Home > Information Security Tips > Network security tips > Maintaining security after a cloud computing implementation
Security UK Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

Maintaining security after a cloud computing implementation


Michael Cobb, Contributor
Rating: --- (out of 5)

You've successfully migrated your organization's selected applications and data into the cloud, and everyone has said what a great job you've done. But you and I both know the task of maintaining the security of these apps and data has only just begun. In this tip, I'll review which technologies and processes must be initiated, monitored and secured after a cloud computing implementation or initiative is up and running.

IAM
Cloud computing turns us all into remote workers, which makes identity and access management (IAM) one of the key challenges after a cloud computing move. It is important to have robust lifecycle management regarding users and user access so that user accounts, credentials and access rights are always relevant and up to date, including disabling an account when an employee leaves. Also look to initiate an IAM strategy that can make full use of federated identity management, which enables users to securely access data or systems across autonomous secu...


RELATED CONTENT
Network security tips
How to prevent iPhone spying: mobile phone management tips
Cloud-based services require stalwart business continuity plans
How to perform an Active Directory health check
Look into SIEM services to cut costs, comply with PCI DSS, HIPAA
Windows management tips: How to backup and restore Active Directory
Cloud computing compliance: Exploring data security in the cloud
Configuring a Windows network infrastructure: Wired, wireless security
How to use Google Webmaster tools to help protect your site
How to set your baseline with host integrity monitoring software
A closer look at Internet Explorer 8 security features

Security for Cloud Computing and Hosted Services
Social networking risks, benefits for enterprises weighed by RSA panel
Microsoft's Charney details new botnet protection, IdM technology at RSA
Cloud-based services require stalwart business continuity plans
Cloud security issues, targeted attacks to be hot-button topics at RSA
Cloud Security Alliance releases top cloud computing security threats
Cloud computing compliance: Exploring data security in the cloud
Preparing the network for a cloud computing implementation
Cloud Security Alliance releases updated guidance
Cloud computing data security starts with internal strategy, experts say
Secure cloud computing: a contradiction in terms?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


rity domains.

More specifically, consider introducing single sign-on (SSO) for enterprise applications and leveraging this architecture to simplify cloud provider implementations. A move to the cloud will appear far more seamless to your users if they are already used to SSO, and it'll make managing trust across different types of cloud services less onerous. You will also have logged baseline data to help you monitor and gauge changes due to cloud activity.

A SSO product should use one of the common standards for implementing federation, such as Security Assertion Markup Language (SAML) and Liberty Alliance ID-FF. These standards extend existing access and identity policies from the internal network beyond the firewall and out to the cloud, while still enforcing the appropriate authentication strength mandated by your information protection and data classification policies.

Bandwidth
The increased Internet usage that cloud computing brings also increases the increased risk of network congestion bottlenecks. Web-based applications are extremely latency-sensitive, many barely functioning if the network is too busy. Downtime or slow processing frustrates employees and can lead to breaches in policy. Slow file or data transfers, for example, can lead workers to use alternative methods that may be far less secure and break security policy rules.

One answer to this problem is to deploy a WAN optimization product, which is designed to ease enterprise application traffic on the network by improving application traffic management and eliminating redundant transmissions. Products such as the Citrix NetScaler from Citrix Systems Inc. offer a Web application firewall and combine traffic management through Layer 4-7 load balancing. Other WAN optimization vendors include Riverbed Technology Inc. and Blue Coat Systems Inc.

Firewalls
Connections between the internal network and the cloud should certainly be encrypted; sending any sensitive or mission-critical data back and forth in the clear over the Internet is like offering attackers an invitation to steal the data. As a network engineer, ensure network devices can handle the processor-intensive, public-key encryption algorithms involved in SSL-encrypted communications. SSL accelerator cards or proxies that handle all SSL operations may need to be added to the infrastructure. However, encryption alone won't stop malware and other network attacks. It's important, therefore, to upgrade the firewalls protecting your internal network so that they can inspect SSL traffic. Encryption should ideally work in union with data loss prevention (DLP) products, which will classify and monitor data while enforcing policies.

Audit
Another important task after a cloud computing implementation will be to conduct an audit of all security policies to ensure they remain relevant. Also review, update and test disaster recovery and business continuity plans and procedures. Processes, and more importantly, people's roles, will have changed now that cloud computing infrastructure is a part of day-to-day systems management. The internal IT team will certainly need to work closely with the cloud provider so each understands the other's responsibilities within the context of the continuity plan, including which aspects of any recovery will be handled by whom. Being prepared for service disruptions will reduce the severity of any event.

Finally, don't take statements in your provider's SLA for granted. Check that it does perform backups and patch systems within the agreed timeframes. You should certainly request a copy of the findings of its own audits and ensure that any recommendations have been implemented. Engaging in constructive dialogue will make addressing both parties' security issues a lot easier, so make sure you are in regular contact, particularly during any application or system upgrades. This communication will help prevent changes from adversely affecting your compliance with relevant industry or government regulations.

About the author:
Michael Cobb, CISSP-ISSAP is the founder and managing director of Cobweb Applications Ltd., a consultancy that offers IT training and support in data security and analysis. He co-authored the book IIS Security and has written numerous technical articles for leading IT publications. Mike is the guest instructor for several SearchSecurity.com Security Schools and, as a SearchSecurity.com site expert, answers user questions on application security and platform security.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.co.UK.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



UK Data Security Solutions: Data Privacy, Identity Theft, Data Loss
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts