Hybrid Infrastructure security from the ground
Transcript
hello cloud people hello tech people thank you for joining me today I am so excited to talk to you about one of my absolute favorite topics in check security it is the topic that does not get the love but it's deserved but that's okay because it's gonna get some love for me today so my session let's get start it with my session the hybrid infrastructure security from the ground ok let's go I am Becky Elliot I am a consultant and writer I worked for myself you
can follow me on twitter at Becky L Elliot you can check out my website at Becky Elliot comm I am a member of some really awesome tech groups with people far more awesome than me and I also have my CISSP ok so let's get to security challenges we live in a world where pretty much everything is online right refrigerators microwaves light bulbs applications are moving to the cloud SAS hybrid cloud multi-cloud you name it it's on my right and at the same time this idea of
a clear and delineated perimeter is dissolving right it used to be that if you were internal you were trusted if you were external you weren't right and now there really is no internal it's all sort of meshed together and then in addition we're kind of getting to this point where who are like what can you trust you have light bulbs and other IOT devices participating in denial of service attacks right and then at the same time you have the real threat of insider threats you have
the bradley manning's the Edward Snowden's and then you even have the unsuspecting users who click on email attachments so they shouldn't write it has never been easier to be compromised like we live in a world where a breach happens right so Equifax had their public facing web server that was for complaint right it was a complaint database threat actors were able to use a vulnerability to ultimately gain access to their internal network and they were able to uncover 141 records sensitive data right and then you
have target where you have the HVAC system and the threat actor was able to basically use the access that they gained to that to reach the payment systems and install malware right and with that 41 million records were compromised and so we have major compromises from the exploit of unrelated workloads right so this really is a world where maybe too much trust was given kind of concept like zero trust save the day let's like out zero trust is never trust always verify right this is a
lot different than me always trust but verify no longer can you assume that because someone is on your and again not just someone like some device some application because it's located on premises that it's trustworthy right this really is a world where everything has to be verified and authenticate it and they all trust you've probably heard this word and it's more than a buzzword it is a decade old it may not be kubernetes hot but you know what maybe it's the year of zero trust especially
when you have all of these remote workers getting online okay and so let's talk about the principles of zero trust it is secure not that I get access right it is lease privilege and that is the minimum that any service application workload device needs right nothing else and inspecting and logging traffic and that is a real challenge unless you're using machine learning or anything like that because inspecting and logging traffic and take up a lot of storage space and unless you're able to really inspect it
it is just a lot of storage so both Google and Gartner have there flavors of zero trust beyond core and lean trust and Google actually has been working on the encore for seven plus years and so they've done a lot of work with bringing zero trust to JCP okay so what does zero trust look like when you see it in action right it's fleas privilege again that's pretty self-explanatory and then it's also whitelist and that is were you explicitly define the connections or the applications or
you explicitly define what is allowed access everything else is tonight it's pretty much an implicit deny and that's kind of the opposite of a blacklist where you define what isn't allowed and it's also it sanity management right MFA for the win it's security automation right the the same tools its micro segmentation and that is really sort of getting like workloads and applications into little buckets and so my first segmentation is actually really good at helping prevent those lateral movement attacks or helping contain the spread so
if so it compromises your HVAC system they don't automatically get into your payment system and then there's also user and entity behavior analytics and that is where it has intelligence to know that hey if a user logs in in San Francisco three hours later that same user cannot be in China right that login request has defied the laws of physics right that's just not possible and it's just kind of getting some intelligence and to really behave your analytics and this is really important for preventing those
insider threats so let's talk about the zero trust it's not it is not a magical way to prevent breaches will it help yes but it's it's not it's not magic right and it's not a replacement for sloppy a cyber hygiene so I go back see we're already having problems with patching and vulnerability management zero trust would not have saved them right and it's not a single product or solution it's also not easy but it will actually support your compliance and help you minimize the scope of
soft and PCI so an important change the Forrester is made recently as the they have updated this model to sort of put data at the center right it's really easy when you work in apps to kind of get a caught up in this idea that it's the servers that you're protecting right it's like oh no the server was compromised but really those threat actors they're not after your servers they're after the data right they're after they're after your data okay and so as I mentioned this
is this foresters new 0hs extended framework and really you can see that this has been updated to have data at the centre and then it has the pillars of workloads right networks devices people and then visibility and analytics and automation orchestration and this is just really key for you being able to manage the explosion of data and the complexity in today's environment right you are not able to do these things without visible and analytics or automation and orchestration okay and as you can see zero Trust
is on the rise okay so let's talk about some of the implementation challenges zero trust like any kind of change that you're gonna make it requires organizational buy-in like it's hard work like it's a significant amount of effort and you're not going to do it unless there is tsiyon right the other thing is that there are people who say that zero Trust is very challenging for organizations that have technical debt and that is pretty much everyone most organizations are not like zoom where they take a
three-month pause on features so that they can pay down the privacy and security technical debt that they have and honestly the only reason that they're probably doing that is because it needs media but that does not happen in the real world like technical debt is a fact of life can I do right okay and so this is zero Trust is a journey it's not a destination right it's kind of analogous to if you Marie Kondo your entire house you were not too cluttered for life you
need to continue to stay on top of it also if you Marie Kondo your closet you still are better off than if you have it Marie Kondo to anything okay so they are trust is part of your defense in depth strategy and what that means is breach is inevitable right compromises will happen and so you don't rely on only one strategy for for prevention right you build up a wold defense of multiple strategies okay so what are some tips get clear with your why and your
house do trust will support the business goals and that's like really important whatever you do anything hard like why are you doing it and so it's possible that's a reason that you are embarking on zero trust is because it makes PCI compliance a lot easier and it allows you to narrow the scope right and that ultimately saves the business money number two start small and make gradual changes zero trust is not something that you can do all at once but you can start with your meeting
build applications or you can smart start with your small minor applications and kind of work up to it and kind of see how things go ah so and this kind of goes back to foresters updated model it's really important that you know your environment and make sure it's documented automation helps and fortunately it's a lot easier to do this than it was ten years ago the tools are there and last sassy and secure access surface edge I feel like I need to mention this just for
this being a zero trusting session and it is pretty much name to the future of network security and cloud right and it basically is delivered as a service it's real time it is converged with Casspi zero trust firewalls in this service and it is something to watch and so if you want to I got worried about sassy it is check out Tom's howling works presentation call to action let's continue this conversation I would love to talk with you on Twitter or you can connect with me
on LinkedIn and if you would like to see these slides or get additional resources like an open-source tool that you can run a zero trust check on scan the QR code below thank you [Music]