Solutions

Strengthening Security for Public Cloud Environments Cloud Security

クラウドの責任分離
As the phrase “Cloud First” suggests, many IT departments are already migrating, or considering migrating, a large portion of their information assets to the cloud. By moving to the cloud, organizations can provision server and network infrastructure without building it in-house, deploy required systems quickly and at lower initial cost, and reduce total cost of ownership. However, even with the cloud services, it is essential to understand the shared responsibility model and implement appropriate security measures. In particular, in the case of IaaS in public cloud environments, responsibility for the OS running on the hardware, databases, applications, and account management lies with the customer organization.

Security Required for Public Cloud Environments

  1. Protection Against the Latest Attacks

    Many cloud service providers offer security measures. However, these measures are generally provided on a service-by-service or feature-by-feature basis and differ from the security solutions offered by specialized security vendors. As a result, they may not be able to protect against the latest threats, such as zero-day attacks, and log analysis may require a combination of multiple services. For this reason, additional security measures are required for public cloud environments, just as they are for on-premises environments.

    ◆ Key Security Measures Provided by Cloud Service Providers and Their Limitations

    Security Measure ProvidedIssues
    Access Control (IP address–based) ・Unable to perform detailed packet inspection
    ・Unable to protect against zero-day attacks
    ・Unable to apply controls based on user information
    Web Application Firewall ・Does not support protocols other than web protocols
    ・If a web server is compromised, it cannot detect communications with external servers such as C&C servers
    Log Analysis (Optional Add-on) ・Log storage and analysis are provided separately, with usage-based pricing depending on the volume of data, resulting in additional costs
    ・Log analysis using the standard service alone requires specialized expertise and may also require a combination of multiple services
  2. Visualization of Security Configurations

    While the adoption of public cloud services continues to accelerate, information security incidents caused by misconfiguration and human error are also rapidly increasing. It is no longer uncommon to see data breach cases where, due to incorrect permission settings in a cloud service, customer information that should never have been accessible was unintentionally exposed. Even if the initial configuration is appropriate at the time of deployment, security vulnerabilities can emerge over time due to various factors—such as accidental errors during later configuration changes, inappropriate operations caused by lack of knowledge, or the neglect of obsolete resources, Furthermore, as public cloud usage grows and the scale of provided and consumed services expands, it becomes increasingly critical to maintain an accurate view of configuration settings across diverse resources and to manage permissions for all accounts in order to preserve security.

  3. Strengthening the Information Security Management Frameworks

    27001と2017
    Across all environments - including cloud, hosting, ASP, and on-premises - , it is critical to cover the fundamentals of security. In practice, this means aligning with the organization’s information security strategy and policies, classifying information assets and data according to their importance, and then designing access controls, operational processes, and incident response structures that match each level of importance. ISO/IEC 27017 is a guideline standard that defines information security controls for cloud services. By reinforcing an existing ISO/IEC 27001–based information security management system with ISO/IEC 27017, organizations can build a robust information security management framework that properly addresses cloud services as well.

Asgent’s Services and Product Portfolio

Scope of Products Products /Services Overview
Protection against the latest cyber attacks Product
Check Point Cloud Firewall

Provides multi-layered protection for cloud environments. It complements the security features provided as standard by cloud service providers and delivers next-generation firewall capabilities such as sandboxing and file sanitization.

Service
Security Plus
Managed Security Service

Addresses the critical challenges faced by organizations lacking in-house security expertise, where log analysis and responding to sophisticated cyberattacks can be complex and demanding. Security devices running in cloud environments are monitored 24/7/365 by Asgent’s dedicated security analysts.

Visualization of security settings Service
Security Plus
Security Assessment Services
: Web Application Assessment

To maintain the security of systems exposed in the cloud, this service identifies whether security issues (vulnerabilities) are present. It examines and detects vulnerabilities in customers’ web applications. After the assessment, we provide a detailed and easy-to-understand report outlining the findings and recommending appropriate measures for remediation and future action.

Service
Security Plus
Security Assessment Services
: Platform Assessment

Clarifies whether security issues (vulnerabilities) exist in systems published on cloud environments, helping maintain their security posture. We examine and identify flaws (vulnerabilities) in servers, network devices, operating systems, and middleware. Upon completion, we deliver comprehensive and intuitive reports, providing detailed findings alongside strategic recommendations for effective remediation.

Strengthening the information security management framework Service
Information Security Audit

Supports the development of an internal framework that enables the organization to understand the status of information security measures for its information assets and to identify issues that need to be addressed.

Service
ISO Consulting

We support organizations in establishing the internal framework required to obtain ISO/IEC 27017 certification.