SlideShare a Scribd company logo
1 of 20
Cloud Computing Due Diligence - WTF?
                                                                  Jimmy Blake
                                                                 @jimmyblake



               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
Jimmy Who?


            • CSO for one of the UK’s largest SaaS providers
            • Talking mainly from a SaaS perspective
            • Dozens of client risk assessments a month
            • ISO 27001 Lead Auditor
            • These are my opinions, not necessarily those of
                    my employer


               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
Cloud Computing
                                         Don’t
                                      make me APT
                                       your cyber-
                                        defences                    http://csrc.nist.gov/groups/SNS/cloud-computing/




                                                                 Essential Characteristics
                                                                 Service Model
                                                                 Deployment Model
                                                                 ...blah blah blah


               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
Businesses Are Moving to the Cloud


                                                            Well governed organisations
                                                            make decisions after
                                                            consideration of risk




               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
Businesses Are Moving to the Cloud


                                                            Well governed organisations
                                                            make decisions after
                                                            consideration of risk

                                                            ...and we all know how many
                                                            well governed organisations
                                                            there are out there.



               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
Who Does the Due Diligence??

          • Understands security, not risk
          • Knows on-premise, not cloud
          • Still thinks he has a secure
                  perimeter
          • Likes to be able to hug servers
          • He, and his toys, may be
                  displaced by the solution


               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
The Cost of Due Diligence: Do The Math

                  Average Due Diligence Questionnaire = 2 hours
                  Average Audit = 6 man hours


                  4,000 customers = 3,000 working days per annum


                  ...and you want cost savings???



               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
Certification: ISO:IEC 27001:2005



          • Scope?
                •      Very few scopes include production
                       platforms

          • Is your acceptable risk < or >
                  then the provider’s?




               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
ISO 27001: What They Really Mean




                                                                     Cloud
                           Our On-Premise
                                                                   Provider’s
                           27002 controls
                                                                 27002 controls
               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
Certification: SAS-70 (soon SSAE16)




          • Control Statements
          • Great for auditing against SOX
                  404 controls




               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
Getting Real

                      How do you ensure
                  physical access to your data
               centres is restricted to those who
                   need it for a job function?



                                                                 By not having 100 customers a
                                                                 day walking through on audits...




               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
Getting Real

                                                                         So I hope that answers your
                                                                       question on how we handle key
                                                                 rotation on our distributed filing system
                                                                  utilising AES 256-bit encryption? Can I
                  The IT Manager backs up to                          ask how you do it at the moment?
            tape and leaves the tapes in the back of
                       his car overnight.

                                                                   The tapes are encrypted of course?

                                    ....

                                                                    Please tell me the car isn’t left on
                                                                         his driveway overnight?

                                    ....


               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
Turning the Tables
         RFP responses contain a lot of sensitive information

                   How do you classify                              How many people
                    completed RFP                                have access to completed
                       responses?                                     RFP responses?



                       How do
                 you ensure access                                 How do you dispose
             control and prevent leakage                         of printed copies of RFP
                 of completed RFP                                       responses?
                     responses?


               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
Industry Representation or Prospects?




               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
What We Need
                Software-as-a-Service is often about replacing
               specific on-premise solutions within the business




               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
What We Need
                Software-as-a-Service is often about replacing
               specific on-premise solutions within the business

                           baseline

                                                                  Cloud
                      On-premise                                 Provider
                         risk                                      risk




               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
What We Need


                           baseline


                      On-premise
                         risk
                                                                  Cloud
                                                                 Provider
                                                                   risk


               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
What We’re Getting




          Great, now I’ve got 6 lots of audit and certification....


               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
A Final Plea
          Customers:
          Baseline on your current risk exposure

          Due your due diligence, but make it proportionate

          If you want champagne, expect to pay for it

         Industry Bodies:
         Come together for a unified standard of audit and assessment

         Represent cloud customers and the service provider, not infrastructure vendors


         Cloud Providers:
         Embrace transparency




               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011
Cloud Computing Due Diligence - WTF?
                                                                            Jimmy Blake
                                                                           @jimmyblake
                                                                 http://jimmyblake.com




               Security B-Sides London: Cloud Computing - WTF?

Wednesday, 20 April 2011

More Related Content

Similar to Cloud computing due diligence WTF?

DevOps and the cloud: all hail the (developer) king - Daniel Bryant, Steve Poole
DevOps and the cloud: all hail the (developer) king - Daniel Bryant, Steve PooleDevOps and the cloud: all hail the (developer) king - Daniel Bryant, Steve Poole
DevOps and the cloud: all hail the (developer) king - Daniel Bryant, Steve Poole
JAXLondon_Conference
 
DevOps Con 2015: Radical Agility with Autonomous Teams and Microservices in t...
DevOps Con 2015: Radical Agility with Autonomous Teams and Microservices in t...DevOps Con 2015: Radical Agility with Autonomous Teams and Microservices in t...
DevOps Con 2015: Radical Agility with Autonomous Teams and Microservices in t...
Henning Jacobs
 
Dev ops con 2015 radical agility with autonomous teams and microservices in...
Dev ops con 2015   radical agility with autonomous teams and microservices in...Dev ops con 2015   radical agility with autonomous teams and microservices in...
Dev ops con 2015 radical agility with autonomous teams and microservices in...
Jan Löffler
 
CIO Summit Berlin 2011
CIO Summit Berlin 2011CIO Summit Berlin 2011
CIO Summit Berlin 2011
Jitscale
 

Similar to Cloud computing due diligence WTF? (20)

Cloud Security: Perception Vs. Reality
Cloud Security: Perception Vs. RealityCloud Security: Perception Vs. Reality
Cloud Security: Perception Vs. Reality
 
Cloud security and cyber security v 3.1
Cloud security and cyber security v 3.1Cloud security and cyber security v 3.1
Cloud security and cyber security v 3.1
 
DTS Solution - ISACA UAE Chapter - ISAFE 2014 - RU PWNED - Living a Life as a...
DTS Solution - ISACA UAE Chapter - ISAFE 2014 - RU PWNED - Living a Life as a...DTS Solution - ISACA UAE Chapter - ISAFE 2014 - RU PWNED - Living a Life as a...
DTS Solution - ISACA UAE Chapter - ISAFE 2014 - RU PWNED - Living a Life as a...
 
Build a network to thrive in the Digital age
Build a network to thrive in the Digital ageBuild a network to thrive in the Digital age
Build a network to thrive in the Digital age
 
DevOps and the cloud: all hail the (developer) king - Daniel Bryant, Steve Poole
DevOps and the cloud: all hail the (developer) king - Daniel Bryant, Steve PooleDevOps and the cloud: all hail the (developer) king - Daniel Bryant, Steve Poole
DevOps and the cloud: all hail the (developer) king - Daniel Bryant, Steve Poole
 
JAXLondon 2015 "DevOps and the Cloud: All Hail the (Developer) King"
JAXLondon 2015 "DevOps and the Cloud: All Hail the (Developer) King"JAXLondon 2015 "DevOps and the Cloud: All Hail the (Developer) King"
JAXLondon 2015 "DevOps and the Cloud: All Hail the (Developer) King"
 
Exponential-e | Cloud Revolution Seminar at the Ritz, 20th November 2014
Exponential-e | Cloud Revolution Seminar at the Ritz, 20th November 2014Exponential-e | Cloud Revolution Seminar at the Ritz, 20th November 2014
Exponential-e | Cloud Revolution Seminar at the Ritz, 20th November 2014
 
A Blueprint for Cloud-Native Financial Institutions
A Blueprint for Cloud-Native Financial InstitutionsA Blueprint for Cloud-Native Financial Institutions
A Blueprint for Cloud-Native Financial Institutions
 
Cloud Team Alliance @ EU Buxelles
Cloud Team Alliance @ EU BuxellesCloud Team Alliance @ EU Buxelles
Cloud Team Alliance @ EU Buxelles
 
AWS per il settore pubblico in Italia
AWS per il settore pubblico in ItaliaAWS per il settore pubblico in Italia
AWS per il settore pubblico in Italia
 
AWS re:Invent 2016: IoT and Beyond: Building IoT Solutions for Exploring the ...
AWS re:Invent 2016: IoT and Beyond: Building IoT Solutions for Exploring the ...AWS re:Invent 2016: IoT and Beyond: Building IoT Solutions for Exploring the ...
AWS re:Invent 2016: IoT and Beyond: Building IoT Solutions for Exploring the ...
 
Structure 2014 - Launchpad Competition
Structure 2014 - Launchpad CompetitionStructure 2014 - Launchpad Competition
Structure 2014 - Launchpad Competition
 
2011 VMI DEMO Conference Highlights
2011 VMI DEMO Conference Highlights2011 VMI DEMO Conference Highlights
2011 VMI DEMO Conference Highlights
 
DevOps Con 2015: Radical Agility with Autonomous Teams and Microservices in t...
DevOps Con 2015: Radical Agility with Autonomous Teams and Microservices in t...DevOps Con 2015: Radical Agility with Autonomous Teams and Microservices in t...
DevOps Con 2015: Radical Agility with Autonomous Teams and Microservices in t...
 
Dev ops con 2015 radical agility with autonomous teams and microservices in...
Dev ops con 2015   radical agility with autonomous teams and microservices in...Dev ops con 2015   radical agility with autonomous teams and microservices in...
Dev ops con 2015 radical agility with autonomous teams and microservices in...
 
Radical Agility with Autonomous Teams and Microservices in the Cloud
Radical Agility with Autonomous Teams and Microservices in the CloudRadical Agility with Autonomous Teams and Microservices in the Cloud
Radical Agility with Autonomous Teams and Microservices in the Cloud
 
E Crime Symposium June 10
E Crime Symposium June 10E Crime Symposium June 10
E Crime Symposium June 10
 
2011-08-10 In-Q-Tel Technology Focus Day, Trends & Observations in Open Sourc...
2011-08-10 In-Q-Tel Technology Focus Day, Trends & Observations in Open Sourc...2011-08-10 In-Q-Tel Technology Focus Day, Trends & Observations in Open Sourc...
2011-08-10 In-Q-Tel Technology Focus Day, Trends & Observations in Open Sourc...
 
Bridging the Enterprise and the Cloud from Layer 7
Bridging the Enterprise and the Cloud from Layer 7Bridging the Enterprise and the Cloud from Layer 7
Bridging the Enterprise and the Cloud from Layer 7
 
CIO Summit Berlin 2011
CIO Summit Berlin 2011CIO Summit Berlin 2011
CIO Summit Berlin 2011
 

More from Security BSides London

More from Security BSides London (8)

Agnitio: its static analysis, but not as we know it
Agnitio: its static analysis, but not as we know itAgnitio: its static analysis, but not as we know it
Agnitio: its static analysis, but not as we know it
 
The Funny Thing About Information Security
The Funny Thing About Information SecurityThe Funny Thing About Information Security
The Funny Thing About Information Security
 
Breaking out of restricted RDP
Breaking out of restricted RDPBreaking out of restricted RDP
Breaking out of restricted RDP
 
Breaking, Entering and Pentesting
Breaking, Entering and Pentesting Breaking, Entering and Pentesting
Breaking, Entering and Pentesting
 
All your logs are belong to you!
All your logs are belong to you!All your logs are belong to you!
All your logs are belong to you!
 
Practical Crypto Attacks Against Web Applications
Practical Crypto Attacks Against Web Applications Practical Crypto Attacks Against Web Applications
Practical Crypto Attacks Against Web Applications
 
Jedi mind tricks for building application security programs
Jedi mind tricks for building application security programsJedi mind tricks for building application security programs
Jedi mind tricks for building application security programs
 
Dns tunnelling its all in the name
Dns tunnelling its all in the nameDns tunnelling its all in the name
Dns tunnelling its all in the name
 

Recently uploaded

Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 

Recently uploaded (20)

Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 

Cloud computing due diligence WTF?

  • 1. Cloud Computing Due Diligence - WTF? Jimmy Blake @jimmyblake Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 2. Jimmy Who? • CSO for one of the UK’s largest SaaS providers • Talking mainly from a SaaS perspective • Dozens of client risk assessments a month • ISO 27001 Lead Auditor • These are my opinions, not necessarily those of my employer Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 3. Cloud Computing Don’t make me APT your cyber- defences http://csrc.nist.gov/groups/SNS/cloud-computing/ Essential Characteristics Service Model Deployment Model ...blah blah blah Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 4. Businesses Are Moving to the Cloud Well governed organisations make decisions after consideration of risk Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 5. Businesses Are Moving to the Cloud Well governed organisations make decisions after consideration of risk ...and we all know how many well governed organisations there are out there. Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 6. Who Does the Due Diligence?? • Understands security, not risk • Knows on-premise, not cloud • Still thinks he has a secure perimeter • Likes to be able to hug servers • He, and his toys, may be displaced by the solution Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 7. The Cost of Due Diligence: Do The Math Average Due Diligence Questionnaire = 2 hours Average Audit = 6 man hours 4,000 customers = 3,000 working days per annum ...and you want cost savings??? Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 8. Certification: ISO:IEC 27001:2005 • Scope? • Very few scopes include production platforms • Is your acceptable risk < or > then the provider’s? Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 9. ISO 27001: What They Really Mean Cloud Our On-Premise Provider’s 27002 controls 27002 controls Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 10. Certification: SAS-70 (soon SSAE16) • Control Statements • Great for auditing against SOX 404 controls Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 11. Getting Real How do you ensure physical access to your data centres is restricted to those who need it for a job function? By not having 100 customers a day walking through on audits... Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 12. Getting Real So I hope that answers your question on how we handle key rotation on our distributed filing system utilising AES 256-bit encryption? Can I The IT Manager backs up to ask how you do it at the moment? tape and leaves the tapes in the back of his car overnight. The tapes are encrypted of course? .... Please tell me the car isn’t left on his driveway overnight? .... Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 13. Turning the Tables RFP responses contain a lot of sensitive information How do you classify How many people completed RFP have access to completed responses? RFP responses? How do you ensure access How do you dispose control and prevent leakage of printed copies of RFP of completed RFP responses? responses? Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 14. Industry Representation or Prospects? Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 15. What We Need Software-as-a-Service is often about replacing specific on-premise solutions within the business Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 16. What We Need Software-as-a-Service is often about replacing specific on-premise solutions within the business baseline Cloud On-premise Provider risk risk Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 17. What We Need baseline On-premise risk Cloud Provider risk Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 18. What We’re Getting Great, now I’ve got 6 lots of audit and certification.... Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 19. A Final Plea Customers: Baseline on your current risk exposure Due your due diligence, but make it proportionate If you want champagne, expect to pay for it Industry Bodies: Come together for a unified standard of audit and assessment Represent cloud customers and the service provider, not infrastructure vendors Cloud Providers: Embrace transparency Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011
  • 20. Cloud Computing Due Diligence - WTF? Jimmy Blake @jimmyblake http://jimmyblake.com Security B-Sides London: Cloud Computing - WTF? Wednesday, 20 April 2011