The Public Cloud: Seven Best Practices to Secure It

By SokoDirectory Team / August 7, 2019




The simplicity and cost-effectiveness of the public cloud have led to more and more organizations to take advantage of Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP).

You can spin up a new instance in minutes, scale resources up and down whenever you need while only paying for what you use, and avoid high upfront hardware costs.

While the public cloud solves many traditional IT resourcing challenges, it does introduce new headaches.

The rapid growth of cloud usage has resulted in a fractured distribution of data, with workloads spread across disparate instances and, for some organizations, platforms.

As a result, keeping track of the data, workloads, and architecture changes in those environments to keep everything secure is often a highly challenging task.

Public cloud providers are responsible for the security of the cloud (the physical datacenters, and the separation of customer environments and data).

However, the responsibility for securing the workloads and data placed in the cloud lies firmly with the customer. Just as organizations need to secure the data stored in their on-premises networks, so they need to secure their cloud environment.

Misunderstandings around this distribution of ownership is widespread and the resulting security gaps have made cloud-based workloads the new pot of gold for today’s savvy hackers.

Seven Steps to Securing the Public Cloud

The secret to effective cybersecurity in the cloud is improving your overall security posture: ensuring your architecture is secure and configured correctly, that you have the necessary visibility into your architecture, and importantly, into who is accessing it.

Step 1: Learn your responsibilities

This may sound obvious, but security is handled a little differently in the cloud. Public cloud providers such as Amazon Web Services, Microsoft Azure, and Google Cloud Platform run a shared responsibility model – meaning they ensure the security of the cloud, while you are responsible for anything you place in the cloud.

Step 2: Plan for multi-cloud

Multi-cloud is no longer a nice-to-have strategy.  Rather, it’s become a must-have strategy. There are many reasons why you may want to use multiple clouds, such as availability, improved agility, or functionality. When planning your security strategy starts with the assumption that you’ll run multi-cloud – if not now, at some point in the future. In this way, you can future-proof your approach.

Step 3: See everything

If you can’t see it, you can’t secure it. That’s why one of the biggest requirements to getting your security posture right is getting accurate visibility of all your cloud-based infrastructure, configuration settings, API calls, and user access.

Step 4: Integrate compliance into daily processes

The dynamic nature of the public cloud means that continuous monitoring is the only way to ensure compliance with many regulations. The best way to achieve this is to integrate compliance into daily activities, with real-time snapshots of your network topology and real-time alerts to any changes.

Step 5: Automate your security controls

Cybercriminals increasingly take advantage of automation in their attacks. Stay ahead of the hackers by automating your defenses, including remediation of vulnerabilities and anomaly reporting.

Step 6: Secure ALL your environments (including dev and QA)

You need a solution that can secure your all environments (production, development, and QA) both reactively and proactively

Step 7: Apply your on-premises security learnings

On-premises security is the result of decades of experience and research. Use firewalls and server protection to secure your cloud assets against infection and data loss, and keep your endpoint and email security up to date on your devices to prevent unauthorized access to cloud accounts.

Moving from traditional to cloud-based workloads offers huge opportunities for organizations of all sizes. Yet securing the public cloud is imperative if you are to protect your infrastructure and organization from cyberattacks. By following the seven steps you can maximize the security of your public clouds, while also simplifying management and compliance reporting.

Written by: Harish Chib, Vice President – Middle East & Africa of Sophos 

Read Also: Sophos Acquires Rook Security to Provide Managed Detection and Response





More Articles From This Author








Other Related Articles










SOKO DIRECTORY & FINANCIAL GUIDE

ARCHIVES

2019
  • January 2019 (256)
  • February 2019 (216)
  • March 2019 (285)
  • April 2019 (254)
  • May 2019 (272)
  • June 2019 (252)
  • July 2019 (340)
  • August 2019 (211)
  • 2018
  • January 2018 (291)
  • February 2018 (219)
  • March 2018 (278)
  • April 2018 (225)
  • May 2018 (238)
  • June 2018 (178)
  • July 2018 (257)
  • August 2018 (249)
  • September 2018 (256)
  • October 2018 (287)
  • November 2018 (284)
  • December 2018 (187)
  • 2017
  • January 2017 (183)
  • February 2017 (195)
  • March 2017 (207)
  • April 2017 (104)
  • May 2017 (169)
  • June 2017 (205)
  • July 2017 (190)
  • August 2017 (195)
  • September 2017 (186)
  • October 2017 (235)
  • November 2017 (253)
  • December 2017 (266)
  • 2016
  • January 2016 (165)
  • February 2016 (165)
  • March 2016 (190)
  • April 2016 (143)
  • May 2016 (246)
  • June 2016 (183)
  • July 2016 (271)
  • August 2016 (249)
  • September 2016 (234)
  • October 2016 (191)
  • November 2016 (243)
  • December 2016 (153)
  • 2015
  • January 2015 (1)
  • February 2015 (4)
  • March 2015 (166)
  • April 2015 (109)
  • May 2015 (117)
  • June 2015 (121)
  • July 2015 (150)
  • August 2015 (157)
  • September 2015 (189)
  • October 2015 (170)
  • November 2015 (174)
  • December 2015 (208)
  • 2014
  • March 2014 (2)
  • 2013
  • March 2013 (10)
  • June 2013 (1)
  • 2012
  • March 2012 (7)
  • April 2012 (15)
  • May 2012 (1)
  • July 2012 (1)
  • August 2012 (4)
  • October 2012 (2)
  • November 2012 (2)
  • December 2012 (1)
  • 2011
    2010
    2009
    2008
    2007
    2006
    2005
    2004
    2003
    2002
    2001
    2000
    1999
    1998
    1997
    1996
    1995
    1994
    1993
    1992
    1991
    1990
    1989
    1988
    1987
    1986
    1985
    1984
    1983
    1982
    1981
    1980
    1979
    1978
    1977
    1976
    1975
    1974
    1973
    1972
    1971
    1970
    1969
    1968
    1967
    1966
    1965
    1964
    1963
    1962
    1961
    1960
    1959
    1958
    1957
    1956
    1955
    1954
    1953
    1952
    1951
    1950