Proof, Not Promises

author-image
DQChannels Bureau
New Update
style="margin-bottom: 0in; font-weight: normal; line-height: 100%; text-decoration: none;"
align="LEFT">
We
know
all too well that we are only as good as the last attack we have
withstood. And let's face it, while we have relied on numerous
'giants' over the years to create the success we've had, we've
also had to navigate our way around a few pygmies. To paraphrase the
philosopher George Santayana: “Those who do not study and
understand the past will be condemned to relive it”. And, while I
don't think we should take ourselves too seriously, we should also
be very proud of what we have accomplished. Learning from our
successes and failures, building on the rich heritage of our giants,
we continue our important work and with an eye to the future. Abraham
Lincoln once said that 'the best thing about the future is that it
comes only one day at a time'. We now recognize the limitations of
perimeter defenses and the need for information-centric security has
become conventional wisdom. We now acknowledge that to be
information-centric, security controls must be more intelligent,
flexible and dynamic-Thinking Security. We now understand that
security budgets are finite and for that to be cost-effective,
security infrastructures must be grounded in a thorough understanding
of risk, balancing the elimination of threats, with probability and
materiality. We now know a criminal ecosystem has developed and that
nation states and non-state actors like Wikileaks pose new threats
that can only be countered with our own cooperative ecosystem. That
despite day-to-day competition vendors must integrate
technologies.... Industries must share best practices and threat
intelligence....And governments must cooperate with one another and
the private sector. And last year, the rallying cry from my keynote
was “safety in the cloud” and the chance for a “Security
Do-over.” So this year my theme is “Trust in the Cloud”. Last
year my keynote was about the promise. This year it's about the
proof. The promise is that you can achieve safety in the cloud. The
promise is that we can fundamentally do security differently and
better. The proof comes when, by leveraging virtualization
technology, we demonstrate better control and visibility, the key
elements of trust, in cloud environments. At this point, the IT
industry believes in the potential of virtualization and cloud
computing. IT organizations are transforming their infrastructures
which means we're well on our way to an era of 'applied IT'
where investments will focus less on infrastructure and more on
leveraging IT to solve higher level business problems. But in any of
these transformations the goal of security remains the same-getting
the right information to the right people over a trusted
infrastructure in a system that can be governed and managed. But
independent of this transformation to cloud we're seeing an
enormous amount of change across the dimensions of information,
identities and infrastructure- creating a nightmare of control
problems and visibility issues...The antithesis of trust.
Advertisment
  • style="margin-bottom: 0in; font-weight: normal; line-height: 100%; text-decoration: none;"
    align="LEFT"> face="Times New Roman, serif">First, we have a tidal
    wave of information being created and more and more sensitive
    information being shared. This creates significant information
    governance challenges regarding where sensitive data moves; who gets
    it; how it's protected at rest and in motion; how, in a world of
    replication, we delete it; etc.
  • style="margin-bottom: 0in; font-weight: normal; line-height: 100%; text-decoration: none;"
    align="LEFT"> face="Times New Roman, serif">Secondly, identities are
    proliferating. In addition to our traditional internal users, we have
    customers, partners, a growing number of mobile workers using consumer
    devices and even machines, accessing our infrastructure and
    information. Everyone and everything needs access.
  • style="margin-bottom: 0in; font-weight: normal; line-height: 100%; text-decoration: none;"
    align="LEFT"> face="Times New Roman, serif">Third, the entire IT
    stack is changing.We now have a virtual layer that abstracts the
    underlying storage, compute, and network infrastructure. Our boundaries
    become logical rather than physical. Our workloads now move, so we can
    no longer depend on the physical infrastructure as a proxy for the
    information or process we are trying to protect. And as the endpoint
    splinters into a thousand variations, the IT team is losing control and
    visibility over that too.
Advertisment
style="margin-bottom: 0in; font-weight: normal; line-height: 100%; text-decoration: none;"
align="LEFT">
There
are
2 other dimensions of change. Threats have shifted from viruses
and malware to more advanced persistent threats, and 'low and slow'
crimeware making static policies and signatures all but useless. The
same is true for insider attacks. There's no virus signature for a
crooked database administrator. Compliance also continues to evolve
with more regulation, more changes within regulations, and greater
reporting requirements. Considering all the challenges created by
these changes, it may at first seem that virtualization and cloud
complicate the problem. It's widely reported that confusion and
fear are holding organizations back from adoption. But, deliberately
or not, organizations are already moving to the cloud in response to
business demands. Fearful or not, these changes are making cloud
adoption inevitable. Virtualization is our silver lining in the
cloud. If leveraged properly virtualization can also be the pathway
to surpassing the level of control and visibility that physical IT
offers, transforming the infrastructure itself into a vital resource
for improving security and compliance in three striking ways.

style="margin-bottom: 0in; font-weight: normal; line-height: 100%; text-decoration: none;"
align="LEFT">
  • style="margin-bottom: 0in; font-weight: normal; line-height: 100%; text-decoration: none;"
    align="LEFT"> face="Times New Roman, serif">First, we have a tidal
    wave of information being created and more and more sensitive
    information being shared. This creates significant information
    governance challenges regarding where sensitive data moves; who gets
    it; how it's protected at rest and in motion; how, in a world of
    replication, we delete it; etc.
style="margin-bottom: 0in; font-weight: normal; line-height: 100%; text-decoration: none;"
align="LEFT">
  • style="margin-bottom: 0in; font-weight: normal; line-height: 100%; text-decoration: none;"
    align="LEFT"> face="Times New Roman, serif">Second, security becomes
    built-in and automated. In clouds, where information, VMs and entire
    virtualized networks relocate in the blink of an eye, security measures
    must be just as dynamic. Achieving this means building security into
    virtualized components and, by extension, distributing security
    throughout the cloud. Also, automation will be absolutely essential to
    enabling security and compliance to work at the speed and scale of the
    cloud. Policies, regulations and best practices will be codified into
    security management systems and enforced automatically, reducing the
    need for intervention by IT staff.
  • style="margin-bottom: 0in; font-weight: normal; line-height: 100%; text-decoration: none;"
    align="LEFT"> face="Times New Roman, serif">And third, security
    becomes risk-based and adaptive because static security approaches
    can't address evolving threats. In the near future, trusted clouds will
    employ predictive analytics based on their understanding of normal
    states, user behaviors and transaction patterns to spot high-risk
    events and allow organizations to proactively adapt defenses.
Advertisment
style="margin-bottom: 0in; font-weight: normal; line-height: 100%; text-decoration: none;"
align="LEFT"> size="3">Adopting
these principles enables a heightened level of control and visibility
that will lead to trust. While I've advocated for these principles
in the past, we are now at an inflection point where they are being
applied in solutions arriving in the market place.

size="3"> style="text-decoration: none;">Excerpts
from
the 20th RSA Conference 2011 keynote address by Art Coviello,
executive vice president EMC and executive chairman, RSA, at their
20
face="Times New Roman, serif"> style="font-weight: normal;">th color="#000000"> style="text-decoration: none;">
Annual RSA Conference 2011