psirt new experience managing cloud vulnerabilities · 2019. 4. 29. · share experience handling...

19
PUBLIC Angela Lindberg, SAP April 4, 2019 PSIRT New Experience Managing Cloud Vulnerabilities NOTE: Delete the yellow stickers when finished. See the SAP Image Library for other available images.

Upload: others

Post on 29-Sep-2020

9 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

PUBLIC

Angela Lindberg, SAP

April 4, 2019

PSIRT New ExperienceManaging Cloud Vulnerabilities

NOTE: Delete the yellow stickers when finished.

See the SAP Image Library for other available images.

Page 2: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,
Page 3: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

4 Vancouver

6 Walldorf

10 Bangalore

Page 4: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,
Page 5: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

5PUBLIC© 2019 SAP SE or an SAP affiliate company. All rights reserved. ǀ

Purpose

▪ Share experience handling customer cloud penetration reports

▪ Observations and challenges

▪ Engage in discussion, any insights, advice, best practices…

Proposed Agenda

▪ 30 minutes of presentation and sharing experience

▪ 15 minutes of discussion to share solutions or ideas to streamline process

References

▪ ISACA: Security Mysteries in the Cloud - https://www.isaca.org/Journal/archives/2015/Volume-

3/Pages/security-mysteries-in-the-cloud.aspx

Purpose and Agenda

Page 6: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

Outcome new ideas

Page 7: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

Customers moving from on-premise to

Cloud the benefits and security

considerations

Page 8: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

8PUBLIC© 2019 SAP SE or an SAP affiliate company. All rights reserved. ǀ

Cloud provides service, architecture and deployment models

Cloud Architecture - multitenant & single-tenant

Page 9: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

9PUBLIC© 2019 SAP SE or an SAP affiliate company. All rights reserved. ǀ

▪ Top consideration Security and Privacy

▪ Regulatory, compliance or audit requirements

▪ Request to audit = cloud pen-test

▪ Shared responsibility customer and Cloud provider

Cloud security considerations

Page 10: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

A new experience handling customer

reported cloud vulnerabilities…

Page 11: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

11PUBLIC© 2019 SAP SE or an SAP affiliate company. All rights reserved. ǀ

▪ Automated tools results may include:

– high numbers of false positives

– generic descriptions

– lack details to validate

– shared responsibility inside and outside the company

▪ Priority ratings

Cloud penetration testing approach and results

Page 12: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

12PUBLIC© 2019 SAP SE or an SAP affiliate company. All rights reserved. ǀ

▪ All sorts of findings, not all are vulnerabilities

▪ Repeated findings customers test independently of each other

▪ Challenge cleanse report

▪ Solutions? knowledge base, or establish security expert for

each cloud offering

Findings reported

Page 13: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

13PUBLIC© 2019 SAP SE or an SAP affiliate company. All rights reserved. ǀ

▪ Expectations vary from high to passive

▪ Review based on customer priority

▪ Common Vulnerability Scoring System (CVSS) not as important for

Cloud - internally used to validate findings

▪ Service Level Agreement (SLAs) currently under review for cloud

offerings

Consumer service expectations

Page 14: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

14PUBLIC© 2019 SAP SE or an SAP affiliate company. All rights reserved. ǀ

▪ Communication expands to a customer support role

▪ New skills required to manage expectations and ensure

confidence

▪ Considerations secure communications – Non Disclosure

Agreement (NDA)

▪ Tracking and reporting findings

Communication role redefined

Page 15: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

15PUBLIC© 2019 SAP SE or an SAP affiliate company. All rights reserved. ǀ

▪ Engineers review full report

▪ Prioritize based on customer priority

▪ Create ticket in back end systems for validated findings

– not linked to on-premise ticketing system

▪ Cloud and on-premise versions require co-ordination

▪ Cloud fix applied for all customers

Cloud areas review and remediation

Page 16: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

16PUBLIC© 2019 SAP SE or an SAP affiliate company. All rights reserved. ǀ

Page 17: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

Cloud process continues to evolve

Page 18: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

Thank you.

Contact information:

Angela Lindberg

Security Response Analyst

Page 19: PSIRT New Experience Managing Cloud Vulnerabilities · 2019. 4. 29. · Share experience handling customer cloud penetration reports Observations and challenges Engage in discussion,

19PUBLIC© 2019 SAP SE or an SAP affiliate company. All rights reserved. ǀ

▪ https://nmap.org/

▪ https://portswigger.net/burp

▪ https://www.tenable.com/products/nessus/nessus-professional

References