I would like to distinguish a project impact analysis (PIA) from a risk assessment of the business solution under debate. The former is a business case justification. The latter allows the stakeholders (e.g. CISO, CIO, CEO etc.) to identify potential threats, prioritize those threats into risks and identify the controls that can reduce the risks to acceptable levels.
A due diligence exercise should examine capital outlay, development costs and long-term costs such as continued operations and maintenance. The cloud option (definitions aside) and whether it is a sound business case will be dependent on the cloud provider. Certainly issues such as regulatory compliance, process safety, validated platform can be show-stoppers. However the as-is system and the target cloud provider must be taken into consideration.
In my opinion a risk assessment does not need to be a long drawn out process. It can also be completed in a matter of days. It is the only way to provide management with the tools needed to perform their fiduciary responsibility of protecting the assets of the enterprise in a reasonable and prudent manner. For example, multi-tenancy is likely a regulatory concern and on the surface Amazon Web Services appears to fail this test. Dig a little deeper and it turns out that Amazon Web Services allows a customer to avoid virtual machine co-residency. Now the probability that a “cross-channel attack” will result in data loss is questionable. The purpose of a risk assessment is to quantitatively or qualitatively make that risk decision and approval to operate.
Friday, November 13, 2009
Get to know your network -- where ever it is
Skybox, Redseal, Cauldron are examples of Enterprise Risk Modeling (ERM) vendors. The tools filter noise, prioritize actions and put the attention on relevant exposures. Here is vulnerability reduction use-case:
Overlay the vulnerability results for a subnet or a set of host machines with a network scan. Then visualize the network topology instead of using VISIO diagrams. It is then easier to zoom in and group zones and classify hot-spots. You can track a SQL Injection vulnerability to inform remediation decisions such as applying a software patch. Cartography of the network is akin to a Google Map. You can spot quick wins such as an expansion of vulnerability scanning coverage. Another type of improvement can be to reduce or avoid false positives. You can look at a high vulnerability score’s and determine whether it will cascade into a worse problem. Finally visualization is a powerful way to present and communicate data in a meaningful way to the right audience. A picture speaks a thousand words.
What you can do with these tools, depend on what you feed it. You can automate firewall and network access compliance. You can inventory assets. You can grab vulnerability data.
Overlay the vulnerability results for a subnet or a set of host machines with a network scan. Then visualize the network topology instead of using VISIO diagrams. It is then easier to zoom in and group zones and classify hot-spots. You can track a SQL Injection vulnerability to inform remediation decisions such as applying a software patch. Cartography of the network is akin to a Google Map. You can spot quick wins such as an expansion of vulnerability scanning coverage. Another type of improvement can be to reduce or avoid false positives. You can look at a high vulnerability score’s and determine whether it will cascade into a worse problem. Finally visualization is a powerful way to present and communicate data in a meaningful way to the right audience. A picture speaks a thousand words.
What you can do with these tools, depend on what you feed it. You can automate firewall and network access compliance. You can inventory assets. You can grab vulnerability data.
Thursday, November 12, 2009
Regulated Industry and Cloud Computing. Just A Note.
I’ve had some experience with regulated industry and cloud computing. It’s important to start by defining the issue. I’ve come across a variety of significant concerns from contractual arrangements, trans-national transactions, co-location of virtual machines, placement of data and transparency. There will be plenty of government rules and compliance check-lists that are at logger heads with the inherent set-up of a shared infrastructure or personnel that have not passed a minimum back-ground check.
The prominent cloud providers (e.g. Google, Amazon Web Services) are already making architectural and infrastructure changes. Google has announced its GovCloud SaaS offering with Google hosting that is solely dedicated to US Federal, State and Local Government – bounded within North America. It’s a work in progress.
Federal government agencies are mandated by law (Federal Information Security Management Act) to implement security protection commensurate with risk. The mandate is to develop and maintain minimum controls and to ensure independent testing and evaluation of those controls.
Those public cloud providers (IaaS, PaaS, SaaS) that offer a communal IT model are opening up a new threat profile. More than one organization hosted on the same physical server, saving data in the same storage device and co-mingled traffic passing across the same interconnects and network edge. They will make compliance claims and do not supply policy an security documentation. All will not be hack-proof and the burden of proof of compliance will fall on the system owner.
It may seem blindingly obvious, but there are certain industry segments that fall into the hard, medium and simple category for cloud computing. No export control. Easy. Healthcare is medium/hard depending on the application. Legal council is a stakeholder and advisor.
The classification and sensitivity of data will dictate the acceptance of risk and the choice of a cloud provider. But if we are talking about PII/PHI and high-impact systems then certainly government agencies are going the route of a private cloud model. Now there are ways to create a secure virtual environment. The security must encompass the physical machine and attendants of those machines. Any regulated industry client will (or has) performed their own PII risk assessment (e.g. NIST 800-122). A risk assessment from a regulatory point of view to inform whether it makes sense to move to the cloud is also necessary.
If the contract is inflexible and non-negotiable then one simply has to walk away and look for another cloud provider that is willing to negotiate. And if the cloud provider claims to be more secure than a regular old data-center – then it should be OK for them to prove it to the customers satisfaction.
The prominent cloud providers (e.g. Google, Amazon Web Services) are already making architectural and infrastructure changes. Google has announced its GovCloud SaaS offering with Google hosting that is solely dedicated to US Federal, State and Local Government – bounded within North America. It’s a work in progress.
Federal government agencies are mandated by law (Federal Information Security Management Act) to implement security protection commensurate with risk. The mandate is to develop and maintain minimum controls and to ensure independent testing and evaluation of those controls.
Those public cloud providers (IaaS, PaaS, SaaS) that offer a communal IT model are opening up a new threat profile. More than one organization hosted on the same physical server, saving data in the same storage device and co-mingled traffic passing across the same interconnects and network edge. They will make compliance claims and do not supply policy an security documentation. All will not be hack-proof and the burden of proof of compliance will fall on the system owner.
It may seem blindingly obvious, but there are certain industry segments that fall into the hard, medium and simple category for cloud computing. No export control. Easy. Healthcare is medium/hard depending on the application. Legal council is a stakeholder and advisor.
The classification and sensitivity of data will dictate the acceptance of risk and the choice of a cloud provider. But if we are talking about PII/PHI and high-impact systems then certainly government agencies are going the route of a private cloud model. Now there are ways to create a secure virtual environment. The security must encompass the physical machine and attendants of those machines. Any regulated industry client will (or has) performed their own PII risk assessment (e.g. NIST 800-122). A risk assessment from a regulatory point of view to inform whether it makes sense to move to the cloud is also necessary.
If the contract is inflexible and non-negotiable then one simply has to walk away and look for another cloud provider that is willing to negotiate. And if the cloud provider claims to be more secure than a regular old data-center – then it should be OK for them to prove it to the customers satisfaction.
Sunday, October 25, 2009
Amazon Web Services: file this under growing pains...
About a week (~ Oct 14th) Amazon Web Services (AWS) EC2 servers attempting to deliver business-critical emails were blocked or fatally rejected because AWS IP addresses were added to a blacklist by Spamhaus.org. Problem resolved.
Not very pleasant for companies providing business-class mail server hosting on AWS.
Oct 15th AWS worked with Spamhaus to remove all EC2 ranges from their PBLs.
The latest from Amazon Oct 21st:
“It is our intention to make it easy to reliably send email from the EC2 environment. As a result of our experience last week, we have released some changes to improve the ability of valid users to send email from EC2. We have started a new thread with the details of the improvement we have made: http://developer.amazonwebservices.com/connect/thread.jspa?threadID=37650. Please let me know if you have any further issues or questions”
Not very pleasant for companies providing business-class mail server hosting on AWS.
Oct 15th AWS worked with Spamhaus to remove all EC2 ranges from their PBLs.
The latest from Amazon Oct 21st:
“It is our intention to make it easy to reliably send email from the EC2 environment. As a result of our experience last week, we have released some changes to improve the ability of valid users to send email from EC2. We have started a new thread with the details of the improvement we have made: http://developer.amazonwebservices.com/connect/thread.jspa?threadID=37650. Please let me know if you have any further issues or questions”
Saturday, October 24, 2009
The workhorse technology behind cloud computing is virtualization. Get to know it well.
The magic pixie dust that makes a cloud a cloud is virtualization technology. The trick is to decouple the physical world of fixed hardware where one computer can behave as though it were many. Where your workspace is in the cloud and all you need is a Netbook (maybe an exaggeration).
One of the more curious aspects of virtualization is the “virtual machine”. It is most affiliated with data-center server virtualization. A virtual machine is nothing more than a file that represents its physical counterparts. No hardware to purchase. No shipping fees. No wires to plug-in. (For those readers that are experts on virtualization, please forgive the oversimplification.)
Hundreds of virtual machines are likely working in earnest inside your own organization. And yes, you are likely your very own cloud provider.
All those virtual machines are important to your business. They can run your email system, your expense reporting application or your customer portal.
So let’s briefly look at some of the ways that the virtual world of servers is vastly different than the physical one.
We are familiar with our laptops going to sleep. (and waking up with a hang-over). How about if 10, 20 or 30 virtual machine go to sleep and wake up at varying times. Will all occurrences of a virus be identified across running, suspended and shutdown virtual machines? Not likely a big deal issue. But its worth thinking about the implications of appropriately configuring the virus scan.
Relocating a physical server is back-breaking work. You pick it up, twist your neck and fall down. A virtual machine (after all it’s a file) can be made to zip across a network. Let’s think about that for a moment. What if it gets intercepted and lands in the wrong hands? A physical machine has to be carried into a facility. Is it easier for a virtual machine file that is not legit to find its way into your network? Not if you have policies in place to have a master or gold copies.
Another interesting property in the virtual world is time. A virtual machine has to keep time, if nothing else than to remind you of mum’s birthday. Time is important. It is used to time-stamp transactions. However timestamps written in log files can also be stomped upon by a perpetrator to mask their activities.
There are plenty of best practices to implement a safe and sound virtual infrastructure. Take a look at your policies and procedures to make certain they are available and executable. Some examples:
· Continue to protect the physical environment.
· Control who creates virtual machines
· Quality control must include real-time configuration management
· Consider encryption as an extra layer of protection for high-risk assets
· Get to know your virtualization technology and how it can be exposed
You can’t get into the virtual world without stepping through the physical world. However, things that happen in the virtual world are not a direct reflection of the physical world. Get savvy.
One of the more curious aspects of virtualization is the “virtual machine”. It is most affiliated with data-center server virtualization. A virtual machine is nothing more than a file that represents its physical counterparts. No hardware to purchase. No shipping fees. No wires to plug-in. (For those readers that are experts on virtualization, please forgive the oversimplification.)
Hundreds of virtual machines are likely working in earnest inside your own organization. And yes, you are likely your very own cloud provider.
All those virtual machines are important to your business. They can run your email system, your expense reporting application or your customer portal.
So let’s briefly look at some of the ways that the virtual world of servers is vastly different than the physical one.
We are familiar with our laptops going to sleep. (and waking up with a hang-over). How about if 10, 20 or 30 virtual machine go to sleep and wake up at varying times. Will all occurrences of a virus be identified across running, suspended and shutdown virtual machines? Not likely a big deal issue. But its worth thinking about the implications of appropriately configuring the virus scan.
Relocating a physical server is back-breaking work. You pick it up, twist your neck and fall down. A virtual machine (after all it’s a file) can be made to zip across a network. Let’s think about that for a moment. What if it gets intercepted and lands in the wrong hands? A physical machine has to be carried into a facility. Is it easier for a virtual machine file that is not legit to find its way into your network? Not if you have policies in place to have a master or gold copies.
Another interesting property in the virtual world is time. A virtual machine has to keep time, if nothing else than to remind you of mum’s birthday. Time is important. It is used to time-stamp transactions. However timestamps written in log files can also be stomped upon by a perpetrator to mask their activities.
There are plenty of best practices to implement a safe and sound virtual infrastructure. Take a look at your policies and procedures to make certain they are available and executable. Some examples:
· Continue to protect the physical environment.
· Control who creates virtual machines
· Quality control must include real-time configuration management
· Consider encryption as an extra layer of protection for high-risk assets
· Get to know your virtualization technology and how it can be exposed
You can’t get into the virtual world without stepping through the physical world. However, things that happen in the virtual world are not a direct reflection of the physical world. Get savvy.
Wednesday, October 7, 2009
Google Apps: Here I Am
At Tech Labs we are constantly working to get to know all the major Cloud Computing providers and thier virtual wares. Microsoft, Salesforce.com and of course Google.
And Google is well on it’s way to building a reputation and trust that an enterprise can live with. The Google Apps web site already claims more than 1 million businesses running on the platform.
I sat down with one of our consultants to understand some of the details behind Google Apps and what it takes to properly implement the product for an enterprise.
Some of our conversation:
1. What is Google Apps - in your words?
Google Apps is a suite of products. You get Gmail, Talk, Calendar, Docs, and Sites - all of which are part of the $50/user/year licencing fee. Storage allocation is 25GB per user. The first foray for most clients is likely Gmail and Calendar and its not unusual to see "silent rollouts" of Google Docs and Googles Sites as collaboration tools.
2. Security is one of the benefits touted by using Google Apps? Explain.
Gartner estimates over 20,000 to 30,000 samples of potential malware are sent for analysis each day. And more than 5 million U.S. consumers lost money to phishing attacks during the 12 months ending in September 2008, a 39.8% increase over the number of victims a year earlier.
Gmail is likely to stay more up-to-date with email filters that can spot malicious file attachments and URL filters to inspect for exploits are vital. However even that line-of-defense will suffers from the delay in finding and blocking zero-day attacks. Other cyber security capabilities will be needed.
More than half of employees who left their companies in 2008 took some sensitive corporate data with them. Nearly 80% of these employees said that they knew it was against company policy to take the data, but they did it anyway (source: Ponemon Institute & Symantec). One source of data leakage is email messages that are used to exchange files loaded with hyper-sensitive information.
Google Apps store documents in the 'Cloud' and instead pass around hyperlinks which point to documents that can only be shared with those that you previously granted permissions. Google Message Discovery and Google Message Security offer security and archival features that advance compliance requirements.
Still questions abound such as government and regulatory compliance and service levels
2. Where do you think Google Apps is headed in the enterprise?
Google Apps lineage is of course consumer-focused, however it is evolving rapidly with each major release.
At the sametime it is still not as feature rich as existing offerings by mainstay vendor such as Microsoft.
Microsofts Business Productivity Online Suite (Microsoft BPOS) is appealing because it is available in both a pure SaaS model and a dedicated version. The advantages include custom security, adherance to compliance mandates and the ability to tailor features.
Google Apps is advertised is a SaaS offering ideally to avoid one-off deployments. Users only have the option to get the same release. A pure SaaS offering has to carely balance the desire to quickly mobilize new features and get them safely deployed into production.
Finally a key success factor to the roll out of Google Apps within an enterprise is to have a solid training and communications plan and strategy to allow for a smooth user adoption.
Thanks Jonathan Hsu!
And Google is well on it’s way to building a reputation and trust that an enterprise can live with. The Google Apps web site already claims more than 1 million businesses running on the platform.
I sat down with one of our consultants to understand some of the details behind Google Apps and what it takes to properly implement the product for an enterprise.
Some of our conversation:
1. What is Google Apps - in your words?
Google Apps is a suite of products. You get Gmail, Talk, Calendar, Docs, and Sites - all of which are part of the $50/user/year licencing fee. Storage allocation is 25GB per user. The first foray for most clients is likely Gmail and Calendar and its not unusual to see "silent rollouts" of Google Docs and Googles Sites as collaboration tools.
2. Security is one of the benefits touted by using Google Apps? Explain.
Gartner estimates over 20,000 to 30,000 samples of potential malware are sent for analysis each day. And more than 5 million U.S. consumers lost money to phishing attacks during the 12 months ending in September 2008, a 39.8% increase over the number of victims a year earlier.
Gmail is likely to stay more up-to-date with email filters that can spot malicious file attachments and URL filters to inspect for exploits are vital. However even that line-of-defense will suffers from the delay in finding and blocking zero-day attacks. Other cyber security capabilities will be needed.
More than half of employees who left their companies in 2008 took some sensitive corporate data with them. Nearly 80% of these employees said that they knew it was against company policy to take the data, but they did it anyway (source: Ponemon Institute & Symantec). One source of data leakage is email messages that are used to exchange files loaded with hyper-sensitive information.
Google Apps store documents in the 'Cloud' and instead pass around hyperlinks which point to documents that can only be shared with those that you previously granted permissions. Google Message Discovery and Google Message Security offer security and archival features that advance compliance requirements.
Still questions abound such as government and regulatory compliance and service levels
2. Where do you think Google Apps is headed in the enterprise?
Google Apps lineage is of course consumer-focused, however it is evolving rapidly with each major release.
At the sametime it is still not as feature rich as existing offerings by mainstay vendor such as Microsoft.
Microsofts Business Productivity Online Suite (Microsoft BPOS) is appealing because it is available in both a pure SaaS model and a dedicated version. The advantages include custom security, adherance to compliance mandates and the ability to tailor features.
Google Apps is advertised is a SaaS offering ideally to avoid one-off deployments. Users only have the option to get the same release. A pure SaaS offering has to carely balance the desire to quickly mobilize new features and get them safely deployed into production.
Finally a key success factor to the roll out of Google Apps within an enterprise is to have a solid training and communications plan and strategy to allow for a smooth user adoption.
Thanks Jonathan Hsu!
Thursday, September 3, 2009
Cloud: Finding True North
I recently presented a workshop on cloud computing to a fairly large pharmaceutical company.
The discussion rolled and swayed across all ports. IT is still relevant. Cloud computing is a component of the business service management strategy. Virtualization and IT automation are stepping stones. We shared our insights from working with many large enterprises.
Towards the end of the session, you could tell the audience was eager to start searching for their own "true north" when it came to Cloud Computing. What's the best way to oriented with all the pundits, research and facts?
Joe Tobolski (Global Lead of Infrastructure at Accenture Technology Labs) hit the spot with these closing remarks and guiding principles:
The discussion rolled and swayed across all ports. IT is still relevant. Cloud computing is a component of the business service management strategy. Virtualization and IT automation are stepping stones. We shared our insights from working with many large enterprises.
Towards the end of the session, you could tell the audience was eager to start searching for their own "true north" when it came to Cloud Computing. What's the best way to oriented with all the pundits, research and facts?
Joe Tobolski (Global Lead of Infrastructure at Accenture Technology Labs) hit the spot with these closing remarks and guiding principles:
- Cloud Computing Strategy is one component of your IT’s Business Service Management strategy -- they are not separate and distinct.
- There is no single approach to Cloud Computing – the market will remain highly fragmented.
- Carefully evaluate candidate applications and IT services that can take advantage of cloud computing. Applications that don’t horizontally scale internally will not give you cost savings if hosted externally on a cloud.
- There is an “asymmetrical cost” to go into a cloud and then transition out. Still, carefully plan your exit strategy.
- Security and compliance are not portable across clouds and internal IT – but don’t let that slow your approach to Cloud Computing. Pick a suitable application and get going.
Walid
Subscribe to:
Posts (Atom)
