IT Assurance in the Cloud–A Journey Between Trust and Obligation

There is no question that there are significant opportunities available in the cloud business. Many organizations are looking at cloud computing to increase the effectiveness of IT initiatives, reduce in-house operations cost, increase operational flexibility and generate a competitive advantage. However, like most technology changes, cloud computing presents its share of risks and challenges.

As the risks are better understood, businesses rely less on trust and put information security obligations on their cloud providers. Where security had been one of the main obstacles for cloud adoption in the past, vendors now understand the security and privacy concerns of their global customers and have adopted a business model built on enhanced security features such as encryption, and identity and access management, to name two examples. The result:  cloud services are heading to the next level of maturity.

A 2015 cloud survey  conducted by ISACA Germany and PwC (in German) found about one-third of organizations expected to achieve a better security risk profile by adopting cloud computing.

Whether we are security practitioners at the first line of defense, risk management professionals at the second line or information systems auditors at the third line, the challenges that come with cloud remain the same:  How do we achieve adequate assurance over our crown jewels in the cloud? There is no single answer, of course. In fact, we are all on a journey from trust to obligation!

Here are the five pillars of cloud security:

  • Organization
  • Technology
  • Security and data protection
  • Governance, compliance, legal and audit
  • Service management

Auditors, security or risk professionals will look at some of what these areas cover naturally. Other factors might be overlooked but are critical to successful cloud migrations and should be given special attention.

Organization
The organizational aspects of cloud computing start with the organization’s strategy for cloud adoption (e.g., what benefits does my organization expect from cloud computing?) and include human resource planning (e.g., What roles do I need to create to manage relationships with a cloud provider? Do I need to re-think my team size by shifting some of the workload to the cloud?).

This task typically comes with organizational change management activities and review of business processes (e.g., How do I need to adapt my organizational structure and business processes to maximize benefits from the cloud?).

Technology
Technology is obviously the backbone of cloud computing that challenges us on numerous aspects and should be given due consideration around interoperability and compatibility of new cloud technology with existing (legacy) systems.

Looking at the cloud holistically, it requires us to re-think the application architecture, the supporting infrastructure capability, as well as a different application development and support model.

Security and Data Protection
In most cases cloud computing entails company data leaving the trusted perimeter of the organization. This brings multiple information security and data protection challenges into the game that we need to manage.

Namely, these are internal or external cybersecurity threats that require joint attention by the cloud service provider, but the organization that promotes data to the cloud has its role to play. This is particularly true for encryption of sensitive data and preventing data loss or leakage.

By nature, cloud resources are shared resources. In consequence, identity and access management becomes very critical and many questions should be asked, such as “How are my data segregated from other customers’ data?” or “Who has access to my data?” With cloud computing typically comes considerations about the geolocation of data. This has a direct legal impact on data protection.

In addition, we should consider business continuity management as part of security to reduce the impact of a negative event on our business.

Governance, Compliance, Legal and Audit
Vendors need to be actively managed. This is particularly true for cloud service providers. It puts additional governance, risk and compliance factors onto the agenda. First of all, this includes the legal requirements of having the right contracts, service levels and data protection specifications implemented. This typically depends on the industry and jurisdiction of the consumer of cloud computing.

Secondly, the right structures need to be in place to enable efficient governance that is a shared responsibility between the service provider and the customer of the services.

From a risk perspective, it is important to cover terms for sub-cascading outsourcing to another third party as well as the ability to audit the cloud service provider from end to end.

Service Management
Finally, we talk about outsourcing of services. Therefore, an ongoing effort to actively manage contracts and service levels are key. A cloud service provider should be assessed based on its ability to integrate service management with the consumer to manage availability of the service including seamless incident/problem management processes.

Successful service management also includes capacity management to handle the load of multiple customers on a shared environment.

Kraft will present IT Assurance in the Cloud – A Journey Between Trust and Obligation at EuroCACS in Dublin 30 May-June 1 2016.

Matthias Kraft, CISA, CISM, CGEIT, CRISC

[ISACA Now Blog]

Cloud Computing: A Little Less Cloudy

Today, consumers have an increasing interest in implementing cloud solutions to process and store their data. They are looking to take advantage of the benefits provided by cloud computing, including flexibility, cost savings, and availability. Fortunately, there are many cloud solutions available to consumers, touting cloud computing features such as multi-tenancy, virtualization, or increased collaboration. But is it really a cloud service?

With the rapid growth of these types of solutions, consumers and other interested organizations want to identify whether a service is actually a cloud service.

In actuality, there is such thing as a cloud service. It has a definition and we have seen federal agencies require cloud service providers to justify why their service is considered a cloud service.

The five essential cloud characteristics are based on the National Institute of Standards and Technology’s (NIST) definition of cloud computing in Special Publication (SP) 800-145. Here,NIST defines cloud computing as a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.

According to NIST SP 800-145, a cloud service employs all of the following five characteristics:

  1. On-demand self-service – A consumer can unilaterally provision computing capabilities, such as server time and network storage, as needed automatically without requiring human interaction with each service provider.
  2. Broad network access – Capabilities are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (e.g., mobile phones, tablets, laptops, and workstations).
  3. Resource pooling – The provider’s computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand. There is a sense of location independence in that the customer generally has no control or knowledge over the exact location of the provided resources but may be able to specify location at a higher level of abstraction (e.g., country, state, or datacenter). Examples of resources include storage, processing, memory, and network bandwidth.
  4. Rapid elasticity – Capabilities can be elastically provisioned and released, in some cases automatically, to scale rapidly outward and inward commensurate with demand. To the consumer, the capabilities available for provisioning often appear to be unlimited and can be appropriated in any quantity at any time.
  5. Measured service – Cloud systems automatically control and optimize resource use by leveraging a metering capability at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and consumer of the utilized service.

Whether you are a cloud service provider, consumer, or other interested party, it is important to identify how the cloud service offering meets each of the five essential characteristics. For example, cloud service providers in the FedRAMP authorization process usually document how their service meets each of the five essential cloud computing characteristics in their System Security Plan (SSP).

It goes without saying that regardless of whether or not a service meets the definition of a cloud service, the cloud service provider and consumer must always plan and prepare for the security risks associated with providing or using a the cloud service and the types of data the cloud service will consume. The cloud service provider is responsible for selecting a security program framework to implement security controls specific for cloud environments and the data protection requirements of their customers. Equally, the consumer must be fully aware of the data they plan to process and/or store with the cloud service and their responsibilities to protect that data.

Christina McGhee, Manager/FedRAMP Technical Lead, Schellman

[Cloud Security Alliance Blog]

Cloud Security Alliance Asia Pacific Hosts Its 5th Annual CSA APAC Summit

SINGAPORE – May 11, 2016 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, announced today that it hosted its 5th annual CSA APAC Summit in Singapore, beginning May 3rd. The weeklong event was attended by thought leaders, policy and decision makers representing key industry organizations, cloud customers, and the R&D community. Attendees represented both end-user and industry viewpoints and provided networking and business opportunities. The event was a curtain raiser for IDA’s CloudAsia 2016, which occurred May 3-5 also in Singapore.

The keynote presentations this year featured:

  • Khoong Hock Yun, Assistant Chief Executive Officer (Development) and Chief Data Officer of Infocomm Development Authority of Singapore (IDA)
  • Daniele Cattedde, Chief Technology Officer of Cloud Security Alliance
  • David Shearer, CEO of (ISC)2
  • Dr. Meng-Chow Kang, Chief Information Security Officer, APJC Region of Cisco Systems, Inc.
  • Evan Dumas, Head, Emerging Technologies APAC, Middle East, & Africa of Check Point
  • Martin Leo, Executive Director, Morgan Stanley Investment Management
  • Todd Partridge, Director of Product Marketing of Intralinks Holdings, Inc
  • Wally Lee, Cybersecurity Architect, Cybersecurity Global Practice of Microsoft

A complete agenda for CSA’s APAC Summit can be found here.

This year’s event also included a number of key panel presentations focused on emerging trends and issues in cloud computing:

  • “Overcoming the Top Threats to Cloud Computing” by Eric T. Ashdown of Cyber Security Managing Partner of Ridge Partners LLC, Kawin Boonyapredee of Qualys, Mandar Bale of FireEye & Benildus Nadar of Deep Identity chaired by Luciano “J.R.” Santos, Executive Vice President of Research of Cloud Security Alliance
  • “Cloud and the Enterprise 2016” chaired by Jimmy Sng, Partner, of PricewaterhouseCoopers with panelists across Information Security Manager of Waikato District Health Board, Audit Director for Technology of Australia and New Zealand Banking Group, Technical Advisor of Asia Pacific of (ISC)2 & Security Consultant at Hewlett-Packard Enterprise

The theme of this year’s summit centered on how the future of information security lies in the cloud. An earlier CSA survey conducted identified mobile security as an area of concern. CSA’s Mobile Application Security Testing (MAST) working group, which strives to create a more secured cloud ecosystem to protect mobile applications, will be releasing the Mobile Application Security Testing (MAST) whitepaper after going through 4 months of public review process. Co-chair Keng Lee discussed this whitepaper during the summit. The whitepaper will also be used in the development of a new certification scheme, CSA STAR Mobile that will test and certify mobile applications. There may be additional scope of work that will address application store security issues among others.

CSA also hosted its 4th annual APAC Chapter Leadership Workshop on May 4, an annual event that provides a platform to report Chapter activities and progress and work plan for the year. 25 Chapters out of 31 across Asia Pacific participated in this workshop to discuss the Chapter strategies moving forward for this year.

On May 5, CSA hosted its 1st in-person CSA STAR Certification Summit. This Summit brought Certification Bodies and representatives from Governments from Asia Pacific, Europe and Americas together to discuss the future of cloud computing certification and assurance, while also addressing current challenges on cloud computing security and privacy assurance and compliance. This invitation only event focused on building strategies on CSA National Certification approach and roadmap.

The CSA CXO luncheon also occurred on May 5. Senior government officials and corporate decision makers participated in the quarterly lunch, which is theme based and facilitated by a research analyst. The takeaways received from the luncheon create continuous touch points until the next luncheon.

For more information on the CSA APAC Summit and other line of events, please contact csa-apac-info@cloudsecurityalliance.org.

About Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products. CSA’s activities, knowledge and extensive network benefit the entire community impacted by cloud — from providers and customers, to governments, entrepreneurs and the assurance industry — and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem.

Contact

Kari Walker for the CSA
ZAG Communications
703.928.9996
kari@zagcommunications.com

[Cloud Security Alliance Research News]

Regulatory Management and Measurement Rules

The ISO 31000:2009, Basel III recommendations, the EU Capital Requirement Directives and the Own Risk and Solvency Assessment (ORSA)/Forward Looking Assessment of Own Risk (FLAOR) processes of Solvency II Directives profoundly affect the financing and the insurance of companies in all business sectors and local authorities.

US companies use US National Association of Insurance Commissioners (NAIC) recommendations based on the fundamental principles of ORSA; EU firms refer to FLAOR recommendations; and companies in other countries (e.g., Canada, Japan, China) refer to Solvency II as an international best practice.

This regulatory change began in June 2008 when the American International Group (AIG) faced a financial disaster. The risk maps and risk registers in place, usually under Basel II, were designed to capture incident data to calculate the relative value at risk (VaR) using a stochastic approach (statistics and probability). In this approach, VaR equals unexpected loss. Following the subprime mortgage crisis in 2008, clause 5 of ISO 31000:2009 recommended risk treatment from the point of view of the corporate manager and not from the point of view of the stochastic engineer. It is the cost accounting process of the absolute VaR (VaR = expected loss + unexpected loss) taking into account the risk appetite tolerance threshold.

In March 2012, as part of the NAIC Solvency Modernization Initiative (SMI), the NAIC voted to adopt a significant new addition to US insurance regulation:  ORSA. The manner of the calculations used in an ORSA report was left to the discretion of each insurer. This led to variations in the measurement techniques of ORSA among companies. The insurers were concerned because a hard and fast, one-size-fits-all solution does not exist. The output was specific to the company, and a set of documents should demonstrate the results of the self-assessment and understanding of own-risks.

The Information Technology-Investor Relationship Management (IT-IRM) proposes a standardized, logical process to the ORSA measurement. Our recent Journal article covers how this IT application makes ORSA a logical assessment based on real-time data, making risk controllable and assessable using the same base criteria for economic capital and the same indicators, factors or the causes as the determinants of operational risk.

Read Simon Grima, Robert W. Klein, Ronald Zhao, Frank Bezzina and Pascal Lélé’s recent Journal article:
Strengthening Value and Risk Culture Using a Real-time Logical Tool,” ISACA Journal, volume 3, 2016.

[ISACA Journal Author Blog]

Networking in an Increasingly Stable Environment

The economy continues to improve, at least from an audit and IT audit perspective. Between 2011 and now, the job market strengthened significantly. Five years ago, within 48 hours of posting a job through search sites, I would have 5-15 viable candidates. Usually I never had to post on job search sites; someone in my professional network would ping me with interest. Now, I will post on searches and barely get a handful of candidates after a month. The economy has improved; maybe not to early 2000 numbers, but the market is doing very well.

The good job market can lull people into a networking slumber. When the recession hit 7+ years ago, I heard many candidates say, “I never thought I would be in this situation; I wish I had kept up with my network.” Every job market is cyclical, and you do not know when you might need to tap into your network, regardless of your field.

Networking Activities

Professional Associations:  Stay involved in all professional associations relevant to your career. It may be difficult to attend every meeting, but choose a few that pique your interest, put them on your calendar and commit to paying your membership. Additionally, take advantage of volunteer opportunities.

Key Contacts:  Schedule at least two business lunches/coffees per week, to keep in touch with the contacts most relevant to your success. Connect with that group at least twice a year.

Recruiters:  Do not ignore calls from executive recruiters. Good recruiters want to establish a relationship with you, regardless if you are looking or not. Pick a handful of recruiters you trust and stay abreast of the job market.

LinkedIn:  This is easily discounted when you are comfortable in your job. Staying active on LinkedIn expands your network and keeps you connected with professional contacts. Do this twice a day—put it on your calendar for 10 minutes first thing in the morning and 10 minutes after lunch.

  • LinkedIn Optimization
    LinkedIn is Facebook for professionals. If you are not on LinkedIn, your relevancy is minimized to everyone but your current role. Every professional must have a LinkedIn profile, know how to use it and understand how to optimize its effectiveness. Here are a few LinkedIn tips
  • What Is LinkedIn for?
    LinkedIn enables users to connect and share content with other professionals, including colleagues, potential employers and business partners. However, many users make LinkedIn personal, including birth announcements, surgery updates, marriage announcements, etc. Keep LinkedIn business-related and professional, which can be a fine line. Remember, the more professional you keep it, the less unprofessional you can look.
  • Professional Email Address
    Many people use a personal address as their main contact email, which is acceptable. However, people do not realize how unprofessional their email address may be. Unprofessional email addresses I’ve seen on Linkedin include transam2002, joshistheman and rocketsfan2661. As a recruiter, this is something I always look at. If someone cannot determine if their email address is unprofessional, I tend to scrutinize their profile in much more detail.
  • Customize Your Profile URL
    When my kids were born, I bought their namesake web sites and created their personal emails. At the time I thought it was a good idea, but as the kids have gotten old enough to use email, this has become a wonderful idea. The kids really like having a simple email address. The same is true for your LinkedIn URL. If you don’t have a profile, go claim it. If you do, make sure your URL is personalized and clean, like this:  https://www.linkedin.com/in/dannymgoldberg.LinkedIn is a wonderful social networking tool, even for introverts. Go claim your profile and start with the above steps.

All of these networking activities can expand your network and help you stay in touch with your industry. Remember:  you don’t want to ever have to say “I wish I would have….”

Danny Goldberg, CISA, CGEIT, CRISC, is founder of GoldSRD, a provider of high-quality, interactive internal audit training. Goldberg will present a free webinar titled, Becoming the Boss: 10 Key Steps for Advancing to Executive Management, 11AM (CDT), Thursday, 19 May. Sign up here.

Danny Goldberg, CISA, CGEIT, CRISC, founder, GoldSRD

[ISACA Now Blog]

English
Exit mobile version