EBA欧洲银行-Session-2-Mario-Maawad-Cloud-Financial-Services_11页_1mb
报告摘要
CaixaBank Cloud Computing Summary
Core Content
CaixaBank is the leading financial group in Spain, operating in both banking and insurance sectors. It has adopted a strategy of diversification, including investments in international banks and leading service companies. As part of its digital transformation, CaixaBank has developed a comprehensive Security Guideline for Cloud Computing to ensure the safe and secure delivery of cloud services.
The guideline outlines a structured approach to managing cloud services, starting with risk identification, followed by the development of a security strategy, security controls definition, and cloud service acquisition. It emphasizes the importance of CSP evaluation, contractual security measures, and ongoing review and monitoring of cloud services.
Main Points
1. Cloud Computing Overview
- NIST Definition: Cloud computing is a model that enables on-demand network access to shared computing resources, characterized by five essential features, three service models, and four deployment models.
- ISO/IEC 17788: Defines cloud computing as a scalable and elastic pool of shareable physical or virtual resources, with on-demand self-service provisioning and administration.
- Multi-tenancy: A key feature ensuring isolation between tenants and their data and computations.
2. Cloud Service Models
- Service Models:
- Infrastructure as a Service (IaaS): ✓
- Platform as a Service (PaaS): ✓
- Software as a Service (SaaS): ✓
- Capabilities Types:
- Infrastructure: ✓
- Platform: ✓
- Application: ✓
- Additional capabilities include:
- Network as a Service (✓ for all)
- Data Storage as a Service (✓ for all)
- Compute as a Service (✓ for Infrastructure)
- Communication as a Service (✓ for Platform and Application)
3. CaixaBank's Cloud Strategy
- NO CLOUD Strategy (2012): A restrictive security guideline was defined to limit cloud service adoption.
- YES SECURE CLOUD Strategy (2015): A new, more flexible approach was introduced, focusing on secure cloud services.
4. Security Guideline for Cloud Computing
-
Process Steps:
- Risk Identification
- Security Strategy
- Security Controls Definition
- Cloud Service Need
- CSP Evaluation
- Cloud Service Acquisition
- Review and Monitoring
- Cloud Service Audit
-
Key Security Measures:
- Personal Data Protection: Compliance with Spanish data protection laws.
- Credit Card Data Protection: Compliance with PCI DSS.
- User and Administrator Management: Secure administration and authentication.
- Cryptography: Used for communications and data storage.
- Contracts with CSP: Include clauses for security, auditability, scalability, and legal compliance.
- Internal and External Audits: Ensuring ongoing security compliance.
5. CSP Evaluation Criteria
- Certification Scope: Must align with the contracted service.
- Third-Party Audit: CSP must be audited by an independent and qualified third party.
- Control Maturity: Consider the maturity level of implemented security controls.
6. Certifications for CSP Security
- CSA STAR: A widely recognized certification for cloud security.
- ISO/IEC 27001:2013: International standard for information security management.
- SSAE 16: Provides assurance on controls at a service organization.
- PCI DSS v.3: Ensures secure handling of credit card data.
Future Steps
CaixaBank plans to:
- Define a checklist for evaluating the security level of cloud services.
- Implement a cloud service risk assessment process.
- Raise awareness among cloud users and contractors.
- Identify and regularize existing cloud services.
- Review, monitor, and audit cloud services continuously.
Key Contacts
- Mario Maawad Marcos
- Position: Director of Fraud Prevention / Security & Service Control
- Role: Co-Chair of the Financial Services Working Group at Cloud Security Alliance
- Email: mmaawad@caixabank.com
Conclusion
CaixaBank has evolved from a restrictive "NO CLOUD" strategy to a more secure and flexible "YES SECURE CLOUD" approach. It places strong emphasis on security compliance, risk management, and third-party audits to ensure that cloud services are both secure and aligned with its operational and legal requirements. The organization is actively working on improving its cloud security framework and increasing awareness among stakeholders.
试读结束,高清完整版pdf/doc/ppt,请点下载