Securing the Multi-Cloud: 3 Steps for Maintaining Control and Visibility

3 min read
Curated from csoonline.com →

A hybrid, multi-cloud environment offers the advantages of high resiliency combined with the agility to adapt quickly to changing digital business requirements. In one recent analysis, 86% of surveyed organizations stated that they had already adopted a multi-cloud strategy. Tempering the advantages of such a strategy, however, are a number of related security concerns. For example, if migrating to one cloud environment expands the attack surface, multiple clouds magnify it even further. Organizations need to consider how to scale protection to accommodate issues like growth, as well as how to consistently track and secure workloads that span multiple cloud environments.

Segmentation. When workloads are distributed across multiple clouds, threats can likewise be readily propagated. In traditional networks, IT teams use segmentation as a best practice for containing threats. In a multi-cloud environment, the challenge of containing threats is compounded by the need to consistently segment applications, workflows, and data even as they move across private, IaaS, and SaaS cloud environment.. But as data and applications—and in turn, attack vectors—flow across different cloud environments, the ability to apply segmentation best practices is limited using traditional network segmentation practices. It instead becomes critical to employ consistent tagging and labeling practices that will help in both applying consistent security policies, as well as potentially identifying and responding to threats when and where they occur. Furthermore, the ability to trace those threats back to their origin to assess the scope of damage and to mitigate risk and vulnerabilities as close to the root cause as possible become more realistic when employing consistent asset labeling techniques.

Visibility. Visibility is another of the fundamental concerns in a multi-cloud reality. Securing today’s rapidly changing and high-performance environment requires continually assessing the security of the organization’s IT portfolio in its entirety. While IT teams may have visibility into each cloud network through cloud-specific tools, they usually cannot detect or correlate threats across multiple cloud environments, nor can they immediately assess the impact of a threat to one cloud resource or another. They are also challenged to deploy consistent security functionality and policy enforcement across a variety of often very different ecosystems.

Integration. Part of the challenge is that most multi-cloud environments resemble a mesh network, which makes it hard to reach into every cloud environment simultaneously to detect and respond to threats. Therefore, the need for deep integration across security functions and centralized management increases, as it is virtually impossible to identify many of today’s more sophisticated threats, let alone coordinate an effective response without those capabilities in place. And given the speed of today’s attacks, response time requirements are high, which means organizations also need tools to alleviate the need of spending hours matching and aggregating data from different cloud management portals or comparing signals from different clouds and to understand the attack before deciding on appropriate actions.

The biggest issue organizations face when attempting to secure a multi cloud infrastructure is establishing consistent management and enforcement of security policies. Single pane of glass management systems that control security functions across different cloud environments are needed in order to provide deep visibility, integrated event correlation, centralized policy management, and consistent controls and response.

To achieve this, native integration into cloud platforms is essential.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at csoonline.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.