Over a million developers have joined DZone.
{{announcement.body}}
{{announcement.title}}

Will Your Cloud Provider Play Nice With Your Third-Party Security Vendor? [Video]

DZone's Guide to

Will Your Cloud Provider Play Nice With Your Third-Party Security Vendor? [Video]

Watch this interview, which delves into the murky area of cloud security. At the end of the day, the important question to keep in mind is, ''Who configures what?''

· Cloud Zone
Free Resource

MongoDB Atlas is a database as a service that makes it easy to deploy, manage, and scale MongoDB. So you can focus on innovation, not operations. Brought to you in partnership with MongoDB.

When a company moves to the cloud, there are many parties responsible for security. Even with contracts, it may not always be clear where the boundaries of responsibility between the companies, the users, the cloud providers, and third-party security vendors lie. Security professionals I spoke to at both the Black Hat USA 2016 conference and Security BSides Las Vegas noted they’ve had clients who were surprised to discover a certain security service was not offered by their cloud provider, even though it was written out in the contract.

“You want to be clear on who is in charge of what when it comes to delivering your security needs in the cloud infrastructure especially when they’re delivered by a third party vendor,” said Keren Elazari (@k3r3n3), an independent security consultant, researcher with Tel Aviv University, and founder of Security BSides Tel Aviv.

The confusion really comes into play when an organization hires a third party vendor to work with the cloud provider.

Ultimately, Elazari said you simply have to ask, “Who configures what?”

For example, a web application firewall is delivered on the cloud and usually by the cloud as well. “You want to be clear that you can use those web application firewall services in the cloud and that the provider that is giving you the infrastructure for the cloud is going to play nicely with your security provider,” said Elazari.

MongoDB Atlas is the best way to run MongoDB on AWS — highly secure by default, highly available, and fully elastic. Get started free. Brought to you in partnership with MongoDB.

Topics:
cloud ,security ,application ,service ,cloud infrastructure ,cloud providers ,vendors

Published at DZone with permission of David Spark. See the original article here.

Opinions expressed by DZone contributors are their own.

The best of DZone straight to your inbox.

SEE AN EXAMPLE
Please provide a valid email address.

Thanks for subscribing!

Awesome! Check your inbox to verify your email so you can start receiving the latest in tech news and resources.
Subscribe

{{ parent.title || parent.header.title}}

{{ parent.tldr }}

{{ parent.urlSource.name }}