Thursday, 15 October 2009
Resources for the busy security pro...
Firstly: http://archives.neohapsis.com/
There are loads of security mailing lists - the site above is a convenient method for keeping track of the most useful ones. I'd recommend their Yesterday, Today, Full-Disclosure and DailyDave archives. There are other aggregators but I've been using this one for years and I'm a loyal soul...
Secondly: http://www.monkey.com/~jose/secblogs.html
As with mailing lists, there are loads of security blogs and loads of blog aggregators. I tend to use the one above as it aggregates blogs I'm interested in and provides a manageable number of links per day - I don't feel overwhelmed by the sheer volume of posts!
Hope you find them useful. If you have any other resources that you think would help a busy security guy keep up to date (in a quick and manageable way!) please add some comments.
Thursday, 1 October 2009
Cloud Security Summit
If you're interested in cloud security, my web-cast can be found here:
http://www.brighttalk.com/webcasts/5688/play
If you have any questions or want to leave any feedback, feel free to comment :-)
Monday, 28 September 2009
CloudCamp London 5
After the talks we broke into Vendor Tracks and Open Space discussions - one of the attendees suggested a session around security which I volunteered to moderate. I've written up these discussions and the write-up is shown below. If any of the attendees feel I missed anything out or have misrepresented the conversation please feel to comment or drop me an email. Enjoy!
London CloudCamp #5 Open Space – Security (Room 3)
Chatham House rule applies!
i) Public sector in the Cloud
Discussion began with whether the Public Sector would adopt cloud due to their security requirements. It was noted that the UK Government is planning a G-Cloud as part of the Data Centre Consolidation Strategy – this was also a recommendation into the Carter Review (Digital Britain). Attendees were also pointed towards the blog of John Suffolk, the HMG CIO – http://johnsuffolk.typepad.com. It was thought unlikely that public clouds would be suitable for processing of protectively marked information (i.e. RESTRICTED and above) – although it may be possible to use them for storage and transport if data is encrypted and decrypted on-premise. There was thought to be more likelihood of public clouds being used within local government where security requirements are less stringent due to their data typically being at PROTECT. The main sticking point from a security perspective was currently thought to be around the lack of assured products to support domain separation.
ii) Certificate based authentication
There was a discussion as to whether cloud computing made it difficult to use server certificate based authentication due to the need to tie certificates to domain names or IP addresses. It was not thought to be a problem with IaaS (where this can be controlled by the consumer – if the right technologies are used). Thought to be problematic with PaaS and SaaS.
iii) PCI-DSS and ISO27001
There was a question as to the overlap between PCI-DSS and ISO27001. The group believed that there is significant overlap between the two standards but that PCI-DSS was more prescriptive and so compliance with ISO27001 did not mean compliance with PCI-DSS. PCI-DSS has specific requirements around handling of cardholder data, vulnerability assessments etc that are more granular than those within ISO27001. The recent blog post including the AWS statement that it was not possible to be completely PCI-DSS level 1 compliant using only their EC2 and S3 services was discussed. It was noted that you can simply hand off payment processing to a third party payment processor or keep such processing in-house. It was also noted that there is a separate PCI standard covering the development of payment processing applications.
iv) Privacy
We had a brief discussion around privacy legislation – one of the attendees noting that Germany is about to enact a notification law such that any organisation suffering a data breach must notify all affected customers (either by individual letter or by taking out a 2 page advert in a national newspaper).
v) Use of cloud resources for illegal purposes
We had a particularly interesting conversation around the use of cloud computing resources for illegal purposes – for example the distribution of cracked software keys. This discussion was illustrated through real examples of previously identified instances of such activity. This does raise interesting questions about whether cloud providers should be monitoring for such activity or whether they, like telco's, should act simply as carriers.
vi) Data leakage
The idea that data could be split throughout the cloud to make re-constitution more difficult was discussed. It was thought that this was already one of the benefits of cloud computing – should a service provider lose a disk, it is most likely to contain fragments from a number of clients rather than a substantial chunk of a single organisation's data.
Miranda Mowbray's obfuscation tool and the Vanish tool (Washington State University) were mentioned as being of interest to those looking to keep sensitive data under control. Both noted as being primarily of academic interest at this time.
vii) Virtual Desktop Infrastructures
There was some discussion of VDI in the cloud. Noted that the public sector may “browse-down” from a more sensitive domain to a lesser domain, e.g. to offer Internet access via terminal services but that "browse-up” was frowned upon.
viii) Security Benefits
It was thought that the cloud model can offer some security benefits – e.g. Increased/improved security monitoring, patching, security expertise and physical security. Likely to be of more benefit to SMEs but could also be of benefit to larger organisations (most of whom should already have invested in the necessary functions).
ix) Security as a Service
The prospects of security as a service were discussed. It was noted that businesses such as MessageLabs have been doing this for years! Security filtering in the cloud is a valid service. Could also expect to see identity providers in the cloud in the future.
Monday, 21 September 2009
Cloud miscellany
But back in the real world it's been interesting at work with respect to how many of our current bids and engagements are now considering delivery, at least in part, via cloud computing models. There seems to be a real shift to treating cloud computing as just another part of the delivery model a la outsourcing, right shoring etc. I have to say that I thoroughly approve of this change - technology for the sake of technology, or even change for the sake of change, is never a wise thing unless of course you're in a particularly bad place and are due a change in luck! What we do have to remember is the potentially game-changing nature of certain cloud computing characteristics - in particular increased agility - which means that we need to be careful not to limit our imaginations to doing just the same things but in a different way. Don't forget to think different, but most importantly don't forget to think!
Friday, 21 August 2009
BrightTALK Cloud Security Summit
There are some well-known and well-respected figures presenting during the summit - details of the other presentations and presenters can be found at:
http://www.brighttalk.com/summit/cloudsecurity
Come along, I'm sure it'll be fun. I may even have thought of some interesting voting topics by that point as well - I'd welcome suggestions if anyone out there would care to volunteer some?
Monday, 10 August 2009
I hate that question...
I think it's a naive question to ask and that it's even sillier to come out with an answer (unless you've spent the time to understand a very specific situation). There are lots of different perspectives and lots of different classes of organisation with different needs and capabilities. For example, if you're a small business with little experience with an application then it's likely that a SaaS provider will provide a more secure (albeit multi-tenant) solution than you could build yourself. However, if you're a large enterprise then I think a fair argument could be made that you could build a more secure, single tenant application on your own platform on a shared IaaS cloud infrastructure than the multi-tenant equivalant offered by a SaaS provider. Of course, the observant amongst you may have noticed that I said "more secure" without actually defining secure - look at the name of the blog, I'm musing :0)
Upshot, as with most things, know your requirements and choose the solution that's the best fit. This cloud stuff really is not rocket science. (Unless of course you're NASA: http://nebula.nasa.gov :-)
Thursday, 6 August 2009
Enabling confidence in the cloud
http://www.computerweekly.com/Articles/2009/08/05/237195/enabling-confidence-in-the-cloud.htm
In other news: I gave a presentation on cloud computing to some senior executives of a major HMG department yesterday. I have to say that I was encouraged by the nature of the questions being asked by the audience - they demonstrated both a solid grasp of the underlying concepts of cloud computing and also a genuine interest in understanding the commercial and business benefits that the cloud model offers. I think that's one of the strengths of cloud computing - the business benefits in terms of flexibility and removal of some of the barriers to business innovation are obvious, the trick is going to be to derive the appropriate assurance models and drive the necessary cultural changes. Time for everyone to learn some new skills methinks :-)
