True cloud security is about being proactive about learning hackers' strategies and motivations — not depending on the false sense of security offered by so many security products out there, according to Snyk Chief Architect Josh Stella.
"Every day, hackers are sidestepping security perimeters, crossing arbitrary boundaries, and evading security solutions to ultimately get at the data they want without detection," Stella said. To properly prepare for oncoming adversaries, cloud security teams and the executives leading them should be experts on every element of their organization's cloud security, he explained.
One of the key things enterprises need to know is the state of compliance in the cloud environment. "Those that are doing cloud security correctly know exactly where their environment is and isn't in compliance," Stella said.
Security teams should review internal security policies frequently to make sure new use cases and attack vectors are taken into consideration, he recommends.
API SecuritySecuring the cloud API control plane is another crucial part of holistic cloud security because all cloud breaches follow the same pattern — control plan compromise.
While the security industry is aware that hackers look for misconfigurations in the control plane, it "remains a step behind the hackers because many vendor solutions do not protect their customers against attacks that target the cloud control plane," he explained.
This means it's up to each organization to take responsibility for the security of their cloud environments beyond the 'secure' comfort afforded to them by one security product or another.
"Assessing the blast radius risk of any potential penetration event due to misconfiguration, app vulnerabilities, API keys in source code, etc., requires expertise in cloud security architecture to identify and avoid the design flaws that attackers exploit every day," he added.
Expressing Security PoliciesThe manner in which an enterprise expresses its security policies is also instrumental in the success or failure of its cloud security.
According to Stella, security policies are either written in human language and reviewed by humans or written using policy-as-code (PaC).
With the former, it's impossible to entirely secure the cloud environment, Stella said. "It takes time to manually review policies and enforce them in your environment at a time when cloud breaches take minutes to execute. And the risk of human error and differences in interpretation is always present."
Using PaC, however, machines interpret a security policy the same way each time, allowing for continuous evaluation of cloud infrastructure on a much larger scale "than any army of humans could ever hope to do," he said.
If pieces of the security policy need to change from one deployment to another, for example, those exceptions can be expressed as code to ensure proper documentation. And security automation with PaC allows for problems to be discovered and resolved before reaching production, Stella added.
What About My Small Security Team?But being your own cloud security expert isn't easy when bandwidth is often a rare commodity. Even in the midst of the ongoing cybersecurity skills gap, Stella says any size IT security team can be successful with cloud security.
"Even if you have a team of one, you can start to leverage automation. No one is ever finished on this journey, but if you don't start you can't move forward," he wrote in an email to SDxCentral.
He recommends small security teams find someone excited about automating security and give that individual the resources they need to get started. By training them and providing them with the correct tools, "you will make progress," he said.
"You may not have the ability to dedicate an entire team to this function, but by leveraging tools and automation, you can start to have an impact. By using policy as code — an effective way to uniformly define, maintain and enforce security and compliance standards — even a small team can have a massive impact," Stella added.
Comments