the integration into our existing systems there? Those are some of the more complex questions that as you develop partnerships with these vendors and they said build value, that you can start getting into deeper trust issues that they really understand what your back end infrastructure looks like.
Sanjog Aul [00:44:28]:
Coming back to security So if you were to look at the state in which the data either sits at one place that is at rest or it’s on the move to and fro between the infrastructure to wherever it is being sent to, in both of those cases do you think you have a picture in mind which is going to allow you to put a stamp of approval in terms of security versus how it is being done today? Is there a gap or a delta that exists?
Elayne Starkey [00:44:56]:
Yeah. Well again it comes back to the data and it comes back to the classification of the data and if it is such, it requires the data to be encrypted in transit as if we’re being to and from clap as well as encrypted at rest. And certain classifications do require that level of protection. I think the encryption in transit, we’ve been doing that a little bit longer I think than the encryption at rest. It’s a little bit more mature certainly that’s one of our terms and conditions. We require it for any movement of non public data that’s moving to and from the cloud. The encryption at rest it had matured but I think there’s more process that has to be wrapped around it in terms of the key management and key storage and who has access to keys and what’s the life of the all those issues about the kind of the key management feet which again has to be discussed and agreed to with the provider so that everyone is clear exactly how those fees are going to be managed.
Sanjog Aul [00:46:01]:
So if a cloud provider is able to provide you an adequate set of controls and demonstrate to you that it works in terms of securing the data while it’s at rest and or it’s on the move, what else is left for you to give thumbs up to, say a public cloud provider to be able to handle all of your data, I mean in an ideal case, perhaps a couple of years from now, what else would you have looked at?
Elayne Starkey [00:46:26]:
Well, some of the other things that we haven’t mentioned to date was the how they handle a security breach issue, how promptly we would be notified if there is some type of breach or even just the detection of some type of suspicious intrusion. How all that is handled, what we get informed of, what we don’t get informed of. Those are some of the things that would be part of our discussion. Dan eluded his to it earlier about the if for some reason you need to get data back or you need to terminate the agreement, the some type of orderly return of the data to you, including certification that they have disposed of the data securely and all of the certificates of destruction that may be required for audit and other compliance. Make sure that’s all provided. I think that fairly easy as long as it’s a friendly termination, if you will. Could get a little dicey if everything, if the engagement is ending on bad terms. So yeah, there’s things that we’ve talked about, certainly, but there’s.
Elayne Starkey [00:47:28]:
I get the feeling you’re trying to get us to a point where we say, yeah, we can get comfortable with this and I think what we’re saying is the set, Sanjog, is that we’re, yeah, we’re moving in that right direction, but we’re not there yet. I think we’re making progress. I’m hopeful that we’ll get to that point of that warm and fuzzy feeling that you described.
Sanjog Aul [00:47:49]:
Rola all right, so Dan, 30 seconds for you. Provide like very concise input which we can take to our provider community and also the executive management so that you can successfully be the champion versus being seen as a damper on this cloud computing. What are they supposed to do in their respective areas?
Dan Lohrmann [00:48:13]:
I think that the desire is there for the efficiencies in the CSO community. In the CIO community, we want to make sure that the vendors have compliancy built in, understand our business or whatever that business might be, whether it’s PCI compliant, FISMA compliance, HIPAA compliance, SOCA compliance, understand what those are from an end to end perspective and not just from a, okay, well my box is compliant or my data center is compliant or my little piece here. I mean think of it in terms of what the CIO has to do and Lane and I have to do, which is an end to end approach, the full lifecycle of the data and the system and if you can put yourself in that and say I’ve got a solution that can address all of those different issues, then I think that there’s. That that’s gonna, that’s absolutely gonna be well received and I think there’s a desire, I certainly have a desire to enable cloud computing that’s why I’m on the Tech America Foundation Cloud Commission. We’re trying to work through the detailed aspects of this. The federal government is with Fedramp and the Tech America foundation, others I know I work in this.
Dan Lohrmann [00:49:19]:
Homeland Security is working this. So I think there’s a desire to enable this. I think we’re making progress, but I think we have to look at how you do it today in your private data centers or private clouds, make sure we understand the end to end compliance issues and then provide that service in a way that provides value to the customer.
Sanjog Aul [00:49:39]:
On behalf of the show and our listeners, thank you so much. Elayne and Dan, this definitely is a good discussion which actually brings some important points to the table that the onus lies with the provider and as well as with the folks who are going
Sanjog Aul [00:49:51]:
adopt this new paradigm and hopefully we will see that warm and fuzzy feeling that we will embrace and around this cloud computing and make it secure. Thank you so much again.
Dan Lohrmann [00:50:01]:
Thank you for having us.
Sanjog Aul [00:50:02]:
And if you have any questions, listeners, please send us to viewsiotalkradio.com that is viewsiotalkradio.com thank you again for listening to CIO Talk Radio. This is Sanjog Aul, your talk show host till next week. Take care and God bless.
Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More
-
- Cloud Enabled Security
- Private/Hybrid Cloud, Security, & Taking that First Step into the Cloud
- Cloud Security as a Shared Responsibility
- Controlling Cloud Security Through Continuous Visibility
- Cloud Security Wish List
- Security Concerns Linger As the Clouds Roll By
- Security in the World of Mobility, the Cloud, and Social Media
- Cloud, Mobility, Social Networking, and Inter/National Security


