<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failing on Cloud Security in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Failing-on-Cloud-Security/m-p/26945#M3373</link>
    <description>&lt;P&gt;I think the model is fine currently, my thoughts are a&amp;nbsp;lot of this comes down directly to training or lack of sufficient or appropriate training for all people/stakeholders: Cloud Architects, Application Developers and the management of IT teams. If managers had appropriate awareness and training, they could adopt and implement appropriate processes to handle cloud.&lt;BR /&gt;&lt;BR /&gt;I also see Shadow IT is the biggest cause of the above issues. in such a fast, agile cloud-native, SaaS world, managers and departments are frequently bypassing the safeguards and slow and monolithic change controls of IT. Which again comes to due to lack of appropriate processes and control.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;As it drilled into us, Security is driven from the top down.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Aug 2019 14:02:51 GMT</pubDate>
    <dc:creator>Wayne_Evans</dc:creator>
    <dc:date>2019-08-16T14:02:51Z</dc:date>
    <item>
      <title>Failing on Cloud Security</title>
      <link>https://community.isc2.org/t5/Industry-News/Failing-on-Cloud-Security/m-p/26510#M3322</link>
      <description>&lt;P&gt;The tipping point for cloud security has arrived and very few organizations are ready &lt;A href="https://resource.elq.symantec.com/e/f2" target="_blank" rel="noopener"&gt;reports&lt;/A&gt; Symantec.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Key takeaways from the report include:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;83% claimed they don’t have the right processes in place to effectively manage security incidents&lt;/LI&gt;&lt;LI&gt;93% said they are having trouble keeping track of workloads&lt;/LI&gt;&lt;LI&gt;73% said they’ve experienced an incident because their cloud security isn’t mature enough&lt;/LI&gt;&lt;LI&gt;65% of organizations failed to implement MFA in IaaS environments&lt;/LI&gt;&lt;LI&gt;80% don’t use encryption&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I really wonder whether the CSP shared responsibility model is the problem? Certainly, its not the solution since the survey says security professionals are not architecting security into their cloud deployments.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:17:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Failing-on-Cloud-Security/m-p/26510#M3322</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2023-10-09T09:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Failing on Cloud Security</title>
      <link>https://community.isc2.org/t5/Industry-News/Failing-on-Cloud-Security/m-p/26620#M3344</link>
      <description>&lt;P&gt;So what do you think could be the solution. The one problem that I can highlight is that low quality cloud architect and not enough resources to manage &lt;A href="https://www.cloudways.com/blog/best-iaas-providers/" target="_blank" rel="noopener"&gt;iaas cloud infrastructure&lt;/A&gt;. Management of cloud securirty could be a very tricky task and to counter it you need a dedicated team for cloud architects which could cost you a lot. So, most organization don't pay much attention in this department and thus faces the consequences.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 10:27:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Failing-on-Cloud-Security/m-p/26620#M3344</guid>
      <dc:creator>JaimeBurgos</dc:creator>
      <dc:date>2019-08-09T10:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: Failing on Cloud Security</title>
      <link>https://community.isc2.org/t5/Industry-News/Failing-on-Cloud-Security/m-p/26945#M3373</link>
      <description>&lt;P&gt;I think the model is fine currently, my thoughts are a&amp;nbsp;lot of this comes down directly to training or lack of sufficient or appropriate training for all people/stakeholders: Cloud Architects, Application Developers and the management of IT teams. If managers had appropriate awareness and training, they could adopt and implement appropriate processes to handle cloud.&lt;BR /&gt;&lt;BR /&gt;I also see Shadow IT is the biggest cause of the above issues. in such a fast, agile cloud-native, SaaS world, managers and departments are frequently bypassing the safeguards and slow and monolithic change controls of IT. Which again comes to due to lack of appropriate processes and control.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;As it drilled into us, Security is driven from the top down.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 14:02:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Failing-on-Cloud-Security/m-p/26945#M3373</guid>
      <dc:creator>Wayne_Evans</dc:creator>
      <dc:date>2019-08-16T14:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Failing on Cloud Security</title>
      <link>https://community.isc2.org/t5/Industry-News/Failing-on-Cloud-Security/m-p/26965#M3378</link>
      <description>&lt;P&gt;Please.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remember: "cloud" is not new. "Cloud" is not magic. "Cloud" isn't really even a thing. It just means "somebody else's computer." You need to know how much (and what type) of protection they do, what protection you need, and how to patch any gaps.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 19:34:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Failing-on-Cloud-Security/m-p/26965#M3378</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-08-16T19:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: Failing on Cloud Security</title>
      <link>https://community.isc2.org/t5/Industry-News/Failing-on-Cloud-Security/m-p/27026#M3387</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Please.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remember: "cloud" is not new. "Cloud" is not magic. "Cloud" isn't really even a thing. It just means "somebody else's computer." You need to know how much (and what type) of protection they do, what protection you need, and how to patch any gaps.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Essentially, CLOUD is simply "off-premises, and usually&amp;nbsp;someone else's, computer."&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not really much different from the old IBM 360 Time Sharing days.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 20:54:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Failing-on-Cloud-Security/m-p/27026#M3387</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2019-08-18T20:54:15Z</dc:date>
    </item>
  </channel>
</rss>

