Você está na página 1de 10

June1,2011

JustinDrain jdrain@computer.org

June6,2012 RaisingSecurityIQ

<PresenterName>

Disclaimer
Theviewsandopinionsexpressedduringthisconferencearethoseof thespeakersanddonotnecessarilyreflecttheviewsandopinions heldbytheInformationSystemsSecurityAssociation(ISSA),the SiliconValleyISSA,theSanFranciscoISSAortheSanFranciscoBay AreaInfraGardMembersAlliance(IMA). NeitherISSA,InfraGard,nor anyofitschapterswarrantstheaccuracy,timelinessorcompleteness oftheinformationpresented. Nothinginthisconferenceshouldbe construedasprofessionalorlegaladviceorascreatingaprofessional customerorattorneyclientrelationship. Ifprofessional,legal,or otherexpertassistanceisrequired,theservicesofacompetent professionalshouldbesought. TheseviewsandopinionsarealsodonotreflectthoseofFremont Bancorp.
June6,2012 RaisingSecurityIQ

<PresenterName>

June1,2011

Introductions
JustinDrain,CISM,CRISC,CISSP
DataSecurityManager FremontBank

SecurityExperience:banking,aerospace,federal government,medical

June6,2012 RaisingSecurityIQ

<PresenterName>

Agenda
CloudByAnyOtherName CloudUp! Uh,Why?(WhyNot?) UncomfortableDiscovery HandlingtheTruth Recovery WinningtheWarNextTime Recap&TakeAWays
June6,2012 RaisingSecurityIQ

<PresenterName>

June1,2011

Cloud ByAnyOtherName
Buzzwords SaaS (softwareasaservice) PaaS (platformasaservice) IaaS (infrastructureasaservice)

June6,2012 RaisingSecurityIQ

<PresenterName>

Cloud ByAnyOtherName WhoDoesWhat


SaaS providersSalesforce.com,Sage Platform providersGoogleApps,iCloud Infrastructure providerslikeAmazonEC2,

GoGrid Virtualization technologyproviders VMware,Xen

June6,2012 RaisingSecurityIQ

<PresenterName>

June1,2011

CloudServiceModels
PrivateCloud
o CompanyOwnedOrLeased o InSomeCases OnSite

PublicCloud
o LargeScaleInfrastructureforPublicSale

CommunityCloud
o SharedInfrastructureCommunity

HybridCloud
o ComposedOfMultipleClouds
June6,2012 RaisingSecurityIQ

<PresenterName>

CloudAdvantages
WhatDoYouGet?
FinancialCostSavings ImprovedComputingAndNetwork

Performance ScalabilityOfServices/Operations(PayAs YouGo) SimplificationOfITSolutions


June6,2012 RaisingSecurityIQ

<PresenterName>

June1,2011

Toahammer, everything lookslikea nail

DontBe

TheNail
Enable,NotBlock
<PresenterName>

June6,2012 RaisingSecurityIQ

CloudUp! Uh,Why?/WhyNot?
RiskofnotCloudingUp WhyBiggerIsBetter WhyBiggerIsNotAlwaysBetter NotPerformance Risk

June6,2012 RaisingSecurityIQ

<PresenterName>

10

June1,2011

UncomfortableDiscovery (orDude,WheresOurData?)
StopMeIfYouveHeardThisOne
RequestonanidleThursday CousinJoeysoft Staging VendorManagement? UnfamiliarBreachnotice?

June6,2012 RaisingSecurityIQ

<PresenterName>

11

HandlingtheTruth
FiveStagesofIncidentDiscovery
1.Denial 2.Anger 3.Bargaining 4.Depression 5.Acceptance

June6,2012 RaisingSecurityIQ

<PresenterName>

12

June1,2011

VirtualProblems RealAnswers

Acceptance

June1,2011

<PresenterName>

13

Recovery BandAids&Bullets
WhatCan/ShouldBeDone(asidefrom

prayer) Assess Stabilize DoingWhatItTakesToMakeItRight WhoAreYouGoingToCall? Compliancevs.Fauxpliance LegallyDefensible


June6,2012 RaisingSecurityIQ

<PresenterName>

14

June1,2011

WinningTheWarNextTime
WeDontKnowWhatWeDontKnow.

BePrepared(orRemembertheBasics) SecuritySLA VisibilityIntoProviders Systems; SharedReachLiability


3Rs(Reporting,Response,Reading) 3rdPartyAnd4thPartyAgreements Costs

June6,2012 RaisingSecurityIQ

<PresenterName>

15

WinningTheWarNextTime
PlayingThe

FearCard WeArentthe OnesYou Needto Convince


<PresenterName>

June6,2012 RaisingSecurityIQ

16

June1,2011

WinningTheWarNextTime
WheresMyLawyer? RiskAssessmentIn/From/ToTheCloud? IncidentResponse? Encryption,Duh! SecurityBypassed(BeIntheRoom still)

June6,2012 RaisingSecurityIQ

<PresenterName>

17

RecapandTakeaways
BePrepared 3Rs(WhatsYOURPolicy?) DontBetheNail
FearISanOptionSometimes

DontForgetTheBasics

June6,2012 RaisingSecurityIQ

<PresenterName>

18

June1,2011

FinalThought
The state of mind which enables a man to

do work of this kind is akin to that of the religious worshiper or the lover; the daily effort comes from no deliberate intention or program, but straight from the heart.
-Albert Einstein
Physical Society address, 1918
<PresenterName>

June6,2012 RaisingSecurityIQ

19

Thank You! Questions? JustinDrain jdrain@computer.org


Disclaimer Theviewsandopinionsexpressedduringthisconferencearethoseofthespeakersanddonotnecessarilyreflecttheviewsand opinionsheldbytheInformationSystemsSecurityAssociation(ISSA),theSiliconValleyISSA,theSanFranciscoISSAortheSan FranciscoBayAreaInfraGardMembersAlliance(IMA). NeitherISSA,InfraGard,noranyofitschapterswarrantstheaccuracy, timelinessorcompletenessoftheinformationpresented. Nothinginthisconferenceshouldbeconstruedasprofessionalorlegal adviceorascreatingaprofessionalcustomerorattorneyclientrelationship. Ifprofessional,legal,orotherexpertassistanceis required,theservicesofacompetentprofessionalshouldbesought.

June6,2012 RaisingSecurityIQ

<PresenterName>

20

10

Você também pode gostar