אבטחת מחשוב ענן 101: מהם הסיכונים?
Once seen as an addition to the on-premises data storage solutions, the cloud as a technology has changed a lot since 2002 introduction of Amazon Web Services. It’s estimated that the global spend on cloud services will reach $474 in 2022 with cloud revenue to surpass estimate non-cloud revenue for enterprise IT markets in the next few years and 85% of organisations adopting the cloud-first principle by 2025.
This unprecedented usage growth for the cloud technology comes at a price, though. Ability to share and access data from anywhere in the world has enabled global businesses to operate and thrive – especially during the Covid-19 pandemic – but it also brought a swarm of cybersecurity risks and issues with 74% of large US companies experiencing a data breach in the last 12 months.
מהן הסיבות העיקריות לכך וכיצד עסקים יכולים להפוך את עצמם לעמידים יותר בפני כשלי אבטחת ענן?
בואו נבדוק עד כמה מאובטחת טכנולוגיית הענן המסופקת על ידי הספקים.
עד כמה מאובטח הענן?
בקצרה: זה מאובטח מאוד.
Similarly to other cloud providers, Amazon Web Services now offers full compliance and certification aligned with sector-specific standards such PCI-DSS, GDPR, HIPAA, SOC 2, and many others. The cloud providers have also been continuously implementing solutions and tools that avert or mitigate security threats. They also conduct and are subjected to regular and comprehensive maintenance and security audits as they are – unsurprisingly – interested in the longevity and the reliability of the services. Cloud providers such as AWS (Amazon Web Services) and Azure build secure tools and it is now up to us – their regular users – to use them safely.
במאמר זה, אני בוחן את הנושא של סיכוני אבטחת מחשוב ענן. אציג גם עצות מעשיות כיצד להתמודד עם סיכונים אלה משני מומחי הענן שלנו: Tomasz Wojciechowski, ראש אבטחת סייבר שזה עתה מונה ב-Spyrosoft, ושלנו ראש הנדסת הענן, לוקאש מרצ'ינק.
מהם הסיכונים של מחשוב ענן?
כפי שניתן להסיק מהמבוא, רמת הסיכון הגבוהה יותר עבור עסקים המבקשים להשתמש בפתרונות הענן שלהם או לתחזק אותם טמונה במה שמכונה 'גורם אנושי' ולא בחוסר אמינות מצד הספקים – הנתונים מראים כי 95% מכשלי אבטחת הענן נגרמים בשל גורם זה.
כשלים באבטחת מידע
אם בוחנים את הנושא הזה, השאלה החשובה ביותר היא למי יש גישה לנתוני החברה שלך ובאיזו מידה. האקרים מחפשים פגיעויות קלות להשגה והיבט ניהול הגישה מוזנח ברוב החברות.
כאשר יש מספר משתמשים ומספר סביבות ענן לניהול, הבטחה שלא קיימים פערים עלולה להיות קשה, במיוחד עבור ארגונים גדולים המשתמשים בשירותי on-demand עם המערכות והכלים שלהם עצמם. במילים פשוטות: אם הנתונים שלכם אינם מוצפנים, משותפים עם משתמשים רבים בו-זמנית על פני מספר פלטפורמות ענן ואינם מנוטרים, הם אינם מאובטחים.
בעיות תאימות
As stated above, most of cloud providers are compliant and offer certificates for industry-wide data management norms. The services themselves may be secure but it does not mean that you should not worry about internal standard compliance. Make sure that you see compliance as an organisation-wide issue and conduct regular checkups or even use third-party bodies to assess the level of compliance for all your resources, be it internal and external.
היעדר אסטרטגיית ניהול ריבוי עננים
ניהול מספר פתרונות ענן בו-זמנית אינו משימה קלה. אם אתה עובד בארגון גלובלי גדול המשלב Amazon Web Services עם Google Cloud ו-Microsoft Azure בפרויקטים שלו, יש צורך לפתח נוהל כיצד תיגש לשימוש בשילוב מורכב שכזה. במאמר זה דוח Gartner על מעבר לענן, 81% מהחברות הצהירו שהן כבר עובדות עם שני ספקי ענן או יותר.
גישה ל-API ללא אימות
While using Application Programming Interfaces (APIs) for both external suppliers and your employees will help keep data in sync and automate their processes, this can also mean that your business will be more vulnerable to cyber attacks. Implementing a web application security system, adequate authorisation as well as authorisation protocols will ensure that your data is and stays secure.
אין מספיק מומחי אבטחת סייבר
אם אי פעם ניסיתם לגייס מומחה לאבטחת סייבר, ייתכן שאתם מודעים לכך, אך הבה נאמר זאת פעם נוספת: קיים מחסור עולמי באנשי מקצוע בתחום אבטחת הסייבר.
As ISC גילו במחקרם, there are currently 3.12 million unfilled cybersecurity roles worldwide. The sector is poised to be the fastest growing tech sector with employment growth rate of 31% in US only according to the data collected by the US Bureau of Labor Statistics. If your organisation is already struggling with this global issue, invest in internal educational schemes and upskilling your employees to ensure that you have enough resources to protect your company data.
בעיות בשליטה על הפרדת דיירים
According to Tomasz Wojciechowski, the risk of such a breach is low and although it can happen that is not something that occurs very often. It is worth mentioning nevertheless as tenants’ separation control issues can pose a serious threat to medium-sized and large organisations when many users have access to the same cloud-based resource. Failure to maintain separation between multiple tenants can lead to a vulnerability that – in turn – can be easily spotted and exploited by hackers.
כיצד להפחית או למנוע סיכונים אלו?
אז מהן הפעולות שתוכלו לנקוט כדי למתן או למנוע את סיכוני המחשוב בענן הללו? הנה רשימה של שיטות עבודה מומלצות מהמומחים שלנו, Lukasz Marcinek ו-Tomasz Wojciechowski.
הכשירו את הצוות שלכם
שיתוף קבצים לא מוצפן, סיסמאות קלות לפיצוח וחומרה אישית כגון מחשבים ניידים וטלפונים ניידים לצורכי עבודה, כמו גם התקפות פישינג, הם בין הטעויות הנפוצות ביותר שעובדים בארגונים קטנים וגדולים עושים.
כדי להבטיח שהצוותים שלכם לא ייפלו במלכודות אלו, קיימו מפגשי הדרכה שגרתיים ויישמו תזכורות קבועות למשימות שעלולות להיות מסוכנות. ייתכן שיידרשו גם ביקורות עמידה שגרתיות והדרכה על תקני בטיחות ספציפיים לתעשייה.
השתמשו במתווכי אבטחת גישה לענן (CASBs)
This reinstates the previous points mentioned above but it is something that is not highlighted enough in the enterprise world, according to our Head of Cybersecurity, Tomasz Wojciechowski. Cloud Access Security Brokers (CASBs) are security policy tools that are implemented to serve as a layer between cloud service users and cloud service providers. Encryption, tokenisation, malware detection, authentication and logging are all examples of such tools.
ניטור וניהול הנתונים שלך
לדברי ראש מחלקת הנדסת הענן שלנו, Lukasz Marcinek, אם אתם מעניקים גישה למשאבים מבוססי ענן כלשהם לעובדים או לקבלנים שלכם, השתמשו עקרון ההרשאה המינימלית. עקרון ההרשאה המינימלית (PoLP) הוא כאשר משתמש מקבל את רמת הגישה או ההרשאות המינימלית להשלמת משימות העבודה שלו. מה שמכונה 'זחילת הרשאות', שבה רוב המשתמשים או כולם מקבלים הרשאות מלאות וגישה בלתי מוגבלת לכל המשאבים, הוא נוהג גרוע.
פעלו לפי Cloud Adoption Framework
לכל ספק ענן יש מסגרת אימוץ ענן משלו – כולל ... Microsoft ו AWS – וזה יהיה מועיל בתכנון המעבר שלך לענן, באסטרטגיית האבטחה שלך ואפילו במתן שמות למשאבים שלך. התחל בפיתוח מצב האבטחה הסופי הרצוי ופעל משם על ידי מיפוי למושגים ולמסגרות, הקצאת תפקידים – עם מדיניות 'אפס אמון' המוטמעת במפת הדרכים של ההקצאה – והובל את השינוי ברמה העסקית והארגונית.
פיתוח אסטרטגיית ניהול סיכונים
אני מזכיר זאת אחרון, אך פיתוח אסטרטגיית ניהול סיכונים ברת-קיימא אינו משימה קלה, במיוחד במגזרים מפוקחים במידה רבה כגון רכב ובריאות. בהתאם לעסק שלכם וליעדים הארגוניים, ייתכן שתצטרכו להשתמש במספר כלים וטכניקות שונים לניהול סיכונים, כולל הערכת איכות נתוני סיכון ומטריצת הסתברות והשפעהלבנות אסטרטגיה שתוכל לתמוך בחברה שלכם בטווח הארוך.
קראו גם: כיצד אנו ניגשים לניהול סיכונים ב-Spyrosoft
תורך
אם אתם מעוניינים בשירותי הסייבר שלנו או שיש לכם פרויקט שברצונכם לדון בו, אל תהססו לפנות לצוות שלנו דרך אתר אבטחת סייבר או ישירות ב-LinkedIn.


