Welcome!

@CloudExpo Authors: Zakia Bouachraoui, Elizabeth White, Liz McMillan, Pat Romanski, Roger Strukhoff

Related Topics: @CloudExpo, Microservices Expo, Agile Computing, Cloud Security, @DXWorldExpo, SDN Journal

@CloudExpo: Article

Cloud Security: Not an Oxymoron

The realities of security practices at leading cloud providers

Some businesses today are nervous about moving to cloud-delivered technology because it means allowing their system data to reside somewhere other than their own data center. For some, this can be a tough concept to grasp, especially for those who have spent 25 years or more hosting their company's systems and data. But cloud computing providers could not exist without implementing strong security controls for their customers' information. The reality is that leading cloud solutions include security features well beyond what most manufacturing companies can afford to implement on their own.

In this article readers will learn about some realities of the security practices at leading cloud providers and the questions that should be asked by those considering use of a cloud solution.

Does the cloud solution have a risk assessment process that addresses risks to information assets?
The starting point of an effective security process is the identification of the information security risks for the cloud provider. Risk assessments are performed to identify the various sources of information and how the information might be breached. There are a number of different risk assessment models that exist and cloud service providers should have a process to identify information risks. After identifying risks, the company can then develop controls to mitigate those risks.

Has the cloud solution implemented documented security policies and procedures?
Based on risks identified through the risk assessment process, the cloud service provider should develop a set of policies and supporting procedures to implement necessary controls to address its risks. Ad hoc policies and procedures or those that are not documented and implemented at a cloud service provider should raise red flags. Instead, sophisticated security policies and procedures should be implemented that establish the organization's practices and are required, ultimately establishing accountability for achieving control objectives.

Does the cloud solution perform security vulnerability or penetration testing?
Penetration or vulnerability tests are scans against the company's infrastructure to determine whether there are any security vulnerabilities (for example, a critical system patch that hasn't been applied where hackers could exploit this weakness). The purpose of these types of tests are to identify where systems might be subject to internal or external attacks and to identify what measures can be taken to protect against or eliminate these threats. Companies with good security practices regularly perform these tests and take actions to respond to threats identified.

What measures have been implemented by the cloud solution to physically protect their data center?
Physically secure data centers are critical to protecting cloud systems. Cloud providers should be able to provide state-of-the-art data centers with restricted access and sufficient physical barriers to prevent unauthorized access attempts. Well-protected data centers can be very costly and many manufacturers cannot afford to provide the level of security attained by cloud providers.

What types of third-party audits are performed for the cloud solution?
There are a number of third-party audits that cloud service providers may obtain. Third-party audits provide independent assurance related to various operations of the cloud provider. Reports that are common in the cloud industry include SOC 1, SOC 2 and in some cases, SOC 3 reports, which are "Service Organization Controls" audit reports performed and signed by a certified public accountant. These reports cover different types of controls at cloud service providers. These reports can be a valuable source of information related to controls at the cloud provider.

More Stories By Tom DeCoe

Tom DeCoe is Plex Systems’ vice president of infrastructure and is responsible for defining the strategic development of the Plex Manufacturing Cloud and ensuring its technology meets and exceeds customers’ requirements to support efficient business processes in the manufacturing enterprise. He is a graduate of Central Michigan University with a BS in Computer Science and Math.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


CloudEXPO Stories
The precious oil is extracted from the seeds of prickly pear cactus plant. After taking out the seeds from the fruits, they are adequately dried and then cold pressed to obtain the oil. Indeed, the prickly seed oil is quite expensive. Well, that is understandable when you consider the fact that the seeds are really tiny and each seed contain only about 5% of oil in it at most, plus the seeds are usually handpicked from the fruits. This means it will take tons of these seeds to produce just one bottle of the oil for commercial purpose. But from its medical properties to its culinary importance, skin lightening, moisturizing, and protection abilities, down to its extraordinary hair care properties, prickly seed oil has got lots of excellent rewards for anyone who pays the price.
The platform combines the strengths of Singtel's extensive, intelligent network capabilities with Microsoft's cloud expertise to create a unique solution that sets new standards for IoT applications," said Mr Diomedes Kastanis, Head of IoT at Singtel. "Our solution provides speed, transparency and flexibility, paving the way for a more pervasive use of IoT to accelerate enterprises' digitalisation efforts. AI-powered intelligent connectivity over Microsoft Azure will be the fastest connected path for IoT innovators to scale globally, and the smartest path to cross-device synergy in an instrumented, connected world.
There are many examples of disruption in consumer space – Uber disrupting the cab industry, Airbnb disrupting the hospitality industry and so on; but have you wondered who is disrupting support and operations? AISERA helps make businesses and customers successful by offering consumer-like user experience for support and operations. We have built the world’s first AI-driven IT / HR / Cloud / Customer Support and Operations solution.
ScaleMP is presenting at CloudEXPO 2019, held June 24-26 in Santa Clara, and we’d love to see you there. At the conference, we’ll demonstrate how ScaleMP is solving one of the most vexing challenges for cloud — memory cost and limit of scale — and how our innovative vSMP MemoryONE solution provides affordable larger server memory for the private and public cloud. Please visit us at Booth No. 519 to connect with our experts and learn more about vSMP MemoryONE and how it is already serving some of the world’s largest data centers. Click here to schedule a meeting with our experts and executives.
Darktrace is the world's leading AI company for cyber security. Created by mathematicians from the University of Cambridge, Darktrace's Enterprise Immune System is the first non-consumer application of machine learning to work at scale, across all network types, from physical, virtualized, and cloud, through to IoT and industrial control systems. Installed as a self-configuring cyber defense platform, Darktrace continuously learns what is ‘normal' for all devices and users, updating its understanding as the environment changes.