November is a busy month for the Tech sector, specifically Cyber, with a lot of related topics to celebrate and raise awareness around, such as Black Friday safety and Computer Security Day. But, as usual, CSP has their monthly newsletter full of key advice and discussing important subjects. Kevin Else goes over Zero Trust, and Chris discusses if technical and security governance within large organisations stifle innovation, find out more below.
Who Do You Trust?
Poorly or incorrectly configured devices and services are one of the key vulnerabilities that computer criminals look for, technical vulnerabilities in the code or construction of a device or service. You can have all the security bells and whistles in the world, but if the door (metaphorically) is left open you have wasted your money.
‘But it’s all in the cloud, so it’s their responsibility’, I hear you say. Well no. It’s your data and if you have left access to it open for all, then it’s not your cloud service providers responsibility.
Zero Trust
You need to have a default of no access, then open it up gradually, monitor its use and remove it if it’s not required. This is the “Zero trust” approach, which you may have heard. But zero trust is a lot more than that. It means placing technical controls at every level, so that, in theory, you do not trust any components within your infrastructure and that you are limiting and validating every piece of information at every point within your data flow.
Product or Strategy?
Sounds expensive! Well no. Zero trust is not a product, it’s a strategy. All of your current infrastructure will have access controls of some type. Implement them correctly with just enough access as your starting point. Will it break things? Initially yes, but in the long term it will protect you better and become easier to manage, as you understand the data flows within your organisation.
And that understanding of your network traffic can often lead to improvements in the speed and quality of the data transfers and the interoperability of systems.
Myths and Cliches
One of the other misconceptions is that zero trust only works on in-house environments. This is not just wrong; it goes against the security principles you need to implement within a cloud-based infrastructure, even more than an onsite one. ‘The cloud is just someone else’s computer’ is an old cliché, but it is true. So, why wouldn’t you tightly control who has access to your data, when it is in the cloud? The major cloud providers actively encourage it and provide reporting and management tools to do it.
Does technical and security governance within large organisations stifle innovation?
The continuous development and enhancement of capabilities delivered by Cloud vendors, provides technology delivery teams an easily accessible set of building blocks to exploit, in order to deliver novel business services.
Infrastructure is delivered as code rather than through procurement, shipping, installation and configuration of server hardware, storage and networking components.
Capabilities can also be delivered as a SaaS platform where the features required to meet the business requirement, such as Desktop software, Analytical tools, Finance and CRM functions, to name a few, are packaged and ready for use by users requiring only a light touch management wrap provided by the organisation.
These factors mean that the elapsed time between a business’ needs being identified, and a solution being proposed and instantiated should be relatively short. The paradigm of agile delivery and the ability to implement new functionality and features using a pipeline, building on previous deployments supports a continuous improvement approach. This provides organisations with the capability to iterate and improve functionality over reasonably short “sprints”.
So why do many apparently innovative projects seem slow to deliver benefits?
Organisations quite rightly want to have solutions delivered within a framework that leverages economies of scale and maintains the chosen security posture of the organisation. Total Cost of Ownership can be influenced by several factors:
Product Cost –An organisation may find it cost effective to use a particular product or vendor in quantity rather than a diverse set to provide equivalent functions. In many organisations cost will be the overriding factor.
Skills – By restricting projects to using a defined product set and detailing their specific use cases, using standards and patterns the organisation can be confident that it has the skills to build and support the solution.
Existing fit – The organisation may have invested significant time and money in establishing standards to ensure usability and interoperability of its technology services.
Security standards – Compliance with organisational security policies and standards, is often seen as a barrier and challenge by project teams. Security standards within an organisation should be clearly linked to the threats and vulnerabilities that the standards are designed to address. This information should be easily accessible to the project teams. This will aid understanding and help ensure that the solutions proposed address the concerns.
Conclusion
Governance does not have to stifle innovation, but a novel solution for a particular problem should still address the economic, operability and security requirements of the organisation.
Organisations must manage the potential tension between technical innovation and governance. The governance process must ensure that any constraints it applies set boundaries that address significant business concerns and not worry about minutiae or vested opinions. RISK – REWARD considerations should be the prime factor on which governance decisions are based.
Where Cloud based deliveries are concerned, then the organisation must ensure that, prior to business services being placed, the necessary security and operability services are provided at an organisational level for projects to consume. They must not be left for projects to deliver on a case-by-case basis.
