Securing the cloud layer by layer

1 May 2015 Infrastructure, Integrated Solutions

Security has typically been, and continues to be, one of the major areas of concern for organisations contemplating a move into the cloud, and for good reason. Security breaches can have far-reaching consequences that could cripple a business, and legislative compliance issues add further complications. However, security challenges, particularly regarding the public cloud, have led to a misconception that a private cloud is the most secure offering.

AJ Hartenberg, portfolio manager: data centre services at T-Systems in South Africa.
AJ Hartenberg, portfolio manager: data centre services at T-Systems in South Africa.

The perception that the private cloud is less vulnerable to security breaches is a risky one, as the reality is that the cloud, like any IT environment, is only as secure as it is made to be. Outsourcing to a specialist cloud provider, on the other hand, carries significantly reduced risk, as these providers have more extensive resources and expertise, and often are at the forefront of security practices. Securing the cloud, whether this is private or outsourced, requires a layer-by-layer approach to minimise vulnerability. Whether organisations opt for the private model, or take the decision to outsource to a specialist, there are many security factors that need to be considered.

One of the very first security aspects, and one that is so simple it is often overlooked, is access rights to elements within the actual cloud platform. If user IDs and passwords are not secure, the entire environment could potentially be compromised. If users have access to areas they should not, vulnerabilities are created. As a result, the first layer of cloud security should be to create stringent rules around passwords, from characteristics of the password to enforcing regular password changes, to ensuring appropriate levels of access for users.

In addition, it is essential to apply different levels of security at different stages within the cloud platform, to secure all layers from the physical environment to the various cloud components. This includes the hypervisor layer, which incorporates a variety of different components that must be secured. In addition, the different layers should be segregated to prevent users from being able to penetrate from one area to another or break out of the various layers. Securing network access is also essential, including aspects such as intrusion prevention services (IPS), properly configured firewalls, network switch configuration and more.

Management still applies

These elements are similar to those required to secure any IT environment, however, the cloud serves to exacerbate the problems of not having adequate security. In a cloud environment, the entire system is at risk if security is ineffective, and in fact practically all systems are easily accessible if passwords can be hacked, traced or broken. This is why segregation is so important – to ensure that even if one system is breached, the entire system is not compromised. If this is not done correctly, a single misplaced or unsecured password could result in a person with malicious intent accessing everything from HR and finance to sensitive company information and strategic documentation. End user passwords remain the single most overlooked element of security, and must be secured.

In addition, organisations should ensure that strict operating system access rights are applied to ensure users cannot access file systems they do not need to access. This needs to be implemented at a file level, with permissions to read, write, create files and so on, to minimise damage should a breach occur. Access to applications should be controlled via two-factor authentication – using a password as well as an additional means of clarification – and access rights should only be granted as necessary.

For example, a marketing employee does not need to access HR or finance applications, so they should not be able to do so. Furthermore, application identities should not be generic. Each employee should have their own ID to access applications, to ensure greater levels of security and control.

Policies, procedures and processes also need to be put into place to ensure security. Standard policies need to govern access and application rights and roles defined per user: if a user has a certain role, they need a certain level of access to certain applications. This policy should drill down to a specific and granular level per user. Procedures need to be repeatable and ensure that all security aspects are governed and not overlooked. Processes too must be streamlined and repeatable, and people need to be made aware of these processes to ensure they can be followed. This in turn aids in compliance as it simplifies auditing with documented, signed and repeatable policies, processes and procedures.

Deferring to specialists

Security, particularly when it comes to the cloud, is a complex task that, when considered at this level, is often too complex for many organisations to adequately assure using in-house skills. As a result, utilising a specialist cloud provider can be of enormous benefit in ensuring all of the elements of security are put into place and in reducing risk. Cloud service providers have greater access to resources, making it easier for them not only to ensure adequate security, but also to identify a breach and take proactive measures to prevent a breach happening.

Outsource providers have a stringent approach to security with regular audits and penetration testing, to ensure segregation of layers is in place. Furthermore, they are often at the forefront of security due to close relationships with vendors that underpin cloud computing, including hypervisor vendors.

Securing the cloud is a complex task that can have significant negative consequences if ineffectively addressed. From standard security such as firewalls, intrusion detection and prevention, anti-virus and encryption operating systems and applications, there are many aspects and layers to consider. In addition, passwords are vitally important, but are something that is very often overlooked. Partnering with a specialist cloud provider can assist organisations to ensure their cloud IT infrastructure and services are adequately secured, so that they can leverage the benefits without falling prey to the pitfalls of a security breach.

For more information contact T-Systems in South Africa, +27 (0)11 266 0266, lebohang.thokoane@t-systems.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

AI projects are failing at alarming rates
AI & Data Analytics Infrastructure
As organisations around the world accelerate their investments in artificial intelligence, digital transformation and data analytics, a growing number of industry experts are warning that many companies are still approaching these initiatives in fundamentally flawed ways.

Read more...
Understanding the Shared Responsibility Model
Infrastructure Security Services & Risk Management
While the cloud can certainly be a growth enabler in many ways, it can also introduce new security risks. Companies want to have a clear understanding of where their security duties end and where their cloud service provider’s begin.

Read more...
Data privacy best practices for physical security teams
Genetec Surveillance Integrated Solutions IoT & Automation
Physical security systems produce large amounts of information from video footage, access control records, and licence plate data. Recommendations assist organisations in safeguarding sensitive data, while ensuring effective security operations.

Read more...
Gallagher Security strengthens KwaZulu-Natal presence
Gallagher News & Events Integrated Solutions
Gallagher Security has reinforced its commitment to the KwaZulu-Natal region with its Command the Future event. The full-day event welcomed over 100 channel partners, end users, and consultants, marking Gallagher’s third major event in Durban.

Read more...
Cloud security in visitor management and access control
SA Technologies Access Control & Identity Management Infrastructure Residential Estate (Industry) Commercial (Industry)
Cloud has become the default platform for modern security operations, from visitor management portals and remote access control to incident logging, reporting, analytics, and integrations. But “in the cloud” does not mean “someone else is securing it for us”.

Read more...
Surveillance & AI roundtable
DeepAlert Lytehouse Refraime SMART Security Solutions Technews Publishing Editor's Choice Surveillance Integrated Solutions AI & Data Analytics
SMART Security Solutions held an online roundtable with a few surveillance experts to explore the intersection of surveillance and AI, gaining insights into the market and how control rooms are evolving.

Read more...
Coordinated efforts lead to successful crime response
News & Events Surveillance Integrated Solutions
A synchronised operation involving Vumacam’s control room operators, the Johannesburg Metropolitan Police Department (JMPD), and 24/7 Drone Force, resulted in the successful identification and apprehension of a suspect linked to a reported theft case.

Read more...
New commercial and technical appointments at Veeam
News & Events Infrastructure
Veeam Software has announced two senior appointments in its South African business as it continues to invest in local market growth and partner and customer engagement.

Read more...
Access as a Service is inevitable
Technews Publishing SMART Security Solutions ATG Digital Access Control & Identity Management Infrastructure
When it comes to Access Control as a Service (ACaaS), most organisations (roughly 90% internationally) plan to move, or are in the process of moving to the cloud, but the majority of existing infrastructure (about 70%) remains on-premises for now.

Read more...
Privacy by design or by accident
Security Services & Risk Management Infrastructure
Africa’s data future depends on getting it right at the start. If privacy controls do not withstand real-world conditions, such as unstable power, fragile last-mile connectivity, shared devices, and decentralised branch environments, then privacy exists only on paper.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.