Fines for tampering with electricity meter range between SR5000 and SR100000 New amendments made in Electricity Law    Saudi Arabia deports 8,051 illegal residents in a week    Saudi Arabia is among world's top donors with assistance worth SR528 billion    GCC – Japan negotiations make progress in sealing free trade agreement    Inzaghi hails Al Hilal's fearless Club World Cup run    UNRWA calls for urgent fuel delivery to Gaza to prevent shutdown of basic services    Syria rules out foreign borrowing as central bank hails post-Assad recovery    Pakistan army kills 30 militants in cross-border clash near Afghanistan    State of emergency declared in Crete after wildfire devastates Ierapetra    OPEC+ further accelerates oil output hike by 548,000 bpd in August    Football world mourns Diogo Jota and brother André Silva at funeral in Portugal    Al Hilal exit Club World Cup after narrow defeat to Fluminense    Saudi Arabia tops global ICT Development Index for 2025    Hotel occupancy in Saudi Arabia rises to 63% as tourism workforce tops 983,000 in Q1 2025    Alkhorayef Commercial Company partners with XSQUARE Technologies to elevate logistics automation in Saudi Arabia    Portugal and Liverpool FC winger Diogo Jota dies in car accident in Spain    Michael Madsen, actor of 'Kill Bill' and 'Reservoir Dogs' fame, dead at 67    BTS are back: K-pop band confirm new album and tour    Michelin Guide launches in Saudi Arabia with phased rollout in 2025    'How fragile we are': Roskilde Festival tragedy remembered 25 years on    Sholay: Bollywood epic roars back to big screen after 50 years with new ending    Ministry launches online booking for slaughterhouses on eve of Eid Al-Adha    Shah Rukh Khan makes Met Gala debut in Sabyasachi    Pakistani star's Bollywood return excites fans and riles far right    Exotic Taif Roses Simulation Performed at Taif Rose Festival    Asian shares mixed Tuesday    Weather Forecast for Tuesday    Saudi Tourism Authority Participates in Arabian Travel Market Exhibition in Dubai    Minister of Industry Announces 50 Investment Opportunities Worth over SAR 96 Billion in Machinery, Equipment Sector    HRH Crown Prince Offers Condolences to Crown Prince of Kuwait on Death of Sheikh Fawaz Salman Abdullah Al-Ali Al-Malek Al-Sabah    HRH Crown Prince Congratulates Santiago Peña on Winning Presidential Election in Paraguay    SDAIA Launches 1st Phase of 'Elevate Program' to Train 1,000 Women on Data, AI    41 Saudi Citizens and 171 Others from Brotherly and Friendly Countries Arrive in Saudi Arabia from Sudan    Saudi Arabia Hosts 1st Meeting of Arab Authorities Controlling Medicines    General Directorate of Narcotics Control Foils Attempt to Smuggle over 5 Million Amphetamine Pills    NAVI Javelins Crowned as Champions of Women's Counter-Strike: Global Offensive (CS:GO) Competitions    Saudi Karate Team Wins Four Medals in World Youth League Championship    Third Edition of FIFA Forward Program Kicks off in Riyadh    Evacuated from Sudan, 187 Nationals from Several Countries Arrive in Jeddah    SPA Documents Thajjud Prayer at Prophet's Mosque in Madinah    SFDA Recommends to Test Blood Sugar at Home Two or Three Hours after Meals    SFDA Offers Various Recommendations for Safe Food Frying    SFDA Provides Five Tips for Using Home Blood Pressure Monitor    SFDA: Instant Soup Contains Large Amounts of Salt    Mawani: New shipping service to connect Jubail Commercial Port to 11 global ports    Custodian of the Two Holy Mosques Delivers Speech to Pilgrims, Citizens, Residents and Muslims around the World    Sheikh Al-Issa in Arafah's Sermon: Allaah Blessed You by Making It Easy for You to Carry out This Obligation. Thus, Ensure Following the Guidance of Your Prophet    Custodian of the Two Holy Mosques addresses citizens and all Muslims on the occasion of the Holy month of Ramadan    







Thank you for reporting!
This image will be automatically disabled when it gets reported by several people.



Adapting to hybrid, public clouds needs full grasp of IT to rest of business
Published in The Saudi Gazette on 14 - 07 - 2016

JEDDAH — If, just a few years ago, you were to ask CIOs in Saudi about their advice for securing a public cloud, the odds aren't bad that their response would have been "Just don't use one." Today, you're far more likely to get a nuanced response, the result of increased practical experience with both security and broader governance issues in public clouds.
However, as Oscar Wilde wrote, "Experience is the name that we give to our mistakes." What follows are some of the security and governance-related mistakes that architects, IT managers, and consultants in the country have made that have led to them gaining much valuable experience.
A lot of the pushback against the use of public clouds (and, for that matter, other trends such as employee-owned smartphones and laptops) has focused on the risks. Or the what could go wrong. Risks certainly need to evaluated and perhaps mitigated. For example, an organization might allow employees to use public cloud resources and personal devices but only if they use two-factor authentication.
However, risks also need to be considered in a business context. Perhaps using some third-party service does introduce a new level or type of risk such as the provider going out of business or discontinuing a service. But if the business benefit associated with getting access to, say, better customer analytics is significant, perhaps the incremental risk is worthwhile. Or not. In any case, the risk has to be viewed in a broader context than a narrow IT-focused one.
A widespread focus on risk, rather than cost/benefit, led directly in many cases to what came to be known as "Shadow IT." Faced with IT organizations that decided the safest and most secure approach was to simply prohibit (or perhaps "take time to further study") public clouds and other new aspects of computing, lines of business and individual users just took out their credit cards. They procured services on their own.
This was (and is) not a problem in some cases; with technology so pervasive within modern businesses, it's neither practical nor beneficial for IT to be involved in every technology decision. However, at the same time, IT can play a valuable role in establishing best practices for security and evaluating third-party solutions. Those benefits go away when decisions are effectively being hidden from the IT organization.
Much of the resistance to public clouds seems to have come from its comparison to what was largely a strawman--namely the on-premise IT infrastructure that never had a misconfigured firewall, was never accessed by a rogue employee, and that was always promptly updated and patched with the latest security updates. Certainly, some IT organizations run a tight ship. Others not so much (especially in smaller organizations lacking specialized security expertise). However, one doesn't need to read too many headlines before coming across examples of on-premise data breaches.
Especially with the increase in laws requiring that customer data breaches be disclosed, it's clear that data breaches are common--no matter where the computing is hosted.
None of this is to say that one shouldn't do due diligence with respect to the processes, certifications, and track record of public cloud providers. However, that due diligence needs to take into account that perfection isn't a reality just about anywhere.
Once organizations adopt public clouds for at least some of their workloads, some then go on to make what is effectively the opposite mistake. Having decided that public clouds are acceptable, they delegate aspects of security to the provider that they, in fact, maintain control over and therefore responsibility for. (When discussing public cloud providers, there's the idea of a "shared responsibility model" whereby, depending upon the type of cloud service, the provider is responsible for certain aspects of security while the user retains responsibility for others.)
For example, in the case of Infrastructure-as-a-Service, the user provides and maintains the operating system images running in the cloud. This means that the user needs to apply the same best practices around obtaining the software from trusted sources, keeping it updated and patched, monitoring it for vulnerabilities, and operating it in a secure manner that they'd use in their own datacentre.
Historically, IT built infrastructure and wrote applications to run on that infrastructure. With public clouds and other third-party services, IT has been forced to transform into a broader business enablement role. This hasn't always been an easy transition. It means taking a far more multi-faceted approach to delivering and managing a broad set of services in partnership with the lines of business.
From a security and governance perspective, this has often led to a lack of consistent policy over sharing data with third-party services and over where data can be stored. It's led to a fragmentation of identity services and access controls. It's led to the inconsistent application of best practices such as described above.
IT organizations are addressing some of these issues with specific technologies such as cloud management platforms, single sign-on, and identity management. However, dealing with this changing environment is also driving organizational changes such as the creation of cross-functional teams that include both IT and business owners. And that's perhaps the most important message. Adapting to hybrid and public clouds will often require some specific practices, processes, and technologies. But it also requires an understanding of how IT and the relationship of IT to the rest of the business is changing.


Clic here to read the story from its source.