Privacy, security and ethical reflection

profileSangeeth08
ITC568_201860_Wk10_Governance.pptx

ITC568 Cloud Privacy and Security

Governance, Auditing and Incident Handling

Week 10

Dr Peter White

Develop and present a cloud governance framework to underpin the cloud operations for an enterprise

Agenda

© Peter White, 2017

2

‘Good governance is about the processes for making and implementing decisions. It’s not about making ‘correct’ decisions, but about the best possible process for making those decisions.’

The characteristics of good governance are:

Accountability

Transparent

Responsive

Effective and Efficient

Participatory

Follows the rule of law

© Peter White, 2017

3

What is Governance

http://www.goodgovernance.org.au/about-good-governance/what-is-good-governance/#sthash.XA7zQAFm.dpuf

Use of the cloud is like any other investment – it needs to be governed

There needs to be a set of rules, procedures, guidelines that are in place to allow an organisation to get effective use of their use of the cloud

These cloud governance rules could be (and probably should be) based on the existing on-premise IT governance rules

© Peter White, 2017

4

How does Governance fit in the cloud?

There are some additional considerations in a Cloud Governance plan:

Risk Management assessment

Policies and procedures

Processes

Organisational structures

Skills and competencies

Organisational culture & behaviours

© Peter White, 2017

5

What do we need to consider?

Does management have a plan for use of the cloud?

Have they assessed value and opportunity costs?

Have they assessed:

A gain in competitive advantage?

A reach to new markets?

Improving existing products and services?

Retain existing customers?

Increases in productivity?

Cost containment?

Develop new products and services?

Break out of geographic barriers?

© Peter White, 2017

6

Initial management questions

How do these cloud services support the organisational mission?

Has there been a systematic evaluation of organisational readiness?

Will the organisational culture clash with cloud service implementations?

Do cloud related processes clash with established process?

Are the cloud service support skills available at all support levels?

Will the organisational structure allow maximum effectiveness of cloud service usage?

© Peter White, 2017

7

Initial management questions

How will the introduction of cloud services affect investment in existing services?

How will you measure and track the value of the RoI of cloud services vs the risk?

Is there a good level of understanding of the:

Contractual arrangements with the cloud provider?

SLA conditions including:

obligations, pricing model, payment terms, measurements and metrics, penalties

© Peter White, 2017

8

Initial management questions

Start with your Risk Management assessment & plan:

What are the biggest risks that you face?

What is the priority order of these risks?

What controls are to be used to manage them?

How will they be monitored?

Who will monitor them?

How will you report on the effectiveness of the controls?

© Peter White, 2017

9

Initial process questions

There are a number of questions that will now exist around process and workflow:

How will the use of the cloud service affect the existing work process?

What changes will the cloud service make to the existing workflow?

What changes need to be made to existing policies and procedures?

Have the business stakeholders approved the change?

What change management is required?

What training is required?

Do existing customers need to be notified?

© Peter White, 2017

10

Initial process questions

What are the data sets that will be used in the cloud service?

What is their criticality to business operations?

What is their RTO and RPO?

Where will the data be located?

What is the backup plan for the data?

What is the recovery plan for the data?

How do these plans fit into:

Existing data backup process?

Existing BCP?

Is encryption to be used for data:

At rest?

In transit?

Who holds the keys?

© Peter White, 2017

11

Initial process questions

Security governance questions:

What are the security issues identified in the security assessment?

What controls will be used to mange them?

Who can access the cloud service:

Authentication process for:

Internal users

External users

How will users authenticate?

What can users access in the cloud?

Which cloud services and what data sets?

Additional cloud services?

Which users can replicate/delete data in the cloud?

How will existing security policies be enforced and monitored?

Are existing security policies adequate for the cloud service?

How do we monitor unauthorised access to data or applications?

Who will do the security monitoring?

How will you report on the effectiveness of the security controls?

© Peter White, 2017

12

Initial process questions

Data Governance questions

What is the data classification for data stored in the Cloud?

Is any data PII data?

What is the location(s) of the Cloud storage?

How does that affect data sovereignty?

How does that affect our liability under the Privacy Act?

What other privacy acts & regulations may apply, eg. GDPR?

How are we protecting the data?

Do different levels of protection apply to different categories of data?

© Peter White, 2017

13

Initial process questions

Compliance questions:

What are the legislative and regulatory requirements?

How does use of the cloud service fit into:

Current compliance monitoring?

What changes need to be made?

How will compliance reporting work with the cloud service?

© Peter White, 2017

14

Initial process questions

What are you going to audit, and why?

Regulatory compliance

Visibility

Track changes to users, roles, security groups

Track logons, activity and access to resources

Track resource configurations

Tools:

Internal tools:

Logs, auditing tools, log analysis (SPLUNK or similar)

External tools:

CloudWatch – operational settings and resources

CloudTrail – auditing for account activity and API calls

© Peter White, 2017

15

Auditing

An incident is an unplanned interruption to an IT service or a reduction in quality of an IT service

Understand the domain and scope of incident response in the Cloud:

Security is a shared responsibility:

The CSP is generally responsible for security OF the Cloud

The customer is generally responsible for security IN the Cloud

Incident response may be a JOINT and COORDINATED response of the CSP and Customer in cooperation with each other

© Peter White, 2017

16

Incident Response

© Peter White, 2017

17

Incident Response

Best practice:

Establish control

Determine the impact

Recover as needed

Investigate the root cause

Implement improvement

Iterate!

© Peter White, 2017

18

Incident Response

Preparation:

Architect for failure and not just for infrastructure

Implement clear, simple, lightweight governance with clear ownership

Architect & build for speed, agility, security & integrity

Implement clear simple controls & have run books for responders

Automate!

Leverage “least privilege”, and avoid “key man” risk by using highly available & automated process

Validate readiness by frequent tests

Consider the use of Chaos Engineering ( Look at the use of the Chaos Monkey at Netflix at https :// youtu.be/rKAo2wANiHM)

© Peter White, 2017

19

Incident Response

Governance mechanisms:

Who comprises the Governance body?

What is their purpose?

What are the policies that they need to promulgate?

Will the Board sign off these policies?

How will the policies be communicated?

How will the policies be enforced?

© Peter White, 2017

20

Initial process questions

Start with:

Information Security assessment

Risk Management assessment

Know your:

Management plans, mission, RoI and investment plans, evaluations and roadmaps

Add:

Risk management controls

Process and workflow plans

Data plans

Security governance plans

Auditing plans,

Compliance plans,

Incident response plans, and

Governance mechanisms

To get:

Your Cloud Governance plan

© Peter White, 2017

21

Build your plan

Reading:

Honig, S. (2015). Governance in the Cloud. In Ko, R., & Choo, K.(Eds.). (2015). The Cloud Security Ecosystem: Technical, Legal, Business and Management Issues. Waltham, MA: Syngress.

Takabi, H., et al. (2010). "Security and privacy challenges in cloud computing environments." IEEE Security & Privacy 8(6): 24-31. http://ieeexplore.ieee.org.ezproxy.csu.edu.au/document/5655240/

Rebollo, O., Mellado, D., Fernandez-Medina, E., & Mouratidis, H. (2015). Empirical evaluation of a cloud computing information security governance framework. Information and Software Technology, 58(2015), 44-57. http://www.sciencedirect.com/science/article/pii/S0950584914002146

Cloud Security Aliance (2011). "Security Guidance for Critical Areas of Focus in Cloud Computing V3.0." from https://downloads.cloudsecurityalliance.org/initiatives/guidance/csaguide.v3.0.pdf.

ISACA. (2013). Cloud Governance: Questions Boards of Directors Need To Ask. Retrieved from http://www.isaca.org/Knowledge-Center/Research/Documents/Cloud-Governance_whp_Eng_0413.pdf?regnum=

AGIMO. (2012). Community Cloud Governance - An Australian Government Perspective.  Canberra. Retrieved from http://apo.org.au/node/30444

Watch:

What is data governance https:// youtu.be/sHPY8zIhy60

Best Practices for Security at Scale https:// youtu.be/wq1l8FiF4B0

Governance on AWS https:// youtu.be/2xWWsO9x5Dw

Change management, Auditing and Compliance in an AWS Hybrid Environment https:// youtu.be/5csB0dcgzzo

Incident Response in the Cloud https:// youtu.be/ZyeTSI900zw

Chaos Monkey at Netflix at https:// youtu.be/rKAo2wANiHM

© Peter White, 2017

22

Tasks: