Welcome!

Java IoT Authors: APM Blog, Stackify Blog, XebiaLabs Blog, Liz McMillan, William Schmarzo

Related Topics: @CloudExpo, Java IoT, Cloud Security

@CloudExpo: Blog Post

Achieving a Secure Cloud Infrastructure for Enterprise SaaS Applications | @CloudExpo #Cloud

Simplifying security for SaaS applications

Software as a Service (SaaS) is a model that has become a popular choice for deploying enterprise applications, delivering efficiencies and value to organizations in many ways. The benefits SaaS solutions deliver include not only avoiding the major resource drain and licensing costs associated with deploying business-critical software across the organization, they also relieve IT from ongoing maintenance tasks associated with on-premise deployments, such as performing upgrades, installing patches and managing availability. Moreover, SaaS can enhance flexibility and scalability for enterprise applications and workloads. Of course, while these benefits gained from adopting SaaS solutions in the enterprise are significant, they must nevertheless be balanced against potential risks. In particular, consideration must always be given as to whether cloud applications are sufficiently secure.

A use case for enterprise SaaS: Customer communications in regulated industries
One use case for which SaaS applications have the potential to deliver numerous advantages is customer communication management (CCM) in regulated industries. To meet compliance rules and regulations applicable to customer communications, organizations typically face inflexible formatting requirements and document models as well as tight deadlines. In many cases, the processes relied on to ensure that customer communications are compliant are manual and labor intensive. The complexity of the task is compounded by the need to manipulate individual file structures, account for duplication of content and engage in coordination with outside agencies. Mistakes are costly, because failure to remain in full compliance risks having to pay significant financial penalties or becoming subject to legal action.

Adopting an automated SaaS workflow can avoid these hurdles by leveraging accurate, preset processes instead of time-consuming, error-prone and expensive manual activities. Dynamic formatting can replace manual layout methods, eliminating the need for outside agencies or dedicated internal staff for this process. Centralization of content will streamline its management, add control, provide visibility into the workflow process and significantly reduce costs. As a result, time-to-market can be improved.

Of course the most important advantage to be gained from automating previously manual processes for regulated communications is that it will ensure that customers receive timely, compliant and effective documents that enhance the customer experience and loyalty.

Cloud security - A critical consideration in regulated industries
While the advantages of using SaaS applications for CCM in regulated industries are clear, it's also the case that the workflows in these organizations routinely involve sensitive customer data. For that reason, security tops the list of priorities that should be addressed in considering a SaaS solution.

A recent survey by the Ponemon Institute found that enterprises storing sensitive or confidential business data in the cloud environment made a number of common mistakes when it comes to ensuring security, including:

  1. Most companies are not evaluating SaaS applications for security prior to deployment.
  2. IT is in the dark about cloud services in their organizations. Instead, procurement and cloud users are responsible for cloud security.
  3. Cloud deployment strategies often leave out the use of security technologies in the cloud environment.
  4. Inspection of data in the cloud rarely happens.
  5. Despite concerns about security, organizations are not willing to pay for extra cloud security.

Moreover, while 90 percent of IT survey respondents said SaaS will be important to meeting IT strategies over the next two years and 79 percent said security is an important consideration in their cloud migration decision, only 33 percent believe their organizations are achieving necessary objectives for cloud security.

In light of these survey results, organizations should take steps to mitigate the potential for making similar security mistakes. But attaining a secure cloud posture is not an easy task. It involves procuring, integrating and managing dozens of point security products, as well as making all the necessary changes to processes, staff training and resource utilization.

In addition, even when a secure cloud environment is achieved, it must be maintained through constant monitoring, periodic risk reassessments and other techniques. Controls must be established that comprehensively address:

  • Risk management, which must be assessed both initially and periodically.
  • Security architecture. A careful analysis of how the organization fulfills its unique security requirements.
  • Incident handling, involving the creation of an entire program covering the incidence response lifecycle.
  • Threat management. Deploying technologies to identify and investigate potential threats and instituting ongoing practices to prevent them.
  • Vulnerability management, which entails identifying and remediating exploitable flaws and configuration errors in software.
  • Change control. Tracking additions, alterations and removals that might affect and organization's security architecture, and
  • Data security lifecycle support. Employing encryption technologies to protect data in transit and data at rest as well as secure backup, restore and deletion capabilities.*

As the survey results showed, it is unlikely that these tasks will be accomplished by an organization's internal IT team given that it may not even participate in the selection or know about the SaaS applications deployed by business users. That means that business users and, by default, their organizations, are relying on the SaaS provider to ensure that adequate security protections are in place, which may not be an accurate assumption.

Simplifying security for SaaS applications
Rather than attempting to accomplish all the foregoing tasks internally, organizations needing to protect sensitive data can simplify the process by investigating whether the cloud infrastructures that store their data workloads, applications and assets are secure. When it comes to SaaS applications, an important consideration is whether the SaaS provider is partnering with a secure cloud hosting provider that has the expertise and technologies in place to ensure proactive protection of the organization's sensitive data. The secure cloud hosting provider should have the ability to accomplish all of the foregoing tasks, maintaining security for all applications and data that the organization accesses through the cloud. This approach has the potential to be much more cost effective, efficient and comprehensive for the organization than attempting to handle cloud security using internal IT resources.

In order to ensure a secure cloud environment, an organization should confirm that the following three objectives are met:

  • The organization has achieved complete visibility within the cloud environment.
  • Dwell time - the amount of time that a threat actor remains undiscovered and unmitigated within the environment - should be reduced from weeks or months to days or even hours.
  • Lesser threat actors should be automatically blocked so that the security controls - including technology and trained personnel - can focus on finding and stopping more sophisticated threats.*

Combining a cloud-based SaaS solution for generating highly regulated customer documents with secure cloud hosting of all deployments of this and other SaaS platforms in the organization has the potential to provide the best possible security while enhancing the organizations agility when delivering regulated communications to customers.

This approach can provide a comprehensive way to ensure security of data while also meeting an organization's threshold compliance requirements for compliant customer communications.

*See Armor White Paper, "Inside the 6 principal layers of the cloud security stack"

More Stories By Waqar Ahmad

Waqar Ahmad is Chief Information Security Officer for Elixir Technologies. He is a senior advisor to the solutions architect group and served as Elixir’s vice president of engineering for 10 years. Visit www.elixir.com for more information.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
In his session at 21st Cloud Expo, Carl J. Levine, Senior Technical Evangelist for NS1, will objectively discuss how DNS is used to solve Digital Transformation challenges in large SaaS applications, CDNs, AdTech platforms, and other demanding use cases. Carl J. Levine is the Senior Technical Evangelist for NS1. A veteran of the Internet Infrastructure space, he has over a decade of experience with startups, networking protocols and Internet infrastructure, combined with the unique ability to it...
"There's plenty of bandwidth out there but it's never in the right place. So what Cedexis does is uses data to work out the best pathways to get data from the origin to the person who wants to get it," explained Simon Jones, Evangelist and Head of Marketing at Cedexis, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
"Cloud Academy is an enterprise training platform for the cloud, specifically public clouds. We offer guided learning experiences on AWS, Azure, Google Cloud and all the surrounding methodologies and technologies that you need to know and your teams need to know in order to leverage the full benefits of the cloud," explained Alex Brower, VP of Marketing at Cloud Academy, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clar...
Large industrial manufacturing organizations are adopting the agile principles of cloud software companies. The industrial manufacturing development process has not scaled over time. Now that design CAD teams are geographically distributed, centralizing their work is key. With large multi-gigabyte projects, outdated tools have stifled industrial team agility, time-to-market milestones, and impacted P&L stakeholders.
Gemini is Yahoo’s native and search advertising platform. To ensure the quality of a complex distributed system that spans multiple products and components and across various desktop websites and mobile app and web experiences – both Yahoo owned and operated and third-party syndication (supply), with complex interaction with more than a billion users and numerous advertisers globally (demand) – it becomes imperative to automate a set of end-to-end tests 24x7 to detect bugs and regression. In th...
"Akvelon is a software development company and we also provide consultancy services to folks who are looking to scale or accelerate their engineering roadmaps," explained Jeremiah Mothersell, Marketing Manager at Akvelon, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
"MobiDev is a software development company and we do complex, custom software development for everybody from entrepreneurs to large enterprises," explained Alan Winters, U.S. Head of Business Development at MobiDev, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
SYS-CON Events announced today that CrowdReviews.com has been named “Media Sponsor” of SYS-CON's 22nd International Cloud Expo, which will take place on June 5–7, 2018, at the Javits Center in New York City, NY. CrowdReviews.com is a transparent online platform for determining which products and services are the best based on the opinion of the crowd. The crowd consists of Internet users that have experienced products and services first-hand and have an interest in letting other potential buye...
"IBM is really all in on blockchain. We take a look at sort of the history of blockchain ledger technologies. It started out with bitcoin, Ethereum, and IBM evaluated these particular blockchain technologies and found they were anonymous and permissionless and that many companies were looking for permissioned blockchain," stated René Bostic, Technical VP of the IBM Cloud Unit in North America, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Conventi...
SYS-CON Events announced today that Telecom Reseller has been named “Media Sponsor” of SYS-CON's 22nd International Cloud Expo, which will take place on June 5-7, 2018, at the Javits Center in New York, NY. Telecom Reseller reports on Unified Communications, UCaaS, BPaaS for enterprise and SMBs. They report extensively on both customer premises based solutions such as IP-PBX as well as cloud based and hosted platforms.
"Space Monkey by Vivent Smart Home is a product that is a distributed cloud-based edge storage network. Vivent Smart Home, our parent company, is a smart home provider that places a lot of hard drives across homes in North America," explained JT Olds, Director of Engineering, and Brandon Crowfeather, Product Manager, at Vivint Smart Home, in this SYS-CON.tv interview at @ThingsExpo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
Coca-Cola’s Google powered digital signage system lays the groundwork for a more valuable connection between Coke and its customers. Digital signs pair software with high-resolution displays so that a message can be changed instantly based on what the operator wants to communicate or sell. In their Day 3 Keynote at 21st Cloud Expo, Greg Chambers, Global Group Director, Digital Innovation, Coca-Cola, and Vidya Nagarajan, a Senior Product Manager at Google, discussed how from store operations and ...
It is of utmost importance for the future success of WebRTC to ensure that interoperability is operational between web browsers and any WebRTC-compliant client. To be guaranteed as operational and effective, interoperability must be tested extensively by establishing WebRTC data and media connections between different web browsers running on different devices and operating systems. In his session at WebRTC Summit at @ThingsExpo, Dr. Alex Gouaillard, CEO and Founder of CoSMo Software, presented ...
WebRTC is great technology to build your own communication tools. It will be even more exciting experience it with advanced devices, such as a 360 Camera, 360 microphone, and a depth sensor camera. In his session at @ThingsExpo, Masashi Ganeko, a manager at INFOCOM Corporation, introduced two experimental projects from his team and what they learned from them. "Shotoku Tamago" uses the robot audition software HARK to track speakers in 360 video of a remote party. "Virtual Teleport" uses a multip...
A strange thing is happening along the way to the Internet of Things, namely far too many devices to work with and manage. It has become clear that we'll need much higher efficiency user experiences that can allow us to more easily and scalably work with the thousands of devices that will soon be in each of our lives. Enter the conversational interface revolution, combining bots we can literally talk with, gesture to, and even direct with our thoughts, with embedded artificial intelligence, whic...
SYS-CON Events announced today that Evatronix will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Evatronix SA offers comprehensive solutions in the design and implementation of electronic systems, in CAD / CAM deployment, and also is a designer and manufacturer of advanced 3D scanners for professional applications.
Leading companies, from the Global Fortune 500 to the smallest companies, are adopting hybrid cloud as the path to business advantage. Hybrid cloud depends on cloud services and on-premises infrastructure working in unison. Successful implementations require new levels of data mobility, enabled by an automated and seamless flow across on-premises and cloud resources. In his general session at 21st Cloud Expo, Greg Tevis, an IBM Storage Software Technical Strategist and Customer Solution Architec...
To get the most out of their data, successful companies are not focusing on queries and data lakes, they are actively integrating analytics into their operations with a data-first application development approach. Real-time adjustments to improve revenues, reduce costs, or mitigate risk rely on applications that minimize latency on a variety of data sources. In his session at @BigDataExpo, Jack Norris, Senior Vice President, Data and Applications at MapR Technologies, reviewed best practices to ...
An increasing number of companies are creating products that combine data with analytical capabilities. Running interactive queries on Big Data requires complex architectures to store and query data effectively, typically involving data streams, an choosing efficient file format/database and multiple independent systems that are tied together through custom-engineered pipelines. In his session at @BigDataExpo at @ThingsExpo, Tomer Levi, a senior software engineer at Intel’s Advanced Analytics gr...
When talking IoT we often focus on the devices, the sensors, the hardware itself. The new smart appliances, the new smart or self-driving cars (which are amalgamations of many ‘things’). When we are looking at the world of IoT, we should take a step back, look at the big picture. What value are these devices providing? IoT is not about the devices, it’s about the data consumed and generated. The devices are tools, mechanisms, conduits. In his session at Internet of Things at Cloud Expo | DXWor...