Monday, 15 June 2020

Cloud Access Security Brokers

In part three of our series on how to create a cloud security plan, we took a closer look at cloud security best practices that can help any business across all industries. We briefly mentioned that using a Cloud Access Security Broker (CASB) as an advantageous option. Since many people aren’t aware of this technology and how it works, we thought it would be important to take a deeper dive into the details of CASB and how it can help your company create a comprehensive cloud security plan.


What is CASB?

Essentially, a CASB is a software that forms an additional layer of protection between your company and the cloud. Instead of sending information directly to the cloud, it will first pass through the CASB where it will be checked against a variety of security standards. This makes it easier to enforce security measures and meet compliance standards. The CASB can either be located on-premise or hosted in the cloud.

Advantages of a CASB

One of the biggest challenges of maintaining cloud security is ongoing monitoring. This is an essential component, especially as new attacks emerge and cloud resources evolve, potentially creating new vulnerabilities. A CASB will provide an additional defense against high-risk events. The software includes malware prevention along with encryption services so that even if there is a data breach, outside parties won’t be able to decipher the information.

Additional advantages include:

Better visibility. A CASB will allow you to easily view all aspects of cloud applications and how they are being used. You can see who is using the platform, where they are located and what devices they are using. Without full visibility, information is not being properly controlled, which creates unnecessary risks.

You can use the CASB to constantly test your data and protocols against compliance standards. This will help you comply with government and industry regulations that are designed to protect consumer information and implement security best practices.

Insider threat reduction. In some cases, employees are the most pressing threat to vital data. A CASB will allow you to detect and quickly respond to unauthorized users accessing different areas of the cloud. You can easily create privileges and authentication protocols that will more effectively protect data and limit access.

All of these advantages are essential to a comprehensive cloud security plan. A CASB simply makes it easier to execute all of these steps and provide a more secure approach that continues to monitor changes.

CASB Deployment Options

Ultimately, a CASB can be deployed in three different ways:


Forward Proxy. In this case, the CASB is used to proxy traffic to multiple platforms. This places the CASB behind the firewall and adds protection before connecting to the internet. It also provides inline security so that security measures are actively deployed and monitoring live traffic.


Reverse Proxy. With a reverse proxy, the CASB sits in front of the cloud provider, blocking the network traffic and forcing information to go through the same set of inline security measures.
API Mode. With API mode, the CASB can be directly integrated into the cloud service. The main advantage of this approach is that you can secure both managed and unmanaged traffic.

You can also use any combination of these deployment approaches to enhance security even further. Fortunately, there are many reputable CASB providers who have well-established and proven solutions. Microsoft, Symantec, McAfee, and other big names all offer CASB services so that you can take your cloud security plan to the next level.

To learn more about CASB options and how you can use this tool to adhere to cloud security best practices and maximize your cloud technology without compromising data, contact the experts at prancer. We help businesses continue to meet cloud compliance standards by creating validation networks. Our team can answer all your cloud security questions and help take full advantage of the latest resources without compromising security.

Monday, 8 June 2020

Cloud Security Guidelines

Every cloud security plan is going to look different based on your business and your industry. However, there are some general rules when it comes to best practices that will help provide guidance as your work towards establishing a flexible and scalable cloud security plan. In the third installment of our series, we will take a closer look at cloud security best practices and how you can use these to shape your security plan.



1.  Partner with a Trusted Cloud Provider
The very first step in establishing solid cloud security is to partner with a trusted and reputable cloud provider. As you shop around, look for providers who offer built-in security protocols that will support your efforts to secure data and meet compliance standards. The right provider will have earned a range of security compliance certifications that are publicly advertised for maximum transparency. In addition, you want a provider who can offer a marketplace of partners so that you can shop different solutions and integrate them into your deployment for a customized security plan.

2.  Understand Your Responsibilities
When you partner with a cloud provider, you are both responsible for certain aspects of security. It is important that you understand which tasks fall to which party. You don’t want to assume that the provider is taking care of a security protocol only to discover that it was your responsibility. A reputable cloud provider will provide a transparent shared responsibility model so that you have easy access to this information.

3.  Train All Users
When it comes to cloud computing, the users can either be an asset or a liability. Well-trained users will understand and implement security practices and avoid creating unnecessary vulnerabilities. By making users aware of the dangers of poor security practices and training them to spot abnormalities that could signal malware or phishing scams, you can turn them into a powerful security tool. If you work in an industry with complex compliance standards, it may be worth investing in having an employee complete industry-specific training and earn a certification. This will provide valuable in-house oversight.

4.  Create Secure Endpoints
Cloud technology has made it easier than ever for employees to work remotely and use mobile devices to access the cloud. Oftentimes, they are using personal devices, which means they won’t automatically have extra security that may come with company owned devices. In addition, in most cases, they are using a web browser to access documents. All of these endpoints must be secured. A reputable provider will offer protections that include: antivirus tools, firewalls, mobile device security features and other detection tools that can be used to identify any breaches.

5.  Ensure Visibility of Your Cloud
Using resources on the cloud can create a fast-paced environment. This can be further complicated by the fact that many companies use multiple cloud services. These factors can affect visibility and make it difficult to avoid creating blindspots. You will want a solution that allows for maximum visibility so that you can identify risks and maintain a clear vision of the entire system.

6.  Create a Password Policy
One of the easiest things you can do to support cloud security is to create a company-wide password policy. For example, require that users change their password every 90 days and prevent simple passwords by either generating unique passwords or requiring that they are 14 characters long and include a symbol, number and one uppercase letter. Multi-factor authentication can also help prevent unauthorized access. These types of policies can go a long way in preventing attacks.

7.  Encrypt All Your Data
Whether your data is being stored or in transit, it should always be encrypted. While a provider may offer encryption services, keep in mind that going this route means that they will have access to the encryption key. You can further increase security by using your own encryption solution. Even if a malicious party is able to access your data, they won’t be able to do anything with the information.

Any business can benefit from putting these cloud security best practices into place and working with a reputable provider who will work to support your security efforts. In the next part of our series, we will take a look at one final best practice: using a Cloud Access Security Broker. Many people aren’t familiar with this tool, so we will be using the next post to take a deep dive into this option and discuss what it is and how it can help.

If you have any additional questions about cloud security and compliance, contact the experts at prancer. We offer a pre and post-deployment could validation framework for IaC that supports continuous compliance. A team member will be happy to answer all your question and get you started on the road to better cloud security and compliance.

Monday, 1 June 2020

Cloud Computing Security Plan

In this series, we will take a closer look at how to create a cloud security plan that will protect your cloud-based systems, infrastructure, and important data. A comprehensive and flexible security plan is key to protecting your clients’ information and complying with industry and governmental regulations. Security breaches can result in a loss of business along with fines. Fortunately, establishing a cloud security plan can be easier than you might think. The first step is to recognize potential threats. That is part one will take a closer look at cloud security risks.



Common Cloud Security Risks

1.   Loss of visibility
One of the major advantages of cloud computing is the ability to connect people in various locations through the use of different devices. As the workforce becomes more mobile, employees are accessing company portals and files on smartphones, tablets, and other tools. This can create a complex system that can be hard to monitor. It is easy to lose sight of who is accessing what data. If you don’t know exactly what is happening, you can’t take the necessary steps to protect data and restrict access. The right cloud security plan will take this into account and maximize visibility for relevant parties.

2.   Compliance Issues
Different industries are governed by compliance regulations that are designed to protect both businesses and clients. It is important to continue to test for compliance in order to avoid costly violations and security breaches. You must work closely with your cloud provider to ensure continuous compliance even as new people, resources, and applications are added to your cloud.

3.   Poor Security Strategies
Oftentimes, businesses make the move to the cloud too quickly. There can be a rush to migrate to the cloud and become operational before there has been enough time and energy put into creating strategies that will protect the infrastructure. While it can be tempting to move quickly, taking the time up front to create security strategies can save time and money in the long run.

4.   Contract Breaches
It is important to fully understand how your data will be stored and exactly who will have access. You may have non-disclosure agreements with clients and it is possible to upload information to the cloud that might be in violation of these agreements. This type of breach may be accidental, but it can still come with serious consequences. The first step in avoiding this risk is to make sure that you understand the terms and conditions of your cloud provider.

5.   Insider Threats
Not all security threats involve malicious outside parties trying to gain access to your infrastructure and data. Security risks also exist on the inside of the company. Employees may not intentionally violate security rules, but intention doesn’t change the results of their actions. In most cases, these incidents are the result of poor training. Employees should be well-versed in security best practices and every company should have these clearly documented in order to avoid problems.

6.   Vulnerable API
Programmers use Application Programming Interfaces (API) to create software. External APIs can create vulnerabilities in the cloud and make it easier for cybercriminals to access data. This is a security risk that should not be overlooked or underestimated.

7.   Misconfiguration
As more resources are added to the cloud, there is the potential for services to become misconfigured. Misconfiguration issues commonly occur when companies maintain default security settings and fail to update access controls. As a result, data can become exposed and unauthorized individuals will gain access to restricted areas. You can end up with manipulated and even deleted information.

No matter what size company you have or what industry you are a part of, these common cloud security risks could be putting your business in danger. Remember that the first step to creating a secure cloud environment and meeting compliance regulations is to understand existing risks. This information is vital to any security plan.

In part two of our series on cloud security, we will take a closer look at why cloud security is required and the potential consequences of poor security practices. If you have any additional questions about cloud security or compliance, contact the experts at prancer. We specialize in providing companies with cloud validation frameworks so that you can continuously test and maintain security throughout the DevOps Pipeline.

Tuesday, 26 May 2020

PCI & Cloud Compliance in the Modern Age



Today, many of us rely on the convenience of online shopping to quickly purchase items we couldn’t find in neighborhood stores or to simply avoid having to go to the store altogether. Online payments also make it possible to secure plane tickets, make hotel reservations, and even pay bills. However, the payment landscape that we know now developed over time. The real boom in online shopping can be traced back to the emergence of the internet. From then on, payment card data continued to be used more widely and transmitted on a global level. In response, individual card providers began their own programs to ensure certain levels of protection, but it wasn’t until 2004 that the Payment Card Industry Security Standards Council (PCI SSC) created global standards. Today, the Council is tasked with the additional challenge of creating regulations in the age of cloud computing. At the same time, businesses must comply with and validate these requirements.

This post will take a closer look at current PCI regulations and different ways that businesses are meeting compliance standards.

PCI Data Security Requirements

The PCI has created a total of twelve different compliance requirements that are organized into six groups known as “control objectives”:

Build and Maintain a Secure Network and Systems
Protect Cardholder Data
Maintain a Vulnerability Management Program
Implement Strong Access Control Measures
Regularly Monitor and Test Networks
Maintain an Information Security Policy
While some of the details and sub-categories pertaining to control objectives have changed over time, these core values have been in place since the inception of the PCI SSC.

Validating PCI Compliance

Validation of compliance can be conducted on several different levels according to how many transactions they handle on a yearly basis. More transactions require increased levels of scrutiny and compliance validation.

Level 1 companies that process over 6 million transactions in the course of a year will need to be evaluated by a Qualified Security Assessor (QSA) who is an independent evaluator who has been certified by the PCI SSC. They are responsible for evaluating compliance according to certain criteria.

In addition, all Level 1 companies are required to fill out a Report on Compliance (ROC) when they undergo an audit. This document is used to outline in detail all the policies and strategies that are being used to prevent cardholders from becoming the victims of fraud.

Businesses that fall in the Level 2 category and process between 1 and 6 million transactions will be required to use an Internal Security Assessor (ISA). This individual is a member of the company who has earned a PCI SSC certification. This allows them to conduct self-assessments. They may be asked to work closely with QSAs to ensure compliance.

PCI SSC also requires that all companies fill out a self-assessment questionnaire (SAQ) every year. If the assessment reveals that the company is not fully compliant in certain areas, they must provide a plan for full implementation and show that they are able and willing to address the problem.

Benefits of PCI SSC Compliance and Validation

The goal of PCI SSC is to protect both consumers and merchants. When a consumer is subject to a scam or fraud, the consequences can be far-reaching. Their personal information can be compromised, their credit scores can be affected, and much more. Merchants who experience a breach can face financial liabilities and the loss of consumer trust, which can significantly hurt business. Compliance is a vital aspect of maintaining healthy global markets where both merchants and shoppers can operate confidently.

How to Improve Your PCI SSC Compliance

Prancer is one tool that allows companies with a cloud validation framework that can test for compliance along the entire development and implementation pipeline. This allows for both pre and post-deployment validation so that you can create a strong foundation and continue to test and make changes as needed. Not only does this improve security and compliance, it allows DevOps teams to avoid delays and continue to safely deploy new applications.

If you handle card payments and need help with your PCI SSC compliance strategies, contact prancer today. We can help you improve security, meet global regulations and earn the trust of consumers.

Monday, 18 May 2020

What is Cloud Validation and Why Does it Matter?

Many industries have their own standards when it comes to protecting data. From finance and healthcare to pharmaceuticals, every industry has created certain regulations that are designed to protect consumer data and comply with state and federal laws. When cloud computing was introduced, there was a lot of anxiety around whether this new platform would be able to offer the same security and allow businesses to meet compliance standards. Over time, new security tools and protocols have been introduced that have made cloud-based systems more secure and efficient than ever before. Many of these advances and the current state of cloud computing can be attributed to cloud validation. Keep reading to learn more about cloud validation and why it matters.


The Need for Cloud Validation

Essentially, cloud validation means that you design an environment, test whether it works as intended, and record the results of the test. For industries with evolving compliance standards and regulations, continuous validation will be necessary in order to ensure that the cloud has adapted to new circumstances. Ideally, you will experience consistent results so that you can feel confident that your cloud system is working as designed and can continue to keep pace with changes.

While you could leave the validation and revalidation process up to developers, this approach can create some potential problems. Placing validation in the hands of one individual or a small team of IT professionals can slow down the entire process. You may have to push out changes faster than they are able to manually deploy. In addition, this approach leaves room for security vulnerabilities and human error.

The Basics of Cloud Validation

A better and more efficient method is to create a cloud validation framework where you can automate most aspects of the validation process. This not only speeds up validation and deployment, but it also improves security. When it comes to validation, here are the basic elements that should be in place:

Unit testing: it is important to compliance test individual resources to make sure all the configurations are correct and under compliance

1- Basic functionality testing. The cloud system should be validated to make sure that it is being used as intended. This is especially important and changes are made.

2- Risk mitigation. It is important to be aware of risks that are specific to your industry and those that may have already been identified and outlined by regulatory agencies. Once you have a clear understanding of existing risks, you can validate the cloud against these threats.

3- Effective change controls. A well-designed cloud system will allow you to validate certain areas as they are updated so that you don’t necessarily have to revalidate the entire system. These change controls provide better management tools so that you can ensure continuous compliance even as the system continues to change and evolve.

4- These basic elements play an important role across all industries and should be prioritized during the validation process. Businesses can then continue to customize the validation process as needed.

With the right cloud validation system in place, you don’t have to be afraid of change. You can continue to update and improve your system without worry about causing problems, creating vulnerabilities, or running into compliance issues. Cloud validation is the tool that will allow you to continue to adapt without skipping a beat as regulations evolve. If you would like to learn more about cloud validation and why it matters to your business, contact the team at prancer. We can help answer all your questions and launch your validation project.

Wednesday, 13 May 2020

The Basics of Infrastructure as Code Validation

Infrastructure as code is a powerful tool that has developed in the wake of cloud computing technology. It allows businesses to manage cloud infrastructures and deploy new applications purely through code. There is no longer a need for manual configuration and you can continually update the infrastructure and applications by following the same process of development and deployment. IaC validation plays a key role in this process by allowing you to test against known issues and continue to monitor and test even during production.  



The Importance of IaC Validation

IaC is really only an effective tool worth incorporating into your DevOps process if you are willing to continuously run tests and validate your code. Otherwise, you run serious risks when it comes to application security and function. With IaC, your applications can be continually updated while they are still running and everything is under compliance. This is a major advantage, but it does require a certain degree of monitoring so that you can quickly react as unknown issues arise.

Different Validation Strategies

Typically, IaC uses a declarative language, such as JSON or YAML which is human readable, to define the desired configuration state and environment. This information is then processed through a platform that allows for automation. Terraform is a popular option, but also we have native tools available from cloud providers such as AWS cloud formation, Azure ARM templates and Google cloud deployments. While this approach speeds up the deployment process, any code should be tested with the same diligence as other software projects. Exposing a security hole via IaC is usually more dangerous since we are exposing the infrastructure, not just one application. 

On the most basic level, any IaC file should be reread and compared against pre-established company standards and industry compliance. This may not catch more subtle problems with functionality, but it is an important step in providing consistent code that meets certain quality requirements. IT professionals can manually perform these validations, which take time and could be error prone, or there are automated tools that can help with the task.

Businesses should also test units of files during the provisioning and configuration stages. While IaC involves stringing together units, it is possible to isolate a unit and run it in a test environment for validation purposes. Once individual units have passed testing, it is time to validate the entire system and verify how different units work together to support a specific workflow. This is an important step in confirming that the system meets expectations.

These initial validation and testing steps provide a strong foundation, but a comprehensive approach that looks to harness the power of IaC, identify problems and improve security will include a plan for monitoring. As mentioned before, any changes to the IaC has the potential to trigger new issues. Automated alerts can be put in place to detect abnormalities and streamline the monitoring process.

Of course, there are a variety of other testing options and each approach will be specific to a business and their IaC. Smaller businesses may not have the IT team in place to handle these challenges, which is why third party options can be a good choice. Cloud validation providers can help with IaC validation and security so that you can focus on development.

If you want to learn more about IaC validation, your testing options and how a third party provider may be able to help, contact prancer today. We specialize in helping businesses take advantage of cloud technology and our experts can design a testing and validation strategy that speaks to your specific needs. 

Monday, 4 May 2020

Cloud Validation and Why it Matters

If you have been exploring cloud technology and trying to decide which solutions could benefit your business, you have probably come across the term cloud validation. This is an important part of setting up your cloud network and safely deploying solutions that meet certain standards and requirements that can vary according to industry and each business. In this post, we will take a closer look at cloud validation, what it means and why it matters when it comes to taking advantage of cloud technology.




Definition of Cloud Validation 

Essentially, cloud validation is the process of checking to make sure that your cloud infrastructure not only meets performance goals, but also adheres to any other specifications. Each business should have a clear set of standard operating procedures (SOPs) that are well documented. SOPs will allow you to experience consistent performance even as the company changes and expands. With SOPs in place, you will have a standard by which to measure cloud performance. 

Each industry also has various specifications and requirements that must be taken into account when designing and securing a cloud network. For example, the healthcare industry is required by HIPAA to meet certain standards when it comes to protecting patient privacy. Healthcare providers also have to follow specific rules when it comes to storing and sharing medical records to prevent any data breaches. 

Cloud validation is used to test whether the environment meets all requirements by providing observable results that can be recorded and analyzed. This process will need to be repeated as regulations evolve and the cloud-based system continues to change and grow.  

3 Essential Components of Cloud Validation  

While the exact composition of cloud validation will vary according to each business, there are some essential components that should always be in place:

1. Ensuring that the environment is able to meet its intended use. On the most basic level, validation looks at basic functionality and confirms performance. 

2. Verifying that any potential risks have been minimized as much as possible. Cloud-based systems are more secure than ever before because of advances in security best practices. Any cloud validation should include a close look to make sure that any and all necessary protections are in place.

3. Checking for change control management tools. As your business grows, certain areas of your system will need to periodically go through the validation process again. The initial validation will make sure that there are control tools in place that will allow for growth and simplify the continued validation process. 

Cloud based systems are becoming the standard in business. Now that this technology has the ability to offer more innovations, higher bandwidths and better security, entire industries are making the switch to cloud-based systems. Cloud validation allows you to gain a better understanding of the current state of your system and ensure that it is meeting all requirements that may be handed down by larger governing bodies and individual SOPs.

At Prancer, we provide businesses with both pre and post deployment cloud validation framework so that you can easily enjoy continuous cloud compliance. Contact us today to learn more about our services and how we can help you meet performance and compliance requirements.