Organizing Sensitive Data in the Cloud

What does a cloud vendor do to properly segment various types of sensitive data within its cloud? Gregory Machler discusses how to capture the metadata you'll need.

By Gregory Machler
Mon, August 30, 2010

CSO — There's a tremendous buzz today about cloud computing, but before outsourcing your critical business systems to the cloud let's review some security concerns.

The Web is Dead: Long Live the Cloud
Slideshow: Cloud Storage Lives Up to the Hype

The most critical business applications deal with corporate HR, finance, credit card, and other sensitive data. If any of this information is compromised lawsuits may ensue and your corporate brand is tarnished. This is a nightmare that could lead to customers avoiding purchasing your products or services. How can cloud computing effectively protect sensitive data?

See more advice from Gregory Machler in " Deep Theater Defense

There are three areas that need to be addressed to effectively push your applications into the cloud:

  • Create a second layer of firewall protection (defense in depth);
  • Analyzing application documentation to determine new firewall rule changes; and
  • Collection of system and application metadata that enables a smooth transition.

Let's start with defense in depth.

First, put sensitive data in a second tier of firewall segments behind the main corporate firewalls. This second-tier firewall and corresponding network shields sensitive applications and their data from being easily accessed if the Web-facing firewalls are breached. For example, let's look at grocery stores. It would be wise to deploy at least four firewall/network segments: one for HR data, one for financial data, one for credit card PCI (Payment Card Industry) data, and one for services that the other segments share. The segment containing services that are shared could contain common support services such as network and systems management, encryption and PKI functions, access control services, and security event management functions.

Also see "Cloud security in the real world: 4 examples

Another architectural implementation that protects corporations from internal data theft is the creation of a Tunneling Access Protocol. The Tunnel Access Protocol is an access control function that forces all administrators to log information before they perform administration on segment systems. Hence, all administrative access is tracked, discouraging internal theft of information

The second area that needs addressing is the analysis needed to determine successful migration of the application to behind the cloud's second-tier firewalls. I recommend starting with the application design document first. It gives you a big-picture understanding of which business need the application performs, what middleware is used, what databases are used, and what protocols it uses. It also often contains the logical architecture.

It is important to focus on all the systems the application interacts with. Your security team will have a variety of information collected about the application: what data is sensitive, how and what tools are used to encrypt the data, and penetration testing results if it is a Web-facing application. Also, I recommend creating a protocol diagram showing all servers and their IP addresses, the protocols being used, and the protocol (TCP or UDP) ports being used. This network view specifically shows which servers need to talk to each other and what protocols (ports) they will use to do it. It is not necessary to include switches, routers and other network infrastructure components because the protocols/ports just ride over them. If the protocol diagram is thorough, it should be a simple step to create the firewall rules. Firewall rules are made up of source and destination IP (Internet Protocol) addresses, protocol used, and ports that ride on top of those protocols.

Continue Reading

Originally published on www.csoonline.com. Click here to read the original story.
The HP Business Decision Appliance is a solution optimized for Microsoft SQL Server 2008 R2 and Microsoft SharePoint Server 2010 and designed for enterprises that want to provide business intelligence (BI) capabilities in a pre-configured single enclosure.
In today's environment, where organizations rely on accurate and timely data for both strategic and tactical decision making, the need to have reliable business data is critical to gain competitive advantage and maintain efficiency. The HP Business Data Warehouse Appliance optimized for SQL Server 2008 R2 is designed and tuned for data marts and small-scale data warehouses, providing a single view of data across your business.
In this white paper, IDC highlights the latest research about demand for and benefits of integrated data warehousing solutions. Data warehousing solutions such as integrated hardware and software appliance as well as predefined reference configurations are discussed as two key options for deployment. The paper introduces joint HP and Microsoft data warehousing solutions and provides recommendations for large organizations evaluating data warehousing solutions for the purpose of supporting improved decision-making processes
To be responsive to an ever-changing business environment, decision-makers need easy access to information and the tools that allow them to derive new insights on demand. The HP Business Decision Appliance, designed jointly by Microsoft and HP, optimized for SQL Server 2008 and SharePoint Server 2010, supports this objective with a combination of hardware and software tuned specifically for high-performance, simpler manageability, and ease of use. Furthermore, the HP Business Decision Appliance is designed with a rapid setup process that provides these benefits from the first day.
For enterprises requiring an integrated data warehouse solution with the right price-performance ratio, the HP Enterprise Data Warehouse Appliance offers a powerful, reliable solution that scales cost-effectively to meet their data needs. This appliance makes scalable data warehousing available to more organizations by consolidating separate, dedicated database resources on a standards-based infrastructure that is easy to deploy, operate, and expand.
For your IT organization to keep pace with the business, you need a new, faster approach to infrastructure deployment-an approach that increases agility and accelerates time to application value. That's HP Converged Systems. Built on Converged Infrastructure, these systems deliver the industry's first portfolio of pre-integrated, tested, and optimized infrastructure solutions for applications running in virtual, cloud, dedicated, or hybrid environments.
Please join guest speaker IDC Analyst Carl Olofson as he discusses Enterprise Data Center challenges and why database consolidation is important and necessary. And hear from HP expert Joe Sullivan, who will discuss the HP Database Consolidation Appliance and how it addresses enterprise industry challenges. Joe will provide an overview of product architecture and details on how the appliance enables companies to build their own private cloud. This webcast will provide the latest information for simplifying your data management needs while reducing costs.
Fact: The demand to respond faster and with greater insight to business demands, based on data, is increasing. Fact: More organizations are turning to business intelligence (BI) and data warehousing for insightful decision-making.
The first appliance in the industry which consolidates and manages thousands of databases, integrates hardware, software and support and is scalable to meet your changing business needs.
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as support considerations
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and disaster recovery and support considerations.
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere® 5, VMware is helping customers accelerate the deployment of business-critical applications, including Exchange, SQL, SAP and Oracle.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center