Achieving Assurance and Compliance in the Cloud Digital Government Cyber Security Conference Cheryl Wilner, CEO Bethesda Advanced Solutions Ronald Regan Building, Washington DC May
Copyright © 2011 Cloud Security Alliance Securing Government Data Government Agencies largest concern with moving to the cloud is Security…....and regardless of any signed contract or SLA, at the end of the day the buck stops with you!
Copyright © 2011 Cloud Security Alliance Cloud Computing Security: Largest Barrier to Adoption
Copyright © 2011 Cloud Security Alliance What is Different about Cloud Security? SERVICE OWNER SaaSPaaSIaaS DataJointTenant ApplicationJoint Tenant ComputeProviderJointTenant StorageProvider Joint NetworkProvider Joint PhysicalProvider
Copyright © 2011 Cloud Security Alliance Hacking is More Efficient in a Cloud
Copyright © 2011 Cloud Security Alliance Government Agencies What are you going to do with 20+ years of “stuff”?
Copyright © 2011 Cloud Security Alliance
Copyright © 2011 Cloud Security Alliance
Copyright © 2011 Cloud Security Alliance
Copyright © 2011 Cloud Security Alliance Thank you to COL Chris Miller, CIO/G-6 ADCCP Army Data Center Consolidation Program for providing his slides.
Copyright © 2011 Cloud Security Alliance
Copyright © 2011 Cloud Security Alliance The Cloud Security Alliance The Cloud Security Alliance CSA is a Global, not-for-profit organization Over 31,000 individual members, 120 corporate members, and 60 chapters Building best practices and a trusted cloud ecosystem Agile philosophy, rapid development of applied research GRC: Balance compliance with risk management Reference models: build using existing standards Identity: a key foundation of a functioning cloud economy Champion interoperability MISSION - “To promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing.”
Copyright © 2011 Cloud Security Alliance CSA Metro DC Chapter
Copyright © 2011 Cloud Security Alliance CSA Guidance Research Popular best practices for securing cloud computing Flagship research project V2.1 released 12/2009 V3 research underway, targeting Q release wiki.cloudsecurityalliance.org /guidance Operating in the Cloud Governing the Cloud Guidance > 100k downloads: Guidance > 100k downloads: cloudsecurityalliance.org/guidanc e cloudsecurityalliance.org/guidanc e
Copyright © 2011 Cloud Security Alliance Summary Create a Plan You will need help as this is not a walk in the park You have more “stuff” than you think Security is the highest priority concern This is not as easy as it looks and it will take longer than you think
Copyright © 2011 Cloud Security Alliance Contact Cheryl Wilner, CEO Bethesda Advanced Solutions (BAS)