Taking a holistic approach to tackling the Top Threats to Cloud Computing in a multi-cloud world – Security Boulevard

Posted: September 27, 2022 at 8:20 am

Can you remember the halcyon days of the video game arcades? This will probably date me, but I have fond memories entering the magical world of a gaming arcade while in first year at university. When the odd early morning Control Systems or Principles of Electricity lecture didnt sound too compelling, Id skip class and head to the local arcade with my friends for an hour or two of Defender, Tempest, Frogger, Space Invaders, or Pac-Man.

I was briefly reminded of the arcade gaming world when I came across a recent publication by the Cloud Security Alliance (CSA): Top Threats to Cloud Computing Pandemic Eleven. The paper discusses cloud security themes and considers a range of cloud-related threats for practitioners and those planning migration to the cloud. As you can see from the front cover illustration above, they have designed the artwork inspired by the Pac-Man maze user interface with the 11 threats replacing the traditional Pac-Man ghosts.

The 11 issues are based on feedback from 700 industry experts who identified these, listed in priority as the top issues in their cloud environments. Each of the 11 topics are discussed briefly before considering the business impact, offering key takeaways and then anecdotes and real examples of exploits and exfiltrations to illustrate what has and can happen if you dont protect against these threats. Each threat is also cross-referenced to other CSA resources such as their Security Guidance document and Cloud Controls Matrix (CCM) template spreadsheet. Useful for any cloud practitioners looking to tighten up their cloud environment.

The 11 threats outlined in the report are as follows:

Things have moved on since the 1980s when Pac-Man was ubiquitous, and the attack vectors were the fast-moving ghost gang characters. Blinky was one of them. Maybe you can remember the others? Internet search engine reports Pinky, Inky, and Clyde were the other ghosts in the Pac-Man gang. Full marks if you named all four! Reading the CSA publication reminded me how challenges have evolved from the on-premises environment where the threats were known, the data center was in close proximity, and the processes and procedures were documented and practiced. In the cloud, we have shared responsibility, and the dynamic as well as the threat models/attack vectors have changed.. Yes, the cloud offers the rigor and security diligence of the major cloud service providers but the need for careful allocation of system admins, setting least privilege, environmental hardening, due diligence, and compliance has not gone away.

Entrust CloudControl offers a compliance-centric, enterprise-grade solution for virtualized and containerized environments. It ensures DevSecOps and security administrators can establish, manage, and maintain a robust security posture across multiple clouds and on-prem environments. This prevents inadvertent or malicious misconfigurations leading to failed audits, service disruption, or breaches in security.

For those organizations migrating to multi-cloud and hybrid deployments, Entrust provides a complete suite of security solutions offering the right tools to protect against the top cloud computing threats outlined by the report. Entrust offers solutions that deliver across categories and enable enterprises to achieve their multi-cloud security strategy through a single vendor, securing the workload, creating trust in the environment in which it runs, and ensuring compliance with defined policy managed and maintained across all artifacts and across all deployment environments.

The post Taking a holistic approach to tackling the Top Threats to Cloud Computing in a multi-cloud world appeared first on Entrust Blog.

*** This is a Security Bloggers Network syndicated blog from Entrust Blog authored by Iain Beveridge. Read the original post at: https://www.entrust.com/blog/2022/09/taking-a-holistic-approach-to-tackling-the-top-threats-to-cloud-computing-in-a-multi-cloud-world/

Read the original:

Taking a holistic approach to tackling the Top Threats to Cloud Computing in a multi-cloud world - Security Boulevard

Related Posts