Cloud Channel Summit 2015 @rhipecloud #RCCS15



Similar documents
The Cloud Security Alliance

TOOLS and BEST PRACTICES

A view from the Cloud Security Alliance peephole

Open Certification Framework. Vision Statement

Global Efforts to Secure Cloud Computing. Jason Witty President, Cloud Security Alliance Chicago

Asia Pacific the Future of Cloud Computing

Assessing Risks in the Cloud

Privacy Compliance and Security SLA: CSA addressing the challenges

GRC Stack Research Sponsorship

Welcome to UL Protecting People, Products and Places

Building an Effective

Corporate Presentation

Accelerating Cloud adoption with Security Level Agreements automation, monitoring and industry standards compliance

Cloud Security considerations for business adoption. Ricci IEONG CSA-HK&M Chapter

Information Security ISO Standards. Feb 11, Glen Bruce Director, Enterprise Risk Security & Privacy

GLOBAL PAYMENTS AND CASH MANAGEMENT. Solutions For Asia-Pacific

Global Student Mobility 2025 Forecasts of the Global Demand for Pathways to Higher Education in the Schools, VET and ELICOS sectors

European Cloud Computing. Strategy. Cloud standards. Ken Ducatel DG CONNECT

Cloud Security Certification

Compliance Herausforderung und Chance, auch in Asien-Pazifik

SGS SOFTLINES INTERNATIONAL TRAINING PROGRAM

HUDSON SALARY GUIDES 2015

Progress Exchange 2013

CashPro Online Getting Started Guide. Supply Chain for Sellers

Insurance Overview. Dan Bardin Prudential Corporation Asia November 2004

The Business Enablers Macau

AAPBS. Association of Asia-Pacific Business Schools.

This is a licensed product of Ken Research and should not be copied

ISO 9001:2015 QUALITY MANAGEMENT SYSTEMS AUDITOR/LEAD AUDITOR

BUSINESS INTELLIGENCE & TARGET MARKETING. Copyright CNCData. All Rights Reserved.

CS Awards in Americas

Analysis of Asia Pacific Hosted Market

Flexible Cloud Services to Compete

Radio Spectrum and Technical Standards Advisory Committee

Cloud Security Alliance: Industry Efforts to Secure Cloud Computing

Development Programme

The role of certification and standards for trusted Cloud solutions

Wrapping Audit Arms around the Cloud Georgia 2013 Conference for College and University Auditors

Medical Tourism Malaysia. Tan Sri Dato Dr Abu Bakar Suleiman President International Medical University (IMU), Kuala Lumpur, Malaysia

Data Risk Management: ISM Ground to Cloud Summit. accelerate your ambition 1

Asia-Pacific Web Application Firewall Market Increasing Attacks on the Application Layer are Driving the Market

VPS Series Static Balancing Valve

J.D. Power Asia Pacific Reports: Price Hikes Spark Sharp Decline in Customer Satisfaction with Auto Insurance Providers

An introduction to BSI

The Southeast Asia Data Centre Market A look at new players and key drivers as well as the opportunities and challenges in Asia

HUDSON SALARY GUIDES 2015

Foreign Taxes Paid and Foreign Source Income INTECH Global Income Managed Volatility Fund

The Shifting Datacentre Landscape. Sally Parker, Research Director Enterprise Systems, Software and Services

The Importance of International Services Standardisation in Australia

Sybase Solutions for Healthcare Adapting to an Evolving Business and Regulatory Environment

Recruitment Process Outsourcing (RPO)

Asia-Pacific Datacenter Services Market 2010 New Contenders Emerging on the Horizon

Asia-Pacific Secure Content Management Market 2012 Stable Growth is Anticipated in the and Web Security Segments

CashPro Online Getting Started Guide. Automated Clearing House

FACT SHEET INTERNATIONAL SERVICES GLOBAL INTERNET ACCESS (GIA)

Overview of Asian Insurance Markets

High Level Importance: ISO Microbiology compliance

An introduction to EFMD accreditations: EQUIS and EPAS

Christopher Findlay University of Adelaide. Hussain G. Rammal University of South Australia

10.0 FPSB s Country/region-specific Trademark Symbols and Legal Notices

Tel (03) Fax (03) ACIIA ADVOCACY PROJECT ASIAN STOCK EXCHANGE PERSPECTIVES ON INTERNAL AUDIT

ISO/IEC/IEEE The New International Software Testing Standards

michael page international Asia Pacifi c Global strength. regional expertise. local partnerships.

Fast, scalable and CAPEX-free servers in Pacnet's advanced data centers PACNET HARDWARE-AS-A-SERVICE

Corporate Jet & Helicopter Finance Asia 2013

Governance, Risk and Compliance Assessment

Transformation of payment systems: channels, technologies and business models

Achieving Functional Safety with Global Resources and Market Reach

Deploying Cloud Security Standards The MTCS Experience

Building a Logistics/Supply Chain Hub The Singapore Experience. Hum SinHoon NUS Business School National University of Singapore

Functional Safety Certification and the ULA

Cloud Security. Nantawan Wongkachonkitti Electronic Government Agency, Thailand Cloud Security Alliance, Thailand Chapter October 2014

Asian Stock Markets in 2015:

Need to reassure customers that your cloud services are secure? Inspire confidence with STAR Certification from BSI

Introduction Animation in Asian Societies Establishment of Local Animation Industry LOCAL CONTENT PRODUCTIONS SUCCESSFUL BUSINESS MODELS Drivers for

FedEx is the preferred and primary courier company for BP small package, parcel and express envelope (up to 150 lbs.) requirements worldwide.

opinion piece IT Security and Compliance: They can Live Happily Ever After

Need to reassure customers that your cloud services are secure? Inspire confidence with STAR Certification from BSI

CCH Online Library DEEP LINKING & PRODUCT CONTENT DEEP LINK LIST. Page 1

Submission to the Ministry of Business, Innovation and Employment, on the Issues Paper:

The role, responsibilities and status of the clinical medical physicist in AFOMP

AIA Singapore Launches FIRST-IN-MARKET Mobile Application for Employees to View Their Employee Benefits and Submit Insurance Claims on the Go

Websalad Connect. A fresh approach to digital marketing... PAGE 1

Pacnet MPLS-Based IP VPN Keeping pace with your growth

Transcription:

Cloud Channel Summit 2015 @rhipecloud #RCCS15

About the Cloud Security Alliance Global, not-for-profit organisation 300 member driven organization with over 56,000 individual members in 65 chapters worldwide Building best practices and a trusted cloud ecosystem Agile philosophy, rapid development of applied research GRC: Balance compliance with risk management Reference models: build using existing standards Identity: a key foundation of a functioning cloud economy Champion interoperability Enable innovation Advocacy of prudent public policy To promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing.

Regional HQ based in Singapore; registered as a Company Limited by Guarantee in August 2012 Representative office in Beijing established in 2014 22 Chapters, 2 regional coordinating bodies Official chapters *Japan Korea Greater China Regional Coordinating Body Beijing, Shanghai, Guangzhou *Hong Kong & Macau, *Taiwan *Thailand Singapore India Regional Coordinating Body Mumbai, Bangalore, NCR, Hydrabad Australia *New Zealand Malaysia In development chapters Indonesia Pakistan Islamabad India New Delhi, Chennai, Pune

(Perceived) Loss of control Lack of clarity around the definition and attribution of responsibilities and liabilities Difficulties achieving accountability across the cloud supply chain Incoherent global (and even sometimes regional and national) legal framework and compliance regimes Cloud Barriers

.and more barriers The lack of transparency of some service providers or brokers Lack of clarity in Service Level Agreements Lack of interoperability Lack of awareness and expertise

In 3 words: LACK OF TRUST Copyright 2011 Cloud Security Alliance www.cloudsecurityalliance.org

HOW DO WE BUILD TRUST & TRANSPARENCY?

Certification for cloud services In US Looked upon as a critical service to be provided by AICPA members In the Agenda of the EU Requested from Art29 WP as a measure for privacy compliance various Member States are looking at a certification/accreditation schema for cloud service (especially in Public Procurement) In APAC Already part of the cloud strategy in countries such as Singapore, Thailand, China, Hong Kong and Taiwan to leverage CSA STAR into national cloud certification scheme or public procurement requirement

Requirements Provide a globally relevant certification to reduce duplication of efforts Address localized, national-state and regional compliance needs Address industry specific requirements Address different assurance requirements Address certification staleness assure provider is still secure after point in time certification User-centric Voluntary, business driven Leverage global standards/schemes Do all of the above while recognizing the dynamic and fast-changing world that is cloud

Objectives To improve customer trust in cloud services To improve security of cloud services To increase the efficiency of cloud service procurement To make it easier for cloud providers and customers to achieve compliance To provide greater transparency to customers about provider security practices To achieve all the above objectives as cost-effectively as possible

The Answer from Cloud Security Alliance

CSA STAR: Security, Trust & Assurance Registry Launched in 2011, the CSA STAR is the first step in improving transparency and assurance in the cloud. Searchable registry to allow cloud customers to review the security practices of providers, accelerating their due diligence and leading to higher quality procurement experiences. The STAR is a publicly accessible registry that documents the security controls provided by cloud computing offerings Helps users to assess the security of cloud providers It is based on a multilayered structure defined by Open Certification Framework Working Group

What is CSA STAR Certification? Optimizing Cloud Security, Trust and Transparency The CSA STAR Certification is a rigorous third party independent assessment of the security of a cloud service provider. Technology-neutral certification leverages the requirements of the ISO/IEC 27001:2005 & the CSA Cloud Controls Matrix (CCM) Integrates ISO/IEC 27001:2005 with the CSA CCM as additional or compensating controls. Measures the capability levels of the cloud service. It assigns a Management Capability score to each of the CCM security domains.

The OCF structure The CSA Open Certification Framework is an industry initiative to allow global, accredited, trusted certification of cloud providers.

STAR Certification: Certificate

Approving Assessors They must demonstrate knowledge of the Cloud Sector Either through verifiable industry experience this can include though assessing organizations Or through completing CCSK certification or equivalent They must be a qualified auditor working a ISO 27006 accredited CB Evidence of conducting ISO 27001 assessments for a certification body accredited by an IAF member to ISO 27006 or their qualifications as an auditor for that organization. They must complete the CSA approved course qualifying them to audit the CCM for STAR Certification (This course will be carried out by BSI)

Members Network in Asia Pacific

Government Relationship

Key MOUs signed P-P-P Research Singapore Institute of Technology CEPREI Certification Body (The Fifth Electronic Institute of Ministry of Industry and Information Technology) China Electronics Standardization Institution of Ministry of Industry and Information Technology Institute of High Energy Physics (IHEP), Chinese Academy of Science China Cloud OS Pioneer Strategic Alliance (CCOPSA) China Advanced Technology Investment Ltd The Cloud Identity Institute of Peking University s College of Engineering HP China University of Waikato University of Mahidol

Introducing Certificate of Cloud Security Knowledge (CCSK) The industry s first user certification program for secure cloud computing Based on CSA research framework, specifically the Security Guidance for Critical Area of Focus in Cloud Computing Designed to ensure that a broad range of professionals with responsibility related to cloud computing have a demonstrated awareness of the security threats and best practices for securing the cloud

CSA EVENTS CSA ASEAN Summit June 11-12, 2015, Bangkok, Thailand CSA APAC Summit July 21, 2015, Singapore CSA Innovation Conference October 28-29, 2015, Singapore CSA APAC Congress (tentative) November 11-12, 2015, Beijing, China

Very important No Certification can ever guarantee information is 100% secure however STAR certification ensures an organisation has an appropriate system for the type of information it is dealing with and that it is well managed and focused on cloud specific concerns.

Contact us www.cloudsecurityalliance.org info@cloudsecurityalliance.org www.linkedin.com/groups?gid=1864210 @cloudsa Enquiries.my@rhipe.com