APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for...

38
Session ID: Session Classification: Ken Low Director of Enterprise Security, Asia Pacific, Trend Micro Chairman, Asia Pacific Executive Council, Cloud Security Alliance CLD-W03 Intermediate APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD SECURITY AND ADOPTION

Transcript of APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for...

Page 1: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Session ID:

Session Classification:

Ken Low Director of Enterprise Security, Asia Pacific, Trend Micro

Chairman, Asia Pacific Executive Council, Cloud Security Alliance

CLD-W03

Intermediate

APAC OF POSSIBILITIES:

TIPS FOR INCREASING

CLOUD SECURITY AND

ADOPTION

Page 2: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Clouds Everywhere Above

2

Copyright 2013 Trend Micro Inc.

Page 3: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

One Cloud …..

3

Copyright 2013 Trend Micro Inc.

Page 4: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top
Page 5: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Largest pure-play security provider

Deliver top ranked security solutions

Market leader in Server, Virtualization, and Cloud security

Secures your journey to the cloud

Take advantage of the cloud

Source: IDC (2011), Technavio (2011 & 2012)

Trend Micro Overview

5

Copyright 2013 Trend Micro Inc.

Page 6: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Global Alliances

6

Copyright 2013 Trend Micro Inc.

Page 7: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Global Alliances

7

Copyright 2013 Trend Micro Inc.

Page 8: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

8

Global Alliances

Page 9: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Cloud Security in Asia Pacific

Page 10: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Source: 2013 BSA Global Cloud Computing Scorecard

10

Copyright 2013 Trend Micro Inc.

Page 11: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Source: 2013 BSA Global Cloud Computing Scorecard

11

Copyright 2013 Trend Micro Inc.

Page 12: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Source: Cloud

Readiness Index 2012,

Asia Cloud Computing

Association

12

Copyright 2013 Trend Micro Inc.

Page 13: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Predicted national cloud-related job growth figures from 2012-2015:

► Japan 155%

► Australia: 129%

► Singapore: 109%

► Malaysia: 107%

► Indonesia: 103%

► India: 99%

Source: IDC

Cloud-related job growth in Asia Pacific

13

Copyright 2013 Trend Micro Inc.

Page 14: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Trend Micro’s annual survey of 1400 IT decision makers from the U.S., UK,

Germany, India, Canada, Japan and Brazil found significant regional

differences in cloud security.

► India had the highest incidence (67 percent) of data security lapse or issue,

a full 12% higher than the next highest country, Brazil (55 percent.)

► India also had the highest – 12 percent -- increase of security lapse or issue

from 2011

► Japan had a 7 percent increase in security lapse or issue, about the same

as Canada at 6 percent

► Japan is less likely to adopt cloud computing than all the other countries

surveyed.

► Japan also has the lowest usage level for VDI, public cloud and private

cloud.

Source: Trend Micro

National differences in cloud security

14

Copyright 2013 Trend Micro Inc.

Page 15: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Tips for increasing cloud security and adoption

Page 16: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Cloud Marketing Fairytales: Who Owns Security

You Shared

Public Private

Shared

Hybrid

Copyright 2013 Trend Micro Inc.

16

Page 17: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

The AWS Shared Responsibility Model

Facilities Physical Security Physical Infrastructure Virtualized Infrastructure

Enterprise Applications

Enterprise Operating Systems

Partner Eco-System

Cu

sto

mer

Do

mai

n

AW

S D

om

ain

Operating Systems Application Security Groups OS Firewalls Anti-Virus Account Management Storage Encryption

17 Copyright 2013 Trend Micro Inc.

17

Page 18: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

CSP is responsible for the compliance of what they manage

Customer is responsible for what’s not addressed by CSP

Customer is responsible for monitoring CSP’s compliance

PCI DSS Cloud Computing Guidelines

Copyright 2013 Trend Micro Inc.

18

Page 19: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Security and availability are inseparable

What’s holding back cloud adoption? (Trend Micro survey)

54% - security of data or cloud infrastructure

50% - performance / availability of cloud

Copyright 2013 Trend Micro Inc.

19

Page 20: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Where Does Cloud Security Come From?

Security Tools

Cloud Service Provider

You

Security Knowledge

Technical Operations

Domain | Few years ago | Now

Software & Cloud

Hardware & Software

Big Data & Research

Threat Research

Copyright 2013 Trend Micro Inc.

20

Page 21: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

THREAT DATA

CUSTOMERS

THREAT

INTELLIGENCE

Using The Cloud For Security Knowledge

Identifies

Multiple data centers

Multiple threat vectors

Living data

Massive scale

1.15B Threat Samples Daily

90K malicious threats daily

200M Threats blocked daily

Copyright 2013 Trend Micro Inc.

21

Page 22: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

► Cloud providers need non-cloud security

data

► Security companies need really good clouds

► Cloud providers better choose security

partners carefully

► Security providers better choose cloud

partners carefully

Industry Implications

Copyright 2013 Trend Micro Inc.

22

Page 23: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Where Does Cloud Security Come From?

Tools

Cloud Service Provider

You

Knowledge

Operations

Domain | Few years ago | Now

Software & Cloud

Hardware & Software

Big Data & Research

Threat Research

Software & Cloud

Copyright 2013 Trend Micro Inc.

23

Page 24: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

► Foundational cloud components are pluggable

► Security is not (mostly)

► Security industry software and VM model is not

CSP ready

► CSPs want carrier-grade security tools, not

server-grade

Industry Implications

Copyright 2013 Trend Micro Inc.

24

Page 25: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

► Cloud security tools need native multitenancy

► Software release cycle mismatch: software vs cloud

► Security performance hit costs CSPs real margin

► Time to rethink cloud security so it works better with

CSPs

► Time to move security consoles to the cloud

Why Software and VMs Won’t Satisfy CSPs

Copyright 2013 Trend Micro Inc.

25

Page 26: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

► Performance

► Multi-tenancy

► Management

Upgrade Your Cloud Security in 3 Easy Steps!

Copyright 2013 Trend Micro Inc.

26

Page 27: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

► Agentless for virtual, private, and public cloud

environments

► Integrated single agent available when

required

► SaaS based console and management for

agility

Upgrading Cloud Security Performance

Copyright 2013 Trend Micro Inc.

27

Page 28: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

► Multitenant architecture

► Delegation and self-service for cloud tenants

► Automated deployments of components for elastic scaling

► Common cloud API integration (AWS, vCloud, etc.)

► Shared security profiles across all deployments

Upgrading Cloud Security Multitenancy

Copyright 2013 Trend Micro Inc.

28

Page 29: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

► Shared security profiles across all deployments

► Common cloud API integration (AWS, vCloud, etc.)

► Single management pane-of-glass for private, VPC,

public

► Hierarchical policy management

► Cloud-resident, SaaS-based security consoles

Upgrading Cloud Security Management

Copyright 2013 Trend Micro Inc.

29

Page 30: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Future of Cloud Security: Shared Dependency

Security tools

Cloud Service Provider

Knowledge

Operations

Software & Cloud

Big Data & Research

Domain | Now | Future

Cloud Service Provider

Cloud resident Cloud aware

Cloud managed Cloud release cycles

Realtime data Cloud & non-cloud

Research

Copyright 2013 Trend Micro Inc.

30

Page 31: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Securing Your Journey To The Cloud

Page 32: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Productivity

HR

CRM

Customer Support

Finance

Supply Chain

Commerce

Employees Partners

Customers

Business App Owners

Data Center Ops

Copyright 2013 Trend Micro Inc.

Page 33: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Data Center

Productivity

HR

CRM

Customer Support

Finance

Supply Chain

Commerce

Data Center Ops

Copyright 2013 Trend Micro Inc.

Page 34: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Data Center

Physical Virtual Private Cloud

• Server and VM integrity

• Appropriate policy enforcement

• Data protection, especially in the cloud

• Performance and manageability

Public Cloud

Data Center Ops

Security

Copyright 2013 Trend Micro Inc.

Page 35: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Data Center

Physical Virtual Private Cloud Public Cloud

Cloud and Data Center Security

Anti-Malware Integrity Monitoring

Encryption Log Inspection

IPS & Virtual Patching

Firewall

Integrated Cloud Security

Copyright 2013 Trend Micro Inc.

Page 36: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

► Help cloud providers address the top barrier to cloud adoption – security.

► Cloud providers in APAC need to clarify their offerings, policies,

technology, service-level agreements and how they manage cloud security,

privacy and security incidents.

► The Cloud Security Alliance offers free cloud security self-reporting

frameworks for cloud providers to address enterprise concerns about

security in the cloud.

► Partner with virtualization aware security vendors to create compelling

secure cloud service offerings for enterprises e.g. agentless virtualisation

security like Trend Micro’s Deep Security.

► Creating safe clouds in APAC will help regional economies grow quickly,

powered by the growth of the cloud.

Cloud Security Tips for Now

Copyright 2013 Trend Micro Inc.

Page 37: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

• 20-21 August 2013,

8am – 6pm

• Raffles City

Convention Centre,

Singapore

• Register:

www.cloudsec.co/sg

Page 38: APAC OF POSSIBILITIES: TIPS FOR INCREASING CLOUD … · Japan also has the lowest usage level for VDI, public cloud and ... Public Private ... Help cloud providers address the top

Thank You

Ken Low Director of Enterprise Security, Asia Pacific, Trend Micro

Chairman, Asia Pacific Executive Council, Cloud Security Alliance

http://sg.linkedin.com/in/kenlow