SlideShare a Scribd company logo
Security of SaaS and Private CloudConsiderations for CFO’sIan FarquharAdvisory Technology Consultant
Profile: Ian FarquharCareer:RSA, The Security Division of EMC (2008-Present)Cisco Systems (2004-2008)Sun Microsystems (1999-2004)Silicon Graphics/Cray Research (1994-1999)Macquarie University Department of Research Electronics (1993-1994)Macquarie University Office of Computing Services (1988-1993)Twenty years of experience in computer and information securityTechnology Evangelist for RSARSA specialist for ANZ in:Data Loss PreventionCryptographyPolicySecurity evaluation
Definitions: Public vs. Private CloudAccording to Gartner: The distinguishing characteristics of a private cloud environment are that the infrastructure is internally owned and operated, and that systems can be dynamically provisioned and activated. The distinguishing characteristics of a public cloud environment that are most important for security assessment and monitoring are that the infrastructure is not owned by the customer and that the service is provided via a shared infrastructure. Or... (from the RSA Conference):A private cloud is inside the firewall, a private cloud is outside. Security CIA:Confidentiality, Integrity and Availability
Definition: Software-as-a-Service (SaaS)SaaS is the provision of software in a services model.Gartner defines SaaS as "software that's owned, delivered and managed remotely by one or more providers." In a pure SaaS model, the provider delivers software based on a single set of common code and data definitions that are consumed in a one-to-many model by all contracted customers anytime, on a pay-for-use basis, or as a subscription based on use metrics. Other *aaS acronyms:PaaS: Platform-as-a-ServiceIaaS: Infrastructure-as-a-ServiceSaaS and PaaS are not really new conceptsMainframe-era “Bureau Services” were just SaaS or PaaSEven virtualization is not new: IBM/VM circa 1969
Issues to Consider: SaaS (and Public Cloud)Legal issuesIf it isn’t in the contract, it should beWhat are the service level agreements?  How are they measured?Do they match your expectations?  What is the dispute process?Who owns your data?Where is it processed?Where is the DR site? Where is it replicated?Jurisdictional issuesData location (compliance)Legal issues (eg. US Patriot Act)Legal search and seizure considerationsSaaS provider closure or acquisitionWhat legal rights do you have?If you can access the data, in what form?  (and don’t forget the backups)How quickly could you migrate this business function?
Issues to Consider: SaaS (and Public Cloud)Provider Terminating ContractHow much notice do you get?Do you have any right of appeal?Can they terminate your service and leave you without access to “your” data?“The Forced March”Will upgrades at the SaaS provider introduce unexpected work (cost)?Forced up-sell due to discontinuation of an older versionHow much notice do you get?What guarantees are in the contract?Connectivity and Performance IssuesSaaS makes your business dependent on Internet accessDon’t forget the SLA’s from your ISP or carrierHow would your  business cope with a network outage?Don’t forget to factor in the cost of network managementIs your network traffic protected in transit?  (SSL issues.)
Issues to Consider: SaaS (and Public Cloud)ExpertiseIf you find you need expertise above basic support, where does it come from and how much does it cost?Generic “Security” IssuesEndpoint security still is criticalWhat is the SaaS provider’s security posture?How do they authenticate users?What guarantees do you have that the SaaS provider is implementing best practice?Who can access your data?  (Separation).(Not applicable for “pay as you go”).  How is the service funded?Fundamentally, HOW DO YOU KNOW?Or, WHAT IS THE RATIONAL BASIS FOR YOUR TRUST?
Issues to Consider: Private CloudMost of the security issues with Private Cloud are not newSome security features are better on private cloud than on raw hardware (eg. DR)Limiting this to private-cloud specific issuesAll best IT practice applies similarly to private cloud, as it does to existing IT infrastructurePrivate cloud is fundamentally about increasing efficiencyIssues:Network infrastructure and designAdministrative access – a rogue or careless admin can do a lot of damageProliferation – change control is still critical for a well-run virtual infrastructureSoftware licensingOrphaned VMsData sprawlSecurity patching and offline VMsLegal search and seizureCapacity planningExcellent resource: Cloud Security Alliancehttp://www.cloudsecurityalliance.org/
In SummarySaaS and Public CloudRead and understand the contractDo a thorough cost-benefit analysisPlan for the contingenciesTrust but verifyPrivate CloudAll current best practices apply to private clouds tooPrivate clouds have some security characteristics which are superior to “raw metal” ITThe majority of issues are operational – this is where to focus
The security of SAAS and private cloud

More Related Content

PPTX
Intel SaaS Security Playbook
PPTX
SaaS (Software-as-a-Service) as-a-secure-service
PPTX
Security concerns with SaaS layer of cloud computing
PPTX
Securing Software-as-a-Service: Cover your SaaS and protect enterprise data
PPTX
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
PDF
Implementing zero trust architecture in azure hybrid cloud
PPTX
The Notorious 9 Cloud Computing Threats - CSA Congress, San Jose
PPT
Security As A Service
Intel SaaS Security Playbook
SaaS (Software-as-a-Service) as-a-secure-service
Security concerns with SaaS layer of cloud computing
Securing Software-as-a-Service: Cover your SaaS and protect enterprise data
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
Implementing zero trust architecture in azure hybrid cloud
The Notorious 9 Cloud Computing Threats - CSA Congress, San Jose
Security As A Service

What's hot (20)

PDF
Cloud Security Governance
PDF
Workshop: Threat Intelligence - Part 1
PDF
Security As A Service
PPTX
Security as a Service Model for Cloud Environment
PPTX
Aligning Risk with Growth - Cloud Security for startups
PPTX
Cloud security innovation - Cloud Security Alliance East Europe Congress 2013
PDF
BlockChain Enabled-Cloud Delivered For Network Secuirty
PDF
SECURING THE CLOUD DATA LAKES
PPT
Securing Sensitive Data in Your Hybrid Cloud
PPTX
Vulnerabilities in SaaS layer of cloud computing
DOCX
Cloud keybank privacy and owner authorization
PPTX
2017-10-05 Mitigating Cybersecurity and Cyber Fraud risk in Your Organization
PPTX
Surviving the lions den - how to sell SaaS services to security oriented cust...
PDF
IT Security As A Service
PPTX
Cloud security what to expect (introduction to cloud security)
PDF
CSA Introduction 2013 David Ross
PDF
Strategy Cloud and Security as a Service
PPTX
Security As A Service In Cloud(SECaaS)
PDF
MEKDA: Multi-Level ECC based Key Distribution and Authentication in Internet ...
Cloud Security Governance
Workshop: Threat Intelligence - Part 1
Security As A Service
Security as a Service Model for Cloud Environment
Aligning Risk with Growth - Cloud Security for startups
Cloud security innovation - Cloud Security Alliance East Europe Congress 2013
BlockChain Enabled-Cloud Delivered For Network Secuirty
SECURING THE CLOUD DATA LAKES
Securing Sensitive Data in Your Hybrid Cloud
Vulnerabilities in SaaS layer of cloud computing
Cloud keybank privacy and owner authorization
2017-10-05 Mitigating Cybersecurity and Cyber Fraud risk in Your Organization
Surviving the lions den - how to sell SaaS services to security oriented cust...
IT Security As A Service
Cloud security what to expect (introduction to cloud security)
CSA Introduction 2013 David Ross
Strategy Cloud and Security as a Service
Security As A Service In Cloud(SECaaS)
MEKDA: Multi-Level ECC based Key Distribution and Authentication in Internet ...
Ad

Viewers also liked (20)

PPTX
Df2012 securing information_assets_in_saa_s_clouds_3_0
PDF
SaaS as a Security Hazard - Google Apps Security Example
PPTX
5 Ways To Fight A DDoS Attack
PPTX
Cloud Computing – Opportunities, Definitions, Options, and Risks (Part-1)
PPTX
The Cloud: Privacy and Forensics
PDF
Security on cloud storage and IaaS (NSC: Taiwan - JST: Japan workshop)
PPTX
IoT DDoS Attacks: the stakes have changed
PPT
Cloud Computing Security Challenges
PPTX
Cloud computing security & forensics (manu)
PPT
Moving To SaaS
PDF
Trying to bottle the cloud forensic challenges with cloud computing
PPSX
Cloud Forensics
PDF
2017 03-01-forensics 1488330715
PDF
(130928) #fitalk cloud storage forensics - dropbox
PPTX
IoT Security: Cases and Methods
PDF
12Nov13 Webinar: Big Data Analysis with Teradata and Revolution Analytics
PPTX
How IoT Is Breaking The Internet
PDF
Assessing the Security of Cloud SaaS Solutions
PDF
Privacy and Security in the Internet of Things / Конфиденциальность и безопас...
PDF
IBM Security SaaS IaaS and PaaS
Df2012 securing information_assets_in_saa_s_clouds_3_0
SaaS as a Security Hazard - Google Apps Security Example
5 Ways To Fight A DDoS Attack
Cloud Computing – Opportunities, Definitions, Options, and Risks (Part-1)
The Cloud: Privacy and Forensics
Security on cloud storage and IaaS (NSC: Taiwan - JST: Japan workshop)
IoT DDoS Attacks: the stakes have changed
Cloud Computing Security Challenges
Cloud computing security & forensics (manu)
Moving To SaaS
Trying to bottle the cloud forensic challenges with cloud computing
Cloud Forensics
2017 03-01-forensics 1488330715
(130928) #fitalk cloud storage forensics - dropbox
IoT Security: Cases and Methods
12Nov13 Webinar: Big Data Analysis with Teradata and Revolution Analytics
How IoT Is Breaking The Internet
Assessing the Security of Cloud SaaS Solutions
Privacy and Security in the Internet of Things / Конфиденциальность и безопас...
IBM Security SaaS IaaS and PaaS
Ad

Similar to The security of SAAS and private cloud (20)

PDF
Data Security Issues in Cloud Computing
PPT
Radu crahmaliuc 23feb2012
PPTX
Cloud Services helping in cloud service to be fully knowledgably .pptx
PDF
The text defines three service layers when describing Cloud Computin.pdf
PDF
Navigating the Shifting Tides: Understanding the Evolving Landscape of Cybers...
PDF
SaaS Platform Securing
PPTX
Cloud computing - Assessing the Security Risks - Jared Carstensen
PPTX
Cloud presentation NELA
PDF
Critical_Review_of_Openstack_Security_Is.pdf
PDF
saassecurity-230424030940-08314322.pdf
PPTX
SaaS Security.pptx
PPT
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
PDF
Sia Partners Insights when Considering a SaaS Solution
PDF
Losing Control to the Cloud
PPTX
Active state private paas is not an oxymoron final
PPT
Lecture 10.ppt
DOCX
Public cloud: A Review
PDF
Cloud Security, Standards and Applications
PDF
Dr. Michael Valivullah, NASS/USDA - Cloud Computing
PDF
Securing The Journey To The Cloud
Data Security Issues in Cloud Computing
Radu crahmaliuc 23feb2012
Cloud Services helping in cloud service to be fully knowledgably .pptx
The text defines three service layers when describing Cloud Computin.pdf
Navigating the Shifting Tides: Understanding the Evolving Landscape of Cybers...
SaaS Platform Securing
Cloud computing - Assessing the Security Risks - Jared Carstensen
Cloud presentation NELA
Critical_Review_of_Openstack_Security_Is.pdf
saassecurity-230424030940-08314322.pdf
SaaS Security.pptx
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
Sia Partners Insights when Considering a SaaS Solution
Losing Control to the Cloud
Active state private paas is not an oxymoron final
Lecture 10.ppt
Public cloud: A Review
Cloud Security, Standards and Applications
Dr. Michael Valivullah, NASS/USDA - Cloud Computing
Securing The Journey To The Cloud

More from Azure Group (19)

PDF
CFO Network Event May 2012 - Presentation by David Hooton
PPTX
CFO Network Event May 2012 - Presentation by Stephen Myers
PPT
CFO Network Event May 2012 - Presentation by Paul Brooks
PPTX
Pricing for profit
PPS
Managing HR risk
PPS
Azure redback presentation tax 22 nov11
PPTX
Rob Antulov CFO Network presentation
PPT
Jason Cachia CFO Network presentation March 2012
PDF
Bill Evans CFO Network presentation March 2012
PPT
CFO Network presentation from Janet Young, CFO of Freehills
PPT
CFO Network presentation by Peter McCelland, CFO of Luxottica
PPT
Risk management - Alan Bardwell
PPTX
Enterprise risk management & insurance - Stephen Rinder
PPTX
CFO Risk Intelligence - Harvey Christophers
PPSX
CFO Network – Business valuation
PPSX
Cloud computing for business
PPT
Grant Turley CFO Network presentation
PPSX
Private & public capital raisings pjm presentation
PPTX
Private Equity Update
CFO Network Event May 2012 - Presentation by David Hooton
CFO Network Event May 2012 - Presentation by Stephen Myers
CFO Network Event May 2012 - Presentation by Paul Brooks
Pricing for profit
Managing HR risk
Azure redback presentation tax 22 nov11
Rob Antulov CFO Network presentation
Jason Cachia CFO Network presentation March 2012
Bill Evans CFO Network presentation March 2012
CFO Network presentation from Janet Young, CFO of Freehills
CFO Network presentation by Peter McCelland, CFO of Luxottica
Risk management - Alan Bardwell
Enterprise risk management & insurance - Stephen Rinder
CFO Risk Intelligence - Harvey Christophers
CFO Network – Business valuation
Cloud computing for business
Grant Turley CFO Network presentation
Private & public capital raisings pjm presentation
Private Equity Update

Recently uploaded (20)

PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Empathic Computing: Creating Shared Understanding
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PPTX
A Presentation on Artificial Intelligence
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
cuic standard and advanced reporting.pdf
PDF
Encapsulation theory and applications.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
Building Integrated photovoltaic BIPV_UPV.pdf
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
NewMind AI Monthly Chronicles - July 2025
Empathic Computing: Creating Shared Understanding
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
A Presentation on Artificial Intelligence
Encapsulation_ Review paper, used for researhc scholars
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
The Rise and Fall of 3GPP – Time for a Sabbatical?
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
20250228 LYD VKU AI Blended-Learning.pptx
Dropbox Q2 2025 Financial Results & Investor Presentation
“AI and Expert System Decision Support & Business Intelligence Systems”
MYSQL Presentation for SQL database connectivity
Mobile App Security Testing_ A Comprehensive Guide.pdf
Network Security Unit 5.pdf for BCA BBA.
cuic standard and advanced reporting.pdf
Encapsulation theory and applications.pdf
Spectral efficient network and resource selection model in 5G networks

The security of SAAS and private cloud

  • 1. Security of SaaS and Private CloudConsiderations for CFO’sIan FarquharAdvisory Technology Consultant
  • 2. Profile: Ian FarquharCareer:RSA, The Security Division of EMC (2008-Present)Cisco Systems (2004-2008)Sun Microsystems (1999-2004)Silicon Graphics/Cray Research (1994-1999)Macquarie University Department of Research Electronics (1993-1994)Macquarie University Office of Computing Services (1988-1993)Twenty years of experience in computer and information securityTechnology Evangelist for RSARSA specialist for ANZ in:Data Loss PreventionCryptographyPolicySecurity evaluation
  • 3. Definitions: Public vs. Private CloudAccording to Gartner: The distinguishing characteristics of a private cloud environment are that the infrastructure is internally owned and operated, and that systems can be dynamically provisioned and activated. The distinguishing characteristics of a public cloud environment that are most important for security assessment and monitoring are that the infrastructure is not owned by the customer and that the service is provided via a shared infrastructure. Or... (from the RSA Conference):A private cloud is inside the firewall, a private cloud is outside. Security CIA:Confidentiality, Integrity and Availability
  • 4. Definition: Software-as-a-Service (SaaS)SaaS is the provision of software in a services model.Gartner defines SaaS as "software that's owned, delivered and managed remotely by one or more providers." In a pure SaaS model, the provider delivers software based on a single set of common code and data definitions that are consumed in a one-to-many model by all contracted customers anytime, on a pay-for-use basis, or as a subscription based on use metrics. Other *aaS acronyms:PaaS: Platform-as-a-ServiceIaaS: Infrastructure-as-a-ServiceSaaS and PaaS are not really new conceptsMainframe-era “Bureau Services” were just SaaS or PaaSEven virtualization is not new: IBM/VM circa 1969
  • 5. Issues to Consider: SaaS (and Public Cloud)Legal issuesIf it isn’t in the contract, it should beWhat are the service level agreements? How are they measured?Do they match your expectations? What is the dispute process?Who owns your data?Where is it processed?Where is the DR site? Where is it replicated?Jurisdictional issuesData location (compliance)Legal issues (eg. US Patriot Act)Legal search and seizure considerationsSaaS provider closure or acquisitionWhat legal rights do you have?If you can access the data, in what form? (and don’t forget the backups)How quickly could you migrate this business function?
  • 6. Issues to Consider: SaaS (and Public Cloud)Provider Terminating ContractHow much notice do you get?Do you have any right of appeal?Can they terminate your service and leave you without access to “your” data?“The Forced March”Will upgrades at the SaaS provider introduce unexpected work (cost)?Forced up-sell due to discontinuation of an older versionHow much notice do you get?What guarantees are in the contract?Connectivity and Performance IssuesSaaS makes your business dependent on Internet accessDon’t forget the SLA’s from your ISP or carrierHow would your business cope with a network outage?Don’t forget to factor in the cost of network managementIs your network traffic protected in transit? (SSL issues.)
  • 7. Issues to Consider: SaaS (and Public Cloud)ExpertiseIf you find you need expertise above basic support, where does it come from and how much does it cost?Generic “Security” IssuesEndpoint security still is criticalWhat is the SaaS provider’s security posture?How do they authenticate users?What guarantees do you have that the SaaS provider is implementing best practice?Who can access your data? (Separation).(Not applicable for “pay as you go”). How is the service funded?Fundamentally, HOW DO YOU KNOW?Or, WHAT IS THE RATIONAL BASIS FOR YOUR TRUST?
  • 8. Issues to Consider: Private CloudMost of the security issues with Private Cloud are not newSome security features are better on private cloud than on raw hardware (eg. DR)Limiting this to private-cloud specific issuesAll best IT practice applies similarly to private cloud, as it does to existing IT infrastructurePrivate cloud is fundamentally about increasing efficiencyIssues:Network infrastructure and designAdministrative access – a rogue or careless admin can do a lot of damageProliferation – change control is still critical for a well-run virtual infrastructureSoftware licensingOrphaned VMsData sprawlSecurity patching and offline VMsLegal search and seizureCapacity planningExcellent resource: Cloud Security Alliancehttp://www.cloudsecurityalliance.org/
  • 9. In SummarySaaS and Public CloudRead and understand the contractDo a thorough cost-benefit analysisPlan for the contingenciesTrust but verifyPrivate CloudAll current best practices apply to private clouds tooPrivate clouds have some security characteristics which are superior to “raw metal” ITThe majority of issues are operational – this is where to focus