trust in the cloud

31
1 © Copyright 2011 EMC Corporation. All rights reserved. Trust in the Cloud Sam Curry Chief Technical Officer (GTM) RSA, the Security Division of EMC Copyright © 2011 EMC Corporation. All rights reserved.

Upload: rajesh-nambiar

Post on 12-Jan-2015

382 views

Category:

Technology


2 download

DESCRIPTION

Trust in the Cloud

TRANSCRIPT

Page 1: Trust in the Cloud

1 © Copyright 2011 EMC Corporation. All rights reserved.

Trust in the Cloud

Sam Curry Chief Technical Officer (GTM) RSA, the Security Division of EMC

Copyright © 2011 EMC Corporation. All rights reserved.

Page 2: Trust in the Cloud

2 © Copyright 2011 EMC Corporation. All rights reserved.

Organizations around the world have high hopes for the cloud’s

ability to transform IT infrastructures, applications, and information

management. They truly believe it

can revolutionize business.

But, before they can trust that the cloud is safe for

real business, they need a secure foundation of dynamic controls and trustworthy measurement.

Trust in the Cloud: Proof Not Promises

Page 3: Trust in the Cloud

3 © Copyright 2011 EMC Corporation. All rights reserved.

Challenges for Trust in the Cloud

Sustaining Compliance in an environment with numerous and complex requirements

Enabling Business growth and evolving eGRC needs

Resource Constraints

Improving Operational and IT Effectiveness Acquiring skills,

knowledge and expertise

Page 4: Trust in the Cloud

4 © Copyright 2011 EMC Corporation. All rights reserved.

Increasing Compliance Requirements

4

PCI DSS SOX Regulation

We made it through SOX, then PCI. But I’m faced with more and more

regulations. We need a more efficient way to manage compliance with multiple

regulations and standards. ”

State, Federal & International

Privacy Mandates

Forecast Calls for

More Regulation

Page 5: Trust in the Cloud

5 © Copyright 2011 EMC Corporation. All rights reserved.

Negative Consequences of Inadequate GRC

Lack of consensus leading to

underfunded initiatives

“ ”

Attrition and missed deadlines “ ”

Higher Implementation

costs and solution performance

issues

Reduced Operational effectiveness with inefficient workflows and processes

“ ”

Potential for failed audits and

assessments

“ ”

Page 6: Trust in the Cloud

6 © Copyright 2011 EMC Corporation. All rights reserved.

Implications of Challenges

Security and compliance

concerns stall the adoption of virtualization

Missing opportunity for “better than physical”

security

CISOs need to manage security and compliance

across virtual and physical IT

Page 7: Trust in the Cloud

7 © Copyright 2011 EMC Corporation. All rights reserved.

eGRC Strategy can Help

7

Achieve Consensus

Business Process Automation

Clear Priorities

ROI

Page 8: Trust in the Cloud

8 © Copyright 2011 EMC Corporation. All rights reserved.

Business Impact without eGRC

Compliance initiatives are tackled as individual projects

“ ”

Managers struggle to prioritize resources to mitigate risks and deficiencies based on risk exposure.

Compliance data scattered across multiple silos

“ ”

Resources are wasted manually collecting and re-assembling data rather than analyzing the impact of the data on the business

”Business is assessed multiple times for the same requirements

Page 9: Trust in the Cloud

9 © Copyright 2011 EMC Corporation. All rights reserved.

Business Outcomes Business Impacts

Solution Outcomes

Transparency and accountability: Knowing the status or exceptions and unresolved issues

Threats are identified and remediation actions are easily prioritized and tracked

Partnerships and consistency across business silos

Isolated data is transformed into sustainable processes

Compliance initiatives are tackled as individual projects

“ ”

Managers struggle to prioritize threats by their potential impact to the business.

Compliance data scattered across multiple silos

“ ”

Policy exceptions go untracked and pose risk to the business

Ask once, Answer Many: Reduction or elimination of redundant assessments

9

Visibility Collaboration Accountability Automation Efficiency

Compliance reporting is stored in spreadsheets and represent one point-in-time

Page 10: Trust in the Cloud

10 © Copyright 2011 EMC Corporation. All rights reserved.

Enabling the Cycle of Risk and Compliance

Remediate Findings and Manage Exceptions

Consolidate and Visualize

Compliance Efforts

Prioritize Deficiencies and

Risks

10

Document Your Control Framework and Identify Risks

Page 11: Trust in the Cloud

11 © Copyright 2011 EMC Corporation. All rights reserved.

Enabling GRC

11

Page 12: Trust in the Cloud

12 © Copyright 2011 EMC Corporation. All rights reserved.

The Case for eGRC Strategy Planning

Applications Information Infrastructure

Databases

Operations

Personnel Procedures Workflow Management

Business (Finance & Legal)

IT & Technology

Laws Regulations Business Optimization

eGRC Strategy Planning aligns requirements

across organizational functions with different

and sometimes competing or conflicting

priorities

Page 13: Trust in the Cloud

13 © Copyright 2011 EMC Corporation. All rights reserved.

Bringing in the Business Context

13

Business Domains

eGRC facilitates the processes, information, technology and people required to recognize

context that enables business decisions

BUSINESS DRIVERS OPERATIONAL

INFRASTRUCTURE

Applications

Databases

Devices

Workstations

Vendors

Information

Customers

Regulations

Business Objectives

Threats

Laws

Legal

IT

Finance

Operations

Page 14: Trust in the Cloud

14 © Copyright 2011 EMC Corporation. All rights reserved.

Success Metrics

14

Where before we managed work in two or three places, with RSA Archer you have one place to

manage all of your work. People are completing assessments and mitigating risks,

not focusing on administrative tasks. ”

Time to prepare monthly reporting

Time to demonstrate compliance

with new regulations

# regulatory requirements

met

# closed findings

Decreasing risk of

regulatory audit fines

Page 15: Trust in the Cloud

15 © Copyright 2011 EMC Corporation. All rights reserved.

Achieving Trust

Right Information Right People Trusted Infrastructure

Page 16: Trust in the Cloud

16 © Copyright 2011 EMC Corporation. All rights reserved.

Realizing This Goal Has Become Exponentially Harder

Information Grows

Access Points Proliferate

Risks Multiply

Infrastructure Evolves

Page 17: Trust in the Cloud

17 © Copyright 2011 EMC Corporation. All rights reserved.

The Result?

A dangerous void of trust has

opened up, standing squarely

between organizations and

their ability to reap the cloud’s

well documented benefits.

Page 18: Trust in the Cloud

18 © Copyright 2011 EMC Corporation. All rights reserved.

What’s Needed: Proof

Auditors Regulators

Management

Page 19: Trust in the Cloud

19 © Copyright 2011 EMC Corporation. All rights reserved.

Facets of Multi-Tenancy

Trusted Multi-tenancy model is built on the following six foundational elements: • Secure separation • Service assurance • Security and compliance • Availability and data protection • Tenant management and control • Service provider management and control

Page 20: Trust in the Cloud

20 © Copyright 2011 EMC Corporation. All rights reserved.

Solving the Trust Equation

Page 21: Trust in the Cloud

21 © Copyright 2011 EMC Corporation. All rights reserved.

Inspect and Monitor…

Page 22: Trust in the Cloud

22 © Copyright 2011 EMC Corporation. All rights reserved.

Using the CSA domains

Cloud Architecture

Governance and Enterprise Risk Management

Legal and Electronic Discovery

Compliance and Audit

Information Lifecycle Management

Portability and Interoperability

Security, Bus. Cont,, and Disaster Recovery

Data Center Operations

Incident Response, Notification, Remediation

Application Security

Encryption and Key Management

Identity and Access Management

Virtualization

Cloud Security Alliance’s 13 domains of focus for cloud computing

Assessing Service Provider Compliance

Page 23: Trust in the Cloud

23 © Copyright 2011 EMC Corporation. All rights reserved.

In Fact…

The cloud presents

opportunities to strengthen

information security and

streamline compliance

beyond anything we’ve

ever seen before.

Page 24: Trust in the Cloud

24 © Copyright 2011 EMC Corporation. All rights reserved.

Virtualization Transforms Control & Visibility

Page 25: Trust in the Cloud

25 © Copyright 2011 EMC Corporation. All rights reserved.

Policies Regulations Best Practices

Built-in and Automated

Page 26: Trust in the Cloud

26 © Copyright 2011 EMC Corporation. All rights reserved.

What’s Needed

Synergy of expertise

We’ve integrated our domain

expertise to see what others don’t see and to create

new value.

Power of virtualization

Our deep insight into the virtual layer greatly

enhances the visibility and

control possible in the cloud.

Proof through verification

Our services and solutions are focused on

providing proof, not promises.

Page 27: Trust in the Cloud

27 © Copyright 2011 EMC Corporation. All rights reserved.

Regulations, standards

Generalized security controls

VMware-specific security controls

VMware cloud infrastructure

Virtualization Ecosystem

RSA enVision

Automated assessment

Configuration State

Security Events

Visibility Across Physical & Virtual Environments Cloud Security Alliance Questions and Policies

Page 28: Trust in the Cloud

28 © Copyright 2011 EMC Corporation. All rights reserved.

Achieving that Goal Securely Means…

Page 29: Trust in the Cloud

29 © Copyright 2011 EMC Corporation. All rights reserved.

Identities Infrastructure Information

Security & Compliance

Delivered Within an Ecosystem of Trust

Page 30: Trust in the Cloud

30 © Copyright 2011 EMC Corporation. All rights reserved.

Page 31: Trust in the Cloud

31 © Copyright 2011 EMC Corporation. All rights reserved.

THANK YOU