Cloud Security
&
Managed Security
Services: Challenges & Opportunities
Jorge Sebastiao
COO
Outline
• Opportunities & challenges
• Approach and opportunities in cloud security
• Managed Security Services
• Enterprise
• Cloud Computing
• Conclusions & discussion
2
Cloud, Processes & Transformation
User remains biggest challenge
Growth of cloud end points
Mainframe
Minicomputer
PC
Desktop/
Internet
Mobile
Internet
1
10
100
1000
10000
100000
1000000
10000000
1950 1960 1970 1980 1990 2000 2010 2020 2030
Devices/Users(millions)
Year
Ref: ITU, Morgan Stanley Research, 2009
- Smartphone
- Tablets
- Car Electronics
-- Mobile Medicine
-- Payment Systems
-- Mobile Banking
- GPS/Navigation
- Mobile Video
- Home Entertainment
- Games
- Home Appliances
Cloud and Balance
Security &
Compliance
Convenience
& Cost saving
Cloud and complexity
Cloud is a shared environment
Cloud high profile failures
Cloud and Control
Top 10 Security Issues
1. Governance
2. Compliance
3. Trust
4. Architecture
5. Identity & Access control
6. Isolation in multi-tenancy
7. Data protection
8. Availability
9. Timely Incidence Response
10. Malware propagation
Identified top threats
1. Abuse & Evil Use of Cloud ({I,P}aaS)
2. Insecure Interfaces and APIs ({I,P,S}aaS)
3. Malicious Insiders ({I,P,S}aaS)
4. Shared Technology Issues (IaaS)
5. Data Loss or leakage ({I,P,S}aaS)
6. Account or Service Hijacking ({I,P,S}aaS)
7. Unknown Risk Profile ({I,P,S}aaS)
https://cloudsecurityalliance.org/topthreats/csathreats.v1.0.pdf
Hybrid Cloud & Security
Cloud Security
Key MSS Adoption Drivers
Deploying MSS
Security &
Compliance
Monitor & IR
• Monitoring and threat
management
• Aggregation of logs
• Anomaly detection
• alerts
Perimeter
Protection
• Managed
Firewall, UTM, IPS, Anti-
Malware, etc.
In cloud MSS
• Clean pipes
• Anti-malware, etc
• Antifraud
DOS/DDOS
mitigation
End-user/device
management
Typical Enterprise MSS setup
Importance Security Metrics
Security Metrics
Key Performance Indicators
CoBiT, Compliance, SOC
ITIL
ISO20000
ISMS
ISO27001
BCMS
ISO22301
Time Based Security
Typical Cloud MSS setup
Security - think outside the box
20
Importance of Big Data
Transform
Assess Architect
Security requires transformation
Final Thoughts
Cloud represents important opportunities & challenges
Hybrid models most practical
Security is a challenge
Consider:
– Governance
– Proactive Security
– Collaborate & consolidate expertise
– Security is a continuous skilled process
– TBS – Protection > Detection + Reaction
– Infinite time between failures vs 0 time to recovery
“Don’t bring a knife to a gun fight”
http://linkedin.com/in/sebastiao

IDC Cloud Security and Managed Services Conference Riyadh KSA