Jo Peterson

Keith and Jo Peterson of Clarify360 follow up on her speaking engagement from the CTOAdvisor Virtual event. Here they talk about the importance of Cloud Security and the need for constant safeguards in this ever-changing environment. The CTO Advisor Jo Peterson Play Episode Pause Episode 1x 00:00 / Subscribe Share Apple Podcasts Spotify RSS Feed Share Link Embed <blockquote class="wp-embedded-content" data-secret="nKh7ULY4GF"><a href="http://thectoadvisor.com/jo-peterson/">Jo Peterson</a></blockquote><iframe sandbox="allow-scripts" security="restricted" src="http://thectoadvisor.com/jo-peterson/embed/#?secret=nKh7ULY4GF" width="500" height="350" title="&#8220;Jo Peterson&#8221; &#8212; The CTO Advisor" data-secret="nKh7ULY4GF" frameborder="0" marginwidth="0" marginheight="0" scrolling="no" class="wp-embedded-content"></iframe><script> /*! This file is auto-generated */ !function(d,l){"use strict";l.querySelector&&d.addEventListener&&"undefined"!=typeof URL&&(d.wp=d.wp||{},d.wp.receiveEmbedMessage||(d.wp.receiveEmbedMessage=function(e){var t=e.data;if((t||t.secret||t.message||t.value)&&!/[^a-zA-Z0-9]/.test(t.secret)){for(var s,r,n,a=l.querySelectorAll('iframe[data-secret="'+t.secret+'"]'),o=l.querySelectorAll('blockquote[data-secret="'+t.secret+'"]'),c=new RegExp("^https?:$","i"),i=0;i<o.length;i++)o.style.display="none";for(i=0;i<a.length;i++)s=a,e.source===s.contentWindow&&(s.removeAttribute("style"),"height"===t.message?(1e3<(r=parseInt(t.value,10))?r=1e3:~~r<200&&(r=200),s

Transcript 2,712 words · about 18 min to read

Machine-generated from the episode audio and not hand-corrected, so names and technical terms may be imperfect. The audio is authoritative.

Hey, it's Keith Townsend, Principal of the CTO Advisor, and we're continuing the series in which we have all of our speakers, or as many as we can, from the CTO Advisor virtual conference that happened in April 2020. We're following up with all of the speakers. Today I have Jo Peterson, VP of Cloud Security at Clarify360, and one of my fellow analysts on a couple of councils. Jo, how's it going? It's going great. Thank you so much for having me visit with you.

You know, it feels like we just talked. We were on earlier today a couple of different briefings, and the timing is pretty good. You're talking about cloud security. You're a cloud security expert, and as the industry begins or continues to shift, I think a good question that we can put forth is, like, what's the current definition of cloud security? It seems to be a moving target. It is, and, you know, I hope we dig into this a little bit because it's really changed over the last year or two due to circumstances, but in very broad terms, cloud security is the practice of protecting cloud-based data, applications, and infrastructure from cyber attacks and cyber threats.

So it's really a subset of cybersecurity. Where it gets a little tricky and how cloud security differs from traditional cybersecurity is the fact that administrators must secure assets that reside within a third-party service provider's infrastructure, and the reason I say it gets tricky is that each of the hyperscalers has a bit of a different rule about which party is responsible for securing specific assets on their platforms, right? So flavor of cloud matters, and to make it more complex, you know, it's that flavor thing.

It can be a lot for somebody to get their arms around and understand. Yeah, I know AWS has this concept of shared responsibility, and there's a matrix on what AWS is responsible for and what customers are responsible for. So what you're telling me is that across all the cloud providers, including SaaS providers, that differs? Oh, yeah. Oh, yeah. It differs not only within the flavor of cloud that we're looking at, whether it's infrastructure as a service, software as a service, or platform as a service, but within the providers, it differs as well.

So you hinted to it earlier in your comment that it's changed specifically over the past year and a half since the onset of the pandemic. How so? Well, as we enter the second year of the pandemic, I think that what we believe would be temporary has become permanent. I mean, think about pre-pandemic for a minute. We followed the 80-20 rule for the most part in most companies, meaning 80% of the people were in the office and 20% of them were on the road, right?

That varied by industry, but that was sort of the norm. So everybody was sort of following the old moat and castle kind of concept of cybersecurity. We're borderless now. For example, every home office space has now become a shared office space, and in this highly distributed enterprise footprint, the little old home office router and broadband connection is now the weakest link. So that's what sort of happened. The other side of it is kind of look at retail. I buy everything online now, and I don't know about you, but pretty much everything, I got in that habit during the pandemic.

I mean, it was pretty online-centric before, and I'm like any other consumer. 4% year-over-year in 2020, and they're up 39% as of Q1 2021. Oh, that's like an all-year-over-year number growth. Right? Big, big numbers. When you think about that, they're ginormous numbers. So consumers want to be confident that organizations that have their data are doing things like data destruction or have erasure protocols in place to protect their privacy when they no longer wish to transact with that organization. So data ownership has permanently changed, and the way we see a change in enforceable government regulations to protect that consumer information and guarantee privacy is also going to evolve.

So as we talk about that shifting landscape, and many of the work-from-home platforms are SaaS-based, like my number one platform is one of the shared office solutions. Where does the main responsibility lie in protecting that data? Is it with the provider or the customer? We talked about that shared responsibility model with AWS, but where is the burden? Yeah. It's a great question, Keith. So contrary to what many people think, the main responsibility for protecting corporate data in the cloud does not lie with the service provider.

It lies with the customer. If you think about that, 76% of organizations are using two or more clouds. So one of the biggest asks I hear from customers is visibility. Cybersecurity professionals would find it very helpful to have a single cloud security platform offering a dashboard for configuration, for policies, to protect data consistently and comprehensively across all cloud. And so cloud is this kind of mission-critical part of the digital landscape. And the cloud's there, but some of the tooling, we're getting there, but some of the tooling and even the training, it's just, it's tough to keep up with.

Yeah, just the number of like just open S3 buckets, you know, AWS can provide encryption and key management and all these technologies, but simply protecting the data by putting the right assets controls on it remains the responsibility of the customer. So with that, according to the Cloud Security Alliance, the number one concern regarding cloud security is data breach. And with the customer being responsible for protecting their data, tell us two or three things that come to mind that organizations can do today to protect their data.

Well, that's a great question. So security and DevOps teams need to know exactly what the responsibilities are when they're developing and hosting applications built on top of cloud infrastructure. So I tell people, look, understand your data and security and not only developers, but the data owners and the security functions, you know, the functional units need to understand the types of data they're collecting and the requirements for its storage. You and I've talked about this before. One example is if you're collecting data from other parts of the world, there's different rules, right?

So all UK users data must stay in the UK health data in in Australia must be stored in data centers in Australia, China, Germany, Turkey. They all have enacted must stay regulations for data. So it becomes very complicated for somebody who is running an organization with an international footprint to sort of figure out what has to stay, what has to go, what kind of medium can it be on. Right. So and then, you know, as we get down into the data, if we if we do simple things like we apply data centric security on each field, the cloud provider has has some level of access to your data.

So, you know, encrypting data in transit before it ever gets to the cloud provider matters. Applying per field formatting matters. There's things that you can do that are going to make it tougher to just sort of mess with the data that's there. You know, you're talking about good data hygiene. I like to draw this picture that I call my data infrastructure picture. And regardless of, you know, if you're talking about SAS, IaaS, PaaS, on premises data, you have to understand the profile of the data and its value to the organization and compliance around the data.

I, I do mainly video content. If that raw video content gets out into the wild, there's not too much out there unless, you know, there's a embarrassing expert expert excerpt where in which, you know, I call you Joe Patterson instead of Joe Peterson or something like that. Not very serious, but if there's NDA material in a briefing that I let go, I need to really make sure that I protect that data. That's a good example. So both of, both of us are consultants and analysts, and we like to work from frameworks and security frameworks or security architecture as it relates to a cloud.

Is that different or can you point us to resources that kind of puts this into a framework for us? Sure. So, so great questions. Let me first take a minute and step back in case folks aren't familiar with it and talk about what a cloud security framework does. It acts as an outline for necessary policies and tools and configurations and the rules needed to manage the security of a cloud platform. And it references security standards and organizational guidelines for detecting and responding to network threats.

And there are numerous good frameworks out there, including some of, some of the ones by the hyperscalers. I mean, if you look at the five pillars that AWS puts out, it's, it's great framework. They've done a lot of research and it's very thoughtful. If you were, you know, looking for something more general, look at some of the NIST frameworks that are out there. If you were, you know, if you're in a healthcare vertical and need some context around healthcare specific things, look at high trust common security framework.

If you know you are, if you're familiar with the cloud security Alliance, they've got some, they've got a cloud controls matrix, which is great. If you're dealing with government clients, look at the FedRAMP, you know, configurations. There's lots of great tools out there that are going to be conversation starters for you. And that's what I think they are. conversation starters because each organization is, it's a little bit like a snowflake, right? So Yeah, I love your point about frameworks being conversation starters.

If you don't know where to start, you know, you're at a, at a starting point for creating a cloud security policy, or even a security, a data security posture, or program NIST and AWS five pillars are all great places to start. But again, we talked to a wide variety of folks. We've talked to people who are at the beginning of their journey. And then we talk about people who are a mature journey, mature in their journey. So if you're maturing your cloud journey, or even if you're working on multi cloud, talk to us about the concept of cloud security posture management and why it matters.

So that's a great question, because it's becoming more of a thing. Cloud security posture management, you're going to see it referred to as CSPM scours cloud environments and alert staff to configuration vulnerabilities in the software and compliance risk. And a lot of that stems from human error. So think back years ago, we just have log files, right? And they would give the junior engineer of the log file that was their slog work to do to find anomalies, right? Way before we had alerting and way before we could have some of this automation.

So some of the same things, you know, even though cloud is, has been around since 2007, and getting more and more widely adopted, we're missing some of these tools that sort of help us figure out what's wrong. And this is, you know, this is one way to figure out if you're on target. Cloud native applications require different rules and techniques. As applications grow, they become more dynamic and more complex, and the security around them becomes more complicated. So if you combine cloud workload protection with emerging cloud security posture management, you're going to get ahead of the curve instead of being in this position where you're just trying to catch up and breathe.

All right, so this wouldn't be a technology podcast unless we talked about tools. We love our tools at Enterprise IT, and we'd like to reference Gartner, their 2021 hype cycle for cloud security points to cloud native application protection platforms, CNAP. I'm going to just say, I don't know, I don't know if it's CNAPP or if it's CNAP, but it's CNAPP. Security Services Edge, SSE, we're seeing that a lot in the VMworlds and Citrix of the world. Enterprise Digital Asset Management, or DEDRM.

And then Cloud Infrastructure Entitlement Management, CIEM tools. Can you select one of those tools mentioned and give us your thoughts? Oh, yeah. Well, actually, I want to add one because it's white hot right now. I want to add ZTNA or Zero Trust Network Access. I know that one well. Right. I know you've heard of it. So Zero Trust has become this sort of marketing buzzword. But if we strip away the marketing fluff, ZTNA is really tangible, new and different.

And in case you're not familiar with it, ZTNA, part of the whole Zero Trust umbrella, but just the front end, right, is this IT security solution that provides secure remote access to an organization's applications, data and services based on clearly defined access control policies. So originally, folks were using this as a VPN replacement. Yeah. Unlike a VPN, right? I mean, so unlike a VPN, which focuses exclusively on the network, ZTNA goes up a layer. So you're effectively providing application security that's independent of the network.

And because ZTNA focuses on application access, it doesn't really matter what network the user's on. It simply delivers automatic secure connections to applications no matter where that user is. And it verifies the user and device posture for every application session, even when users are in the office. So you're reducing the attack surface by hiding business critical apps, and it's not a multi-step process, which VPN can be connecting securely, sort of seamless. So I think this is going to matter more and more as more and more applications become SaaS based.

So I'm going to give you the last word. What one thing to process framework will stand out in the next 12 months? I think we're going to see more cloud security posture management, right? I think that's what we're going to see more of, because as organizations are maturing, they're looking for a few specific things. They're looking for 100% cloud estate coverage, and they want tools that leverage cloud configuration and workload data to build this fully contextualized asset inventory and perform this holistic security assessment of the entire footprint.

I think they're looking for multiple tools in one platform, so they're looking for the single platform that is able to deploy multiple tools such as cloud vulnerability management, workload protection, security posture management, and they're looking for noise reduction. What I mean by that is they want a tool that prioritizes the first or the top 1% of alerts that matter. They don't want to be over-alerted. So, Joe, people are always commenting on your clever connections of cat videos to security certification training. If people want to follow these genius, I love them.

You know, I've stopped even reading the security advice. Shame on me. I just enjoy the cat videos. You know, it's perfect internet. If people want to follow you, what's the best way to do that? Well, first of all, you know, the internet was built for cat videos. I mean, just so we can all be clear, right? All right. But thank you for my Twitter handle is at DigitalCloudGal, and, of course, I'm Joe Peterson on LinkedIn. All right, Joe, thanks again for appearing on CTO Advisor content.

It is always a great conversation. I think the last time you were on, we were on with our good friend, Tim Crawford, and we, and Bobby Allen, and we talked workload repatriation. I think I'll reference that video in the notes of this podcast. com. You can DM me if you have questions for Joe, and for some reason you can't reach her, at CTO Advisor on Twitter. Talk to you next CTO Advisor podcast.