Cloud security always seems to be a good news/bad news story, and this year’s Cloud Security Alliance (CSA) Egregious 11 cloud computing threats report reflects this reality.
Every two years CSA’s threats working group comes up with a short list of security concerns (this year it came up with 19), and then it surveys security industry experts (241 this time around), asking them to rate the cloud security issues from one to 10. One means it’s “very insignificant” and 10 means “very significant.” Top Threats to Cloud Computing: The Egregious 11, released this week at Black Hat, is the culmination of this work.
One significant difference about this year’s report is that more traditional cloud security issues that fall to cloud service providers (CSP) — denial of service, shared technology vulnerabilities, CSP data loss, and system vulnerabilities, etc. — which featured heavily in the previous Treacherous 12, dropped off the latest list. This is good news as it suggests companies have a better understanding of cloud security and no longer view cloud computing as an inherent business risk. It also suggests traditional security issues that fall to CSPs are generally being well addressed.
Also in the good news column: the top threats decreased to 11, down from 12 two years ago.
Now the bad news: data breaches are still the No. 1 threat. This and other top threats on the list are usually the result of senior management decisions around cloud strategy and implementation. This suggests these types of threats are becoming more problematic and of increasing concern to enterprises.
“The threats did change in the sense that everything seemed to be more up the technology stack,” said John Yeoh, global vice president of research at CSA. “The foundational security of the cloud providers was less of a concern and we saw more concerns over issues that [enterprises] have control over. Some of the new ones on the report were misconfigurations and inadequate change control.”
Here are the Egregious 11:
- Data Breaches
- Misconfiguration and Inadequate Change Control
- Lack of Cloud Security Architecture and Strategy
- Insufficient Identity, Credential, Access and Key Management
- Account Hijacking
- Insider Threat
- Insecure Interfaces and APIs
- Weak Control Plane
- Metastructure and Application-structure Failures
- Limited Cloud Usage Visibility
- Abuse and Nefarious Use of Cloud Services
“Data breaches was at the top of the last list, too,” Yeoh, said, referring to the Treacherous 12 report. “They are all linked: misconfiguration, insider threats, insecure APIs — they all lead to data breaches. And insufficient identity and access controls lead to insider threats and hijacking.”
In addition to hurting a company’s brand and customer trust, other consequences of a data breach include loss of intellectual property (IP) as well as regulatory, legal, and contractual implications — all of which cost money. Thus, defining the business value of data and the potential impact of its loss is vitally important to organizations that own or process data, the report says.
Data accessible via the internet is most vulnerable to misconfiguration or exploitation, it adds. Encryption can help protect data — but it can also hurt system performance.
Misconfiguration is a bigger challenge in the cloud because cloud-based resources are more complex and dynamic. Incorrectly setting up these computing assets can leave the data vulnerable — like the recent Capital One breach in which a hacker broke through a misconfigured server in Amazon Web Services (AWS).
Traditional controls are not effective in the cloud, and companies should use automation and other technologies that continuously scan for misconfigured resources and fix them in real time, the report says.
Along with detailing each cloud threat, the report also refers readers to several CSA Cloud Control Matrix controls that address each of the 11 threats. This is CSA’s framework of 133 controls specific to cloud and intended to help enterprises asses their risks and build defense mechanism for cloud computing.
One of the overarching messages of the report is that companies should use cloud-native tools because simply using traditional, on-premises methods and technologies don’t always work as well in the cloud. This take away is relevant to all 11 threats, Yeoh said.
“Take advantage of cloud-native tooling when it comes to safe and secure configurations and also notifications,” he said. “One of the new threats this year was limited visibility into cloud usage — that’s one issue where if you don’t have built-in apps in the cloud, and if you’re not turning on the right features in your cloud service, you don’t have that visibility.
Comments