Securing your privileged identity

April 2011 Access Control & Identity Management, Information Security

There are those who argue that the age of cloud computing is merely in the minds of the more far-sighted IT visionaries. I have even met those whose businesses are indifferent to the cloud. This indifference may cost them dearly – and soon.

The UK’s new coalition government is implementing the ‘G-Cloud’ strategy (actually the strategy of the last government) and there are some who claim that it will save the government £3,2bn from its annual IT budget of £16bn. That is not just a big saving for the government – it is an obvious opportunity for suppliers who can ensure it is secure.

The proposal is to replace the present ad-hoc network of department-hosted systems with a dozen dedicated government secure data centres, costing £250m each. The G-Cloud plans could support everything from pooled government data centres to a communal e-mail solution and collaboration. By 2015, the plan is that 80% of government departments could be using this system. But will it be secure enough?

Safeguarding the IT infrastructure from unmonitored access, malware and intruder attacks grows more challenging as the operation evolves for cloud service providers. And as a cloud infrastructure grows, so too does the presence of unsecured privileged identities – those so-called super-user accounts that hold elevated permission to access sensitive data, run programs, and change configuration settings on virtually every component of IT. Privileged identities exist on all physical and virtual operating systems, on network devices such as routers, switches, and firewalls, and in programs and services including databases, line-of-business applications, Web services, middleware, VM hypervisors and more.

Left unsecured, privileged accounts leave an organisation vulnerable to IT staff members who have unmonitored access to sensitive customer data and can change configuration settings on critical components of your infrastructure through anonymous, unaudited access. It can also lead to financial loss from failed regulatory audits such as Payment Card Industry Data Security Standard (PCI-DSS), Health Insurance, Portability and Accountability Action (HIPAA) of 1996, and the Sarbanes–Oxley Act of 2002 standards that require privileged identity controls.

One of the largest challenges for cloud service customers inside and outside of government is attaining transparency into how public cloud providers are securing their infrastructure. How are your identities being managed and secured? Many cloud providers will not give their customers much more of an official answer than a SAS 70 certification. How can we trust in the cloud if the vendors of cloud-based infrastructure neglect to implement both the process and technology to assure that segregation of duties are enforced, and customer and vendor identities are secured?

The cloud vendor’s challenge: accountability

Cloud computing has the potential to transform business technology, but it brings a spectrum of security issues that IT organisations should consider before trusting their sensitive data to the cloud. These issues cause security experts and auditors to rethink many fundamental assumptions about privileged identity management in terms of who is responsible for managing these powerful accounts, how they manage them, and who exactly is in control.

Historically, IT data centres have always been in secured physical locations. Now with cloud computing those locations are no longer maintained directly by the IT organisation. So the question comes down to this: how do you get accountability for management of physical assets that are no longer under your physical control, and exactly what control mechanisms are in place? Can you trust your cloud vendor to secure your most sensitive data? Moreover, if there is a security breach in the cloud, who is to blame? Is it the cloud vendor that disclaims all legal liability in its contract, or an enterprise that relinquishes control of its sensitive data in the first place?

From the vendor’s standpoint, cloud computing promises to reduce customer headcount, make IT more efficient and deliver more consistent service levels. However, there is a paradox that when it comes to security (and control over privileged identities in particular) cloud services are often among the least efficient. Many cloud service providers’ processes – based on ad-hoc techniques like scripting of password changes – are slow, expensive and unreliable. And that is dangerous.

Fortunately the industry is starting to move beyond paralysing discussions about the security and compliance problems that arise from cloud computing to address them head on. One example of this is the Trusted Cloud Initiative, which was launched at RSA Security Conference 2010. The goal of the initiative is “to help cloud providers develop industry-recommended, secure and interoperable identity, access and compliance management configurations, and practices.” However, only time will tell if it will help standardise cloud computing or turn out to be a technology certification of little use.

In addition, several major cloud vendors and ISPs have begun the difficult task of integrating security solutions that are capable of managing the large number of privileged identities that make up their infrastructure (hardware, VM hosts, VM Image OS, application stacks). This has really broken the fundamental model of IT being in control of security and has started to blur the lines between vendor and customer when it comes to the management of security.

The end user’s challenge: transparency

In my opinion, the cloud is a good, compelling idea. It can reduce the cost of IT dramatically. Given that cloud computing is available, the idea of building new data centres these days seems like a last-century way of doing things. On the other hand, for enterprises, the ability to see and touch your own systems in your secured data centre does give confidence that you have some measure control of your destiny. But most large corporations do not have enough IT people or security talent to manage the IT resources they have, and so are turning to outsourcing. Cloud computing is essentially the next generation of outsourcing, so that we are not only reducing man power, but we are getting rid of our hard assets entirely by moving them over to data centres anywhere on the planet that are going to manage this more cheaply than we ever could. And the idea of outsourcing security and liability is extraordinary compelling.

Enterprises should ask the right questions of their cloud providers before taking the leap into cloud and blindly assuming that their data is safe there. Every point of compliance that you are asked to meet an IT organisation and every question you have been asked by an auditor should apply to your cloud vendor – and needs to be asked of them. And because today’s cloud vendors offer literally no transparency and little information, do no be surprised if you do not like the answers you get. Most cloud vendors would say that for security purposes, it is on a ‘need to know’ basis, and you do not need to know. Others state that they are SAS 70 compliant, but that is really just a self-certification.

Here are some questions you must consider asking

* What kind of security does the cloud service provider have in place to protect your privileged accounts and most sensitive data?

* Do they have a privileged identity management technology in place?

* How do they control privileged accounts used in cloud infrastructure to manage sensitive systems and data?

* How do they manage cloud stacks at the physical layer and application stack layers?

* What is your access to audit records?

Whatever regulatory standards your organisation must meet, so too must your cloud vendor. So if you think that by venturing into the cloud you are saving yourself regulatory headaches, think again.

Conclusion

Security is the greatest barrier towards adoption of the cloud, and it is no great surprise that cloud security – managing, verifying and trusting it – was a major theme at the RSA Conference. Unfortunately, improvements in cloud security will not be seen as a priority until a major breach has a significant enough impact on one or more cloud service vendors and customers. That needs to change. When it comes to cloud security, it is the end-user’s duty to understand what processes and methodologies the cloud vendor is using to protect the customer’s most sensitive assets. We do not want the government’s ‘G Cloud’ to be compromised – that would be a public humiliation that would have cloud doubters in their own little heaven.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
AI agents become ‘First Class Identities’
Access Control & Identity Management
AI agents are now approving transactions, accessing systems, triggering workflows, and making decisions autonomously. But uncontrolled AI agents are becoming one of the largest security gaps in modern enterprises.

Read more...
Balancing secure access control and fire safety
Editor's Choice Access Control & Identity Management Fire & Safety
In modern building management, few topics create as much tension as the intersection between security access control and fire evacuation safety. Nichola Allen of G2 Fire sheds light on this delicate balance.

Read more...
Securing water infrastructure for industry and community
Access Control & Identity Management Fire & Safety Government and Parastatal (Industry)
The Badirammogo Water User Association needed a solution that could secure remote sites, reduce reliance on physical guards, and ensure uninterrupted service delivery while remaining aligned with its values and long-term strategy.

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Disconnect between confidence in identity security and operational reality
Access Control & Identity Management News & Events
New FIDO Alliance and HID study reveals gap between identity security confidence and reality; 94% of enterprises claim they can revoke employee access within 24 hours, yet 35% experienced delays or failures in the past two years.

Read more...
Paxton Solo training available to security installers
Paxton Access Control & Identity Management News & Events
Following the launch of Solo, Paxton’s brand-new access control system, the security manufacturer is rolling out dedicated Solo training sessions across South Africa to support security installers working with the system.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.