As companies make the journey to the public cloud, they must learn from the avoidable mistakes that many other companies have made in the recent past in their respective cloud journeys. Just in the last two years, many such simple and avoidable mistakes in securing the application and data hosted in the public cloud have led to massive data and network breaches at large financial and technology firms such as Accenture, Booz Allen Hamilton, Capital One, Facebook, MGM, Microsoft, and Verizon.
To prevent breaches companies must develop a secure enterprise cloud operating model based on a cloud-first paradigm that can achieve a practical, cost-effective, and agile target state, tailored for a public cloud environment such as SaaS, PaaS, or IaaS that supports operationalization and maintains developer and business-compatible evergreen processes. In meeting the target state for infrastructure and application security in the cloud, use a two-phased approach. For Phase 1, establish a core cloud infrastructure security foundation. In Phase 2, establish a cloud application security paradigm on top of the secure foundation.
Security pros can use the following measurable objectives to implement the two phases detailed below:
Phase 1
The steps to design and implement a secure cloud foundation:
To identify, design, and implement the cloud security patterns for the core security domains for a given public or private cloud environment, prioritize the following security domains and technologies:
Phase 2
To establish the cloud application security paradigm:
CISOs need to lead from the front and take an active role in the evangelization and implementation of cloud security controls under the auspices of a secure enterprise cloud operating model.
Raj Badhwar, chief information security officer, Voya Financial
Note: Badhwar based this column on a session he held for the RSA Conference 2021.
The post A roadmap for developing a secure enterprise cloud operating model appeared first on SC Media.
Click to Open Code Editor