Privacy, security and ethical reflection
ITC568 Cloud Privacy and Security
Governance, Auditing and Incident Handling
Week 10
Dr Peter White
Develop and present a cloud governance framework to underpin the cloud operations for an enterprise
Agenda
© Peter White, 2017
2
‘Good governance is about the processes for making and implementing decisions. It’s not about making ‘correct’ decisions, but about the best possible process for making those decisions.’
The characteristics of good governance are:
Accountability
Transparent
Responsive
Effective and Efficient
Participatory
Follows the rule of law
© Peter White, 2017
3
What is Governance
http://www.goodgovernance.org.au/about-good-governance/what-is-good-governance/#sthash.XA7zQAFm.dpuf
Use of the cloud is like any other investment – it needs to be governed
There needs to be a set of rules, procedures, guidelines that are in place to allow an organisation to get effective use of their use of the cloud
These cloud governance rules could be (and probably should be) based on the existing on-premise IT governance rules
© Peter White, 2017
4
How does Governance fit in the cloud?
There are some additional considerations in a Cloud Governance plan:
Risk Management assessment
Policies and procedures
Processes
Organisational structures
Skills and competencies
Organisational culture & behaviours
© Peter White, 2017
5
What do we need to consider?
Does management have a plan for use of the cloud?
Have they assessed value and opportunity costs?
Have they assessed:
A gain in competitive advantage?
A reach to new markets?
Improving existing products and services?
Retain existing customers?
Increases in productivity?
Cost containment?
Develop new products and services?
Break out of geographic barriers?
© Peter White, 2017
6
Initial management questions
How do these cloud services support the organisational mission?
Has there been a systematic evaluation of organisational readiness?
Will the organisational culture clash with cloud service implementations?
Do cloud related processes clash with established process?
Are the cloud service support skills available at all support levels?
Will the organisational structure allow maximum effectiveness of cloud service usage?
© Peter White, 2017
7
Initial management questions
How will the introduction of cloud services affect investment in existing services?
How will you measure and track the value of the RoI of cloud services vs the risk?
Is there a good level of understanding of the:
Contractual arrangements with the cloud provider?
SLA conditions including:
obligations, pricing model, payment terms, measurements and metrics, penalties
© Peter White, 2017
8
Initial management questions
Start with your Risk Management assessment & plan:
What are the biggest risks that you face?
What is the priority order of these risks?
What controls are to be used to manage them?
How will they be monitored?
Who will monitor them?
How will you report on the effectiveness of the controls?
© Peter White, 2017
9
Initial process questions
There are a number of questions that will now exist around process and workflow:
How will the use of the cloud service affect the existing work process?
What changes will the cloud service make to the existing workflow?
What changes need to be made to existing policies and procedures?
Have the business stakeholders approved the change?
What change management is required?
What training is required?
Do existing customers need to be notified?
© Peter White, 2017
10
Initial process questions
What are the data sets that will be used in the cloud service?
What is their criticality to business operations?
What is their RTO and RPO?
Where will the data be located?
What is the backup plan for the data?
What is the recovery plan for the data?
How do these plans fit into:
Existing data backup process?
Existing BCP?
Is encryption to be used for data:
At rest?
In transit?
Who holds the keys?
© Peter White, 2017
11
Initial process questions
Security governance questions:
What are the security issues identified in the security assessment?
What controls will be used to mange them?
Who can access the cloud service:
Authentication process for:
Internal users
External users
How will users authenticate?
What can users access in the cloud?
Which cloud services and what data sets?
Additional cloud services?
Which users can replicate/delete data in the cloud?
How will existing security policies be enforced and monitored?
Are existing security policies adequate for the cloud service?
How do we monitor unauthorised access to data or applications?
Who will do the security monitoring?
How will you report on the effectiveness of the security controls?
© Peter White, 2017
12
Initial process questions
Data Governance questions
What is the data classification for data stored in the Cloud?
Is any data PII data?
What is the location(s) of the Cloud storage?
How does that affect data sovereignty?
How does that affect our liability under the Privacy Act?
What other privacy acts & regulations may apply, eg. GDPR?
How are we protecting the data?
Do different levels of protection apply to different categories of data?
© Peter White, 2017
13
Initial process questions
Compliance questions:
What are the legislative and regulatory requirements?
How does use of the cloud service fit into:
Current compliance monitoring?
What changes need to be made?
How will compliance reporting work with the cloud service?
© Peter White, 2017
14
Initial process questions
What are you going to audit, and why?
Regulatory compliance
Visibility
Track changes to users, roles, security groups
Track logons, activity and access to resources
Track resource configurations
Tools:
Internal tools:
Logs, auditing tools, log analysis (SPLUNK or similar)
External tools:
CloudWatch – operational settings and resources
CloudTrail – auditing for account activity and API calls
© Peter White, 2017
15
Auditing
An incident is an unplanned interruption to an IT service or a reduction in quality of an IT service
Understand the domain and scope of incident response in the Cloud:
Security is a shared responsibility:
The CSP is generally responsible for security OF the Cloud
The customer is generally responsible for security IN the Cloud
Incident response may be a JOINT and COORDINATED response of the CSP and Customer in cooperation with each other
© Peter White, 2017
16
Incident Response
© Peter White, 2017
17
Incident Response
Best practice:
Establish control
Determine the impact
Recover as needed
Investigate the root cause
Implement improvement
Iterate!
© Peter White, 2017
18
Incident Response
Preparation:
Architect for failure and not just for infrastructure
Implement clear, simple, lightweight governance with clear ownership
Architect & build for speed, agility, security & integrity
Implement clear simple controls & have run books for responders
Automate!
Leverage “least privilege”, and avoid “key man” risk by using highly available & automated process
Validate readiness by frequent tests
Consider the use of Chaos Engineering ( Look at the use of the Chaos Monkey at Netflix at https :// youtu.be/rKAo2wANiHM)
© Peter White, 2017
19
Incident Response
Governance mechanisms:
Who comprises the Governance body?
What is their purpose?
What are the policies that they need to promulgate?
Will the Board sign off these policies?
How will the policies be communicated?
How will the policies be enforced?
© Peter White, 2017
20
Initial process questions
Start with:
Information Security assessment
Risk Management assessment
Know your:
Management plans, mission, RoI and investment plans, evaluations and roadmaps
Add:
Risk management controls
Process and workflow plans
Data plans
Security governance plans
Auditing plans,
Compliance plans,
Incident response plans, and
Governance mechanisms
To get:
Your Cloud Governance plan
© Peter White, 2017
21
Build your plan
Reading:
Honig, S. (2015). Governance in the Cloud. In Ko, R., & Choo, K.(Eds.). (2015). The Cloud Security Ecosystem: Technical, Legal, Business and Management Issues. Waltham, MA: Syngress.
Takabi, H., et al. (2010). "Security and privacy challenges in cloud computing environments." IEEE Security & Privacy 8(6): 24-31. http://ieeexplore.ieee.org.ezproxy.csu.edu.au/document/5655240/
Rebollo, O., Mellado, D., Fernandez-Medina, E., & Mouratidis, H. (2015). Empirical evaluation of a cloud computing information security governance framework. Information and Software Technology, 58(2015), 44-57. http://www.sciencedirect.com/science/article/pii/S0950584914002146
Cloud Security Aliance (2011). "Security Guidance for Critical Areas of Focus in Cloud Computing V3.0." from https://downloads.cloudsecurityalliance.org/initiatives/guidance/csaguide.v3.0.pdf.
ISACA. (2013). Cloud Governance: Questions Boards of Directors Need To Ask. Retrieved from http://www.isaca.org/Knowledge-Center/Research/Documents/Cloud-Governance_whp_Eng_0413.pdf?regnum=
AGIMO. (2012). Community Cloud Governance - An Australian Government Perspective. Canberra. Retrieved from http://apo.org.au/node/30444
Watch:
What is data governance https:// youtu.be/sHPY8zIhy60
Best Practices for Security at Scale https:// youtu.be/wq1l8FiF4B0
Governance on AWS https:// youtu.be/2xWWsO9x5Dw
Change management, Auditing and Compliance in an AWS Hybrid Environment https:// youtu.be/5csB0dcgzzo
Incident Response in the Cloud https:// youtu.be/ZyeTSI900zw
Chaos Monkey at Netflix at https:// youtu.be/rKAo2wANiHM
© Peter White, 2017
22
Tasks: