Welcome!

@CloudExpo Authors: Elizabeth White, William Schmarzo, Liz McMillan, Stefan Bernbo, Yeshim Deniz

Related Topics: @CloudExpo, Java IoT, Microservices Expo, Agile Computing, Cloud Security, SDN Journal

@CloudExpo: Article

"Continuous" Does Not Equal Real Time

Continuous monitoring is enough for compliance, but ISN’T enough for securing data

Every 4,000 miles or so I bring my car into have the oil changed, the brakes checked and tires rotated. Why? Because I know if I leave it to chance, at some point down the road something much more devastating will affect the car. Many of us follow this simple preventive best practice.

Then why is it major corporations and modest enterprises alike wait until their security is breached to address growing concerns of data theft, private information leakage or worse? Many of these companies spend hundreds of thousands of dollars in various security initiatives (especially those bound by a regulatory compliance agency), but still succumb to breaches that cost on average 3.8 million dollars (Ponemon Institute figure) per occurrence to address.

Two instances dropped into my in box this week, a medical center in Long Beach, California and a Medicaid office in New York State both experienced similar types of breaches that, in my opinion, were completely preventable.

It boils down to continuous monitoring...and that practice doesn't go far enough.

Continuous monitoring is the cornerstone of many compliance mandates. You find it in HIPAA, PCI, FISMA, etc. Something--usually an archival solution gathering sys-log files—must collect records of every event that touches a network perimeter. For a medium size health care facility, that could be more than 500 events per second. For larger companies, like the Long Beach Medical Center and Office of Medicaid Inspector General, the likelihood of continuous activity is 5X that amount. That's a lot of lines of code to comb through to find that breach.

Many hospitals and health care organizations are under great strain to maintain certain security and privacy protocols because of these compliance laws. They spend a great deal of time and money in security, but way too often, we hear of a breach by some facility or that company. There must be a disconnect somewhere.

I think the disconnect is how the term continuous monitoring is defined and applied as a preventive best practice. Mandates state that systems must be continuously monitored, but it can be vague in terms of how often those system logs are reviewed. I know of some organizations that only do it once per month. I know others that don’t do it that often. This is not to say that there is no vigilance out there, but the overarching issue is that no matter how often sys-logs are reviewed, it is done in a rear-view mirror. These are events that have already occurred. If there was a breach or any kind of suspicious or malicious activity, the horse has already left the barn. The damage is done.

Of course continuous monitoring is important. But it doesn’t go far enough. It is not truly preventive. The key is not continuous monitoring, but real-time monitoring--24/7/365.

But many companies don’t have the man-power, the expertise or the technology space to achieve this. And those that do, there is the invitation of extra costs. So they ask, if I am IN compliance, what is my motivation to incur more costs and expend more resources? Anyone who has ignored the red warning light on a dashboard saying it’s time for an oil change might be able to tell you. And so might the auditors dealing with the Long Beach Medical Center and New York Medicaid office breaches. You might be in compliance by the letter of the law, but not it's spirit.

However, those that say they need to spend more money and resources aren’t looking to the cloud. They might not be aware that the SIEM and Log Management developed, delivered and managed from the cloud exponentially increase their security capabilities while significantly limiting costs and headcount. They might not be aware that security-as-a-service is that real-time monitoring enhancement in the “sky” that immediately creates an alert the moment suspicious activity occur and initiate preventive protocols to better safeguard private records. They might not be aware that it can stitch together separate and disparate data silos under a centralized management portal to make spot reviewing, audit reporting and day-to-day maintenance much easier. Honestly if you can accomplish better results for less budget, then it is your duty to at least perform due diligence and explore the option.

This is important in terms of the root causes of the breaches I mentioned earlier. In both cases, the breaches seem to stem from internal sources using unregulated email.

How would real-time monitoring from the cloud have prevented this? Simple, if approached holistically. What is necessary is that credentialing and provisioning functions such as those found in identity management (IDaaS) and enterprise access control (access management) be leveraged with Log Management and correlated through SIEM (intrusion detection, alerting). It seems like trying to take a drink from a fire hose, but once all the data is leveraged and all the unique protocols, escalations, provisioning, rights and rules are centralized, then real-time monitoring can assess (removing all the false-positives and white noise) true threats to the network and take appropriate action…BEFORE the damage is done.

So my call to action is that it is time to reassess what it means to continuously monitor. And that means to find ways to start monitoring in real time and applying preventive and PROACTIVE best practices.

Kevin Nikkhoo

www.cloudaccess.com

More Stories By Kevin Nikkhoo

With more than 32 years of experience in information technology, and an extensive and successful entrepreneurial background, Kevin Nikkhoo is the CEO of the dynamic security-as-a-service startup Cloud Access. CloudAccess is at the forefront of the latest evolution of IT asset protection--the cloud.

Kevin holds a Bachelor of Science in Computer Engineering from McGill University, Master of Computer Engineering at California State University, Los Angeles, and an MBA from the University of Southern California with emphasis in entrepreneurial studies.

@CloudExpo Stories
Cloud applications are seeing a deluge of requests to support the exploding advanced analytics market. “Open analytics” is the emerging strategy to deliver that data through an open data access layer, in the cloud, to be directly consumed by external analytics tools and popular programming languages. An increasing number of data engineers and data scientists use a variety of platforms and advanced analytics languages such as SAS, R, Python and Java, as well as frameworks such as Hadoop and Spark...
Automation is enabling enterprises to design, deploy, and manage more complex, hybrid cloud environments. Yet the people who manage these environments must be trained in and understanding these environments better than ever before. A new era of analytics and cognitive computing is adding intelligence, but also more complexity, to these cloud environments. How smart is your cloud? How smart should it be? In this power panel at 20th Cloud Expo, moderated by Conference Chair Roger Strukhoff, paneli...
"Loom is applying artificial intelligence and machine learning into the entire log analysis process, from start to finish and at the end you will get a human touch,” explained Sabo Taylor Diab, Vice President, Marketing at Loom Systems, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
The current age of digital transformation means that IT organizations must adapt their toolset to cover all digital experiences, beyond just the end users’. Today’s businesses can no longer focus solely on the digital interactions they manage with employees or customers; they must now contend with non-traditional factors. Whether it's the power of brand to make or break a company, the need to monitor across all locations 24/7, or the ability to proactively resolve issues, companies must adapt to...
Cloud promises the agility required by today’s digital businesses. As organizations adopt cloud based infrastructures and services, their IT resources become increasingly dynamic and hybrid in nature. Managing these require modern IT operations and tools. In his session at 20th Cloud Expo, Raj Sundaram, Senior Principal Product Manager at CA Technologies, will discuss how to modernize your IT operations in order to proactively manage your hybrid cloud and IT environments. He will be sharing bes...
A look across the tech landscape at the disruptive technologies that are increasing in prominence and speculate as to which will be most impactful for communications – namely, AI and Cloud Computing. In his session at 20th Cloud Expo, Curtis Peterson, VP of Operations at RingCentral, highlighted the current challenges of these transformative technologies and shared strategies for preparing your organization for these changes. This “view from the top” outlined the latest trends and developments i...
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend 21st Cloud Expo October 31 - November 2, 2017, at the Santa Clara Convention Center, CA, and June 12-14, 2018, at the Javits Center in New York City, NY, and learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
@DevOpsSummit at Cloud Expo taking place Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center, Santa Clara, CA, is co-located with the 21st International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is ...
"We are a monitoring company. We work with Salesforce, BBC, and quite a few other big logos. We basically provide monitoring for them, structure for their cloud services and we fit into the DevOps world" explained David Gildeh, Co-founder and CEO of Outlyer, in this SYS-CON.tv interview at DevOps Summit at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
Join us at Cloud Expo June 6-8 to find out how to securely connect your cloud app to any cloud or on-premises data source – without complex firewall changes. More users are demanding access to on-premises data from their cloud applications. It’s no longer a “nice-to-have” but an important differentiator that drives competitive advantages. It’s the new “must have” in the hybrid era. Users want capabilities that give them a unified view of the data to get closer to customers and grow business. The...
For organizations that have amassed large sums of software complexity, taking a microservices approach is the first step toward DevOps and continuous improvement / development. Integrating system-level analysis with microservices makes it easier to change and add functionality to applications at any time without the increase of risk. Before you start big transformation projects or a cloud migration, make sure these changes won’t take down your entire organization.
Artificial intelligence, machine learning, neural networks. We’re in the midst of a wave of excitement around AI such as hasn’t been seen for a few decades. But those previous periods of inflated expectations led to troughs of disappointment. Will this time be different? Most likely. Applications of AI such as predictive analytics are already decreasing costs and improving reliability of industrial machinery. Furthermore, the funding and research going into AI now comes from a wide range of com...
"When we talk about cloud without compromise what we're talking about is that when people think about 'I need the flexibility of the cloud' - it's the ability to create applications and run them in a cloud environment that's far more flexible,” explained Matthew Finnie, CTO of Interoute, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
Internet of @ThingsExpo, taking place October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 21st Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The Internet of Things (IoT) is the most profound change in personal and enterprise IT since the creation of the Worldwide Web more than 20 years ago. All major researchers estimate there will be tens of billions devic...
SYS-CON Events announced today that MobiDev, a client-oriented software development company, will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place October 31-November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. MobiDev is a software company that develops and delivers turn-key mobile apps, websites, web services, and complex software systems for startups and enterprises. Since 2009 it has grown from a small group of passionate engineers and business...
SYS-CON Events announced today that GrapeUp, the leading provider of rapid product development at the speed of business, will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place October 31-November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Grape Up is a software company, specialized in cloud native application development and professional services related to Cloud Foundry PaaS. With five expert teams that operate in various sectors of the market acr...
What's the role of an IT self-service portal when you get to continuous delivery and Infrastructure as Code? This general session showed how to create the continuous delivery culture and eight accelerators for leading the change. Don Demcsak is a DevOps and Cloud Native Modernization Principal for Dell EMC based out of New Jersey. He is a former, long time, Microsoft Most Valuable Professional, specializing in building and architecting Application Delivery Pipelines for hybrid legacy, and cloud ...
SYS-CON Events announced today that Ayehu will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on October 31 - November 2, 2017 at the Santa Clara Convention Center in Santa Clara California. Ayehu provides IT Process Automation & Orchestration solutions for IT and Security professionals to identify and resolve critical incidents and enable rapid containment, eradication, and recovery from cyber security breaches. Ayehu provides customers greater control over IT infras...
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend 21st Cloud Expo October 31 - November 2, 2017, at the Santa Clara Convention Center, CA, and June 12-14, 2018, at the Javits Center in New York City, NY, and learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
21st International Cloud Expo, taking place October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy. Me...