What firms need to know about securing their cloud migration

By Ricky Ho

Cloud computing in Asia Pacific, especially in Singapore, is growing constantly in importance, and with its growth comes an increasing demand for cloud security. According to research firm IDC, the cloud computing market in Singapore is forecast to grow to about US$1b ($1.4b) by 2017.

Singapore is gearing up to be the world’s first Smart Nation, and cloud computing is expected to be a pivotal part of its infrastructure. The Smart Nation is powered by big data, and the data transmitted within the cloud must be protected with encryption. However big data also brings its own set of complications to cryptography. Whilst encryption is the key to protecting sensitive data, it can also mask the misdeeds of malicious attackers and deny security staff the visibility into the communications to and from the cloud.

Traffic unseen in the cloud
In the ever-changing cloud computing landscape, unmanaged encryption can put organisations at risk. This applies equally to the Smart Nation as well as to enterprises that are moving or have moved to the cloud. Whilst hosted cloud environments are becoming mainstream, the traditional network architectures are still employed, and require support for management and monitoring of third-party encrypted access.

However when faced with such situation, many IT administrators simply let the encrypted traffic flow freely in and out of the network environment. This creates obvious risks as the lack of visibility and limited content control in encrypted channels may enable a covert method for infiltrating the network and/or for exfiltration of sensitive data.

Singaporean utility company requests privileged access monitoring
Like many large organisations, one of the energy and utilities companies in Singapore utilises cloud hosting services to achieve significant efficiency, flexibility, and cost advantages. In 2016 they invited tenders from Cloud Service Providers (CSPs) in Singapore to provide a comprehensive cloud service (with security) offering. Their requirements for security were:
- Monitoring and auditing the privileged user activities in encrypted traffic (in real time)
- Providing a logging mechanism to log all activities for forensic purposes
- Enabling self-service provisioning and management of privileged users

This is not a standalone business case but similar requirements for cloud security service have become common.

Ensure privileged session monitoring in cloud
Traditionally, conventional enterprise privileged access solutions utilised gateways and focussed on interactive users. But this is no longer sufficient – the ongoing migration to the cloud has turned cloud service providers and cloud-using organisations to more advanced security solutions.

If organisations are going to or have already moved to the cloud, advanced privileged session monitoring solutions are definitely needed; and they should be able to:
• Provide logs, centralised management, visibility for all encrypted privileged access
• Filter and proactively detect suspicious traffic
• Monitor privileged sessions (with record and playback functionality)
• Deploy in both public and private cloud environments, without interfering with user and business workflows
• Enable flexible deployment and adaptability to changes in cloud and network environments
• Gain accountability for the shared accounts in the cloud-hosting environment

When organisations use outsourced cloud service, it is highly recommended to select a reliable CSP with a good security track record, i.e. being certified the Multi-Tier Cloud Security Standard by Infocomm Development Authority of Singapore (IDA). More importantly, the CSP needs to be able to deliver secure service offerings and take a variety of stringent measures to their critical access governance so as to ensure the transimitted data is safe and their servers are secure.

Join Singapore Business Review community
Join Singapore Business Review community
A NOTE FROM SINGAPORE BUSINESS REVIEW

You're the reader we write for. You're also the person our partners want to reach.

If that sentence describes you — a founder, a C-suite, someone whose attention companies pay good money for — then you already understand why SBR works. We've spent twenty years earning the trust of readers exactly like you. Which is exactly what makes this an interesting place for your company to show up, too.

The ways it can show up are broader than most people assume — thought leadership articles, sponsored content, industry summits across Southeast Asia, regional awards programmes, podcasts, and media placements in print and digital. The right fit depends on what you're trying to do, which is why we'd rather start with a conversation than send a rate card.

If your company has something this audience should know about, we'd like to hear what you're working on.

No rate cards until we understand the brief. It's a better use of everyone's time.

Top News

30 One-Sentence Stories From People Who Have Built Better Habits
None of these stories are mine. They were sent to me by readers of Atomic Habits. My hope is that these examples will illustrate how real people are putting the book into practice. They will show you what people are actually doing to build good habits and break bad ones. And hopefully, they will spark some ideas for how you can do the same.
SBR 5 Lorem Ipsum News 2 [8 May]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
SBR 4 Lorem Ipsum [8 May Top Stories]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.

Exclusives

How Experts Figure What to Focus On
eliminate the distractions. Commit to one thing and become great at that thing.”
Exclusive three SBR 12 Lorem Ipsum [8 May]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
SBR 3 Lorem Ipsum [ Exclusive 2]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.

Event News

Video [Event News]
Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley