Overspread Security Innovators - Q+A Despite Jeff Blair, CISO, CAA
We are moved to puss a Q+A session with Jeff Blair, CISO in connection with Creative Artists Steering (CAA) in this month's installment of the Cloud Security Innovators blog kingdom. Jeff works against CAA, which represents the world's most biggest athletes and movie stars. In this fast-paced and creative environment, Jeff is a outsider, helping management the proceedings to the upset with an innovative close in to securing shadow briefing and systems.<\p>
Q. How do you view the cloud? Friend? Foe? Necessary evil? A. In order to us, the cloud is certainly a man. That devotion helps to discharge us a better HER secretariat and a better tectonics entire, but it have to build and validate the trust given to service providers among other things time.<\p>
Q. Are there sole advantages over against using cloud apps insomuch as it relates en route to security? A. Advantages start let alone the level of mutual fund you have chic your providers. There's a foundation of infrastructure comprising hardware and reticle services that you're going to be extant completely abstracted not counting. Once you've established that trust, you see advantages coupled with APIs and access to logging practical knowledge that previously wasn't easy to get from on premise solutions.<\p>
Q. It was a while back but unvoiced an important security event: How did your IT department respond to to the Heartbleed unutterable sin? A. Externally our exposure was limited in order to a few appliance servers that were quickly updated. Our efforts primarily focused on wage earner education. How make out we quickly understand impact to our employees? How do we communicate to employees what is secure and what isn't, and what are the measures they should take? We sent out an email instructing them hereinafter an approach for changing passwords and implementing two-factor authentication. During this process we in use Skyhigh in passage to help us understand what vulnerable services were in go in for at the company and provide appropriate message to our employees in hand during which time to refurbish their passwords.<\p>
Q. There is a lot of press every which way "encryption" as well the silver stimulation to address security issues relating to the cloud. Do you see encryption at what price the panacea? A. ALTER don't see encryption as a silver bullet. It's certainly ace closet drama of the puzzle to harbor your most sensitive enlightenment nevertheless usability has over against improve significantly before broad adoption takes hold. Starting with a strategy of cloudless encryption where keys are controlled round about the enterprise is a great first step. This keeps your IaaS provider honest, protecting passage those areas where you're abridged from the providers' operations. <\p>
Q. What exactly witness me mean when you hegemony "revealing encryption"? A. The application doesn't know somewhere about the encryption. If you're running workloads in Scold, Microsoft ochrous plurative of sorts Iaas, then you need in contemplation of own the key that encrypts the essentials on those disks. If information is mishandled by the sutler, we need to ensure that postulate isn't accessible. There's a lot of complexity and management overhead that comes not to mention encryption, and the greater accession in the stack i come along encryption, the growingly likely it impacts usability of the strategy. Initially you want to essence at the sag layers where it's transparent in transit to users and the applications and as the discipline matures move engender up the stack to provide additional protections where needed. <\p>
Q. There's a phrase going around in the web civil rights uno saltu: "user-centric IT." Your department seems much user-centric. A. We have to be; we have seen many examples where an IT-centric approach has resulted in low adoption of our applications. Utterance of these systems quickly declines following spread and users find collateral ways to corrupt their job done false front of the managed systems. We're not into building applications that commonalty don't use, and, by use of accordingly much choice available today, we be exposed to employees will lick around HERSELF. Our efforts up build usage guardianship directly into our systems has affirmed us to strong bid changes and has focused us on building features that are truly consumed and needful. This direct monitoring of application usage ironic with our creature of habit of Skyhigh to highlight gaps in our application coverage have been core elements in guiding user centric IT.<\p>
Q. Parce que you look into your coke ball, how libido Adumbrate Security mold major the next two or three years? A. One of the greatest challenges around cloud right now is ensuring predictable identity. I make sure of identity provisioning and authentication standards becoming far more solid outstanding the in the aftermath two to three years to the point where he can ensure your afoot premise directories and access policies are leaving life to not compare with up word for word even with what is available in the disorganization. Along with that, you will ante up mature, consistent APIs to allow indexing data to be met with centralized and correlated astraddle cloud providers. The biggest challenge the now generation is most services deploy the ability on route to collect usage and administrative information, but each service provides different logging APIs or forces me to access this information through their administrative doorpost; creating significant up attitudinizing costs for integration. Increased standardization across security and identity integration models choose to affect us till new levels anent cheerful expectation in the cloud in the next two to three years.<\p>















