Best Practices for Proper Cloud Configuration
Through the digital transformation, now driven by the Covid-19 pandemic, we see a massive migration to decentralized, cloud-based models. And those who already use these models will further accelerate the migration to the cloud. According to Gartner, by 2021, more than half of global companies that already use Cloud will adopt a strategy in a 100%-Cloud environment.
Proper protection of this type of environment becomes a growing concern for Security teams and a business must. Thus, the risks associated with the lack of proper protection of the Cloud environment must be considered not only by the Security team but also by senior management, in order to ensure the organizations’ digital sovereignty over data, in addition to business continuity.
Lacework researchers, for example, found more than 22,000 container orchestration dashboards and API management systems open on the internet. Among the applications Lacework has found during the research, we have Kubernetes, Mesos Marathon, Swagger API, Red Hat Openshift, and Portainer from Docker Swarm and Swarmpit. Also, according to the research, 95% of these dashboards and management systems were stored on Amazon Web Services (AWS). Although the vast majority of these interfaces have privileged credentials for access control, the researchers consider it an issue that these interfaces are exposed on the internet. This is because anyone with access to dashboards is able to perform tasks such as starting or stopping workloads, adding or removing applications, or even configuring security controls.
Against this background, it would be very easy for security teams to hand over responsibility for the cybersecurity aspect to CSPs (Cloud Service Providers). It is worth mentioning, however, that in distributed environments, organizations should not rely only on their cloud providers to ensure this protection. If the interfaces are not properly configured, the attack surface increases considerably, which brings a greater risk of cyberattacks to organizations’ infrastructure.
Also, new regulatory requirements, such as GDPR and LGPD, require adequate data protection, which can lead to heavy sanctions if not met. For organizations that treat personal data of European citizens, this figure can reach up to 50 million euros, or 50 million reais if the organization treats personal data of Brazilians and is subject to the LGPD, considering that the Brazilian legislation is already in force.
Some of the best practices that can be implemented by the Security teams to reinforce the organizations’ behavior when it comes to the security of Cloud environments and avoid data leaks include:
Having an understanding of their cloud environments
While ease and convenience bring together some of the biggest advantages of using services in a cloud environment, the implementation of workloads is not as trivial as it seems. The security team must commit itself to know all the configurations and permissions of its Cloud-based services, and thus leverage the maximum of the security features integrated with the contracted services. Even though it is an activity that requires extensive effort, it is necessary to ensure the security of the distributed environments.
Checking and configuring credentials and permissions
Organizations that are implementing Cloud approaches may find that using the default security settings is enough to prevent their workloads from being compromised. However, these settings are very basic or even non-existent. Given this, the recommendation is that those responsible for security in the Cloud environment constantly check credentials and permissions and ensure that access to workloads is limited to those who really need access, ensuring the implementation of the Principle of Least Privilege. This can be achieved through a Privileged Access Management solution or PAM. Besides, the use of features such as Multifactor Authentication (MFA) ensures an additional layer of security to the environment immediately.
Performing periodic audits to check for possible configuration failures
It is very common for cybersecurity teams to consider that a well-configured Cloud environment stays this way. With the growing number of users of a distributed infrastructure, any change in settings can leave sensitive data exposed to malicious attackers. When creating a new folder that does not require credentials for authentication, for example, an employee can expose the organization to an attack vector, which could be avoided if there were adequate auditing and monitoring.
Implementing activity records through logs and network segmentation
The large number of users accessing Cloud environments makes management even more difficult. Thus, many CSPs offer the logging functionality, which helps organizations to have greater visibility of the actions performed in these environments. Through these features, one can receive alerts of unauthorized access attempts. It is worth remembering that data protection laws require that the respective leaks be reported within 72 hours after their discovery, and must be duly justified by the data controller if it occurs after this period. Also, according to the 2020 Cost of a Data Breach Report, the average time to identify and contain a data leak is, on average, 280 days.
Choosing the right cybersecurity solutions for protecting the Cloud environment
Companies that want to strengthen their behavior in Cloud security should look for solutions to complement the security features offered by CPSs, which must adhere to security policies, based on the best market practices, including threat detection, intrusion detection and prevention systems – the so-called IDS and IPS -, in addition to PAM solutions.
By following these recommendations, organizations of all sizes can reduce the attack surface and mitigate cybersecurity risks, in order to ensure the trust of their customers, partners, and employees, including the business continuity itself.