2018-12顶级云安全威胁(英文版)-2mb
报告摘要
The Treacherous 12 - Cloud Computing Top Threats in 2016 Summary
Core Content
The Treacherous 12 is a report by the Cloud Security Alliance (CSA) that outlines the top 12 security threats to cloud computing in 2016. It is based on surveys and expert analysis, aiming to provide organizations with a comprehensive understanding of cloud security risks to support informed decision-making. The report emphasizes that cloud security is no longer solely an IT issue but has become a strategic concern at the executive level due to the increasing reliance on cloud services.
Main Points
- Cloud Security Challenges: Cloud computing has transformed business operations but has also introduced new security vulnerabilities and amplified existing ones.
- Top Threats: The report identifies 12 critical security threats, which are ranked based on their perceived relevance and severity.
- Industry Impact: The report includes real-world examples and anecdotes from 2015 and 2016 to illustrate the potential consequences of these threats.
- Methodology: The threats were identified through a two-stage process involving surveys and expert analysis using the STRIDE Threat Model and the NIST Risk Management Framework.
Key Threats
1. Data Breaches
- Description: Unauthorized access or exposure of sensitive data, which can result from attacks, human error, or poor security practices.
- Business Impacts: Data breaches can lead to legal penalties, financial loss, reputational damage, and loss of customer trust.
- Examples:
- BitDefender breach (2015) where customer credentials were stolen.
- Anthem breach (2015) involving stolen credentials and data exfiltration.
- TalkTalk breach (2014-2015) due to lack of encryption.
- Control IDs:
- AIS-04, DSI-02, DSI-05, EKM-02, EKM-03, EKM-04, GRM-02, GRM-10, HRS-01, HRS-03, HRS-04, HRS-08, HRS-09, HRS-10, IAM-02, IAM-04, IAM-05, IAM-07, IAM-09, IAM-12, IVS-08, IVS-09, IVS-11, STA-06.
- Links:
- The Impact of a Data Breach Can Be Minimized Through Encryption
- Dropbox and Box leak files in security through obscurity nightmare
- Anthem's Breach and the Ubiquity of Compromised Credentials
- Stolen Passwords Used in Most Data Breaches
- Anti-Virus Firm BitDefender Admits Breach, Hacker Claims Stolen Passwords are Unencrypted
- TalkTalk Criticised for Poor Security and Handling of Hack Attack
2. Insufficient Identity, Credential and Access Management
- Description: Weak or missing identity and access management systems can lead to unauthorized access, credential theft, and insider threats.
- Business Impacts: Unauthorized access can result in data manipulation, system control, and severe financial and reputational damage.
- Examples:
- GitHub credentials were scraped and misused within 36 hours of a project's launch.
- Praetorian launched a cloud-based password cracking service.
- Control IDs:
- IAM-01, IAM-02, IAM-03, IAM-04, IAM-05, IAM-06, IAM-07, IAM-08, IAM-09, IAM-10, IAM-11, IAM-12, IAM-13, HRS-01, HRS-03, HRS-04, HRS-08, HRS-09, HRS-10.
- Links:
3. Insecure Interfaces and APIs
- Description: Poorly designed or implemented APIs and interfaces can lead to data exposure, unauthorized access, and service disruption.
- Business Impacts: Insecure APIs can expose data, allow malicious actors to manipulate systems, and lead to service outages.
- Examples:
- IRS breach (2015) through a vulnerable API.
- Exposed API keys and credentials leading to data exfiltration.
- Control IDs:
- AIS-01, AIS-04, IAM-08, IAM-09.
- Links:
Other Key Threats
The report also highlights additional critical threats such as Malicious Insiders, Advanced Persistent Threats (APTs), Denial of Service (DoS), and Shared Technology Vulnerabilities, among others. These threats are interconnected and require a holistic approach to cloud security.
Conclusion
The Treacherous 12 report underscores the need for robust security practices, especially in identity management, API security, and system vulnerabilities. It serves as a guide for both cloud users and providers to understand and mitigate these risks. The CSA recommends using the Security Guidance for Critical Areas in Cloud Computing V.3 and the Security as a Service Implementation Guidance alongside this report to form comprehensive cloud security strategies.
Additional Information
- The report is available at https://cloudsecurityalliance.org/group/top-threats/
- The 2016 edition reflects the evolving nature of cloud security threats and the increasing role of executive decision-making in mitigating them.
试读结束,高清完整版pdf/doc/ppt,请点下载