EBA欧洲银行-Session-2Fabio-Gianotti-Cloud-Security-Strategies_9页_2mb
报告摘要
Cloud Security Strategies Summary
Core Content
This document outlines UniCredit's approach to cloud security strategies, emphasizing the importance of strong ICT Security governance in a complex and geographically distributed environment. It highlights the need for a comprehensive and sustainable cloud security framework that aligns with both internal and external regulatory requirements.
Main Points
-
Complexity of the UniCredit Landscape:
The organization operates in a complex environment with numerous branches, employees, and data centers across multiple countries. This complexity is compounded by varying country regulations and different approaches to cloud adoption. -
Cloud Adoption Strategy:
Cloud adoption is framed as a consolidation framework and a business enabler. It allows for more efficient use of resources and enables new business propositions through scalable and flexible computing services. -
Legal and Compliance Considerations:
The European Court of Justice ruling on the invalidation of the Safe Harbor Decision raises questions about data protection compliance. Data laws apply to the data itself, not the application, which can influence how responsibilities are shared with cloud providers. -
Cloud Security Evaluation Dashboard:
A summary of scoring results across various security clusters is provided, highlighting performance differences between providers. The dashboard includes metrics such as Audit & Compliance, Application Security Testing, and Encryption & Tokenization. -
Cloud Security Components:
A comprehensive cloud security strategy must address several key areas:- Governance: Define processes and policies, legal considerations, audit and compliance, business continuity, and user training.
- Data: Classification, backup, retention, ownership, risk assessments, encryption, and secure storage and disposal.
- Users & Identity: Roles, authorization levels, authentication, usage pattern evaluation, and awareness programs.
- Infrastructure: Security functionality, network configuration, cloud hardening, vulnerability management, and operations.
-
Cloud Ready Program:
The program aims to align the Group CIO's global and ICT Security cloud strategy with the feasibility of deploying a unified UniCredit Service Platform. It recognizes cloud computing as a service model, not just a technology, encompassing SaaS, PaaS, and IaaS. It also emphasizes the importance of API exposure for B2B and B2C services.
Key Information
-
Data Protection and Compliance:
Data laws apply to the data, not the application. Encrypting data ensures that cloud providers cannot access it, which can affect compliance responsibilities. -
Security Governance:
Strong ICT Security governance is mandatory and strongly recommended. It involves defining clear ownership, connectivity, privacy, and audit policies. -
Cloud Security Evaluation:
The evaluation dashboard shows that ACME has the highest total score (125.0), followed by Best Provider (119.7), and Provider 3 (0.0). ACME excels in areas such as Audit & Compliance, Governance, and Infrastructure Operations. -
Ongoing Security Activities:
Companies must raise the bar on ongoing security activities and ensure that cloud providers meet minimum security standards. This includes managing increasing complexity through new monitoring points and developing more sophisticated technical skills. -
Strategic Approach:
A holistic view is necessary to bridge the gap between requirements, risks, and skills. The strategy should be omni-comprehensive, addressing data protection, application security, network security, encryption, file sharing, and compliance with local and global regulations.
Final Take-Aways
-
Cloud Benefits:
Cloud computing offers elasticity, scalability, and on-demand computing power, with a growing list of providers. -
Risk Evaluation:
Companies must be structured or restructured to handle a new generation of risk evaluation and adopt a strategic, comprehensive cloud approach. -
Security Governance:
A strong and sustainable security governance framework is essential for cloud adoption, covering all aspects from data management to identity and compliance. -
Provider Evaluation:
Companies should set minimum security expectations for cloud providers and manage the increasing complexity of cloud environments. -
Technical Skills:
Ongoing security activities require more advanced technical skills and a holistic view of the organization's security posture.
试读结束,高清完整版pdf/doc/ppt,请点下载