What firms need to know about securing their cloud migration

By Ricky Ho

Cloud computing in Asia Pacific, especially in Singapore, is growing constantly in importance, and with its growth comes an increasing demand for cloud security. According to research firm IDC, the cloud computing market in Singapore is forecast to grow to about US$1b ($1.4b) by 2017.

Singapore is gearing up to be the world’s first Smart Nation, and cloud computing is expected to be a pivotal part of its infrastructure. The Smart Nation is powered by big data, and the data transmitted within the cloud must be protected with encryption. However big data also brings its own set of complications to cryptography. Whilst encryption is the key to protecting sensitive data, it can also mask the misdeeds of malicious attackers and deny security staff the visibility into the communications to and from the cloud.

Traffic unseen in the cloud
In the ever-changing cloud computing landscape, unmanaged encryption can put organisations at risk. This applies equally to the Smart Nation as well as to enterprises that are moving or have moved to the cloud. Whilst hosted cloud environments are becoming mainstream, the traditional network architectures are still employed, and require support for management and monitoring of third-party encrypted access.

However when faced with such situation, many IT administrators simply let the encrypted traffic flow freely in and out of the network environment. This creates obvious risks as the lack of visibility and limited content control in encrypted channels may enable a covert method for infiltrating the network and/or for exfiltration of sensitive data.

Singaporean utility company requests privileged access monitoring
Like many large organisations, one of the energy and utilities companies in Singapore utilises cloud hosting services to achieve significant efficiency, flexibility, and cost advantages. In 2016 they invited tenders from Cloud Service Providers (CSPs) in Singapore to provide a comprehensive cloud service (with security) offering. Their requirements for security were:
- Monitoring and auditing the privileged user activities in encrypted traffic (in real time)
- Providing a logging mechanism to log all activities for forensic purposes
- Enabling self-service provisioning and management of privileged users

This is not a standalone business case but similar requirements for cloud security service have become common.

Ensure privileged session monitoring in cloud
Traditionally, conventional enterprise privileged access solutions utilised gateways and focussed on interactive users. But this is no longer sufficient – the ongoing migration to the cloud has turned cloud service providers and cloud-using organisations to more advanced security solutions.

If organisations are going to or have already moved to the cloud, advanced privileged session monitoring solutions are definitely needed; and they should be able to:
• Provide logs, centralised management, visibility for all encrypted privileged access
• Filter and proactively detect suspicious traffic
• Monitor privileged sessions (with record and playback functionality)
• Deploy in both public and private cloud environments, without interfering with user and business workflows
• Enable flexible deployment and adaptability to changes in cloud and network environments
• Gain accountability for the shared accounts in the cloud-hosting environment

When organisations use outsourced cloud service, it is highly recommended to select a reliable CSP with a good security track record, i.e. being certified the Multi-Tier Cloud Security Standard by Infocomm Development Authority of Singapore (IDA). More importantly, the CSP needs to be able to deliver secure service offerings and take a variety of stringent measures to their critical access governance so as to ensure the transimitted data is safe and their servers are secure.

Join Singapore Business Review community
Since you're here...

...there are many ways you can work with us to advertise your company and connect to your customers. Our team can help you dight and create an advertising campaign, in print and digital, on this website and in print magazine.

We can also organize a real life or digital event for you and find thought leader speakers as well as industry leaders, who could be your potential partners, to join the event. We also run some awards programmes which give you an opportunity to be recognized for your achievements during the year and you can join this as a participant or a sponsor.

Let us help you drive your business forward with a good partnership!