Businesses of all sizes are looking for Cloud solutions to solve some of their biggest business and technology challenges-reducing costs, creating new levels of efficiency, transform to create agile environment and facilitate innovative business models. Along with the promise of Cloud comes top concern for Security. With rise of applications, transactions and data in the Cloud, business are losing control and have less visibility on who and what is moving in and out of the business boundaries.
Any transformation initiative with Cloud, whether a private, hybrid or public, with early focus on security from architecture, governance, risks, threats and compliance perspective can enable the business with a compelling return on investment with a faster time to business value -regardless of geographic, industry vertical, operational diversity or regulatory needs.
Here, I would like to bring to your attention on Cisco Domain Ten framework v2.0 and my blog on What's New in Cisco Domain Ten Framework 2.0 that is born from Cisco's hard won experience of deploying both private, hybrid and public Cloud environments, Cisco has developed the Cisco Domain Ten framework and capabilities to help customers accelerate IT transformation.
The Cisco Domain Ten does not prescribe that customersmustbuild each domain into their strategy -rather it provides guidance on what aspects should be considered, what impacts should be identified, and what relationships exist between domains. Cisco Domain Ten framework 2.0, we can establish the foundation of a true IT transformation and the factors you need to consider forsuccess. Key is to identify, establish and track strategic, operational and technological outcomes for IT transformation initiates. A major thrust of the Cisco Domain Ten is to help customers strategize for transformation vision, standardize their technology components and operational procedures, and automate their management challenges, to deliver on the potential of IT Transformation-covering Internet, Branch, Campus and Data Center environments.
Security consistently tops CIO's list of cloud concerns. The security domain highlights identification ofsecurity and compliancerequirements, along with an assessment of current vulnerabilities and deviations from security best practices for multisite, multitenant physical and virtual environments for one's IT transformation vision.
Security should be a major consideration in any IT transformation strategy. The architecture should be designed and developed with security for applications, network, mobile devices, data, and transactions across on-premise and off-premise solutions. Moreover, security considerations for people, process, tools, and compliance needs should be assessed by experts who understand how to incorporate security and compliance safeguards into complex IT transformation initiatives.
Security is an integral part of the Cisco Domain Ten framework, applies to all ten domains, and provides guidance to customers on all security aspects that they needs. Our Senior Architect from Security Practice -Ahmed Abro articulates well in Figure -1 Cisco Domain Ten Framework with Security Overlay that there are security considerations for all ten domains for Cloud solutions.
Figure -1 Cisco Domain Ten with Security Overlay
Now that we understand how Cisco's Domain Ten Overlay approach that helps one to discuss security for each domain of Cisco Domain Ten Framework, let's now talk about the how Cisco Domain Ten aligns with Cloud Security Alliance's (CSA) Cloud Control Matrix to discuss the completeness and depth of the approach.
CSA Cloud Control Matrix | Alignment with Cisco Domain Ten |
Application & Interface Security |
|
Audit Assurance & Compliance |
|
Business Continuity Mgmt & Op Resilience |
|
Change Control & Configuration Management |
|
Data Security & Information Lifecycle Mgmt |
|
Datacenter Security Encryption & Key Management |
|
Governance & Risk Management |
|
Human Resources Security |
|
Identity & Access Management |
|
Infrastructure & Virtualization |
|
Interoperability & Portability |
|
Mobile Security |
|
Sec. Incident Mgmt , E-Disc & Cloud Forensics |
|
Supply Chain Mgmt, Transparency & Accountability |
|
Threat & Vulnerability Management |
|
Table -1 CSA Cloud Control Matrix Alignment
with Cisco Domain Ten Framework
From above table, one can see that Cloud Security Alliance Cloud Control Matrix and Cisco Domain Ten aligns well and it also highlights key facts that many areas such as Mobile security requires one to focus on Application and Infrastructure (network, virtual servers), etc to address security needs. One should also note that Cisco Domain Ten's focus on Catalog (Domain 5) & Financials (Domain 6) that highlights security specific SLA and assurance discussions for security controls.
Now that that we discussed, Cisco Domain Ten approach for Security, In the next blog, I would try to discuss how Cisco Service's focus on the strategy, structure, people, process, and system requirements for Security can help business address an increasingly hostile threat environment and help successful migration to Secure Cloud based transformation. We will also discuss current questions in business asks or should ask to understand security and privacy in the vendor's agreements.