Saturday, December 10, 2011

A Strategic Approach to Security Risk while CloudSourcing

I was privileged to address a distinguished audience of leading Indian CIO’s at the IDC Cloud 2.0 Asia Summit in Mumbai last week to present my thoughts on how companies could adopt a strategic approach to using third party hybrid or private clouds from a security perspective. I have summarized my opinion in this narrative.
India is the land of outsourcing and we all have seen the rise of several large IT service providers.  When enterprises outsourced to IT service providers they offshored maintenance, development of their legacy platforms or new platforms which they bought. Instances of shared services were few. When organizations look towards cloudsourcing their key goal is to share. Share an application or infrastructure? Sharing brings greater efficiencies, agility at lower costs and therefore the move to cloud is inevitable
The progress towards a cloud computing is a mixed bag. There are questions and fears but the drive and money is real. Technology and investments will make it a reality. None of us can say that this is a hype which will go away and hence we should do nothing about it. Most companies are planning a cloud strategy or atleast a POC.
When we go to the cloud the security requirements of our business remain the same. They are enshrined in these three tenets – Reputation Protection, Asset Protection and Compliance. But like we trust in God we now need to trust in the cloud service provider.  
There are teething issues like cloud outages which can interrupt and therefore hurt your business. More will surely come down the line. But the bottom line is that maturity takes time.  When such issues hit you at home it may not hurt as much when it hits you visibly, out there on the Internet.
In the IT outsourcing model the customer was able to trust the IT service provider with his data and business process mainly because of his ability to establish security norms and audit them. There was the added benefit of owning or controlling the IT environment and business oversight in terms of financial viability, experience, corporate governance and so on
In case of the cloud service provider, we see parentage and the business model. Sufficient data is not available for us to take decisions. How many cloud service provider will survive is a matter of grave doubt? On top of it we are unable to control or get environment details let alone audit.
In the cloud, risk vectors go up manifold . Cyber criminals want to target this large pot, bang goes the fact that you one among thousands. There are issues with technology and shared infrastructure. Doubts about how companies can actually meet your compliance requirements and uncertainty about your risk profile and the vendor does not share much information with you.
The top four risk groups are:
·    Cyber Criminals, Cyber Terrorists, Cyber Espionage and Cyber Warfare all of which are more likely to target a shared cloud service infrastructure that company infrastructure

·    Technology Refresh, MultiTenancy, Scale and Multicloud which are more likely to increase the set of vulnerabilities in cloud infrastructure

·     Compliance, Data Protection and Law enforcement due the lack of understanding on how these requirements would be met by cloud service providers in a global, multicloud environment

·    Lack of security visibility where CISO’s cannot be assured of the security of their company data
The two main levers in outsourcing contracts that you must control are contractual and audit. The degree of control that you exert on this may positively impact the balance of power in the cloud. At the moment, this lies in the hands of the cloud service providers and you will find great difficulty in both these area. As you go through your cloud adoption process your ability to create and enforce standards in this area will greatly shape your ability to manage risks.
Contractual Clauses Sections you should carefully read
  • Choice of law jurisdiction and dispute resolution;
  • Variation to terms;
  • Privacy laws and transborder data flows;
  • Service level agreements;
  • Transition out arrangements;
  • Warranties and liability limitations; and
  • Multiple parties in the cloud stack
Audit Clauses Limitations
  • No defined clause set for security and backup;
  • Inability to set the terms of reference
  • Inability to audit/ no audit standards
  • No certainty on data flows
  • No certainty on the importance of security to the cloud provider
  • Ownership and legal implication with the company and not cloud provider

Typically you decision to cloud source comes back to the fundamental tolerance of risk that you would like to accept. In simple words the impact on your data and business process should things go wrong. Since IT assets anyway do not belong to you, I have taken this out of the equation.
Early adopters are taking safe bets on the type of cloud service to choose. There are many such as Kaspersky’s Email and Web filtering service to name one that offers more that you can do in your organization at low risk
In order to help you make this choice, last year I had published the top eight questions CIO’s should ask in the SC Magazine US edition. They still are valid and I have added a ninth one too.
1.    Am I using a trusted vendor?
  1. Have I considered the value and risk to the information that I am outsourcing to the cloud provider?
  2. What business continuity and disaster recovery measures are in place in the cloud infrastructure? Does the cloud provider have a backup in place?
  3.  Have I considered the potential implication of employees wanting to sabotage a successful cloud migration strategy?
  4. Have I considered how knowledge of the business process would be retained and versioned, should I wish to switch cloud providers at a future date?
  5. Do I have a detailed list of security controls based on security, operational and business risks to determine how the cloud vendor complies with them?
  6. Does your cloud provider meet the regulatory or compliance requirements needed by your organization?
  7. How do I audit or evaluate security controls placed on the cloud-based infrastructure?
  8. Is the contractual agreement in my favor or am I able to influence it?
        Click here to read the full article “Eight Questions CIO’s Should Ask on Cloud Security”

I must end by encouraging all of you to take part and rely on the body of knowledge being built by the Cloud Security Alliance (http://www.cloudsecurityalliance.org/) which is one of the most substantive programs on cloud security. It is nonprofit and free. Also please become part of the Mumbai Chapter by signing up on our Linked In Group Cloud Security Alliance,Mumbai Chapter, of which I am a founder director.

Wednesday, December 7, 2011

Censoring the India Web ! Why shoot Kapil Sibal?

The media, bloggers and mostly everyone seem to be up at arms against Kapil Sibal. Why? Are they acting for their personal interests? Are they psyched by larger business interest of the Indian media and Internet companies? or are they acting in the interest of free online speech. India is not China and both cannot be equated so why bring up the analogy.

If your 15 year old daughter has something offensive written about her on a social networking site that emotionally affected her. Would your opinion have been different? Would you  run about trying to get a court order to remove the comment or would you have liked it to be erased instantly?

Let us not kid ourselves. Internet companies earn large revenue and can put in systems to moderate, prescreen or atleast remove content quickly without to much of bureaucracy. There is a balance that must be struck, else regulations, penalties and censorship become inevitable. I firmly believe Internet companies should have a more transperant system and attitude towards the needs of various countries.

I would encourage Kapil to step up the pressure to get us a better mechanism to address such issue by self regulation and would personally be unhappy if we have to regulate through policy, but lots depends on the stand of the Internet companies.

Also for those who said prescreening is difficult. Perhaps correctly if we try to build technology to do so, but there could always be the use of  user rating buttons which could flag comments/blogs as inappropriate and send for moderation. I am sure there are many Indian BPO's that would gladly take up the job.

There were a mob of 500 people protesting a morphed image of Dr. Ambedkar near my house in Mumbai, burning vehicles and causing a nuisance to all. And there was the instance of London burning for days powered by messages on phones, tweets and posts. These are the consequences of freedom and democracy and we should in a democratic way decide if we want to live with them or do something else.





























Tuesday, December 6, 2011

Social Media Assessments crucial to measure online risk to company brands

Has your company undergone a social media security assessment which assesses social media employee policies, their implementation and online employee behavior? If not, it’s perhaps time to start as the lines between what’s public and private tend to get blurred online. Online what employees say and do have serious implication on customer opinion, company brand, employee harmony, company trade secrets, and product launches. Most of us have experience with very public rants between employees or between employees and employers on internal and external social sites. Employees posting slurs against other employees or the management online is not uncommon.
A stake is a company’s reputation!
What companies want employees to do is act in accordance to an organizations values and brand guidelines? It’s not a simple do’s and don’ts list; it’s living online the value culture an organization wants to promote.
In the past only specific individuals interacted with the media but today every employee has an online presence. A comment or rant has the ability to reach a flashpoint and go viral. Customers cannot distinguish between official comments from a company spokesman and those made by employees online. Companies therefore need to articulate clear policies that clearly stress on how employees communicate about or comment on their company online. Each employee must act in a manner consistent with the company’s value and brand online.
Social engineering or the art of exploiting trusting employees to ferret confidential information for competitive use becomes much simpler in an anonymous online world. Even if an employee is not socially engineered there is the possibility of putting together bits and pieces of online posted information that may lead a competitor to find useful information.
Typical social media policies articulate the do’s and don’ts of retail blogging, use of social media and set-up of personal sites. They cover what company information employees should not post which ranges from trade secrets, confidential data and internal discussion. Most policies also spell out how employees should react to rumors, customers, other employees, company policies, and the company brand. Policies may vary based on the impact that an employee statement can have on the company.

Sunday, December 4, 2011

Carrier IQ exposes the scant regard business has for consumer interests?

CIQ or Carrier IQ is preloaded software on your mobile phone either by your phone company or your handset manufacturer. It is loaded on million of phones because large telecoms and popular handset manufacturers use it. The software apparently is designed to help better the performance of telecom networks or handsets by tracking and recording low level information which it summarizes or logs for problem resolution. To do so it records key strokes, SMS messages, deciphers outgoing HTTPS streams and in a sense reads all the data one would like to keep private.
Were you as a consumer aware at any point in time of its functionality?
Were you aware that the permission to use this software was embedded in a User Agreement that you signed with the telecom company or with the manufacturer?
In both cases, the answer would perhaps have been a resolute No.
The prime reason is that User Agreements which you sign every time you use an application, services or digital products run in tens of pages and are written in legal jargon which does not allow a normal consumer to fully comprehend the implications of what is being agreed too. Most of these agreements are written to provide maximum protection for the service provider. All consumers should have a right to opt out of services such as these which affect their privacy whether in paid or free services. No services in reality free, as these supposedly free services, are funded by selling your actions or preferences to advertisers. Facebook is valued at 100 Billion US$? You ask yourself why?
I do not think that the intention of these service providers was to snoop on your phone and genuinely believe their action demonstrates how technical people like to better understand metrics to improve and manage services. Perhaps, most of the businesses which used the software did not even question how the product worked? But what if such a system was exploited by a malicious third party, government or telecom employee who figured out a way to use this tool for their benefit?
In any case it exposes how large corporations disassociate themselves and have scant regards for consumer privacy and security concerns. Its certainly not mandated in their policies and code of conduct beyond the mandatory regulatory and compliance requirements. We certainly do not want to be in a situation where billions of devices such as smartphones and tablets are shipped advertently or inadvertently with monitoring software without the user’s knowledge and explicit ability to opt in or out of such an arrangement while using the services
There have been too many such instances and I do believe it time for policy makers to adopt strict policies on the extent and methods which can be used to track user metrics and safeguard security and privacy concerns. Companies should self regulate themselves and their boards establish corporate policy on how customer data can be collected, processed, and stored. This should reflect on their decisions to buy or build metric collecting software for performance or advertising uses among others.