+ All Categories
Home > Documents > Cloud Security Alliance Research & Roadmap Jim Reavis , Executive Director, CSA

Cloud Security Alliance Research & Roadmap Jim Reavis , Executive Director, CSA

Date post: 22-Mar-2016
Category:
Upload: lorie
View: 65 times
Download: 0 times
Share this document with a friend
Description:
Cloud Security Alliance Research & Roadmap Jim Reavis , Executive Director, CSA. Global, not-for-profit organization Over 23,000 individual members, 100 corporate members, 50 chapters Building best practices and a trusted cloud ecosystem - PowerPoint PPT Presentation
Popular Tags:
26
www.cloudsecurityalliance.or Copyright © 2011 Cloud Security Alliance Cloud Security Alliance Research & Roadmap Jim Reavis, Executive Director, CSA
Transcript
Page 1: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Cloud Security Alliance Research & Roadmap

Jim Reavis, Executive Director, CSA

Page 2: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

About the Cloud Security Alliance

Global, not-for-profit organizationOver 23,000 individual members, 100 corporate members, 50 chaptersBuilding best practices and a trusted cloud ecosystemAgile philosophy, rapid development of applied research

GRC: Balance compliance with risk managementReference models: build using existing standardsIdentity: a key foundation of a functioning cloud economyChampion interoperabilityEnable innovationAdvocacy of prudent public policy

“To promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud

Computing to help secure all other forms of computing.”

Page 3: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

http://cloudsecurityalliance.org/research/

RESEARCH

Page 4: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

CSA Guidance ResearchPopular best practices for securing cloud computingFlagship research projectV2.1 released 12/2009V3 research underway, targeting Q3 2011 releasewiki.cloudsecurityalliance.org/guidance

Ope

rati

ng in

the

Cl

oud

Governing the Cloud

Guidance > 100k downloads: cloudsecurityalliance.org/guidance

Page 5: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

CSA GRC StackFamily of 4 research projects

Cloud Controls MatrixConsensus Assessments InitiativeCloud AuditCloud Trust Protocol

Tools for governance, risk and compliance management Control

RequirementsProvider

Assertions

Private, Community

& Public Clouds

Page 6: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Cloud Controls Matrix Tool

Controls derived from guidanceMapped to familiar frameworks: ISO 27001, COBIT, PCI, HIPAA, FISMA, FedRAMPRated as applicable to S-P-ICustomer vs. Provider roleHelp bridge the “cloud gap” for IT & IT auditors

Page 7: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Consensus Assessment Initiative

Research tools and processes to perform shared assessments of cloud providersIntegrated with Controls MatrixVersion 1 CAI Questionnaire released Oct 2010, approximately 140 provider questions to identify presence of security controls or practices Use to assess cloud providers today, procurement negotiation, contract inclusion, quantify SLAs

Page 8: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

CloudAudit

Open standard and API to automate provider audit assertionsChange audit from data gathering to data analysis Necessary to provide audit & assurance at the scale demanded by cloud providersUses Cloud Controls Matrix as controls namespace Use to instrument cloud for continuous controls monitoring

Page 9: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Cloud Trust Protocol (CTP)

Developed by CSC, transferred to CSAOpen standard and API to verify control assertions“Question and Answer” asynchronous protocol, leverages SCAP (Secure Content Automation Protocol)Integrates with Cloud AuditNow we have all the components for continuous controls monitoring

Page 10: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

CSA STAR RegistryCSA STAR (Security, Trust and Assurance Registry)Public Registry of Cloud Provider self assessmentsBased on Consensus Assessments Initiative Questionnaire

Provider may substitute documented Cloud Controls Matrix compliance

Voluntary industry action promoting transparencyFree market competition to provide quality assessments

Provider may elect to provide assessments from third parties

Available October 2011

Page 11: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Trusted Cloud InitiativeComprehensive Cloud Security Reference ArchitectureSecure & interoperable Identity in the cloudGetting SaaS, PaaS to be “Relying Parties” for corporate directoriesScalable federationOutline responsibilities for Identity ProvidersAssemble reference architectures with existing standardswww.cloudsecurityalliance.org/trustedcloud.html

Page 12: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

TCI Reference Model Structure

TCI Reference Architecture

Page 13: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Security as a Service

Information Security Industry re-inventedDefine Security as a ServiceArticulate solution categories within Security as a ServiceGuidance for adoption of Security as a ServiceAlign with other CSA researchDevelop deliverables as a proposed 14th domain within CSA Guidance Version 3.www.cloudsecurityalliance.org/secaas.html

Page 14: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Data Governance Project

Survey of current Cloud Provider data governance practices in the market (e.g. backup, encryption, secure deletion, etc.)Structure based on Domain 5: Information Lifecycle ManagementProject co-sponsored by CSA Silicon Valley and CSA SingaporeTarget Sept. 2011 Report releaseCharter and participation info to be posted on CSA website 1st week of August.

Page 15: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Consensus research for emergency response in Cloud

Enhance community’s ability to respond to incidentsStandardized processesSupplemental best practices for SIRTsHosted Community of Cloud SIRTsBeing spun out into a separate, related entityFully functional SIRT to be launched at CSA Congress Nov. 2011www.cloudsecurityalliance.org/cloudsirt.html

CloudSIRT

Page 16: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Telecom Working Group

Industry a key stakeholder in future of cloudDelivery of cloud security solutionsIncident responseCSA’s liaison to ITU-T

Page 17: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Trusted Standards

CSA “open door” policy with standards bodiesEstablished CAT C Liaison with ISO/IEC SC 27, WGs 1, 4 & 5Co-editor of ISO/IEC SC 27 WG1 Cloud Computing Security Study PeriodCo-editor ISO 27036Formal Liaison with ITU-T

Page 18: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

http://cloudsecurityalliance.org/chapters/

GLOBAL CHAPTERS

Page 19: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Chapters Around the World

50 chapters and growingEvery continent except AntarcticaTranslating guidanceAdapting research to local needsCreating their own research projects

Page 20: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

http://cloudsecurityalliance.org/education/

TRAINING & CERTIFICATION

Page 21: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Certificate of Cloud Security Knowledge (CCSK)

Benchmark of cloud security competencyMeasures mastery of CSA guidance and ENISA cloud risks whitepaperUnderstand cloud issuesLook for the CCSKs at cloud providers, consulting partnersOnline web-based examinationwww.cloudsecurityalliance.org/certifyme

Page 22: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Training Courses CCSK Basic

One day course to enable student to pass CCSK

CCSK Plus Two day course includes practical cloud lab work

GRC Stack Training One day course to use GRC Stack components

PCI/DSS In the Cloud Achieving PCI compliance in cloud computing

http://cloudsecurityalliance.org/education/training/

Page 23: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

http://cloudsecurityalliance.org/events/

CONFERENCES & EVENTS

Page 24: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Upcoming Conferences

CSA Summit Korea, Sept. 29, SeoulCSA Summit Europe, Oct. 10, London (with RSA Europe)CSA Congress, Nov. 16-17, OrlandoCSA Summit RSA, Feb. 27, 2012, San FranciscoSecureCloud 2012 (partnership with ENISA)

Page 25: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

Contact

Help Us Secure Cloud Computingwww.cloudsecurityalliance.orginfo@cloudsecurityalliance.orgLinkedIn: www.linkedin.com/groups?gid=1864210Twitter: @cloudsa

Page 26: Cloud Security Alliance Research & Roadmap Jim  Reavis , Executive Director, CSA

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

www.cloudsecurityalliance.orgCopyright © 2011 Cloud Security Alliance

THANK YOU!


Recommended