Showing posts with label Cloud. Show all posts
Showing posts with label Cloud. Show all posts

Thursday, July 16, 2015

Insider secrets for a security leader to assess a cloud provider

If you use a cloud service or hosting provider you need to read this.  Ensure you have access to all technical documents pertaining to your infrastructure with them.  Demand access to reports on a regular (weekly) basis and make them prove you are getting what you're paying for.

From CSO Online:

Insider secrets for a security leader to assess a cloud provider

For the last 4.5 years at Sumo Logic (Sumo for short) I have been working to help build the once tiny startup renting a shared loft above a bookstore into the cloud-first big data powerhouse we are today. This puts me in an interesting position when I am asked to review other cloud providers' security, privacy and compliance postures as part of our own procurement process.

Thursday, July 9, 2015

What a business leader should know about the cloud and its impact

From Help Net Security:

What a business leader should know about the cloud and its impact

Great companies see business risks as opportunities, and execute strategies accordingly. Such a mentality is compatible with emerging technologies. IT plays a vital role in the deployment of new strategies that mitigate business risk.

With the proliferation of so-called cloud services, the execution has become less complicated. The cloud is no longer an emerging phenomenon, and the number of vendors and services offered with the “cloud“ badge has been exploding. Indeed, there are very few companies in the world that are not currently using cloud services in some form.

Thursday, July 2, 2015

Amazon releases new, easily auditable TLS implementation

If your SOHO/SMB utilizes AWS then this is something you should be planning to implement.

From Help Net Security:

Amazon releases new, easily auditable TLS implementation

A new, open source implementation of the TLS encryption protocol has been unveiled by Amazon Web Services.

Dubbed s2n (shorthand for "signal to noise"), the library doesn't implement rarely used options and extensions, meaning its size - currently some 6,000 lines of code - is much, much smaller than that of OpenSSL, currently the most widely used open source implementation of the SSL and TLS protocols, which contains more than 500,000 lines of code.

Saturday, May 16, 2015

Lost in the clouds: Your private data has been indexed by Google

From CSO Online:

Lost in the clouds: Your private data has been indexed by Google

Our lives are digital now.

Everything we do online leaves a trail that leads directly to us; something privacy advocates are fighting to eliminate. However, we're our own worst enemy when it comes to privacy, and personal cloud adoption has done nothing to help the situation.

Tuesday, May 12, 2015

10 Security Questions To Ask A Cloud Service Provider

From Dark Reading:


10 Security Questions To Ask A Cloud Service Provider


As security teams try to help line-of-business users and other IT practitioners take advantage of cloud benefits as safely as possible, they're increasingly stepping into the role of trusted advisor. The scalability, flexibility, and convenience of software-as-a-service (SaaS), infrastructure-as-a-service  (IaaS), and platform-as-a-service (PaaS) offerings frequently come at the cost of added risk to the business. It is up to information security pros to help evaluate potential providers to best evaluate where those risks are coming from.

Monday, May 11, 2015

Do you know where your sensitive data lives?

From Help Net Security:


Do you know where your sensitive data lives?


The majority of IT security professionals don’t have full visibility into where all their organization’s sensitive data resides, according to Perspecsys.

Tuesday, May 5, 2015

The risks of moving data into cloud and mobile environments

From Help Net Security (podcast):


The risks of moving data into cloud and mobile environments


In this podcast recorded at RSA Conference 2015, Rich Campagna, VP, Products & Marketing at Bitglass, talks about how cloud and mobile and the the largest trends happening in enterprise IT today.

Friday, March 13, 2015

Shadow Cloud Services a serious risk for Government Networks

Not just government, these are a threat to SOHO/SMB's.  For example, if you're a medical practice and have employees; billing, NP's/PA's or Dr.s storing data on a service like Google Drive so they can work on it from home or a public hot spot you could have serious problems. 

From Security Affairs:

Shadow Cloud Services a serious risk for Government Networks

Cloud Security Alliance revealed that shadow cloud service used by employees and unmanaged by IT can pose a major security problem for organizations.