<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Simple effective cloud adoption and strategy in Cloud Security</title>
    <link>https://community.isc2.org/t5/Cloud-Security/Simple-effective-cloud-adoption-and-strategy/m-p/47097#M94</link>
    <description>&lt;P&gt;Thanks john for taking time to reply. that was not really my question. i know about these things CCM, CAIQ, etc... my query is basically how to have a simple cloud adoption strategy and approach so the amount of time spent doing assessment (looking up CAIQ, do CCM mapping, etc) or invoke entire cloud assessment and assurance activity by line two becomes really less. is there a cloud adoption model that we can follow after which such burden of assessment , mapping and reassessment can get reduced or get slimmer or more efficient? ok i know for a fact that if we stick to the same cloud provider, things may be less headache in terms of assurance and assessment of controls (e.g once comprehensively done for AWS then that's it, i dont have to do the heavy lifting again and again) or if we force all services to for example use the once-assessed-and-approved Federation, SSO or IDAM then bingo i dont have to every time do SSO or identify service reassessemnt, etc. i hope i could clarify it. thanks again in advance for any insight.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Aug 2021 10:33:57 GMT</pubDate>
    <dc:creator>rami99</dc:creator>
    <dc:date>2021-08-24T10:33:57Z</dc:date>
    <item>
      <title>Simple effective cloud adoption and strategy</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Simple-effective-cloud-adoption-and-strategy/m-p/47076#M92</link>
      <description>&lt;DIV class="col-md-10 no-gutter"&gt;&lt;SPAN&gt;Hi All,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;As line two looking at cloud risk, I want to know what strategy / architecture can be adopted for a customer (banking) who has so far adopted cloud in a fragmented manner with no centralized model (dump things here and there, open tenants here tenants there across AWS, Azure, Google) causing whole painful and time-consuming yet inefficient cloud / tenant reassessment for risk and security teams every time they open a tenant or introduce a cloud service, etc. With the aim to achieve simplification and consistency across cloud controls and ongoing cloud assurance and assessment. I am looking for a recommendation / strategy to rectify what is already in place and avoid ad-hoc ineffective cloud adoption as business initiatives come up. A robust model / approach to address above mentioned challenges. Please also share any article / resources for this matter.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you in advance.&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 23 Aug 2021 11:14:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Simple-effective-cloud-adoption-and-strategy/m-p/47076#M92</guid>
      <dc:creator>rami99</dc:creator>
      <dc:date>2021-08-23T11:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: Simple effective cloud adoption and strategy</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Simple-effective-cloud-adoption-and-strategy/m-p/47078#M93</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/100709149"&gt;@rami99&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For each big cloud provider, they already have a set of "compliance" check with the industry. You can first look at those, and also understand the share responsibility model depends on the service they provided and what are the responsibility of the CSP and your organisation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example as banking (I assume you are in US), you might look at SOX and also mapping your organisation security control with the cloud security control ( eg. looking at CCM).. eg AWS one.&lt;/P&gt;&lt;P&gt;&lt;A href="https://d1.awsstatic.com/whitepapers/compliance/CSA_Consensus_Assessments_Initiative_Questionnaire.pdf" target="_blank"&gt;https://d1.awsstatic.com/whitepapers/compliance/CSA_Consensus_Assessments_Initiative_Questionnaire.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 12:05:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Simple-effective-cloud-adoption-and-strategy/m-p/47078#M93</guid>
      <dc:creator>csjohnng</dc:creator>
      <dc:date>2021-08-23T12:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: Simple effective cloud adoption and strategy</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Simple-effective-cloud-adoption-and-strategy/m-p/47097#M94</link>
      <description>&lt;P&gt;Thanks john for taking time to reply. that was not really my question. i know about these things CCM, CAIQ, etc... my query is basically how to have a simple cloud adoption strategy and approach so the amount of time spent doing assessment (looking up CAIQ, do CCM mapping, etc) or invoke entire cloud assessment and assurance activity by line two becomes really less. is there a cloud adoption model that we can follow after which such burden of assessment , mapping and reassessment can get reduced or get slimmer or more efficient? ok i know for a fact that if we stick to the same cloud provider, things may be less headache in terms of assurance and assessment of controls (e.g once comprehensively done for AWS then that's it, i dont have to do the heavy lifting again and again) or if we force all services to for example use the once-assessed-and-approved Federation, SSO or IDAM then bingo i dont have to every time do SSO or identify service reassessemnt, etc. i hope i could clarify it. thanks again in advance for any insight.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 10:33:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Simple-effective-cloud-adoption-and-strategy/m-p/47097#M94</guid>
      <dc:creator>rami99</dc:creator>
      <dc:date>2021-08-24T10:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: Simple effective cloud adoption and strategy</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Simple-effective-cloud-adoption-and-strategy/m-p/47986#M104</link>
      <description>&lt;P&gt;Hi Rami, I know this question is a bit outdated but I consider it is very common and something&amp;nbsp; we all have to face. It's my case, we have deployed resources in Azure, then also in AWS and GCP, and at "business speed".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no magic, and I totally agree with you. Going absolutely formal is not going to help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My approach:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Probably there is one cloud service that is a bit more mature, from the operational - management perspective of your organization. More policies, more processes and guidelines (written or absolutely informal). IT people (I'm an IT guy) like order and formality. Probably they are following some kind of practice even if it is not written.&lt;/P&gt;&lt;P&gt;- Start there. Prepare the policies (high level) for the mature part.&lt;/P&gt;&lt;P&gt;- Implement them. That is when things go weird. It is easy and cost-effective to use the tools provided by that mature CSP, but your company is multi-cloud. Isn't it? This requires tools and money or the creation of different teams for every cloud. I know people will blame me, but I'm talking about the real world. Second approach is a mess, and only high-level policies will work, but with the appropriate people, it can be an option.&lt;/P&gt;&lt;P&gt;- Extend the policies and processes. Cloud by cloud. If they are based in "agnostic" tools, perfect. If not, different teams and try to consolidate as much as possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What companies are not aware of is that multi-cloud is expensive, really expensive, and throwing workloads to the "cheapest" one is good is they assume the risks (and that is also a solution). Do not assume the responsibility. Tools or teams. Probably is not the best and adequate response expected in this kind of board, but I know you are in trouble and need practical help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm sure you will get it to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis. Security Engineer. IT manager.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 08:19:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Simple-effective-cloud-adoption-and-strategy/m-p/47986#M104</guid>
      <dc:creator>luisantonio</dc:creator>
      <dc:date>2021-10-20T08:19:59Z</dc:date>
    </item>
  </channel>
</rss>

