critical assets (in step 1), data disclosure could be a risk (identified in step 2) of very high severity level (in step 3). Based upon these, data disclosure risk may be associated with employee records.
Based upon the risk assessment for the assets, a client could consider formulating terms and conditions of the contractual agreement with CSP; for example, a client might insist on having
Cloud service adoption and operation for enterprise businesses should abide by compliance policies. There are primarily two types of policies controlling IT operations in an enterprise that requires compliance even after moving operations to Cloud.
Internal Policy Compliance: Controls the nature of IT operations within an organization. A Cloud client organization needs to maintain same compliance even when operating in Cloud. This would require clear assessment of the potential difficulties in maintaining the compliance in Cloud and a process to ensure that this is effectively achieved.
External Policy Compliance: Includes legal legislations and industry regulations. These external compliance policies control the nature of IT operations related to the flow of data out of an organization. However, they may differ based upon the type of information (for example, source code versus employee records), business (for example medical services versus financial
services), etc.
Meeting all the varied client compliance requirements is generally difficult for a CSP. Compared to Private Clouds, the Public Cloud environment makes compliance more challenging. Therefore, many enterprises may prefer to adopt the hybrid Cloud deployment model so that they can ensure all the necessary policy compliances.
The Concept in Practice section covers some key products which use various technologies introduced in the earlier lesson for security in Cloud and in a VDC environment. These include:
• RSA SecurID
• RSA Archer eGRC
• VMware vShield App
• VMware vShield Edge
• VMware vShield Endpoint
Validating identities is especially critical when users require access anytime, anywhere, and often on devices that the organization has little control over. RSA SecurID® two-factors
authentication provides an added layer of security to ensure that only the right user can access the relevant virtual session within the virtual desktop environment.
RSA SecurID two-factors authentication is based on something a user knows (a password or PIN) and something user has (an authenticator device). It provides a much more reliable level of user authentication than reusable passwords. It generates a new one-time password code every 60 seconds, making it difficult for anyone other than the genuine user to input the correct token code at any given time. To access their virtual desktop, users combine their secret Personal Identification Number (PIN) with the token code that appears on their SecurID authenticator display at that given time. The result is a unique, one-time password that is used to positively assure a user’s identity.
RSA Archer eGRC platform is an advanced security management system that provides a single point of visibility and coordination for physical, virtual, and Cloud assets. It provides the
foundation for all RSA Archer eGRC solutions. The RSA Archer eGRC Platform supports business-level management of governance, risk, and compliance. Users can automate business processes, streamline workflow, control user access, adapt the user interface, and deliver real-time reports.
Core enterprise governance, risk, and compliance solutions that are built on the RSA Archer eGRC Platform include:
• Risk Management: Identify risks to your business, evaluate them through online assessments and metrics, and respond with remediation or acceptance.
• Compliance Management: Document your control framework, assess design and operational effectiveness, and respond to policy and regulatory compliance issues.
• Threat Management: Track threats through a centralized early warning system to help prevent attacks before they affect your enterprise.
• Audit Management: Centrally manage the planning, prioritization, staffing, procedures, and reporting of audits to increase collaboration and efficiency.
• Business Continuity Management: Automate your approach to business continuity and disaster recovery planning, and enable rapid, effective crisis management in one
solution.
• Enterprise Management: Manage relationships and dependencies within your enterprise hierarchy and infrastructure to support GRC initiatives.
VMware vShield™ App is a part of the VMware vShield family. It is a hypervisor-based
application-aware firewall solution. It protects applications in a VDC environment from network-based threats by providing visibility into network communications and enforcing granular policies with security groups.
VMware vShield™ App serves as a hypervisor level firewall and enforces inbound/outbound connection control at the virtual NIC level. Connection control can be based on network, application port, protocol type (TCP, UDP), and application type.
VMware vShield™ App observes network activity between VMs to define and refine firewall policies and secure business processes through detailed reporting of application traffic (application, sessions, bytes).
Other key features include:
•
Security groups eliminate the need for dedicated hardware and VLANs for traffic separation.•
Simplifies compliance with comprehensive logging of all VM network activity•
Supports administrator-defined, business-relevant groupings of VMs by their virtual NICsVMware vShield™ Edge is a part of the VMware vShield family. It is deployed as a virtual appliance and serves as a network security gateway for all vSphere hosts within the VDC. It provides many services including firewall, VPN, and Dynamic Host Configuration Protocol (DHCP) services.
Key security features include:
•
Firewall Service: Provides firewall services for inbound and outbound connection control with rules based on source/destination IP address, source/destination ports, andprotocol type (for example TCP or UDP).
•
It masquerades (i.e., hides) IP addresses in a VDC to untrusted locations.•
Site-to-Site VPN: Provides secure communication between VDCs (or virtual machines). It enables IPSec based VPN using the Internet Key Exchange (IKE) protocol.•
Port Group Isolation: Enables enforcement, at the hypervisor level, of a policy restricting traffic within a VDC to specified port groups. In conjunction with vShield Edge, port group isolation eliminates the need for creating VLANs by creating a barrier between the virtual machines protected by the vShield Edge and the external network. This has the same effect as VLANs in virtual or physical switch environments.•
Logging and Auditing: Supports an administrator-defined logging on/off for key security events (errors, warnings, etc.). An admin can define logging on/off rules for the firewall and the VPN.Note: A virtual appliance is a software application (which might be combined with minimal necessary OS) to run on a VM without installation.
VMware vShield Endpoint is also part of the VMware vShield family. It consists of a hardened special security VM with a third party anti-virus software. VMware vShield Endpoint streamlines and accelerates antivirus and anti-malware deployment because antivirus engine and signature files are only updated within the special security VM.
Key features of VMware vShield Endpoint include:
•
Improves VM performance by offloading file scanning and other tasks from VMs to the security VM.•
Prevents antivirus storms and bottlenecks associated with multiple simultaneous antivirus and anti-malware scans and updates.•
Reduces risk by eliminating agents susceptible to attack and enforce remediation more easily.•
Satisfies audit requirements with detailed logging of antivirus and anti-malware activities.This module covered VDC and Cloud security concerns and threats including multitenancy, data privacy and ownership, and velocity of attack factor.
Cloud infrastructure security mechanisms at compute, storage, and network levels include securing data using encryption, intrusion detection techniques, and methods to provide physical security.
Access control mechanism included RBAC. Identity management included one-time password, federated identity management, and OpenID.
The Governance, Risk, and Compliance (GRC) discussion focused upon various aspects, including information flow regulations and risk assessment process. Finally, the module discussed Cloud security best practices including recommendation of Cloud security Alliance.