IBM is rolling out new capabilities today for its Cloud Security and Compliance Center platform in an effort to help enterprises secure and protect sensitive data across hybrid multicloud environments.

The enhanced offering provides advanced security and compliance capabilities to address the challenges organizations face as they increasingly adopt hybrid cloud approaches. New capabilities include the IBM Cloud Security and Compliance Center Data Security Broker, developed in partnership with Baffle, that provides layers of encryption and anonymization technology to protect sensitive data used in business applications and artificial intelligence (AI) workloads.

Other updates include enhanced cloud security posture management (CSPM), cloud workload protection, infrastructure entitlement management, and compliance automation. Rather than just focus on IBM Cloud, the new Cloud Security and Compliance Center updates are all about multicloud and hybrid cloud support.

“The IBM Cloud Security and Compliance Center supports several cloud environments, including AWS [Amazon Web Services], Azure and Google Cloud,” Nataraj Nagaratnam, IBM Fellow and CTO for cloud security, told SDxCentral. “Across hybrid cloud environments it supports IBM LinuxOne servers and will soon support IBM Power.”

The Baffle connection for cloud data protection

Nagaratnam said the platform update adds data protection to IBM’s current capabilities of infrastructure and workload protection. In essence, it provides a transparent layer of data encryption with format-preserving encryption and anonymization technology to protect sensitive data.

“To date, we have provided cloud data encryption for databases, object storage and such,” he said. “Now, we are using Baffle’s technology to provide application-level tokenization and granular encryption of sensitive fields in databases.”

Nagaratnam noted that modern enterprises require a vast array of hybrid and multicloud environments to support data storage and applications. Until recently, the main protection for the data depended on disk- or file-level encryption, because these methods were easiest to implement. However, he commented that this type of protection left a protection and flexibility gap at the application level. Organizations that wanted to ensure privacy for their application data had to have access and modify the application itself.

“Data Security Broker is at the center of closing this gap,” Nagaratnam said. “It protects the application-sensitive data when stored in databases like PostgreSQL and requires no code changes.”

The new data protection capability is critical for helping with compliance as well. Nagaratnam said the IBM Cloud Security and Compliance Center is designed for clients in any industry. However, he said, it is especially designed for clients in regulated industries like financial services, telco and health care — all areas with stringent requirements for security and compliance, as well as national and international data sovereignty laws.

“In particular, the new Data Security Broker offering addresses the evolving data privacy requirements around protecting personally identifiable information (PII) and the complexities that come with hybrid, multicloud environments,” he said.

Intelligent automation comes to security compliance

As part of the IBM Cloud Security and Compliance Center updates, new automation capabilities are also being added.

Nagaratnam explained that IBM is delivering a set of automation blueprints, called “deployable architectures,” that are prebuilt with security and compliance controls. For instance, with the click of a button, customers can select and deploy their cloud workloads as preconfigured to meet specific security controls.

Additionally, organizations can set a policy so that deployments are checked for compliance before being pushed to production, thus achieving shift-left security and compliance.

“With our intelligent automation technology, we are integrating security and compliance throughout the development lifecycle,” he said.