taming the compliance beast in cloud

17
By Saumya Vishnoi

Upload: saumya-vishnoi

Post on 22-Jan-2018

175 views

Category:

Technology


2 download

TRANSCRIPT

Page 1: Taming the compliance beast in cloud

By

Saumya Vishnoi

Page 2: Taming the compliance beast in cloud

Currently working in FreeCharge Information Security team

Information Security profession – about 6 years of experience

Ex- PCI QSA

Audited multiple environments

Page 3: Taming the compliance beast in cloud

All the information, discussion and views

presented in the talk are

personal !!!

Page 4: Taming the compliance beast in cloud
Page 5: Taming the compliance beast in cloud
Page 6: Taming the compliance beast in cloud

Increases workload

Creates extra process

Costly

Page 7: Taming the compliance beast in cloud

Business enabler –

PCI DSS for processing card details

RBI PSS for getting and running a digital wallet

Give confidence to clients and third party

Force organizations to give security a thought

Act as baseline for security

Compliance acts as an enabler for security

Page 8: Taming the compliance beast in cloud
Page 9: Taming the compliance beast in cloud
Page 10: Taming the compliance beast in cloud
Page 11: Taming the compliance beast in cloud
Page 12: Taming the compliance beast in cloud
Page 13: Taming the compliance beast in cloud

Ensure the compliance of Cloud provider

Check and verify the services that are part of their compliance.

Include them in your third party risk assessment section

Don’t Blindly trust them !!!

Page 14: Taming the compliance beast in cloud

Not just compliance, check their Security policies as well

Regular audits and/or reports

Because they may be compliant but not Secure

Page 15: Taming the compliance beast in cloud
Page 16: Taming the compliance beast in cloud
Page 17: Taming the compliance beast in cloud

EMAIL: [email protected]: @SAUM98