Security in the cloud age
I want to explain from my perspective, what in this new age the security means.
So I will take you trough,
- The big advantage of the cloud
- What does this mean for security
Why is cloud becoming so popular
Today we live in an age of services we rent.
These services are mostly rented from a shared pool of resources that we call The Cloud. I will try not to use the terms that are used by all the cloud people and explain it a bid more.
Like walking into a field of flowers to make a bouquet, you pluck the once you like and build a beautiful bouquet that gives you what you need.
This gives you the flexibility needed to grow when needed and shrink after your business moves on from its project.
Think that during the spike of sales during the holidays, your shop grows to be hosting thousands. Then after the holiday sales you scale back to your normal size.
The big advantage
- You pay for what you need.
- You can hit the gas and drive a big four wheel drive or let go of the gas and be back in a little town car. Whenever you need to.
- No more hardware cost and the trouble of maintaining it.
What does this mean for security
In the many marketing researches done, companies and organisations have one main concern about The Cloud. Is my data and operation secured.
In your own datacenter there are many securities in place, from firewall to virus scanners, from security guards to encryption.
Now how does this work in The Cloud age?
What is the levels of security.
-Physical.
Anything where you can touch the device with the data on it. This being a from a laptop to a USB stick to standing next to the servers having access to the console or storage.
This is mostly secured with:
Security guards at the office and Datacenter's
Encryption of the endpoint. (USB stick/ hard disk)
Password or security device access.
-Virtual/ Digital.
Anything that can get to your device or intercept any data from your network/internet.
This is mostly secured with:
Firewall
Virus scanners (end point on the hardware or some box between the device and the network)
Network traffic encryption
When moving to The Cloud companies focus mainly on the Virtual/digital. And moving from your own datacenter to a cloud provider does bring data security challenges. Before bringing the headcount back of your security teams, you need to weight this risk.
Something easily forgotten in this cloud age is the way we now make the data accessible to the user. IT still is mainly there to give your employe access to the data.
Many new cloud solutions offer syncing options that are beautiful, but you are storing your data locally again. Think of your local Dropbox (and other simalar solution) folder. Also with the browsers moving into the cloud storage, the passwords/history/bookmarks do get saved and synced into the Firefox or Google cloud.
With the many new devices that we get out mail on, we are spreading out the possible attack space. In an old environment we used to only have to secure a windows desktop, now you are looking at Android/ OS X / iOS/ Windows/ Linux/ Chromium and all of its variants.
How do we secure all of this and how do we help you keep control of your data?
I believe that with the cloud portfolio becoming more and more standard and a commodity. The next place too look at is security.
This is why I have started my journey in Symantec.