BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

The Special Case of Privileged Users in the Cloud

Posted June 23, 2011    Peter McCalister

As we have been discussing the last few weeks, if you want to use the cloud and need to do it in a secure and compliant way, it’s a matter of shared responsibility. If you want your cloud vendors to be secure enough to protect your corporation’s most sensitive data, then you have to insist on it, communicate your requirements and oversee the controls. That leaves the final piece of the cloud security puzzle – the special case of the privileged users in the cloud.

While we can debate the relative security of clouds vs. most corporate data centers, there is one area where using a cloud vendor will always represent greater risk – the threat posed by insiders with administrative privileges. According to the recent Ponemon Institute study cloud providers are “least confident in their ability to restrict privileged user access to sensitive data”.

Now part of that lack of confidence is because their customers control privileged access to the operating system of whatever is running in a cloud computing environment. So as a customer you need to take control of that part of the cloud environment and, as many of our customers are doing, use the same tools they do in their data centers to protect privileged account credentials. Many solutions like our Powerbroker Servers product can be configured to run in a public cloud or in a hybrid mode as an extension of the system in your data center.

That leaves the cloud providers privileged users who administer their hypervisor and control plane environments. Encryption of data is a vital protection and can address a number of concerns about malicious insiders particularly with unstructured data. Database encryption in the cloud is tricky and requires a well thought our architecture and key management system.

We don’t know of any confirmed breaches by cloud insiders but that doesn’t mean there isn’t risk. Most customers don’t have deep insight into their cloud provider’s technology stacks and operating procedures. So ask them! Review their SAS 70 certifications. Agree on standards and audit them. Go onsite and check their controls and look at their logs. Once customers make their needs known I think we will quickly see which cloud providers understand the enterprise customer and want to deliver the security required. In the meantime, caveat emptor.

Leave a Reply

Additional articles

PBPS-screenshot-blog aug2014

Failing the Security Basics: Backoff Point-of-Sale Malware

Posted August 22, 2014    Marc Maiffret

At the beginning of this month, US-CERT issued a security alert relating to a string of breaches that had been targeting Point of Sale (POS) systems. The alert details that attackers were leveraging brute forcing tools to target common remote desktop applications such as Microsoft’s Remote Desktop, Apple Remote Desktop, Splashtop and LogMeIn among others….

Tags:
, , , , , ,

Troubleshooting Windows Privilege Management Rules with Policy Monitor

Posted August 21, 2014    Jason Silva

When defining and testing PowerBroker for Windows rules for production or pilots, customers sometimes tell us, “I don’t think this policy / program is working.” This is usually a case of the policy not properly triggering because of the way the rule was created. A unique feature of PowerBroker for Windows compared to other solutions is a client-side…

Tags:
, , ,
darren-mar-elia

BeyondTrust Webcast: Darren Mar-Elia’s 4 Active Directory Change Scenarios to Track

Posted August 20, 2014    Chris Burd

In our latest webcast, we joined Darren Mar-Elia, CTO at SDM Software, to discuss best practices for Active Directory (AD) change management. Here are some key takeaways from the presentation, followed by a link to a full-length video of the presentation. Mar-Elia kicks things off with a critical insight: that the best AD change management…

Tags:
, , , , , , ,