Crowd-2018年云安全报告(英文)-2018.9-37页-4mb
报告摘要
CLOUD SECURITY REPORT SUMMARY
Core Content
This report explores the current state of cloud security, focusing on challenges, solutions, and adoption trends faced by organizations as they transition to cloud computing. It highlights the increasing concerns of cybersecurity professionals and the evolving strategies to address them.
Main Points
-
Cloud Security Concerns are Rising:
Despite the rapid adoption of cloud computing, security concerns are not diminishing. 91% of cybersecurity professionals express extreme to moderate concern about public cloud security, up 11 percentage points from the previous year. The top three cloud security challenges are:- Protecting against data loss and leakage (67%)
- Threats to data privacy (61%)
- Breaches of confidentiality (53%)
-
Misconfiguration is the Biggest Threat:
Misconfiguration of cloud platforms has become the number one threat to cloud security, with 62% of respondents identifying it as such. Other major threats include:- Unauthorized access through employee credential misuse and improper access controls (55%)
- Insecure interfaces/APIs (50%)
-
Operational Headaches in Cloud Security:
Cybersecurity professionals face significant operational challenges in protecting cloud workloads. The top three include:- Visibility into infrastructure security (43%)
- Compliance (38%)
- Setting consistent security policies across cloud and on-premises environments (35%)
-
Traditional Security Tools Fall Short:
Only 16% of organizations believe traditional security tools are sufficient for managing cloud security, down from 22% in the previous survey. 84% of respondents report that traditional tools either don't work in cloud environments or have limited functionality. -
Cloud Security Budgets are Increasing:
Looking ahead, nearly half of organizations (49%) expect an increase in cloud security budgets, with a median increase of 28%. This reflects growing awareness of cloud security risks and the need for investment in protective measures.
Key Solutions
-
Training and Certification:
Training and certifying current IT staff is the most popular path to meet evolving security needs (57%). This indicates the importance of human expertise in cloud security. -
Cloud Provider Security Tools:
50% of respondents use their cloud provider's security tools, such as AWS GuardDuty, to implement proper security controls. -
Third-Party Security Software:
35% of organizations deploy third-party security software to enhance their cloud security posture. -
Effective Security Technologies:
The most effective security technologies identified include:- Data encryption (64%)
- Network encryption (54%)
- Security Information and Event Management (SIEM) (52%)
- Trained cloud security professionals (51%)
- Intrusion detection and prevention (46%)
- Vulnerability assessment (46%)
- Access control (45%)
- Log management and analytics (43%)
- Privileged Access Management (PAM) (42%)
- Data leakage prevention (41%)
Cloud Adoption Trends
-
SaaS Dominates Cloud Adoption:
SaaS remains the most widely adopted cloud model (52%), followed by IaaS (36%) and PaaS (28%). Newer models like BPaaS (11%) and FaaS (10%) show lower adoption rates. -
Hybrid Cloud Strategy is Popular:
40% of organizations use a hybrid cloud strategy, integrating multiple cloud providers into a single seamless environment. 30% use a single cloud, and 30% use a non-integrated multi-cloud approach. -
Top Cloud Providers:
The leading public cloud providers are:- Amazon Web Services (AWS): 72% currently use or plan to use
- Microsoft Azure: 71% currently use or plan to use
- Rackspace Cloud: 67% currently use or plan to use
- Google Cloud Platform: 54% currently use or plan to use
- Oracle Cloud: 50% currently use or plan to use
- IBM Cloud: 47% currently use or plan to use
Best Practices for Cloud Security
-
Data Protection:
Access controls (65%) and encryption (59%) are the primary methods for protecting data in the cloud. The use of cloud provider security services has also increased, moving from fourth to third place (53%). -
Cloud Security Criteria:
The top five attributes organizations look for in a cloud security provider are:- Cloud native security tools (68%)
- Cost effectiveness (64%)
- Seamless integration with cloud platforms (57%)
- Ease of deployment (53%)
- Demonstrated cloud knowledge (50%)
-
Confidence Builders for Cloud Adoption:
To increase confidence in cloud adoption, organizations prioritize:- Encryption of data-at-rest (49%)
- APIs for reporting, auditing, and alerting on security events (46%)
- Setting and enforcing security policies across clouds (45%)
- Automating compliance (45%)
- Creating data boundaries (44%)
- Isolation/protection of virtual machines (43%)
- Limiting unmanaged device access (42%)
- Leveraging data leakage prevention tools (41%)
Security Training
-
Training is Critical:
67% of organizations consider security training and certification valuable for reducing risk and protecting against internal and external threats. -
Effectiveness of Training Programs:
59% of organizations report that their current security training programs are very or somewhat effective.
Conclusion
The report underscores the growing complexity and risk associated with cloud computing, emphasizing the need for updated strategies, technologies, and training. Organizations are increasingly turning to cloud-native tools, provider partnerships, and comprehensive training programs to enhance their cloud security posture. The findings highlight a shift in focus from traditional security methods to more agile, integrated, and cloud-focused approaches.
试读结束,高清完整版pdf/doc/ppt,请点下载