EnterpriseGRC Solutions has invested substantial time in readdressing our Cloud Security Assessment methodology. A lot of our resources were released as far back as 2011 to 2015, which means they are not sufficiently aligned with Zero Trust. Even the work contributed to mapping NIST SP 800-53 rev 5 and CMMC 2.0 during 2021 and 2022 lack specificity in ZTA. The CCM 4.5 clearly points to the use of ZTA, but we're leaning forward in the saddle to define new processes and procedures and then, in turn, to work with our community to suggest new control languages, and to encourage everyone to immediately implement the best and most critical new resources.

It's a journey, not a destination.

Zero Trust Pillars according to the DoD Cloud Security model

We recently added to our capabilities with the Information technology — Cloud computing — Audit of cloud services ISO/IEC TR 3445:2022(E). Let's begin again by asking if we and our clients have sufficiently prepared their Cloud plus Zero Trust Architecture business use case?

In preparing the business case for adopting a cloud strategy, organizations’ internal audit must be able to assess the following:

  • Regulatory compliance: assess the CSPs’ approach to meeting the regulatory requirements with which the organization has to comply.
  • Data location and ownership: assess whether the location of CSP's data storage and processing meets the required jurisdictional conditions.
  • Business viability and recovery: assess the confidence of getting the organization’s data if and when the CSPs lose their business and the impact on recovery capabilities.
  • Colocation and data segregation: assess the physical location of data storage and assurance of data server and separation of the organization’s data.
  • Systems and data: assess the sensitivity and adaptability of the organization’s data considered for possible use in the cloud environment.
  • Organization’s risks and controls: assess CSPs that best align with the organization’s controls and evaluate how best to address any gaps.
  • Roles and responsibilities: determine the roles and responsibilities of both the organization and CSPs in ensuring the use of the cloud services.
  • Assessment of application: determine the suitability of legacy or non-cloud systems viability for cloud migration and applicability for use with cloud services.
  • Assessment of applications for migration: non-cloud to private cloud, non-cloud to the public cloud, private cloud to public cloud, and private cloud to public cloud.
  • Privileged user access: assess CSP's control and assurance of access to the organization's data.

ISO/IEC TR 3445-:2022 (E) Cloud Model

How we responded

  • We completed a full reconciliation to determine where CSF 1.1 and Privacy framework support Cloud and Zero Trust environments and collaborated to establish an inventory the gaps in CSF 1.1 as compared to CCM 4.5 and to planned future additions to that standard.
  • We confirmed and extended our existing mapping ISO/IEC 27017 Cloud Certification to CSF 1.1 to determine alignment in the existing policy framework and to identify 32+ specific cloud requirements for confirmation or added implementation in a Cloudified and Zero Trust assessment
  • As a mechanism to design a phased approach, we applied a “Client as Consumer” paradigm to limit the depth of controls across IaaS and PaaS. Retain risks related to dependency on SaaS and their supporting environments (public, private or hybrid), and endpoint controls b/c these support those SaaS services.
  • Put priority on threats affecting browsers and laptops (UEM/TVM) that connect to SaaS, and Application constraints (AIS) that prevent loading insecure content.
  • Architecture:
  • For every GRC system we are asked to interact with we make sure it has all necessary the new fields and array of selections necessary to cloudify existing questions.
  • Listing an array of common nonconformance statements to assist clients in assessing their cloud risk appetite and posture.

We re-address the ISF Risk Model, return again to the ENISA Risk Model, apply again the ISO/IEC Cloud Guidance from the 27017 Cloud Certification, and examine deeper aspects of the NIST SP 800-53 rev 5, especially concerning the next release of FedRAMP defined Selection Parameters.

Risks associated with Improper Implementation of Cloud – adapted from ISF

Expected Outcome

Importance

Problem Behavior

Add these terms to Problem / Importance of doing it right

Cloud implementations are managed consistently and systematically in the organization

Ignorance

Cloud is already being used without management knowledge and approval

The organization does not enter into contracts unless there’s a clear understanding of the risks

Ambiguity

The organization assigns contracts with insufficient attention given to risk management

Information is protected by the cloud supplier and the organization has the right to audit what they are doing

Doubt

Little or no assurance regarding the management of the organization’s information is provided by or is available from cloud suppliers.

The organization is compliant with all relevant laws and regulations

Trespass

Information gets into the cloud that breaks laws and / or regulations

Information is classified and the classification used to define appropriate controls

Disorder

Information is not protected at each stage of its lifecycle

Proven, standard approaches are used to access, process and update information stored in the cloud

Immaturity or deceit

No standards infrastructure is in place in the organization to guarantee secure use of the cloud, leading to information leakage

Information and systems are available when needed

Complacency

Availability is assumed, but outages happen and cost real money

Cloud Non Conformities - ISF guidance

The Continuous Audit Metrics Working Group is https://cloudsecurityalliance.org/research/working-groups/continuous-audit-metrics/

CSA Continuous Audit Metrics Catalog

Expanding the Shared Responsibility model

Cloud Shared Responsibility Model published in Cloud Security Technical Reference Architecture

Cloud Security Technical Reference Architecture - CISA and USDS, Federal Risk Authorization Management (read more)

How might our customers already be using Cloud?

  • On-demand self-service: A consumer can unilaterally provision computing capabilities, such as server time and network storage, as needed automatically without requiring human interaction with each service’s provider.
  • Broad network access: Capabilities are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (e.g., cell phones, laptops, and PDAs).
  • Resource pooling: The provider’s computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand. There is a sense of location independence in that the customer generally has no control or knowledge over the exact location of the provided resources but may be able to specify location at a higher level of abstraction (e.g., country, state, or datacenter). Examples of resources include storage, processing, memory, network bandwidth, and virtual machines.
  • Rapid elasticity: Capabilities can be rapidly and elastically provisioned, in some cases automatically, to quickly scale out, and rapidly released to quickly scale in. To the consumer, the capabilities available for provisioning often appear to be unlimited and can be purchased in any quantity at any time.
  • Measured Service: Cloud systems automatically control and optimize resource use by leveraging a metering capability at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and consumer of the utilized service.

Exploring current models for the division of responsibilities:

SOFTWARE AS A SERVICE

Customer

Provider

  • Compliance with data protection law in respect of customer data collected and processed
  • Maintenance of identity management system
  • Management of identity management system
  • Management of authentication platform (including enforcing password policy)
  • Physical support infrastructure (facilities, rack space, power, cooling, cabling, etc.)
  • Physical infrastructure security and availability (servers, storage, network bandwidth, etc.)
  • OS patch management and hardening procedures (check also any conflict between customer hardening procedure and provider security policy)
  • Security platform configuration (Firewall rules, IDS/IPS tuning, etc.)
  • Systems monitoring
  • Security platform maintenance (Firewall, Host IDS/IPS, antivirus, packet filtering)
  • Log collection and security monitoring

PLATFORM AS A SERVICE

Customer

Provider

  • Maintenance of the identity management system
  • Management of identity management system
  • Management of authentication platform (including enforcing password policy)
  • Physical support infrastructure (facilities, rack space, power, cooling, cabling, etc.)
  • Physical infrastructure security and availability (servers, storage, network bandwidth, etc.)
  • OS patch management and hardening procedures (check also any conflict between customer hardening procedure and provider security policy)
  • Security platform configuration (firewall rules, IDS/IPS tuning, etc.)
  • Systems monitoring
  • Security platform maintenance (firewall, Host IDS/IPS, antivirus, packet filtering)
  • Log collection and security monitoring

INFRASTRUCTURE AS A SERVICE

Customer

Provider

  • Maintenance of the identity management system
  • Management of identity management system
  • Management of authentication platform (including enforcing password policy)
  • Management of guest OS patch and hardening procedures (check also any conflict between customer hardening procedure and provider security policy)
  • Configuration of guest security platform (firewall rules, IDS/IPS tuning, etc.)
  • Guest systems monitoring
  • Security platform maintenance (firewall, Host IDS/IPS, antivirus, packet filtering)
  • Log collection and security monitoring
  • Physical support infrastructure (facilities, rack space, power, cooling, cabling, etc.)
  • Physical infrastructure security and availability (servers, storage, network bandwidth, etc.)
  • Host Systems (hypervisor, virtual firewall, etc.)

Identify where we and our client rely on Cloud Service Models

Where do you currently leverage cloud services?

NIST SP 500-292 Cloud Consumer model

NIST Cloud Computing Reference Architecture (read more)

SaaS

  • ERP*
  • Human Resources *
  • Social Network ***
  • Financials*
  • Content Management
  • Email & Office Productivity
  • Document Management
  • Collaboration
  • CRM
  • Sales
  • Billing

PaaS

  • Database
  • Application Deployment
  • Integration**
  • Development & Testing
  • Business Intelligence

IaaS**

  • Storage
  • CDN
  • Backup & Recovery
  • Services Management
  • Platform Hosting
  • Compute

* If HR, ERP, and Financial systems are in the cloud there should be a SOC 2 and a SOX assessment associated with their controls.

** Integration and portions of IaaS may fall outside of the customer’s shared responsibility model. If they are using a Public Cloud, our questions may consistently result in the same risk finding. “Uncontrolled purchasing of cloud services; Failure to detect the use of new cloud services; Cloud services implemented without sufficiently addressing security requirements”

***Social Networking Policy - this is a longer topic.

Business Concerns

Interview topics that result in statements involving the Client’s capacity to either benefit from or their inability to benefit from the use of cloud technologies and services.

Cost

  • including capital cost for servers, storage, network, software, and so on, and the operational cost involved in running the IT systems consumes a large portion of a business budget.

Maintenance

  • current applications not only involves money and time, but also quite a bit of management attention.

Security and Risk Management

  • regulatory and legal reasons and for business continuity

User Experience

  • determines the enthusiasm with which applications will be integrated in the day-to-day business

Flexibility

  • Businesses expands and contracts. For most organizations, the flexibility of IT plays a crucial role in facilitating growth.

Expansion

  • IT systems continue to expand beyond the physical borders of the organization

Interview topics that result in statements involving the Client’s capacity to either benefit from or their inability to benefit from the use of cloud technologies and services.

Zero Trust Gateway

Attribute Value

Attribute Label

Description

SaaS

Software as a Service

SaaS is the capability provided to the consumer is to use the provider’s applications running on a cloud infrastructure; the applications are accessible from various client devices through a thin client interface. such as a Web browser (for example, Web-based e-mail); the consumer does not manage or control the underlying cloud infrastructure, including network, servers, operating systems, storage, or even individual application capabilities, except for limited user-specific application configuration settings
Examples Gmail, Salesforce, and Microsoft

PaaS

Platform as a Service

PaaS is the capability provided to the consumer is to deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, or storage, but has control over the deployed applications and possibly application hosting environment configurations.
Examples are specialized software libraries, (API and Programming interfaces)

IaaS

Infrastructure as a Service

IaaS is the capability provided to the consumer to provision processing, storage, networks, and other fundamental computing resources where the consumer can deploy and run arbitrary software, which can include operating systems and applications; the consumer does not manage or control the underlying cloud infrastructure but has control over operating systems, storage, deployed applications, and possibly limited control over select networking components (for example, host firewalls)
Examples are Servers, Virtual machines running as a service

SaaS; PaaS;

Combination

Software services and the platform used to serve and install them.

PaaS; IaaS;

Combination

Platform services and the infrastructure used to deploy and implement them.

SaaS; PaaS; IaaS;

Combination

Services, the services delivery platform, and the infrastructure used to deploy and maintain them. This should include SRO and SQO.

CaaS

Communications as a Service

Communications as a Service (CaaS) is an outsourced enterprise communications solution that can be leased from a single vendor. Such communications can include voice over IP (VoIP or Internet telephony), instant messaging (IM), collaboration and videoconference applications using fixed and mobile devices. CaaS has evolved along the same lines as Software as a Service (SaaS).

Also note this may be used to mean Container as a Service

CompaaS*

Compute as a Service

Compute as a Service

Compliance as a Service (I'd love to invite a speaker to ISC2 East Bay to speak definitively about CaaS v. CompaaS.

DSaaS

Data Storage as a Service

Storage as a service (STaaS) is a data storage business model where a provider rents storage resources to a customer through a subscription. STaaS saves you money through operating expenditure (OpEx) agility (Side note, I plan to have Purestorage as a future speaker at ISC2 East Bay.)

Cloud Deployment

Attribute Value

Attribute Label

Description via popup

Private cloud

Private cloud

The cloud infrastructure is operated solely for an organization.

Community cloud

Community cloud

The cloud infrastructure is shared by several organizations and supports a specific community that has shared concerns (e.g., mission, security requirements, policy, and compliance considerations).

Public cloud

Public cloud

The cloud infrastructure is made available to the general public or a large industry group and is owned by an organization selling cloud services.

Hybrid cloud

Hybrid cloud

The cloud infrastructure is a composition of two or more clouds (private, community, or public) that remain unique entities but are bound together by standardized or proprietary technology that enables data and application portability (e.g., cloud bursting for load-balancing between clouds)..

 

 

PRIVATE

COMMUNITY

PUBLIC

ACCESSIBILITY

Single Organization

Shared with Common Interests / Requirements

General Public / Large Industry Group

MANAGEMENT

Organization or Third Party

Organization or Third Party

Cloud Provider

HOST

On or Off Premise

On or Off Premise

On or Off Premise

 

Virtualization Simplifies Application Development Process

Agile Development

  • Agile Development, which calls for rapid, incremental delivery of new code in a running system driven by specific test cases, can be greatly streamlined by virtualization. The developer can clone an environment to hand over to testers and continue to work without having to spend time laboriously recreating environments for testing.

Multi-tier Environments

  • When dealing with code that runs in different environments, as in commercial software or even when sharing an application between geographies or business units in a single company, it can be hard to replicate bugs and test whether fixes work. Virtualization can aid here in several ways:
  • maintain multiple testing environments without expensive, rarely used hardware.
  • Ability to keep literally all versions of the software run ready
  • Virtual snapshot of a customer's running system and bring it intact into the lab for testing.

Packaging and Installation

  • Conventional approaches to packaging and installation can leave customers and systems administrators with the complex task of installing the application and its dependencies and properly configuring the software. With careful planning, this kind of repetitive systems administration task can become a thing of the past as development teams deploy software as virtual appliances ready to run in a server virtualization environment. With contemporary virtualization platforms, even sophisticated multi-tier applications can be packaged and released, ready to install and go.

Defect Management

  • Some software defects can be extremely hard to track down when they involve networks of application code on different machines performing unpredictably. Defects can be greatly dependent on timing, and so-called Heisenbugs can be incredibly hard to isolate. When an entire network of machines is virtualized and run on a single machine for test purposes, advanced debugging systems like Sun Microsystems' DTRACE can greatly reduce the complexity of the problem.

Virtualization Simplifies Application Development Process

 

Main Menu