lir annual seminar

16
www.cloud-security.org.uk Copyright © 2012 Cloud Security Alliance – UK & Ireland Liberty Hall, Dublin March 30th 2012 LIR Annual Seminar

Upload: lorne

Post on 24-Feb-2016

49 views

Category:

Documents


0 download

DESCRIPTION

LIR Annual Seminar. Liberty Hall, Dublin March 30th 2012. Is the future secure?. Brian Honan CSA - UK & Ireland Chapter. Cloud Security Alliance. Global, not-for-profit organization Over 23,000 individual members, 100 corporate members, 50 chapters - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

Liberty Hall, Dublin March 30th 2012

LIR Annual Seminar

Page 2: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

Brian HonanCSA - UK & Ireland Chapter

Is the future secure?

Page 3: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

Cloud Security Alliance• Global, not-for-profit organization• Over 23,000 individual members, 100 corporate

members, 50 chapters• Building best practices and a trusted cloud

ecosystem• Agile philosophy, rapid development of applied

research• GRC: Balance compliance with risk management• Reference models: build using existing standards• Identity: a key foundation of a functioning cloud economy• Champion interoperability• Enable innovation• Advocacy of prudent public policy

“To promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud

Computing to help secure all other forms of computing.”

Page 4: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

UK & Ireland chapter• Over 2,000 individual members• Focused on Information Risk

Management

“To provide the guidance and tools required to allow business and home users of cloud services to manage risks to their information in order to embrace the opportunities afforded by the

interconnected information society of the 21st century.”

Page 5: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

…from the Knights Templar to Jeremy Clarkson, onto James May and beyond!

We’re going on a journey…

Page 6: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

What is it to be secure?“the state of being free from danger or threat”

Page 7: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

• The original ‘trust authority’

• Conveyed money around the middle east during the crusades

• Founders of modern banking systems…

• …which are based on trust

Why the Knights Templar?…

Page 8: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

• Money isn’t real• You trust the bank to pay you –

based on a promise!

Trust in modern banking…

Page 9: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

• The bank teller model worked for centuries

• Until the 1990’s• When trust moved…

…is it misplaced?

Page 10: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

• Web 2.0 creates new challenges…

• …for which we create new controls

• Which surely enhance security?

• Enter our second guest…

Are we keeping up?

Page 11: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

• Published bank details after HMRC breach in 2008

• Direct debit setup to make charitable contribution

“The bank cannot find out who did this because of the Data

Protection Act and they cannot stop it from happening

again”Jeremy Clarkson

Remember Jeremy Clarkson?…

Page 12: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

What does this prove?• That the boundaries have moved• Security no longer exists as we

understand it• That technology can’t be controlled

using traditional thinking• That we need to evolve our thinkingTime for our third guest…

Page 13: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

• Understanding your assets allows tangible benefit

• Defined frameworks are required

• Requires constant re-evaluation to achieve goals

Enter James May!

Page 14: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

So what about the future?• You’re here, now!• The line between consumerisation

and business is dissolving rapidly• Technology and adoption evolves

faster than ever before• Risks are not to be feared, but

managed• Compliance will not help you!

Page 15: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

So where do we start?• Ask questions about your business• Determine the information assets

being used• Don’t assume control context• Determine the information risks you

need managing• Determine responsibility for operating

controls• Ensure metrics measure desired

control performance

Page 16: LIR Annual Seminar

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

www.cloud-security.org.ukCopyright © 2012 Cloud Security Alliance – UK & Ireland

Want to know more?Have your say and be heard in the Cloud discussion

• Joining us is free• Join at www.cloud-security.org.uk • Email me on

[email protected]• Follow us on twitter: @CSAUKEire