{"id":108063,"date":"2020-03-20T06:00:12","date_gmt":"2020-03-20T13:00:12","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=108063"},"modified":"2020-03-19T13:00:25","modified_gmt":"2020-03-19T20:00:25","slug":"cloud-secure-the-cloud","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2020\/03\/cloud-secure-the-cloud\/","title":{"rendered":"The Best Method to Secure the Cloud Starts Offline"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">I think a lot of us are familiar with \u201choney-do\u201d lists: small chores and stuff we have to do around the house. Most of it we know how to do, or a quick YouTube video can show us the way. But what if you came home one day and your spouse or partner turned to you and said, \u201c<\/span><i><span style=\"font-weight: 400;\">Honey, I want to be more fuel-efficient. I need you to build me a hybrid car \u2013 or better yet, build me a fully electric car<\/span><\/i><span style=\"font-weight: 400;\">.\u201d\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That\u2019s kind of how it feels when your boss walks in and asks you to shift part or all of your company\u2019s infrastructure to the cloud.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When we are tasked with something monumental that we don\u2019t fully understand, like a cloud migration, it can be overwhelming. Most organizations end up doing what is referred to as a \u201clift and shift\u201d of their environment. That is, they try to re-create the infrastructure in the cloud exactly as they have it on-premises or in co-location (co-lo). This can be like fitting a round peg in a square hole: If you push hard enough, it will fit, but it isn\u2019t going to look right, and it will leave gaps. In the case of a lift and shift, this can leave security holes, lead to inefficient processes and increase the costs of running your environment by running extra infrastructure.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Instead, you need to re-engineer your architecture to match the best practices of your chosen public cloud provider. Learning those best practices comes with experience, time and education. To gain experience, you have to spend the time, but I can give you a headstart on the education piece.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><strong>What\u2019s the Best Way to Secure the Cloud?<\/strong><\/h2>\n<p><span style=\"font-weight: 400;\">\u201cThrough 2025, 99% of cloud security failures will be the customer\u2019s fault.\u201d \u2013 <\/span><a href=\"https:\/\/www.gartner.com\/smarterwithgartner\/is-the-cloud-secure\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">Gartner<\/span><\/a><\/p>\n<p><span style=\"font-weight: 400;\">How do you avoid the Gartner prediction so that you do not become part of this statistic? First, you need to understand the public cloud and how to secure it.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The statistic doesn\u2019t mean that there will be a bunch of angry employees running around causing chaos. It refers to a lack of knowledge of how to properly build and secure a cloud environment. Companies need to understand that employees want to do their jobs well and want to be proud of what they are building. But it\u2019s difficult to accomplish a cloud migration without the know-how or the tools to get the job done.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">There are many ways to approach these issues. Two that I think are critical to success involve leveraging culture and tools.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4>Culture<\/h4>\n<p><span style=\"font-weight: 400;\">Many people focus on educational programs themselves \u2013 classes, certifications, etc. I don\u2019t think that is the most important piece to put in place, though \u2013 people can breeze through online classes, learn the bare minimum and get the certifications. But what have they actually learned and how do they apply that?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The most important thing a company can do is to <\/span><a href=\"https:\/\/hbr.org\/2018\/07\/4-ways-to-create-a-learning-culture-on-your-team\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">promote a culture of education<\/span><\/a><span style=\"font-weight: 400;\">. Make <\/span><a href=\"https:\/\/medium.com\/@peoplefirstOPP\/social-learning-how-to-create-a-culture-of-learning-5994786dc5cf\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">everyone feel comfortable<\/span><\/a><span style=\"font-weight: 400;\"> not knowing everything. Too often, companies expect employees to be experts in everything, then turn around and complain about industry skills shortages when that isn\u2019t the case. <\/span><a href=\"https:\/\/www.learnupon.com\/blog\/learning-culture\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">Employees can all work together<\/span><\/a><span style=\"font-weight: 400;\"> to learn the needed skills, embrace education and be patient while everyone is learning. When companies create a cloud native strategy, it is incredibly important to have <\/span><a href=\"https:\/\/trainingindustry.com\/articles\/professional-development\/creating-a-learning-culture-for-the-improvement-of-your-organization\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">education be part of that strategy<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4>Tools<\/h4>\n<p><span style=\"font-weight: 400;\">The best way to learn is hands-on training in conjunction with toolsets that help guide you through the process. This idea brings me to my second critical educational component: having the right tools.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The learning process can be tough enough, and trial and error can be dangerous for a company making the transition to the cloud. Having a set of tools that will tell you whether or not you are building your infrastructure and configuring everything correctly can be a huge weight off your shoulders.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you are using infrastructure-as-code (IaC), you need a comprehensive tool that can check for misconfigurations while you build directly in your integrated development environment (IDE). The same applies if you are building an application using containers: You want a <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2020\/03\/cloud-devops-plugins\/\">tool to automatically check for known vulnerabilities<\/a>, and to help check that each container is meeting compliance standards before it goes live.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Of course, not everyone has access to IaC or containers and has to build things as they go. In that case, you need a toolset that provides asset inventory, audit logs, configuration monitoring and usability in run time that can alert you while you build.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Having alert information gives you peace of mind that everything you\u2019ve built is meeting security standards. And if you do get an alert, you know exactly what you did incorrectly and can make adjustments. We all use email, Slack or Teams, or maybe some ticketing software. Having alerts pop up in those systems while you are building can keep risk down to a minimum.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It\u2019s like cooking: If you clean up as you go, there is much less to do when you\u2019re done. However, if you leave it all till the end, you will be cleaning the kitchen for as long as it took you to cook dinner. The metaphor holds for building software: You never want to build in technical debt. In a world where threat actors are constantly on the move, you have to be vigilant.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Ensuring Success in the Cloud<\/strong><\/h2>\n<p><span style=\"font-weight: 400;\">We want you to be able to do the equivalent of building that hypothetical electric car, to tackle the most intimidating projects and be successful. Make sure you are getting the education you need and that you are being supported along the way. Push for the right tools that can help you to accomplish these monumental tasks every day without wasting your time.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For an in-depth discussion on how to use these tools and how to integrate them into your cloud native strategy, check out our virtual summit on-demand, <\/span><a href=\"https:\/\/vshow.on24.com\/vshow\/Palo_Alto_Networks\/registration\/16700\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">Cloud Native Security Live<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn what education is needed to secure the cloud and re-engineer your network architecture to match your public cloud.<\/p>\n","protected":false},"author":663,"featured_media":108064,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6768],"tags":[7009,6901,423,6890],"coauthors":[7029],"class_list":["post-108063","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-the-cloud","tag-30-days-of-cloud","tag-cloud-native-security-platform","tag-education","tag-prisma-cloud"],"jetpack_featured_media_url":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/03\/30-days-of-cloud_network-security-1200x675-2.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/108063","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/663"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=108063"}],"version-history":[{"count":2,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/108063\/revisions"}],"predecessor-version":[{"id":108079,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/108063\/revisions\/108079"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/108064"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=108063"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=108063"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=108063"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=108063"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}