Thursday, 15 October 2009

Resources for the busy security pro...

I'm going to step away from cloud computing for a change and go back to the main day job - security. Like many security pro's I'm a busy guy but at the same time my clients (and I) expect me to remain up to date with the latest happenings in the security space. Over the years I've whittled down the number of Internet resources I keep track of - I'm going to talk about a couple that I still check on a daily basis in this post.

Firstly: http://archives.neohapsis.com/

There are loads of security mailing lists - the site above is a convenient method for keeping track of the most useful ones. I'd recommend their Yesterday, Today, Full-Disclosure and DailyDave archives. There are other aggregators but I've been using this one for years and I'm a loyal soul...

Secondly: http://www.monkey.com/~jose/secblogs.html

As with mailing lists, there are loads of security blogs and loads of blog aggregators. I tend to use the one above as it aggregates blogs I'm interested in and provides a manageable number of links per day - I don't feel overwhelmed by the sheer volume of posts!

Hope you find them useful. If you have any other resources that you think would help a busy security guy keep up to date (in a quick and manageable way!) please add some comments.

Thursday, 1 October 2009

Cloud Security Summit

I presented my first ever web-cast yesterday as part of the BrightTALK Cloud Security Summit. An interesting experience and strangely enjoyable. I found the BrightTALK platform fairly straightforward to use, although the voting system could be a little more slick. It's a little uncomfortable whilst you're presenting as you've no way of knowing whether you're carrying your audience with you - fortunately the ratings have been quite positive and so I think I got away with it :-)

If you're interested in cloud security, my web-cast can be found here:

http://www.brighttalk.com/webcasts/5688/play

If you have any questions or want to leave any feedback, feel free to comment :-)

Monday, 28 September 2009

CloudCamp London 5

I was lucky enough to attend the 5th London Cloud Camp last week. Once I got my lightning talk out of the way it was an enjoyable event combining an opportunity to catch up with an old friend, make some new contacts and engage in some interesting conversations! [I think my talk went pretty well other than being a little rushed - my own fault for trying to fit a 10 minute talk into a 5 minute slot!]

After the talks we broke into Vendor Tracks and Open Space discussions - one of the attendees suggested a session around security which I volunteered to moderate. I've written up these discussions and the write-up is shown below. If any of the attendees feel I missed anything out or have misrepresented the conversation please feel to comment or drop me an email. Enjoy!

London CloudCamp #5 Open Space – Security (Room 3)

Chatham House rule applies!


i) Public sector in the Cloud

Discussion began with whether the Public Sector would adopt cloud due to their security requirements. It was noted that the UK Government is planning a G-Cloud as part of the Data Centre Consolidation Strategy – this was also a recommendation into the Carter Review (Digital Britain). Attendees were also pointed towards the blog of John Suffolk, the HMG CIO – http://johnsuffolk.typepad.com. It was thought unlikely that public clouds would be suitable for processing of protectively marked information (i.e. RESTRICTED and above) – although it may be possible to use them for storage and transport if data is encrypted and decrypted on-premise. There was thought to be more likelihood of public clouds being used within local government where security requirements are less stringent due to their data typically being at PROTECT. The main sticking point from a security perspective was currently thought to be around the lack of assured products to support domain separation.

ii) Certificate based authentication

There was a discussion as to whether cloud computing made it difficult to use server certificate based authentication due to the need to tie certificates to domain names or IP addresses. It was not thought to be a problem with IaaS (where this can be controlled by the consumer – if the right technologies are used). Thought to be problematic with PaaS and SaaS.

iii) PCI-DSS and ISO27001

There was a question as to the overlap between PCI-DSS and ISO27001. The group believed that there is significant overlap between the two standards but that PCI-DSS was more prescriptive and so compliance with ISO27001 did not mean compliance with PCI-DSS. PCI-DSS has specific requirements around handling of cardholder data, vulnerability assessments etc that are more granular than those within ISO27001. The recent blog post including the AWS statement that it was not possible to be completely PCI-DSS level 1 compliant using only their EC2 and S3 services was discussed. It was noted that you can simply hand off payment processing to a third party payment processor or keep such processing in-house. It was also noted that there is a separate PCI standard covering the development of payment processing applications.

iv) Privacy

We had a brief discussion around privacy legislation – one of the attendees noting that Germany is about to enact a notification law such that any organisation suffering a data breach must notify all affected customers (either by individual letter or by taking out a 2 page advert in a national newspaper).

v) Use of cloud resources for illegal purposes

We had a particularly interesting conversation around the use of cloud computing resources for illegal purposes – for example the distribution of cracked software keys. This discussion was illustrated through real examples of previously identified instances of such activity. This does raise interesting questions about whether cloud providers should be monitoring for such activity or whether they, like telco's, should act simply as carriers.

vi) Data leakage

The idea that data could be split throughout the cloud to make re-constitution more difficult was discussed. It was thought that this was already one of the benefits of cloud computing – should a service provider lose a disk, it is most likely to contain fragments from a number of clients rather than a substantial chunk of a single organisation's data.

Miranda Mowbray's obfuscation tool and the Vanish tool (Washington State University) were mentioned as being of interest to those looking to keep sensitive data under control. Both noted as being primarily of academic interest at this time.

vii) Virtual Desktop Infrastructures

There was some discussion of VDI in the cloud. Noted that the public sector may “browse-down” from a more sensitive domain to a lesser domain, e.g. to offer Internet access via terminal services but that "browse-up” was frowned upon.

viii) Security Benefits

It was thought that the cloud model can offer some security benefits – e.g. Increased/improved security monitoring, patching, security expertise and physical security. Likely to be of more benefit to SMEs but could also be of benefit to larger organisations (most of whom should already have invested in the necessary functions).

ix) Security as a Service

The prospects of security as a service were discussed. It was noted that businesses such as MessageLabs have been doing this for years! Security filtering in the cloud is a valid service. Could also expect to see identity providers in the cloud in the future.



Monday, 21 September 2009

Cloud miscellany

It's been a busy few weeks hence the lack of posts here. Admittedly one of the things taking my time was a week by the seaside so I've not been that hard done by!

But back in the real world it's been interesting at work with respect to how many of our current bids and engagements are now considering delivery, at least in part, via cloud computing models. There seems to be a real shift to treating cloud computing as just another part of the delivery model a la outsourcing, right shoring etc. I have to say that I thoroughly approve of this change - technology for the sake of technology, or even change for the sake of change, is never a wise thing unless of course you're in a particularly bad place and are due a change in luck! What we do have to remember is the potentially game-changing nature of certain cloud computing characteristics - in particular increased agility - which means that we need to be careful not to limit our imaginations to doing just the same things but in a different way. Don't forget to think different, but most importantly don't forget to think!

Friday, 21 August 2009

BrightTALK Cloud Security Summit

I've been lucky enough to ask to web-cast at the BrightTALK Cloud Security Summit on the 30th of September - if anybody fancies listening to me rabbiting on about security in the cloud, you'll be able to attend by clicking on http://www.brighttalk.com/webcasts/5688/attend

There are some well-known and well-respected figures presenting during the summit - details of the other presentations and presenters can be found at:

http://www.brighttalk.com/summit/cloudsecurity

Come along, I'm sure it'll be fun. I may even have thought of some interesting voting topics by that point as well - I'd welcome suggestions if anyone out there would care to volunteer some?

Monday, 10 August 2009

I hate that question...

So I've found another question that irritates me. It's this one: "What's the most secure; SaaS, PaaS or IaaS?". There are lots of things wrong with this question - firstly, define what is meant by secure. Secondly, define your perspective - are you a provider or a consumer. Thirdly, assuming you're a consumer, define what you're doing in the cloud - it's a big concept, there's lots you can do and lots of ways of doing it! And so on and so on...

I think it's a naive question to ask and that it's even sillier to come out with an answer (unless you've spent the time to understand a very specific situation). There are lots of different perspectives and lots of different classes of organisation with different needs and capabilities. For example, if you're a small business with little experience with an application then it's likely that a SaaS provider will provide a more secure (albeit multi-tenant) solution than you could build yourself. However, if you're a large enterprise then I think a fair argument could be made that you could build a more secure, single tenant application on your own platform on a shared IaaS cloud infrastructure than the multi-tenant equivalant offered by a SaaS provider. Of course, the observant amongst you may have noticed that I said "more secure" without actually defining secure - look at the name of the blog, I'm musing :0)

Upshot, as with most things, know your requirements and choose the solution that's the best fit. This cloud stuff really is not rocket science. (Unless of course you're NASA: http://nebula.nasa.gov :-)

Thursday, 6 August 2009

Enabling confidence in the cloud

My latest Computer Weekly column is now on-line:

http://www.computerweekly.com/Articles/2009/08/05/237195/enabling-confidence-in-the-cloud.htm

In other news: I gave a presentation on cloud computing to some senior executives of a major HMG department yesterday. I have to say that I was encouraged by the nature of the questions being asked by the audience - they demonstrated both a solid grasp of the underlying concepts of cloud computing and also a genuine interest in understanding the commercial and business benefits that the cloud model offers. I think that's one of the strengths of cloud computing - the business benefits in terms of flexibility and removal of some of the barriers to business innovation are obvious, the trick is going to be to derive the appropriate assurance models and drive the necessary cultural changes. Time for everyone to learn some new skills methinks :-)