The cloud has revolutionized how businesses operate, allowing them to take advantage of its scalability and flexibility while reducing costs. However, protecting data remains a critical challenge, with 98% of businesses reporting a cloud data breach within 1.5 years1, according to IDC research – highlighting the need for organizations to take additional measures to protect their data.
Cloud-Dienstleister sind sich der Bedeutung des Schutzes von Daten und Anwendungen in ihrer Umgebung bewusst und haben ein Modell der geteilten Verantwortung (Shared Responsibility Model, SRM) entwickelt. Dieses Modell verlangt von Unternehmen, dass sie selbst die Verantwortung für die Sicherheit ihrer Daten und Anwendungen in der Cloud-Umgebung übernehmen.
Cloud-Anbieter verfolgen unterschiedliche Ansätze beim Datenschutz, was die Komplexität noch erhöht, und Unternehmen müssen die spezifischen Details und Feinheiten der einzelnen Anbieter verstehen.
Daher müssen Kunden eine ganzheitliche Datenschutzstrategie entwickeln, um sicherzustellen, dass sie über die erforderlichen Kontrollmechanismen zum Schutz ihrer Daten verfügen – auch wenn sie auf die vom Anbieter bereitgestellten nativen Tools zurückgreifen. In diesem Beitrag wird erläutert, was dieses Modell für Kunden bedeutet und warum eine umfassende Datenschutzstrategie für Cloud- und Hybridumgebungen unerlässlich ist, um Cloud-Dienste sicher und geschützt nutzen zu können.
Warum setzen Unternehmen zunehmend auf Cloud-Computing?
Cloud computing has extended the possibilities for businesses and provides many advantages. Having workloads, applications, and services running on the cloud or hybrid environments gives businesses greater flexibility and incredible scalability to accommodate growth. In addition to these valuable benefits, having a wide variety of software as a service (SaaS) applications delivered via the cloud enhances operations, optimizes resource utilization, and brings agility and efficiency to business workloads. It’s no surprise that most companies have already embraced the cloud or are actively transitioning workloads, with Gartner estimating that over 95% of new digital workloads will be deployed on cloud-native platforms by 20253.
Another key advantage that makes cloud computing so attractive is that it allows users to access data and applications quickly and easily without requiring advanced technical knowledge or expertise. This makes it easier for businesses to deploy applications and manage data in a shorter time– something that would otherwise require significant technical know-how or experience with traditional IT environments.
Aus diesen Gründen setzen immer mehr Unternehmen auf Cloud Computing, um ihre Daten und Anwendungen zu verwalten. Das SRM stellt sicher, dass sowohl Kunden als auch Anbieter verstehen, was innerhalb der Cloud-Umgebung gesichert werden muss, damit Unternehmen die Vorteile dieser Technologie sicher und geschützt voll ausschöpfen können.
Was ist das Modell der geteilten Verantwortung?
Das Shared-Responsibility-Modell (SRM) ist eine Cloud-Sicherheitsstrategie, die besagt, dass Cloud-Anbieter zwar für die Sicherheit ihrer Service-Infrastruktur verantwortlich sind, die Kunden jedoch für die Sicherheit ihrer Daten und Anwendungen innerhalb der Cloud-Umgebung zuständig sind. Diese Aufteilung der Verantwortlichkeiten soll sicherstellen, dass beide Seiten verstehen, was gesichert werden muss und wie dies zu geschehen hat. Dieses Modell ermöglicht es Unternehmen, die Skalierbarkeit und Flexibilität von Cloud-Diensten zu nutzen und gleichzeitig darauf zu vertrauen, dass ihr Anbieter in der Lage ist, eine sichere Infrastruktur aufrechtzuerhalten.
Um Cloud-Dienste sicher und geschützt nutzen zu können, müssen Kunden ihre Rolle im SRM verstehen. Dies bedeutet, eine ganzheitliche Datenschutzstrategie zu entwickeln, die die nativen Tools des Anbieters sowie alle zusätzlichen Sicherheitsmaßnahmen berücksichtigt, die der Kunde möglicherweise ergreifen muss. Auf diese Weise können Kunden ihre Daten besser vor Bedrohungen wie böswilligen Angriffen, unbefugtem Zugriff, Datenlecks und vielem mehr schützen.
Wofür sind Cloud-Anbieter verantwortlich?
Cloud-Anbieter sind für die Sicherheit und den Datenschutz ihrer Cloud-Computing-Infrastruktur verantwortlich, einschließlich der physischen Sicherheit, der Datenspeicherung, des Netzwerkschutzes, der Host-Firewalls, der Zugriffskontrolle und der Behebung von Software-Sicherheitslücken. Sie müssen außerdem sicherstellen, dass ihre Dienste den gesetzlichen und behördlichen Compliance-Anforderungen entsprechen. Neben der Bereitstellung all dieser entscheidenden Komponenten einer sicheren Cloud-Umgebung sind sie auch für die betriebliche Integrität ihres Systems verantwortlich und müssen dessen Verfügbarkeit, Skalierbarkeit, Fehlertoleranz, Leistungsoptimierung, Kostenmanagement und allgemeine Zuverlässigkeit gewährleisten.
Each provider supplies a detailed description of what falls under their cover. For example, in its simplest form, AWS states explicitly that they are “responsible for protecting the infrastructure that runs all of their services in the AWS Cloud.”
Eine weitere wichtige Aufgabe von Cloud-Anbietern besteht darin, ihre Kunden über alle Änderungen oder Aktualisierungen ihrer Plattformen oder Dienste auf dem Laufenden zu halten. Dazu gehört auch, Kunden zu benachrichtigen, wenn ein neuer Sicherheitspatch veröffentlicht wurde oder ein Dienst nicht mehr unterstützt wird. Anbieter sollten zudem über einen klar definierten Prozess verfügen, um schnell und effizient auf auftretende Sicherheitsvorfälle reagieren zu können.
Cloud-Anbieter sollten zudem strenge Verfahren zum Identitätsmanagement anwenden, um zu kontrollieren, wer innerhalb der Cloud-Umgebung Zugriff auf die Kundendaten hat. Dazu gehören die Authentifizierung von Benutzern mithilfe von Multi-Faktor-Authentifizierungsmethoden sowie die regelmäßige Überprüfung der mit jedem Konto verbundenen Berechtigungen, um sicherzustellen, dass nur befugtes Personal auf sensible Informationen zugreifen kann.
Schließlich sollten Cloud-Anbieter gegenüber ihren Kunden transparent darlegen, wie sie deren Daten schützen, und sie über alle neuen Änderungen oder Aktualisierungen hinsichtlich der Einhaltung gesetzlicher Vorschriften informieren, die sich auf deren Geschäftsbetrieb auswirken könnten.
Inwiefern können sich die Verantwortlichkeiten bei den verschiedenen Cloud-Anbietern unterscheiden?
While the Shared Responsibility Model can initially seem simple, cloud providers have different approaches to securing their customers’ data, meaning their responsibilities can vary significantly. For example, some cloud providers may have more stringent access control policies than others, meaning customers may require higher levels of authentication or authorization when accessing their accounts and data.
Auch andere Anbieter stellen verschiedene Tools und Features zur Verfügung, mit denen Kunden ihre Daten schützen können. Einige bieten möglicherweise fortschrittliche Verschlüsselungs- und wichtige Verwaltungsdienste an, mit denen Kunden sicherstellen können, dass ihre Daten in der Cloud sicher sind. Andere stellen ihren Kunden möglicherweise detaillierte Überwachungsfunktionen zur Verfügung, mit denen sie nachverfolgen und überwachen können, wer auf bestimmte Dateien oder Verzeichnisse in ihrer Umgebung zugegriffen hat.
Darüber hinaus unterscheiden sich die Sicherheitsanforderungen der einzelnen Anbieter je nach Art der von ihnen angebotenen Cloud-Dienste.Microsoft erläutert how the division of responsibility changes between customers and Microsoft, according to the deployment type. Infrastructure as a Service (IaaS) providers typically require customers to maintain responsibility for protecting the operating system, applications, and data stored within their virtual machines. Whereas Platform as a Service (PaaS) providers often offer more capabilities out-of-the-box, such as managed databases, web servers, and development frameworks – all of which must be configured according to the customer’s security requirements.
Schließlich sollten Kunden bedenken, dass Cloud-Anbieter zwar für die Bereitstellung sicherer Umgebungen und Tools verantwortlich sind, es jedoch keine Garantie dafür gibt, dass Kundendaten privat und sicher bleiben, wenn Unternehmen die bewährten Verfahren in Bezug auf Zugriffskontrolle, Verschlüsselung und andere erforderliche Maßnahmen nicht angemessen umsetzen. Daher müssen Unternehmen verstehen, in welchem Umfang der jeweilige Anbieter für den Datenschutz verantwortlich ist, um den richtigen Partner für ihre Bedürfnisse auszuwählen.
Companies should carefully review each Cloud Provider’s responsibilities to know precisely what they are responsible for versus their service provider when protecting their data from malicious actors, misconfigurations and meeting compliance requirements.
Wofür sind Kunden verantwortlich?
Despite cloud data being subject to the same responsibilities as any on-premise computing system, many companies remain unaware of this fact. The Shared Responsibility Model outlines that customers are responsible for securing the data and applications within a cloud environment – yet research has found that only 39% of organizations are confident in their ability to do so effectively4.
Um sicherzustellen, dass diese Verpflichtungen erfüllt werden, müssen zusätzliche Sicherheitsmaßnahmen umgesetzt werden, wie beispielsweise Backup and Recovery, Verschlüsselung, Identitäts- und Zugriffsmanagement sowie Überwachung.
Key Data Protection Considerations
- A robust data protection strategy for all workloads is essential for the total visibility and security of hybrid cloud environments. With regular backups of all workloads, organizations can be better prepared to respond in case of data loss due to either a cybersecurity event or a natural disaster. Additionally, having data readily accessible enables IT teams to restore any lost workloads quickly and efficiently with minimal downtime.
- Encryption is critical when protecting sensitive data, such as financial or personal information, from unauthorized access attempts from external sources and internal personnel who could misuse customer information. Still, only 17% of businesses are encrypting at least half of the sensitive data they store in the cloud5. Customers should ensure they have robust encryption protocols across their environment and regularly re-inspect and apply the latest available options.
- Identity and Access Management (IAM) is also essential for cloud service customers. Implementing an IAM system will enable customers to control who has access to their cloud environment on a user level, allowing only authorized personnel to view or modify data. By utilizing multi-factor authentication, customers can enjoy better protection from breaches and limit the potential damage a malicious actor could cause. Additionally, customers should ensure that their authentication methods meet the standards set by their industry’s governing body or regulatory agencies. Furthermore, companies should have a Separation of Duty (SOD) policy to further protect cloud data from misuse by any single account holder.
- Monitoring and managing cloud and hybrid environments is a complex task, as cloud-based data resources constantly change. Therefore, using a monitoring and observability service is essential for administrators to ensure the security and proper management of cloud data. Cloud-native tools such as Amazon CloudWatch and Azure Monitor enable real-time monitoring and visibility into cloud, hybrid, and on-premises applications and infrastructure resources. The provision of data analysis not only helps administrators gain actionable insights from cloud data but also access crucial information about the performance of their cloud environment.
By following the best practices regarding security protocols, businesses can ensure they have the necessary controls to protect their data while taking full advantage of the benefits offered by cloud computing services. Ultimately, it’s up to each company’s circumstances when deciding what specific measures must be taken to keep sensitive information safe from external threats or unauthorized access.
Warum Sie eine ganzheitliche Datenschutzstrategie benötigen
With cloud related threats topping the list of cyber security concerns for UK senior executives and 90% saying they have experienced a greater exposure to cyber risks due to increased digitization in the last two years6, customers should continuously develop and maintain a holistic data protection strategy to ensure their data is secure, even when relying on the cloud provider’s native tools. A holistic approach involves understanding the full scope of data security requirements across multiple clouds and implementing appropriate technical, operational, and physical controls.
One of the most important reasons for this type of strategy is to identify and address any potential risks or vulnerabilities that could occur due to the increased use of cloud services. While cloud providers may have robust security measures in place, only 52% of CISOs are confident they are able to fully enforce a consistent security policy across all applications in the cloud7, meaning any additional security measures taken by businesses can provide extra layers of protection against malicious attacks, unauthorized access, data leakage, and other cyber threats.
Eine ganzheitliche Datenschutzstrategie trägt nicht nur dazu bei, sensible Daten vor potenziellen Bedrohungen zu schützen, sondern kann Unternehmen auch dabei helfen, verschiedene Branchenvorschriften wie HIPAA oder DSGVO einzuhalten. Durch die Einführung eines angemessenen Datenschutzkonzepts können Unternehmen besser sicherstellen, dass sie alle relevanten Compliance-Standards erfüllen und gleichzeitig alle Vorteile der Nutzung cloudbasierter Dienste nutzen.
Encryption and backup are vital considerations customers should keep in mind to ensure data protection. To achieve this, customers should also consider investing in third-party vendors like Commvault that provide additional layers of security for their cloud environments to complement native tools, ensure they meet their responsibilities, and effectively protect their data.
Microsoft bekräftigt diese Aussage in seinerNutzungsvereinbarung, stating, “all online services suffer occasional disruptions and outages, and Microsoft is not liable for any disruption or loss you may suffer as a result.” and “we recommend that you regularly backup Your Content and Data that you store on the Services or store using Third-Party Apps and Services.”
Commvault goes beyond backup by providing a simple and unified Data Protection Platform that spans all customer data – regardless of whether legacy or modern workloads live on-premises, in the cloud, or spread across a hybrid environment. Our knowledge of cloud options and deep integrations with a broad range of cloud providers offers the integration and automation possibilities to meet your unique data management and protection requirements.
Schließlich müssen die Kundenunternehmen eine klare Zuständigkeit für ihre Daten festlegen, damit alle Beteiligten wissen, wer für welche Art von Informationen verantwortlich ist und wie diese über ihren gesamten Lebenszyklus hinweg sicher behandelt werden sollen. Dazu gehört auch, festzulegen, wer Zugriffsrechte auf bestimmte Datensätze hat und wann diese Rechte widerrufen werden müssen (z. B. wenn ein Mitarbeiter das Unternehmen verlässt).
Durch eine ganzheitliche Datenschutzstrategie in Verbindung mit den nativen Tools ihres Anbieters können Kunden ihre Daten besser vor externen Bedrohungen schützen und gleichzeitig sicherstellen, dass ihre Geschäftsabläufe den erforderlichen gesetzlichen Anforderungen entsprechen.
Unternehmen müssen Zeit in die Entwicklung solcher Strategien investieren, um die Vorteile des Cloud-Computing sicher und in vollem Umfang nutzen zu können, ohne sich dabei dem Risiko kostspieliger Sicherheitsverletzungen oder Bußgelder aufgrund späterer Compliance-Verstöße auszusetzen.
Abschließende Überlegungen zu Strategien für den Datenschutz in der Cloud
With cyber-attacks increasing and nearly half of all data breaches happening in the cloud8, organizations must take adequate measures to protect their data and environment. The Shared Responsibility Model is a crucial cloud security strategy that emphasizes an effective combination of customer responsibility in developing proactive defense plans with third-party solutions for additional layers of protection when using cloud services. To successfully implement this approach, customers must understand how responsibilities differ across different providers to minimize potential risks while taking full advantage of the services offered by these platforms.
To learn more about how we protect your Cloud Environments, visit ourdigitale Transformation and SaaS-Delivered Solutionpages. You can also discover more about our latest release on ourwhat’s new page.
References
1.IDC survey, commissioned by Ermetic.– 3.Gartner IT Symposium/Xpo 2021– 4.CSA Understanding Cloud Data Security and Priorities 2022– 5.2021 Thales Global Cloud Security Study– 6.PWC Cyber Security Outlook 2023– 7.BlueFort Security 2022 CISO survey – Help net security– 8.IBM and the Ponemon Institute’s 2021 Cost of a Data Breach