Welcome!

Java IoT Authors: Pat Romanski, Elizabeth White, Liz McMillan, Yeshim Deniz, Mehdi Daoudi

Related Topics: @CloudExpo, Java IoT, Cloud Security

@CloudExpo: Blog Post

Achieving a Secure Cloud Infrastructure for Enterprise SaaS Applications | @CloudExpo #Cloud

Simplifying security for SaaS applications

Software as a Service (SaaS) is a model that has become a popular choice for deploying enterprise applications, delivering efficiencies and value to organizations in many ways. The benefits SaaS solutions deliver include not only avoiding the major resource drain and licensing costs associated with deploying business-critical software across the organization, they also relieve IT from ongoing maintenance tasks associated with on-premise deployments, such as performing upgrades, installing patches and managing availability. Moreover, SaaS can enhance flexibility and scalability for enterprise applications and workloads. Of course, while these benefits gained from adopting SaaS solutions in the enterprise are significant, they must nevertheless be balanced against potential risks. In particular, consideration must always be given as to whether cloud applications are sufficiently secure.

A use case for enterprise SaaS: Customer communications in regulated industries
One use case for which SaaS applications have the potential to deliver numerous advantages is customer communication management (CCM) in regulated industries. To meet compliance rules and regulations applicable to customer communications, organizations typically face inflexible formatting requirements and document models as well as tight deadlines. In many cases, the processes relied on to ensure that customer communications are compliant are manual and labor intensive. The complexity of the task is compounded by the need to manipulate individual file structures, account for duplication of content and engage in coordination with outside agencies. Mistakes are costly, because failure to remain in full compliance risks having to pay significant financial penalties or becoming subject to legal action.

Adopting an automated SaaS workflow can avoid these hurdles by leveraging accurate, preset processes instead of time-consuming, error-prone and expensive manual activities. Dynamic formatting can replace manual layout methods, eliminating the need for outside agencies or dedicated internal staff for this process. Centralization of content will streamline its management, add control, provide visibility into the workflow process and significantly reduce costs. As a result, time-to-market can be improved.

Of course the most important advantage to be gained from automating previously manual processes for regulated communications is that it will ensure that customers receive timely, compliant and effective documents that enhance the customer experience and loyalty.

Cloud security - A critical consideration in regulated industries
While the advantages of using SaaS applications for CCM in regulated industries are clear, it's also the case that the workflows in these organizations routinely involve sensitive customer data. For that reason, security tops the list of priorities that should be addressed in considering a SaaS solution.

A recent survey by the Ponemon Institute found that enterprises storing sensitive or confidential business data in the cloud environment made a number of common mistakes when it comes to ensuring security, including:

  1. Most companies are not evaluating SaaS applications for security prior to deployment.
  2. IT is in the dark about cloud services in their organizations. Instead, procurement and cloud users are responsible for cloud security.
  3. Cloud deployment strategies often leave out the use of security technologies in the cloud environment.
  4. Inspection of data in the cloud rarely happens.
  5. Despite concerns about security, organizations are not willing to pay for extra cloud security.

Moreover, while 90 percent of IT survey respondents said SaaS will be important to meeting IT strategies over the next two years and 79 percent said security is an important consideration in their cloud migration decision, only 33 percent believe their organizations are achieving necessary objectives for cloud security.

In light of these survey results, organizations should take steps to mitigate the potential for making similar security mistakes. But attaining a secure cloud posture is not an easy task. It involves procuring, integrating and managing dozens of point security products, as well as making all the necessary changes to processes, staff training and resource utilization.

In addition, even when a secure cloud environment is achieved, it must be maintained through constant monitoring, periodic risk reassessments and other techniques. Controls must be established that comprehensively address:

  • Risk management, which must be assessed both initially and periodically.
  • Security architecture. A careful analysis of how the organization fulfills its unique security requirements.
  • Incident handling, involving the creation of an entire program covering the incidence response lifecycle.
  • Threat management. Deploying technologies to identify and investigate potential threats and instituting ongoing practices to prevent them.
  • Vulnerability management, which entails identifying and remediating exploitable flaws and configuration errors in software.
  • Change control. Tracking additions, alterations and removals that might affect and organization's security architecture, and
  • Data security lifecycle support. Employing encryption technologies to protect data in transit and data at rest as well as secure backup, restore and deletion capabilities.*

As the survey results showed, it is unlikely that these tasks will be accomplished by an organization's internal IT team given that it may not even participate in the selection or know about the SaaS applications deployed by business users. That means that business users and, by default, their organizations, are relying on the SaaS provider to ensure that adequate security protections are in place, which may not be an accurate assumption.

Simplifying security for SaaS applications
Rather than attempting to accomplish all the foregoing tasks internally, organizations needing to protect sensitive data can simplify the process by investigating whether the cloud infrastructures that store their data workloads, applications and assets are secure. When it comes to SaaS applications, an important consideration is whether the SaaS provider is partnering with a secure cloud hosting provider that has the expertise and technologies in place to ensure proactive protection of the organization's sensitive data. The secure cloud hosting provider should have the ability to accomplish all of the foregoing tasks, maintaining security for all applications and data that the organization accesses through the cloud. This approach has the potential to be much more cost effective, efficient and comprehensive for the organization than attempting to handle cloud security using internal IT resources.

In order to ensure a secure cloud environment, an organization should confirm that the following three objectives are met:

  • The organization has achieved complete visibility within the cloud environment.
  • Dwell time - the amount of time that a threat actor remains undiscovered and unmitigated within the environment - should be reduced from weeks or months to days or even hours.
  • Lesser threat actors should be automatically blocked so that the security controls - including technology and trained personnel - can focus on finding and stopping more sophisticated threats.*

Combining a cloud-based SaaS solution for generating highly regulated customer documents with secure cloud hosting of all deployments of this and other SaaS platforms in the organization has the potential to provide the best possible security while enhancing the organizations agility when delivering regulated communications to customers.

This approach can provide a comprehensive way to ensure security of data while also meeting an organization's threshold compliance requirements for compliant customer communications.

*See Armor White Paper, "Inside the 6 principal layers of the cloud security stack"

More Stories By Waqar Ahmad

Waqar Ahmad is Chief Information Security Officer for Elixir Technologies. He is a senior advisor to the solutions architect group and served as Elixir’s vice president of engineering for 10 years. Visit www.elixir.com for more information.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


IoT & Smart Cities Stories
The platform combines the strengths of Singtel's extensive, intelligent network capabilities with Microsoft's cloud expertise to create a unique solution that sets new standards for IoT applications," said Mr Diomedes Kastanis, Head of IoT at Singtel. "Our solution provides speed, transparency and flexibility, paving the way for a more pervasive use of IoT to accelerate enterprises' digitalisation efforts. AI-powered intelligent connectivity over Microsoft Azure will be the fastest connected pat...
There are many examples of disruption in consumer space – Uber disrupting the cab industry, Airbnb disrupting the hospitality industry and so on; but have you wondered who is disrupting support and operations? AISERA helps make businesses and customers successful by offering consumer-like user experience for support and operations. We have built the world’s first AI-driven IT / HR / Cloud / Customer Support and Operations solution.
Codete accelerates their clients growth through technological expertise and experience. Codite team works with organizations to meet the challenges that digitalization presents. Their clients include digital start-ups as well as established enterprises in the IT industry. To stay competitive in a highly innovative IT industry, strong R&D departments and bold spin-off initiatives is a must. Codete Data Science and Software Architects teams help corporate clients to stay up to date with the mod...
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throug...
Druva is the global leader in Cloud Data Protection and Management, delivering the industry's first data management-as-a-service solution that aggregates data from endpoints, servers and cloud applications and leverages the public cloud to offer a single pane of glass to enable data protection, governance and intelligence-dramatically increasing the availability and visibility of business critical information, while reducing the risk, cost and complexity of managing and protecting it. Druva's...
BMC has unmatched experience in IT management, supporting 92 of the Forbes Global 100, and earning recognition as an ITSM Gartner Magic Quadrant Leader for five years running. Our solutions offer speed, agility, and efficiency to tackle business challenges in the areas of service management, automation, operations, and the mainframe.
The Jevons Paradox suggests that when technological advances increase efficiency of a resource, it results in an overall increase in consumption. Writing on the increased use of coal as a result of technological improvements, 19th-century economist William Stanley Jevons found that these improvements led to the development of new ways to utilize coal. In his session at 19th Cloud Expo, Mark Thiele, Chief Strategy Officer for Apcera, compared the Jevons Paradox to modern-day enterprise IT, examin...
With 10 simultaneous tracks, keynotes, general sessions and targeted breakout classes, @CloudEXPO and DXWorldEXPO are two of the most important technology events of the year. Since its launch over eight years ago, @CloudEXPO and DXWorldEXPO have presented a rock star faculty as well as showcased hundreds of sponsors and exhibitors! In this blog post, we provide 7 tips on how, as part of our world-class faculty, you can deliver one of the most popular sessions at our events. But before reading...
DSR is a supplier of project management, consultancy services and IT solutions that increase effectiveness of a company's operations in the production sector. The company combines in-depth knowledge of international companies with expert knowledge utilising IT tools that support manufacturing and distribution processes. DSR ensures optimization and integration of internal processes which is necessary for companies to grow rapidly. The rapid growth is possible thanks, to specialized services an...
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throug...