Security Standards
February 27, 2012, Cloud Security Alliance Summit, San Francisco—A panel discussed the various national and international standards for security. The challenges are that most of the standards are based on historical and legacy information technologies and they may not apply to cloud environments. Tim Mather from KPMG moderated the panel which included Mark Crandall from Google, Chris Wysopal from Veracode, Ashvin Kamaraju from Vormetric, and Baber Amin from CA technologies.
What standards are under consideration?
Kamaraju answered that the CSA has its cloud control matrix, ISO and others have some existing standards, the federal government has a number of emerging and existing standards which the state and local governments will follow. Commercial entities however will not necessarily adopt government standards.
Wysopal responded that the new European general data protection standard will put all data security under a single European union board, this change will simplify the standards and organizational structures involved in security. The problem is the standard make safe harbor go away and is the first volley in the fight against the US Patriot Act. The standard calls for global response and a 24-hour notification requirement. Failure to meet the notification requirement results of 2 percent of global revenue fine per day per data breach section 2 of this new standard addresses data security
Relevant hardware and software frameworks?
Crandall offered PCI and euro cloud as relevant, both with a good chance to be included in US government requirements. Unfortunately, there is great variation between regulations and judiciary standards, and these different security standards per country cause conflicts in compliance.
Can frameworks provide shallow apps with greater security?
Wysopal suggested that standard PCI DSS provides some application security, but most standards are old. These older standards are based on technologies that are over 10 years old. Federal Risk and Authorization Management Program (FedRAMP) is currently at revision three and working on revision four, and does address commercial services that are supplied to the federal government.
Do standards and alternatives exist for encryption?
Kamaraju offered the NIST standards are used in the US and with all major trading partners except Korea. South Korea uses a different standard which includes hardware additions.
Identity management standards?
Amin stated that the US focuses on identification creation whereas the EU is more concerned with cross-border movements. As a result, they are seen generation becoming a big deal. Federation services would enable authentication authorization & authentication and permit users to carry this event application across jurisdictions. Component level identifications are an unsolved problem.
What are the legal issues in an intra-EU federated ID versus the United States?
Amin noted that Federation technology exists, but data cannot move out of the EU. If people move to the US, they must restart all their security processes.
Crandall added that a pan EU cross-border data flow directive permits the export of data with respect to the EU, and there is no EU law addressing this issue. The US Department of commerce says that safe harbor clauses allow data flow to the US, but these readings didn’t anticipate the Internet and cloud computing. Data location is not the same as data security.
When the various documents have conflicts, how do we determine appropriate jurisdiction? When the EU makes changes and puts them into regulations, houses affect cloud providers in the US who are hosting EU data.
Crandall answered that the new regulations apply to all providers, so customers with data in the EU fall into there is jurisdiction of those separate countries. This is an existing problem with conflicting regulations, so we need cross jurisdictional standards so companies can comply with the majority of those requirements and only have to address the outliers. We need to compress more than 27 separate standards into one.
If encrypted data comes to the US, can someone hold the keys to that data in Europe?
Kamaraju stated that custodianship of the keys equals control and encryption needs key management. Therefore, encryption offers safety and privacy for information protection. The real issue is, what to do with all the data you collect?
Do we really need more regulations and frameworks?
Mather stated that most of these already exist and the challenge is to manage the variations. Most frameworks are cloud aware, and the cloud control metrics from the CSA offer good guidelines.
To defend software agency, do we need to do app vulnerability scans?
Kamaraju said that a risk-based approach is good.
Amin added that these measures only delay breakthroughs and some of the top 10 methods for intrusion are not software.
Wysopal stated that applicable standards should address not just the OS and the top 10, and all of these methods are good starting point for security. They may not be applicable to non-Department of Defense entities.
e-discovery and e-forensics?
Crandall stated that there is an unknown impact in mitigation and both of these technologies add levels of complexity due to various court issues.
Kamaraju opined that the USA Patriot Act and the new EU data security regulations are already in conflict. The new regulations require EU approval to release data into the US.
Wysopal enjoined that the EU protection requirements don’t fully specify lawful access.
Amin commented that cloud services are enterprise entities and not end-users.
Privacy and security, which should have priority?
Wysopal noted that privacy is a superset of security and you need security to make privacy exist.
Crandall appended jurisdictional directives need to address the differing standards.
Should data movement be jurisdiction agnostic?
Crandall answered that safe harbor allows data to move to the US and is included in most standard contract clauses. Unfortunately, the standard contract clauses are not cloud friendly and finding app risks and bindings can ease data transfer issues.
The big issues from the EU data directives?
Amin noted that he’ll take additional work due to the varying standards. The new regulations are simpler and reduce the EU to one set of standards. Some regulations specific to breaches of all contact to only the local authorities rather than to all authorities in Europe, so operational costs and burdens should go down.
Kamaraju added that enterprises are not people. Organizations will integrate their own data and are moving towards more SaaS and IaaS from private clouds per state. The only real issue is movement of sensitive data.
Wysopal amended that with International Traffic in Arms Regulations (ITAR) creates some challenges. People in the US need to look at personal privacy level regulations and move them to be similar to those in the EU.
Other relevant standards?
Kamaraju suggested that Payment Card Industry (PCI) compliance is very important in the financial markets and for e-commerce.
Amin agreed, but the changes with the EU standards require reverse engineering and changes in security levels to address the potential increase in personal information.
Wysopal suggested that there is a challenge to the standard. Data flow requires lawful and timely access, and local-based servers.
Most law enforcement access predates the Internet?
Amin stated that it’s not hard to change technology and adds a small level complexity. It may be better to have such laws but increase the burden on justification requests.
Crandall appended there are challenges in multi-country environments. Other questions are changes to the underlying request for data and whether these requests are legally valid.
When and where does the user come in and when is he or she accountable?
Wysopal stated that the EU is making it happen, but the US is not moving very quickly.


