surviving the lion’s den… the lions den - igtcloud... · igtcloud meetup. about information...

33
Pitching cloud services to security folks Moshe Ferber, CCSK Onlinecloudsec.com Surviving the Lion’s den… IGTcloud Meetup

Upload: others

Post on 23-Jun-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Pitching cloud servicesto security folks

Moshe Ferber, CCSK Onlinecloudsec.com

Surviving the Lion’s den…

IGTcloud Meetup

Page 2: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

About

Information security professional for over 20 years Working on cloud strategy with the world largest software vendors Founded Cloud7, Managed Security Services provider (currently2bsecure cloud services)

Partner at Clarisite – Your customer’s eye view Partner at FortyCloud –Make your public cloud private Member of the board at Macshava Tova –Narrowing societal gaps Certified CCSK instructor for the Cloud Security Alliance. Co-Chairman of the Board, Cloud Security Alliance, Israeli Chapter

Page 3: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Cloud Computing

How the CIO see it?

Page 4: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Cloud Computing

How the End-user see it?

Page 5: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Cloud Computing

How the CFO see it?

Page 6: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Cloud Computing

And how the CISO see it?

Page 7: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Mistakes Cloud provider do #1

Page 8: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Mistakes Cloud provider do #2

Page 9: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Mistakes Cloud provider do #3

Page 10: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Mistakes Cloud provider do #4

Page 11: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

What else ciso’s don’t like

Page 12: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

AgilityAgility

What do you say… And how the CISO understand it

Page 13: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

ScalabilityScalability

What do you say… And how the CISO understand it

Page 14: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

ComplianceCompliance

What you say? How the CISO understand it

Page 15: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

ManageabilityManageability

What do you say… And how the CISO understand it

Page 16: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

ReliabilityReliability

What do you say… And how the CISO understand it

Page 17: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

So what is the ciso looking for?

Page 18: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

So, how do we create trust?

1.Transparency

2.Competency

Page 19: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Transparency

Page 20: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Transparency #1 takeout

Security in the cloud is a sharedresponsibility

Source: Trend Micro Blog

Page 21: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Transparency #2 Security Policy

Security Policy is mandatory, it should contain allaspects of how you protect your customers data.

Page 22: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Transparency #3 Audits

Don’t run away from security audits

Page 23: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Competency

Skill Design Governance

Page 24: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Skill

• Make sure your sales / pre-salesunderstand cloud security.

• Understand the standards andregulation relevant to your sector.

Page 25: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Skill #2

• Make your security building blocktangible to the customers.

Monitoring andIncident management

Application Security

Data Security

Infrastructure Security

Data Center Security

Page 26: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Understand Cloud threats & Risks

Threat RISK

LosingMoney

Theft UnsecureDoor

AttackVector

Page 27: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Cloud Attack vectors

Cloudattack

vectors

Provideradministration

Managementconsole

Multitenancy &

virtualization

Automation&

API

Chain ofsupply

Side channelattack

Insecureinstances

Page 28: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Understanding controls

Preventive

• Firewall(SecurityGroups)

• Authentication• Anti Virus• Guards

Detective

• IDS• System

monitoring• Motion

detector

Corrective

• Upgrades &Patches

• Vulnerabilityscanning

Compensatory

• DRP & Backup• Firewall logs• Reviews• Audit &

reconciliation

Page 29: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Design

Threat Security Service

Spoofing Authentication

Tampering Digital Signature, Hash

Repudiation Audit Logging

InformationDisclosure

Encryption

Denial of Service Availability

Elevation ofprivilege

Authorization

• Integrate security to yoursoftware lifecycle.

• Account for cloud specificthreats.

• Think about separation oftenants.

• Explore encryption at all layers.• Think about 3rd party access.

Page 30: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Governance

• Most security companies simplydon’t know how to do ongoingoperational security.

• If you are guarding banks data,you need Banks operationalcapabilities.

Page 31: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Questions?

Page 32: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

To wrap things up

Speak your customers lingo

Use good building blocks

Don’t hesitate to betransparent on your securitycontrols.

Cloud Security is very much about yourcustomers market sector.

Be proactive in your security, thinkahead of your customers.

Page 33: Surviving the Lion’s den… the lions den - IGTcloud... · IGTcloud Meetup. About Information security professional for over 20 years Working on cloud strategy with the world largest

Moshe Ferber

www.onlinecloudsec.com

http://il.linkedin.com/in/MosheFerber

KEEP IN TOUCH

Cloud Security Course Schedule can be find at:http://www.onlinecloudsec.com/course-schedule