Select your language

Cloud computing, risk analysis and security "dynamic services"

By now we will all agree that we are facing unique changes in the way we understand the management of ICT infrastructures. The irruption of cloud computing services, and with them the IAAS "Infrastructure as a service", will cause in the coming years a restructuring of great caliber in this type of services, largely as a result of the massive development of virtualization services that allows us to change our virtual machines from CPD or datacenter in the blink of an eye, at least theoretically.

All of this has security implications of colossal proportions. Today's fundamentally "static" security models have to evolve into "dynamic" security models adapted to the needs of cloud services, because this trend has no turning back. It is not that we think if the security of "cloud" services is better or worse, it is about designing security services appropriate to this reality, which like everything has positive aspects and negative aspects.

We won on some things. One of our weak points in security has always been availability and business continuity. In this case, in the cloud, with complicated claims scenarios such as the fall of a datacenter due to a natural disaster, the solution seems within the reach of anyone and RTOs seem acceptable for any type of business. Clearly, there are many things to redesign in cloud security services.

Take the case of Google that had, in 2008, 36 locations for its data centers with virtualized environments that allows them to change these locations in a way, let's say, "agile". One of its objectives is, logically, to minimize the cost of hosting your infrastructure and since we can assume that in a datacenter 50% of the cost is the energy cost of cooling, we will understand that Google infrastructure managers are looking for increasingly better terms of energy efficiency. From what we have read the PUE factor (Power use efficency) reached by Google is impressive: 1.21 on average. This means that every useful watt that reaches a machine that serves its customers needs 1.2 watts of actual consumption. Obviously this can be achieved by making use of datacenters that require little energy use to cool the machines and therefore taking, for example, the systems to cold locations that use ambient air to cool the technical rooms. All this can also be complicated using "follow the moon" type strategies through which we look for night rates of energy consumption and therefore economic rates that, in short, allow to reduce the cost of electricity supply of the machine and directly the cost of the service.

If in this environment we begin to think about security, the first reaction is that of stupefaction. If it is already difficult to achieve an adequate level of security in static environments from the physical point of view, if the logical environment, with virtualization, is a highly changing environment and also the physical one too, the result is directly an insane asylum specialized in the practice of torture, as a therapeutic measure, for security professionals.

- Publicidad -

Obviously, this scenario that comes our way is not compatible with the current security practices of most companies specialized in this type of service. This scenario is crying out for us to adapt policies, procedures, controls, security monitoring and management systems to these environments that change at a devilish speed.

Consider, for example, a traditional risk analysis. In our opinion, traditional risk analyses are already not very useful, especially if they make use of heavy and complex methodologies such as some methodologies that we all know ;-). Go ahead that they are very valuable methodologies and that they make up a good theoretical starting point, but that in my opinion cannot be used in a practical way without the relevant nuances. Why? Basically because we face ever-changing environments. When these types of methodologies were designed, they were made thinking about manageable infrastructures, with calm evolutions, and in which reviewing the risk analysis periodically once a year could be enough. These are not the starting hypotheses that we face today and therefore these methodologies do not work when we apply them as they were designed.

We face changing environments from the logical point of view, with continuous variations that have very clear impacts on the security strategy and as if that were not enough, by virtue of what was discussed in the introduction of this entry, we also face changing physical environments. In these circumstances the threats are variable, their probabilities also and therefore the risks too. In short, within the framework of dynamic security services to which we have referred, we will have to design agile methodologies for risk analysis in real time.

We will have to work hard to define a global framework of dynamic security products and services in this new environment, and much has to be said by regular readers of this blog in this matter... spend in any case, whether passed by water or not, a good weekend.

Author: José Rosell
Source: Security ArtWork

Authors: Computer Security News

See original.

No comments

• If you're already registered, please log in first. Your email will not be published.

Comments are closed

The comments for this content are closed.

Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter