Concern about confidence and remoteness in a cloud will expostulate adoption of cloud
encryption systems, though Gartner warns there are 6 confidence issues that businesses should
tackle.
The approaching devalue annual expansion rate of software as a service (SaaS) from 2011 to
2016 is 19.5%, platform as
a service (PaaS) 27.7%, infrastructure
as a service (IaaS) 41.3% and confidence services spending 22%.
However, confidence and remoteness are still cited by many organisations as a tip inhibitors of
cloud services adoption, that has led to a introduction of cloud encryption systems in a past
18 months.
While encryption is critical to a secure adoption of cloud services, it should not be viewed
as a “silver bullet”, warns Gartner in a new investigate note.
Analysts suggest that enterprises should initial rise a information confidence devise that addresses six
security issues.
Failure to do so, they say, could supplement cost and complexity to a adoption of cloud computing
without addressing a elemental issues of information remoteness and long-term confidence and
resiliency.
They advise that badly implemented encryption systems competence also even meddle with a normal
functioning of some cloud-based services.
The 6 issues that contingency be addressed are:
- Breach presentation and information residency
- Data supervision during rest
- Data insurance in motion
- Encryption pivotal management
- Access controls
- Long-term resiliency of a encryption system
Breach presentation and information residency
Not all information requires equal protection, so businesses should classify information dictated for cloud
storage and brand any correspondence mandate in propinquity to information crack presentation or if data
may not be stored in other jurisdictions.
Gartner also recommends that enterprises should put in place an craving information confidence plan
that sets out a business routine for handling entrance requests from supervision law enforcement
authorities. The devise should take stakeholders into account, such as legal, contract, business
units, confidence and IT.
Data supervision during rest
Businesses should ask specific questions to establish a cloud use provider’s (CSP’s) data
storage life cycle and confidence policy.
Businesses should find out if:
- Multitenant storage is being used, and if it is, find out what subdivision resource is being
used between tenants.
- Mechanisms such as tagging are used to forestall information being replicated to specific countries or
regions.
- Storage used for repository and backup is encrypted and if a pivotal supervision plan embody a
strong temperament and entrance supervision process to shorten entrance within certain jurisdictions.
Gartner recommends that businesses use encryption to exercise end-of-life strategies by
deleting a keys to digitally fragment a data, while ensuring that keys are not compromised or
replicated.
Data insurance in motion
As a smallest requirement, Gartner recommends that businesses safeguard that a CSP will support
secure communication protocols such as SSL/TLS for browser entrance or VPN-based connectors for
system entrance for stable entrance to their services.
The investigate note says that businesses always encrypt supportive information in suit to a cloud, but
if information is unencrypted while in use or storage, it will be obligatory on a craving to mitigate
against information breaches.
In IaaS, Gartner recommends that businesses foster CSPs that yield network subdivision among
tenants, so that one reside can't see another’s network traffic.
Read some-more on cloud encryption:
Public
cloud encryption: Encrypted cloud storage options for enterprises
Trend
Micro: Encryption is a substructure of cloud security
Cloud
computing and information protection: Cloud computing encryption tutorial
Cloud
encryption use cases
Encryption pivotal management
Enterprises should always aim to conduct a encryption keys, though if they are managed by a
cloud encryption provider, Gartner says they contingency safeguard entrance supervision controls are in place
that will prove crack presentation mandate and information residency.
If keys are managed by a CSP, afterwards businesses should need hardware-based pivotal management
systems within a firmly tangible and managed set of pivotal supervision processes.
When keys are managed or accessible in a cloud, Gartner says it is needed that a vendor
provides parsimonious control and monitoring of intensity snapshots of live workloads to forestall a risk
of analysing
the memory essence to obtain a key.
Access controls
Gartner recommends that businesses need a CSP to support IP subnet entrance restriction
policies so that enterprises can shorten end-user entrance from famous ranges of IP addresses and
devices.
The craving should direct that a encryption provider offer adequate user entrance and
administrative controls, stronger authentication alternatives such as two-factor authentication,
management of entrance permissions, and subdivision of executive duties such as security, network
and maintenance.
Businesses should also require:
- Logging of all user and director entrance to cloud resources, and yield these logs to the
enterprise in a format suitable for record supervision or confidence information and eventuality management
systems.
- The CSP to shorten entrance to supportive complement supervision collection that competence “snapshot” a live
workload, perform information migration, or behind adult and redeem data.
- That images prisoner by emigration or snapshotting collection are treated with a same confidence as
other supportive craving data.
Longterm resiliency a encryption system
Gartner recommends that businesses know a impact on applications and database indexing,
searching and sorting. They should compensate specific courtesy to modernized acid capabilities,
such as substring relating functions and wildcarding such as “contains” or “ends with”.
If a encryption businessman offers options for “function preserving encryption” — for example, to
preserve arrange — regulations competence need a use of stereotyped and authorized algorithms or explanation of
independent acceptance for a potentially enervated encryption.
Related Topics:
Cloud security,
Cloud computing software,
Regulatory correspondence and customary requirements,
IT for utilities and energy,
IT for consulting and business services,
Cloud storage,
IT for ride and transport industry,
IT for manufacturing,
IT for gift organisations,
IT for telecoms and internet organisations,
Privacy and information protection,
IT for convenience and liberality industry,
IT for tiny and medium-sized enterprises (SME),
IT for supervision and open sector,
IT suppliers,
IT for sell and logistics,
IT for media and party industry,
Hackers and cybercrime prevention,
IT for financial services,
VIEW ALL TOPICS
Article source: http://www.computerweekly.com/news/2240180087/Six-security-issues-to-tackle-before-encrypting-cloud-data