26 December 2019
Cloud Security Issues and Solutions
All cloud-based organizations face compliance issues. This means the cloud provider must comply with national and international requirements.
It is also important to know what types of data are sent to the cloud, and to be able to carefully control this stream. This can be especially difficult when users can subscribe to cloud services without the knowledge of the organization’s management, and DLP systems may not notice the use of cloud services from separate laptops or computers outside the organization. In these cases, it makes sense to use the services of Cloud Access Security Broker-CASB.
Such systems provide:
Visibility. CASBs allow you to search for and discover all used allowed and unauthorized cloud services and visualize them: which cloud applications or services employees have access to and who uses them, from which devices and from which location.
Data protection. CASB allows you to manage cloud access rights to prevent access to unauthorized services and applications, control access to resources from various devices, as well as data access control policies.
Threat Protection CASBs can detect and neutralize malware on cloud platforms. According to studies by Netskope and the Ponemon Institute, 31% of organizations experienced negative impacts on their critical data caused by cloud malware.
Conformity. CASB helps to comply with established internal information security policies and demonstrate regulatory compliance with external regulators.
Protecting customers and endpoints
Clients in the cloud need protection at the same level as clients within the organization’s network. Such protection includes software patches, configuration management, and malware protection. To scale in the cloud, these processes should be automated and, ideally, should be consistent with the processes within the organization’s network. For example, if an organization uses antivirus software of the same manufacturer within the organization’s network, then the antivirus in the cloud system must be of the same manufacturer or of the same type. It is also important to ensure that anti-malware programs do not slow down performance both within the enterprise network and in the cloud.
Identity and Access Management
The main task of identity management is to control access to computer resources, applications, data and services. This problem is solved by IdM or IAM (Identity and Access Management) systems.
Cloud systems can use forms authentication to identify users. The organization can independently provide authentication of users in the cloud service or use the services of identity management service providers. The methods for this are called differently, for example, “authentication identification”, “identification federation” and include a number of protocols . These techniques depend on the systems that the organization wants to use to authenticate users:
AML / WS-Fed is commonly used for enterprises (for example, using Microsoft Active Directory).
OAuth is mainly used by consumer-oriented systems (e.g. Facebook, Google, etc.).
0
0
Comments
Facebook improves connectivity in the African region with an undersea internet cable
7 November 2021Can blind spots be avoided when monitoring DCs?
3 November 2021Influence of automation in DC on engineering personnel
30 October 2021The frequency of accidents in DC has decreased and the sum of damage has increased significantly
26 October 2021
How to avoid mistakes when choosing a hosting
How to avoid mistakes when choosing a hosting
Chinese manufacturer Loongson will enter the market ..
Chinese manufacturer Loongson will enter the market with 16-core processor in 2020
Please sign-in to comment here