{"id":13065,"date":"2016-11-16T14:06:55","date_gmt":"2016-11-16T14:06:55","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/?p=13065"},"modified":"2016-11-16T14:06:55","modified_gmt":"2016-11-16T14:06:55","slug":"securing-the-hybrid-cloud-what-skills-do-you-need","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2016\/11\/16\/securing-the-hybrid-cloud-what-skills-do-you-need\/","title":{"rendered":"Securing the hybrid cloud: What skills do you need?"},"content":{"rendered":"<p class=\"p1\"><span class=\"s1\">Hybrid cloud models offer many well-documented benefits, but they also introduce more complexity for securing data and applications across the enterprise. And this added complexity requires an increasingly diverse skill set for security teams. That\u2019s a challenge, considering the growing cybersecurity skills shortage. In one\u00a0<a href=\"http:\/\/media.ne.cision.com\/l\/vzfltmgu\/www.networkworld.com\/article\/3045801\/security\/cybersecurity-skills-shortage-impact-on-cloud-computing.html\"><span class=\"s2\">recent study<\/span><\/a>, 46% of organisations said they have a \u201cproblematic shortage\u201d of cybersecurity skills \u2013 up from 28% just a year ago. One-third of those respondents said their biggest gap was with cloud security specialists, writes\u00a0<em>Raj Samani, chief technology officer, EMEA, Intel Security Group.<\/em><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Modern security teams require a broad and deep mix of technology skills, ranging from twists on traditional network and OS technology all the way to security on data itself, to address a rapidly evolving threat landscape. But they also need \u201csofter\u201d expertise, such as knowledge of compliance regulations and vendor-management skills. Driving this dual focus is the public cloud\u2019s \u201cshared responsibility model,\u201d in which service providers and enterprises divvy up various levels of protection across the IT stack. These responsibilities \u2013 and the requisite skills \u2013 vary depending on the type of public cloud service.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\"><b>Security skills<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Certain skills are required across all uses of public cloud. For example, you\u2019ll need in-house expertise with encryption and data loss prevention controls for content-rich cloud applications. Your IT teams need to know (and track) where your enterprise data resides in the cloud, what offerings your cloud service providers offer for data protection, and most importantly, how to integrate data protection policies in the cloud with your own company policies. On a similar note, your team will need sophisticated identity and access management (IAM) and multi-factor authentication, including tokenisation, regardless of whether you\u2019re deploying SaaS, PaaS, IaaS, or a combination of those services.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">For SaaS, your security teams needs to be familiar with the various applications in use and how to\u00a0<a href=\"http:\/\/media.ne.cision.com\/l\/vzfltmgu\/www.intel.com\/content\/www\/us\/en\/it-management\/intel-it-best-practices\/saas-security-best-practices-minimizing-risk-in-the-cloud-paper.html\"><span class=\"s2\">use logging and monitoring tools<\/span><\/a>\u00a0to detect security violations and alert appropriate IT staff. Post-incident analysis is a critically important skill for mitigating active threats and improving your security posture for future threats.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">For PaaS deployments, you will also need to add skills to ensure that native cloud applications are being developed with security built in at the API level. Adoption of open security APIs can help to bridge the gaps among proprietary cloud environments.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">For IaaS environments, the ability to provision software-defined infrastructure carries the need for highly technical security professionals who can create policies for server, storage, and network security on AWS or other platforms. These skills include the ability to monitor usage of compute, storage, networking, and database services, as well as the ability to manage security incidents identified in the cloud platform you\u2019re using.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\"><b>Audit and compliance skills<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Many of the softer skills needed for cloud success stem from the need for organisations to gain more visibility into hybrid environments that are becoming more complex as SaaS, PaaS, and IaaS services are cobbled together with each other and private clouds.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Audit rights can be built into a service level agreement (SLA) as a way to make sure the provider complies with corporate security policies and industry or government regulations. This is one reason why the ability to develop comprehensive SLAs with service providers is an increasingly important skill. IT and security teams will need to work together to negotiate terms that provide maximum protection and visibility into third-party services, to ensure that data, applications, and other components of your cloud environment are secure and compliant.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">In addition to formal audits, security professionals require skills (and tools) for continuously monitoring compliance and threats across SaaS, PaaS, and IaaS deployments in two key areas: threats and applications. Starting with threats, achieving (or maintaining) visibility to specific threats across these environments so your organisation has a full view of attacks is critical. That visibility needs to extend across endpoint, infrastructure, and network elements in order to recognise and respond to coordinated, multi-angle attacks.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Second, application security experience with<a href=\"http:\/\/media.ne.cision.com\/l\/vzfltmgu\/www.gartner.com\/it-glossary\/cloud-access-security-brokers-casbs\"><span class=\"s2\">\u00a0cloud access security brokers\u00a0<\/span><\/a>(CASBs) will help security professionals increase the visibility into user behaviour and their needs across public cloud service providers.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">That said, we see convergence between the need for application visibility, threat visibility, and data security for SaaS applications, so look for skills that bridge those three areas as you build an organisation for the future. The same need for a blended skill set will increasingly be true as threat and application needs converge.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Organisations in highly regulated industries also need to devote resources to tracking how third-party providers handle data and applications to ensure compliance with industry-specific regulations. The same goes for global players: Requirements around data storage can vary dramatically by country, requiring in-depth knowledge of local regulations regarding where data resides and how it is transmitted for any geography in which you do business.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\"><b>Skills for hybrid: the new private cloud<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Security practices for a private cloud deployment \u2013 which enables enterprises to keep data and applications under their control \u2013 would seem to be more traditional than public deployments. But the virtualisation technology that is inherent in the private cloud model creates a need for new security skills beyond those for traditional on-premise environments.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">The first is understanding the difference in the infrastructure itself, for example between a traditional virtual machine and a framework like OpenStack. Second, as organisations explore software defined networking (SDN), they see a need for more automation skills, as security policy must co-exist with the orchestration to fully exploit an SDN environment. Third, the security operations centre will need more network insight as the east-west traffic becomes more material to threat analysis.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">These skills become especially important as virtualisation expands beyond servers and into networks and storage.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">That said, most private clouds are truly hybrid clouds \u2013 and these will be the default moving forward. Hybrid clouds demand cross-domain threat visibility, along with the skills across the various cloud types to prioritise and respond to them. This requires both a broader level of technical depth but also more cross-team facilitation and leadership to analyse and respond to critical threats. Revisiting the soft skills points made earlier, this also includes leadership not just within the organisation but across the set of SaaS providers relevant to a given situation.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\"><b>The bottom line on cloud skills<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">The takeaway for security leaders: It\u2019s time to optimise the skills of your team to the different types of cloud. Public cloud security \u2013 spanning SaaS, PaaS, and IaaS environments \u2013 is (a) more about policy, audit, analysis, and teamwork skills rather than pure technical depth, and (b) will include more cross-domain skills than are required in the more silo\u2019d on-premise structure. Creating the proper mix of skill-sets for all of these scenarios will help build your confidence as you build out your hybrid cloud model.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hybrid cloud models offer many well-documented benefits, but they also introduce more complexity for securing data and applications across the enterprise. And this added complexity requires an increasingly diverse skill set for security teams. That\u2019s a challenge, considering the growing cybersecurity skills shortage. In one\u00a0recent study, 46% of organisations said they have a \u201cproblematic shortage\u201d [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":13066,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6],"tags":[22,461,1350,10,50],"class_list":["post-13065","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","tag-cloud","tag-hybrid-cloud","tag-intel-security","tag-security-2","tag-virtualisation"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/13065","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=13065"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/13065\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/13066"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=13065"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=13065"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=13065"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}