|
Mar 17
2012
|
Going beyond compliance: achieving true security in the CloudPosted by: Eric Novikoff Tagged in: Techniques
|
One of the largest barriers to cloud deployments is the actual or perceived lack of security in the shared infrustructure used to provide cloud services. Companies seeking to create applications that meet PCI, HIPAA, or FIPS standards are struggling with the twin challenges of actually meeting the requirements as well as finding auditors that are well enough versed in cloud technology to assess whether those requirements are met by a proposed cloud deployment. On the other side of the fence, vendors are lining up to provide checklist-decorated services of supposedly regulation-compliant infrastructure that dangles the prospect of guaranteed compliance simply by choosing their hosting/cloud solution. It's a mess!
At ENKI, what we've learned is that there are two basic considerations in meeting requirements for compliant cloud security: actually providing infrastructure that meets auditor's requirements AND providing our customers with security solutions that are simple, effective, and flexible enough so that they can tell their clients or end users that they are not just meeting the letter of the law but actually sure that the personally identifiable data is really safe.
Our most sophisticated security-conscious client, a HIPAA-compliant medical information processing service company, is headed by a CEO who explained to me that his major challenge is convincing his customers (medical clinics) that they can trust him, for which HIPAA and SSAE compliance simply wasn't good enough. He knew that he needed to secure his software by design, and then make sure that all the client data was completely inaccessible both at rest and in motion. To accomplish the latter, they have chosen High Cloud Security's data security product, which is going to be rolled out in their processing environments at ENKI.
I recently met with their executive team (they're in Mountain View, like us) and was impressed with the product. The architecture behind their system is to provide a storage republishing engine that handles all encryption, keeping unencrypted data completely out of the cloud storage infrastructure, while republishing a secured block or file based storage to the client VMs. This not only secures the customer's data, but also the VM itself and its swap space - everywhere that an image of the secured data might reside, even temporarily, including backups. In addition, they offer a key separate key management server with role-based access that can be locally or remotely hosted, allowing keys to be managed without the necessity of logging in and providing them to the application before it can run. Key management can be entrusted to the cloud service provider, a third part, or even handled by the clients themselves. While there is no 100% secure way of storing a key (who has the key to where the key is stored?) this solution allows you to choose who you'll trust with your keys, without having to manage them manually. It completely eliminates carrying around printed keys, USB key storage sticks, or other ad-hoc solutions. The one remaining challenge - securing the link from the VM to another to storage - is addressed by having an in-VM version of their storage publisher software. With this method, any operations that the cloud service provider applies to the protected data do not expose any priveleged information - even moving the VM from one datacenter to another.
Because of ENKI's "everyting is virtual" approach to infrastructure, High Cloud Security's services are easy to deploy, and no restriction is placed on the flexibility of their key management: we can run it, you can run it, or you can have a third party run it. You can also use the storage republisher VM entirely for your private application, kept within a VLAN, so that no element of your cloud infrastructure shares unprotected data with another customer, which meets even the most stringent storage privacy requirements.
Please contact us to talk over your compliance requirements and how our virtual private cloud / virtual colocation architecture combined with High Cloud Security can make meeting your compliance requirments a snap.






