February 26, 2015 By Sreekanth Iyer 3 min read

The cloud offers simplified application development and delivery by providing infrastructure, platform and software services that are ready to use immediately. However, the major inhibitor for businesses has been concerns around security. IBM sees this not as a challenge, but rather as an opportunity to enhance your security posture by rethinking your approach to cloud security. Gaining a clear understanding of the various security options and how to apply them in your solution is crucial for successful and secure cloud adoption.

IBM has simplified the typical method for approaching this problem. Whether you’re looking to employ infrastructure-as-a-service (IaaS), platform-as-a-service (PaaS) or software-as-a-service (SaaS), use the framework below when designing your solution. Each platform comes with certain built-in security qualities and lets you use add-ons on top of the platform to secure each workload.

Manage Access

This involves managing identities and governing user access to cloud resources. When you are consuming infrastructure from the cloud, you also need to manage the identity involved in privileged activities, such as those performed by cloud administrators, and the tracking activities of the people involved in development and operations. Another important aspect of managing access is safeguarding people, applications and devices connecting to the cloud, especially when it comes to the use of SaaS offerings. All the good stuff related to access management, such as pattern-based protection, multifactor authentication, context-based access control and privileged and federated access, goes here.

Protect Data

This is all about what you can do to identify vulnerabilities in your application and data and which actions you should take to prevent attacks targeting sensitive data. This solution-oriented approach covers things you should do to encrypt data at rest (files, objects, storage) and in motion, as well as how to monitor data activity to verify and audit data outsourced to the cloud. The vulnerability assessment of both your data and application is an important step in this process because it hardens data sources and Web and mobile applications that are in the cloud.

Gain Visibility

Continuously monitoring each activity and event in the cloud is necessary for complete visibility across on-premise and cloud-based environments. You can also build improved security and visibility into virtual infrastructures by collecting and analyzing logs in real time across the various components and services in the cloud. With visibility across virtualized stacks and IaaS, PaaS and SaaS clouds, you can have a clear view into your enterprise cloud and any associated risks. This should prepare you well for managing your audit and compliance processes.

Read the white paper: Safeguarding the cloud with IBM Security solutions

Optimize Cloud Security Operations

Optimizing the processes, methods and tools for running your security operations is key to keeping the overall cost low. You should always keep assessing security practices, plans and designs and mature them in a timely manner to build out world-class security operations centers. Consolidating your view of this using big data, visualization and intelligent threat analysis — with the right expertise — is key to staying ahead of the threats and being ready to respond to any security incidents along the way.

To learn how to address each of these areas with IBM’s capabilities, take a look at my presentation from IBM InterConnect 2015.

More from Cloud Security

2024 Cloud Threat Landscape Report: How does cloud security fail?

4 min read - Organizations often set up security rules to help reduce cybersecurity vulnerabilities and risks. The 2024 Cost of a Data Breach Report discovered that 40% of all data breaches involved data distributed across multiple environments, meaning that these best-laid plans often fail in the cloud environment.Not surprisingly, many organizations find keeping a robust security posture in the cloud to be exceptionally challenging, especially with the need to enforce security policies consistently across dynamic and expansive cloud infrastructures. The recently released X-Force…

Cloud threat report: Why have SaaS platforms on dark web marketplaces decreased?

3 min read - IBM’s X-Force team recently released the latest edition of the Cloud Threat Landscape Report for 2024, providing a comprehensive outlook on the rise of cloud infrastructure adoption and its associated risks.One of the key takeaways of this year’s report was focused on the gradual decrease in Software-as-a-Service (SaaS) platforms being mentioned across dark web marketplaces. While this trend potentially points to more cloud platforms increasing their defensive posture and limiting the number of exploits or compromised credentials that are surfacing,…

Cloud Threat Landscape Report: AI-generated attacks low for the cloud

2 min read - For the last couple of years, a lot of attention has been placed on the evolutionary state of artificial intelligence (AI) technology and its impact on cybersecurity. In many industries, the risks associated with AI-generated attacks are still present and concerning, especially with the global average of data breach costs increasing by 10% from last year.However, according to the most recent Cloud Threat Landscape Report released by IBM’s X-Force team, the near-term threat of an AI-generated attack targeting cloud computing…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today