Upload
tony-riley
View
117
Download
4
Embed Size (px)
Citation preview
Copyright Oper8 Pty Ltd 17/06/2014 Presented by : Tony Riley
Document ManagementO
per8 Cloud and Managed Services
“It takes many good deeds to build a good reputation, and only one bad one to lose IT.”- Benjamin Franklin
And Security
Copyright Oper8 Pty Ltd 17/06/2014 Presented by : Tony Riley
Document ManagementO
per8 Cloud and Managed Services
PERMISSION SYSTEMS ARE TYPICALLY COMPLICATED
• Complication leads to errors• Security needs need to be communicated to IT staff• A system which allowed the individual to completely control
access would reduce this risk
PHYSICAL SECURITY OF SERVERS, LAPTOPS and DEVICES
• Theft and loss constitute a huge security risk• Data or equipment theft can stop your business in its tracks
• Cloud based storage reduces this risk to almost zero
Copyright Oper8 Pty Ltd 17/06/2014 Presented by : Tony Riley
Document ManagementO
per8 Cloud and Managed Services
KNOW WHERE YOUR FILES ARE• Cloud services typically give you no control over
where your files are stored• Caching within cloud services can further
confuse the issue• You could be inadvertently breaking Australian Privacy
Principles by moving your data offshore without notifying your clients
• A cloud service which lets you control the location of your files would reduce this risk to zero?
Copyright Oper8 Pty Ltd 17/06/2014 Presented by : Tony Riley
Document ManagementO
per8 Cloud and Managed Services
TRACKING ACCESS TO FILES IS IMPORTANT
• Metadata is valuable (information about your Data)
ONSITE BACKUPS ARE INSECURE AND CREATE PRIVACY RISKS• Backups are typically carried around a lot
• Rely on Human intervention• Easily lost or damaged
• A cloud based automated backup service would reduce this risk to zero
• The fact that a file has been accessed is important in itself and leaking of this information
is a privacy risk• A cloud based service which treats metadata as valuable would
reduce this risk
Copyright Oper8 Pty Ltd 17/06/2014 Presented by : Tony Riley
Document ManagementO
per8 Cloud and Managed Services
NETWORK PROTECTION IS NO LONGER RELEVANT• There is a shift to Identity Based Access• Two-factor authentication is becoming more common• A cloud service which offers two-factor authentication reduces
the risk of improper access
“DO NOT TRACK” matters
• Cloud/Web services typically track everything• This leads to the retention of unnecessary
information – breaks Australian Privacy Principles• A service which allows you to control tracking would reduce
this risk
Copyright Oper8 Pty Ltd 17/06/2014 Presented by : Tony Riley
Document ManagementO
per8 Cloud and Managed Services
ENCRYPTION IS IMPORTANT
• Local servers and laptops are typically not encrypted• Having your files unencrypted makes it easy for hackers• A cloud based service which looks after encryption reduces this
risk HEARTBLEED• Was a real problem (CloudFlare was hijacked
within 3 hours of the challenge)• We have no idea (and probably never will know) what information leaked because of it
• A service that was not affected by Heartbleed type issues would be a good choice
Copyright Oper8 Pty Ltd 17/06/2014 Presented by : Tony Riley
Document ManagementO
per8 Cloud and Managed Services
EMAIL IS INSECURE
• Businesses still send confidential content via email• Email servers can be accessed by administrators and IT support• A service which allows the secure transfer of documents would
remove this risk
Questions ??Contact : Tony Riley [email protected]