If You Get Your Security Right
By Dave Anderson
The cloud and security are intrinsically intertwined, and only when both work in symbiosis can a business truly grow. There are 5 main areas where security can team up with the cloud to offer companies the greatest potential to thrive—and it isn’t hard to get it right:
1. Data Protection
Data is key and possibly the most important asset for organizations—a single breach or leak of sensitive data can cripple the entire business, so a data protection strategy must protect the data itself. The ability to move sensitive information into and throughout the cloud is essential for businesses to function and collaborate efficiently, quickly and freely—but this ability must be supported by a comprehensive data protection strategy. The trick is to protect data at the moment of creation, before it moves out of the enterprise or even enters the cloud. Only by doing that can you ensure that any data source is comprehensively protected, and the risk to potential exposure is minimized.
2. Regulatory Compliance and Data Residency Requirements
Sensitive data that is moved into and across cloud infrastructures can easily introduce additional complexity and cost to regulatory compliance—potentially costing thousands in fines and damaging reputations. Companies that ensure sensitive data is comprehensively protected can greatly reduce cost, complexity and overall risk in meeting and maintaining regulatory compliance.
3. Scalability and Flexibility
The cloud has opened up previously unseen opportunities for organizations to grow and expand quickly, smoothly and with ease. With information immediately and easily available anywhere, anytime, regardless their own infrastructure the cloud offers the flexibility and scalability that in the past was an insurmountable obstacle for businesses restricted by their on-site resources. The key to successfully harnessing this opportunity is a flexible data security architecture that is extensible and adaptable across multiple applications and systems, while not adversely impacting the user experience. Failure to put a comprehensive, data-centric protection program can cause cloud initiatives to be delayed or fraught with hidden security issues.
4. Cost Efficiencies
This element is two-fold. Reap the powerful cost savings, by only paying for what you use, so there’s the capital, and operating, expenditure benefits. The second element is that most cloud computing platforms provide the means to capture, monitor, and control usage information for accurate billing. A single, comprehensive data protection platform can eliminate the threat of risky fines from compliance breaches or data loss while also reducing the need to invest into multiple security tools.
Access to Data Anytime, Anywhere
When harnessed correctly, cloud-computing capabilities offer numerous opportunities to drive business innovation. Rather than having to provide remote access to your infrastructure, it is available 24/7 for the workforce to access. No longer will you arrive for a meeting only to find the materials on your USB stick are a previous version. Instead you access the original file wherever you happen to be. Sales teams can check stock levels in real time. An employee stuck at home waiting for a delivery, or in an airport waiting for an ‘ash cloud’ to disperse, can still work as effectively as in the office. By employing a security strategy that protects and travels with all data, anywhere, anytime businesses can confidently tap into this invaluable resource.
With so many key business benefits of the cloud directly affected by and depending on security, one would easily be mislead into thinking that a plethora of security measures has to be adhered to in order to address potential issues. Truth is, it all comes back to the data. A single framework that comprehensively protects all enterprise data from point of creation and throughout its lifecycle can eliminate practically all of the potential security hazards that could threaten the cloud.
Below are 5 tips for a security framework that will allow you to fully harness the cloud’s business benefits:
1. Leverage Data-Centric Encryption
By encrypting data, regardless of type or source, at capture and protecting it throughout the entire lifecycle, wherever it resides and wherever it moves, data can be protected, used and moved across the enterprise and into the cloud without the need to encrypt and decrypt the data as it enters or leaves different IT environments.
2. Maintain Referential Integrity
Format-preserving encryption (FPE) retains the initial structure and format of the data set, encrypting the data while ensuring the structure fits into existing schemas without requiring changes in IT infrastructure or underlying systems in order to store and manage the data. FPE also preserves ‘referential integrity’ of the data, which allows the data to be analysed in a protected state, without having to de-crypt it first.
3. Ensure High Performance Processing
High performance encryption results from eliminating manual and constant encryption and decryption processes as data moves through the enterprise, which removes database performance bottlenecks and enables linear scalability. A data protection strategy that includes encryption and tokenisation which can be performed locally at the application, database, or webserver level allows an organisation to dynamically protect terabytes of data on demand, without having to introduce complex procedures, additional technology or interrupt current business process.
4. Policy Controls
By giving users or applications permission to decrypt or de-tokenize directly, linking directly to enterprise data access rules and policies, the extension of enterprise controls into the cloud can be enabled and user management is simplified.
5. “Stateless” Tokenization
Tokenization is a way of substituting sensitive data with non-sensitive values, and is one of the prescribed data protection methods recommended under industry regulations, including PCI DSS. Stateless tokenization eliminates the token database and any need to store sensitive data as well as the keys that map the tokens to the initial sensitive data. This allows organizations to efficiently address national and international data residency and privacy requirements, as sensitive data can be maintained in a valid jurisdiction with only a representation of the data being moved. In-scope data can be securely moved and stored across cloud environments, and only decrypted and used within jurisdictions where it is specifically permitted.
When harnessed correctly, cloud-computing capabilities offer numerous opportunities to drive business innovation. Recent technology and social connectivity trends have created a perfect storm of opportunity for companies to embrace the power of cloud to optimize, innovate and disrupt their existing business models. Could you join them?
Dave Anderson is Director of Strategy for Voltage Security.