Cloud Computing Security: Identity Management, Encryption, and Data Protection

Alfredlio958

New member
Cloud computing changed the way most businesses manage key operations within their organization. What started as a way to easily cut some costs by reducing the need for extensive physical resources has quickly become a vital part of every modern IT network.

Cloud computing does have some drawbacks. As data and applications move further away from an organization's physical control, managing the security of those resources becomes more difficult. GMI Research predicts the Cloud Computing Market will reach USD 2.5 trillion by 2032. As cloud computing becomes more entrenched in business operations, security concerns for distributed data, identities and applications will require thoughtful and comprehensive solutions.

Why Cloud Security Matters for Today's Companies

Without the cloud, IT security relied on the idea that there was an established perimeter. Users and systems were most likely in the corporate network, and anything outside it was untrustworthy.

That changes with cloud computing.

Employees may work from wherever. Cloud services may run disjointed across multiple cloud environments. Even more, data may flow between multiple cloud services or platforms. Therefore, relying on protecting a network perimeter is insufficient.

Instead, protecting a boundary should include managing identities, controlling access and data, and monitoring everything.

Cloud Security's Identity and Access Management

Especially in cloud computing, identity and access management, or IAM, comes first.

It used to only be important to ask, "Who can gain access to a resource?" Now, we must ask, "Who is allowed to gain access? What is allowed to gain access? When is access allowed? and For how long is access allowed?"

That is everything.

An employee may need access to a cloud based application to complete a specific task. However, this may not mean that access should be granted to the entire cloud based company network.

Modern IAM systems examine user roles, devices, location, behavior, and something considered a risk to decide if access should be allowed.

Least Privilege in Cloud Environments

Cloud environments should especially utilize least privilege.

This means, users and applications should only be granted permission to access resources that are absolutely required to complete a specific task.

Some employees only need to view a database, not change or delete it. The same goes for applications. If an app only needs to access one cloud storage bucket, it shouldn’t be allowed to access all storage resources.

Limiting the scope of permissions can lessen the potential fallout from hacked accounts and rogue activities.

Securing Hybrid and Multi-Cloud Environments

Security in the cloud is complicated even more when different platforms are in use.

An organization might use various cloud services for different workloads. Some might be on the Amazon cloud while others are on the Microsoft and Google clouds. It’s possible that some services are on on-premises data centers.

Each of these environments may have different security controls and different identity systems.

A consistent Identity and Access Management (IAM) strategy is essential. Organizations need an overarching perspective on access to resources across the various environments, instead of a disjointed view for permission management.

An evaluation of access that occurs in a continuous fashion can help pinpoint permissions that are inappropriate.

Data Security via Complete Encryption

One of the most useful strategies for protecting sensitive data in the cloud is encryption.

Encryption involves the conversion of understandable text into a form that cannot be understood without the use of an encryption key.

However, cloud encryption is more involved than just the encryption of files that are stored in the cloud.

Security for data can be more complex depending on the context in which the data exists.

Protecting Data at Every Stage of its Lifecycle

Data at Rest


Cloud storage, backups and other data repositories also require the safeguarding of data from exposure to unauthorized entities.

While many organizations focus on maintaining structured data, they overlook unstructured data. This may include cloud repositories, backups, unstructured data documents, images, and even videos. These data sources may also contain sensitive data, and therefore, require data protection.

Data in Transit

Data in transit moves across applications, users, cloud services, and even different countries. Protection of data in transit focuses on encryption to protect data from being intercepted in the transit between systems. This is of absolute importance in the hybrid multi-cloud environments.

Data in Use

Data in use, or data in processing, poses the most challenge from an encryption perspective. Data in use is exposed in computation, and therefore, a greater challenge is presented for organizations from a data protection perspective.

Why Encryption Key Management is Important

The framework of encryption relies upon robust key management. Poor key management, or exposure of keys, leads to a bypass of data protection. Therefore, organizations should implement greater key management systems.

Cryptographic keys can be protected using hardware security modules or HSM. The use of these modules can be complemented with a key rotation protection system. There is a protection system, and a great deal of control, for those individuals who are offered the keys. There is an implementation of oversight for the individuals who have access to the encryption data.

Cloud Security Strategy Development

When thinking about cloud security, consider how identity controls and data protection systems can be designed to enhance security.

IAM provides strong security by controlling how people (or systems) interact with sensitive data. By applying least-privilege policies, permissions are restricted to the minimum level necessary for an employee or external user. Encryption is used to secure data so that it's protected, even if other security systems are compromised. Effective key management ensures that the encryption system is secure.

The focus is on eliminating the trust assumption for users and systems merely because they are within a given network or cloud environment.

Workload and data migrations to the cloud are causing the need for a focus on security that is dynamic, identity-centric, and data-focused. A cloud security system that is well-architected should constantly analyze data access, maintain protection for data throughout its lifecycle, and be able to adjust to changes in the business needs and threats.
 
Top