BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

The Special Case of Privileged Users in the Cloud

Posted June 23, 2011    Peter McCalister

As we have been discussing the last few weeks, if you want to use the cloud and need to do it in a secure and compliant way, it’s a matter of shared responsibility. If you want your cloud vendors to be secure enough to protect your corporation’s most sensitive data, then you have to insist on it, communicate your requirements and oversee the controls. That leaves the final piece of the cloud security puzzle – the special case of the privileged users in the cloud.

While we can debate the relative security of clouds vs. most corporate data centers, there is one area where using a cloud vendor will always represent greater risk – the threat posed by insiders with administrative privileges. According to the recent Ponemon Institute study cloud providers are “least confident in their ability to restrict privileged user access to sensitive data”.

Now part of that lack of confidence is because their customers control privileged access to the operating system of whatever is running in a cloud computing environment. So as a customer you need to take control of that part of the cloud environment and, as many of our customers are doing, use the same tools they do in their data centers to protect privileged account credentials. Many solutions like our Powerbroker Servers product can be configured to run in a public cloud or in a hybrid mode as an extension of the system in your data center.

That leaves the cloud providers privileged users who administer their hypervisor and control plane environments. Encryption of data is a vital protection and can address a number of concerns about malicious insiders particularly with unstructured data. Database encryption in the cloud is tricky and requires a well thought our architecture and key management system.

We don’t know of any confirmed breaches by cloud insiders but that doesn’t mean there isn’t risk. Most customers don’t have deep insight into their cloud provider’s technology stacks and operating procedures. So ask them! Review their SAS 70 certifications. Agree on standards and audit them. Go onsite and check their controls and look at their logs. Once customers make their needs known I think we will quickly see which cloud providers understand the enterprise customer and want to deliver the security required. In the meantime, caveat emptor.

Leave a Reply

Additional articles

powerbroker-for-mac-diagram-small

PowerBroker for Mac: A Least-Privileged Apple a Day…

Posted July 27, 2015    Jason Silva

BeyondTrust PowerBroker for Mac reduces the risk of privilege misuse by enabling standard users on Mac OS X to perform administrative tasks successfully without entering elevated credentials.

Tags:
, ,
PrivilegedAccountManagement

On Demand Webinar – Now is the time for Privileged Account Management

Posted July 24, 2015    BeyondTrust Software

In this webinar, SANS Instructor and Founder of Voodoo Security, Dave Shackleford, will revisit several hacking and breach scenarios that involved privileged accounts, and use these as examples while discussing tools and tactics to get this problem under control once and for all.

Tags:
, ,
dave-shackleford-headshot

Privileged Account Management: The Time is Now

Posted July 22, 2015    Dave Shackleford

There’s plenty of problems we don’t have great options for in InfoSec today. Malware is a pain point that keeps evolving rapidly. 0-day exploits are tough to prepare for. Privileged account management? We got this. We know the root causes, we know how it manifests, we know how to get it under control effectively, and there are great technology solutions that are enterprise-class.

Tags:
, ,