BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

The Special Case of Privileged Users in the Cloud

Posted June 23, 2011    Peter McCalister

As we have been discussing the last few weeks, if you want to use the cloud and need to do it in a secure and compliant way, it’s a matter of shared responsibility. If you want your cloud vendors to be secure enough to protect your corporation’s most sensitive data, then you have to insist on it, communicate your requirements and oversee the controls. That leaves the final piece of the cloud security puzzle – the special case of the privileged users in the cloud.

While we can debate the relative security of clouds vs. most corporate data centers, there is one area where using a cloud vendor will always represent greater risk – the threat posed by insiders with administrative privileges. According to the recent Ponemon Institute study cloud providers are “least confident in their ability to restrict privileged user access to sensitive data”.

Now part of that lack of confidence is because their customers control privileged access to the operating system of whatever is running in a cloud computing environment. So as a customer you need to take control of that part of the cloud environment and, as many of our customers are doing, use the same tools they do in their data centers to protect privileged account credentials. Many solutions like our Powerbroker Servers product can be configured to run in a public cloud or in a hybrid mode as an extension of the system in your data center.

That leaves the cloud providers privileged users who administer their hypervisor and control plane environments. Encryption of data is a vital protection and can address a number of concerns about malicious insiders particularly with unstructured data. Database encryption in the cloud is tricky and requires a well thought our architecture and key management system.

We don’t know of any confirmed breaches by cloud insiders but that doesn’t mean there isn’t risk. Most customers don’t have deep insight into their cloud provider’s technology stacks and operating procedures. So ask them! Review their SAS 70 certifications. Agree on standards and audit them. Go onsite and check their controls and look at their logs. Once customers make their needs known I think we will quickly see which cloud providers understand the enterprise customer and want to deliver the security required. In the meantime, caveat emptor.

Leave a Reply

Additional articles

smart-rules-manager-assets

Where Passive Scanning Falls Short

Posted July 11, 2014    Morey Haber

In many sports, as in business, teams will promote a strategy to gain an edge – even if the concept is possibly flawed. Consider an American football hurry-up offense: will it cause the defense to stumble, or will it just exhaust the offense? The play has potential pros and cons, and many strategic technologies are…

Tags:
, , , , , , ,

Retina Vulnerability Audits – July 2014 Patch Tuesday

Posted July 9, 2014    BeyondTrust Research Team

The following is a list of Retina vulnerability audits for this July 2014 Patch Tuesday: MS14-037 - Cumulative Security Update for Internet Explorer (2975687) 34517 – Microsoft Internet Explorer Cumulative Security Update (2975687) MS14-038 - Vulnerability in Windows Journal Could Allow Remote Code Execution (2975689) 34518 – Microsoft Windows Journal (2975789) MS14-039 - Vulnerability in On-Screen Keyboard Could Allow…

patch-tuesday

July 2014 Patch Tuesday

Posted July 8, 2014    BeyondTrust Research Team

This July Microsoft has released six security bulletins which account for over 29 unique vulnerabilities. The most critical bulletins are MS14-037 (Internet Explorer), MS14-038 (Windows Journal)  and MS14-040 (Windows AFD). MS14-037 starts things off with another massive Internet Explorer update on the heels of MS14-035 from last month. This new Internet Explorer bulletin covers over…

Tags:
, ,