Wednesday, March 8, 2017

Cloud Computing Forensics Readiness

Photo credit: Shuterstock

In today’s globally connected world, data security breaches are bound to occur. This, in turn, increases the importance of digital forensic readiness, or the ability to access and trust computer log data in the identification of a breach and the determination of what datasets may have been compromised. As organizations rapidly move into the cloud, the complexities of this multi-jurisdictional and multi-tenancy environment has made the importance of cloud forensics even more pronounced. This reality has also drastically heightened the legal risk associated with information technology operations. Cloud and digital forensics readiness are therefore critical to business disaster recovery, continuity of business services and cloud ecosystem management.

  • Reducing the cost of cyber investigations;
  • Quick determination of relevant attack vector;
  • Reduction in the cost for data disclosure;
  • Faster restoration from damage; and
  • Cyber insurance discounts.


Forensic readiness will also help your organization regain control after any sort of data breach. It will help limit the damage and costs from just about any digital incident. When forensics readiness is taken into account, post breach digital investigation often become simpler in that retrieval of digital evidence can occur without running into some of the better known challenges. Even more important is when forensics is part of the business continuity plan, digital evidence is actually acquired and stored before an incident occurs without interrupting business operations.




Cloud and digital forensics should be looked at across three separate dimensions: technical, organizational, and legal. The technical dimension is mainly focused onL
  • Forensics data collection;
  • Elastic, static and live forensics;
  • Evidence segregation;
  • Investigations in virtualized environments; and
  • Pro-active preparations.

The organization dimension is strongly influenced by the roles played by the relevant cloud service provider and the cloud service consumer. To establish a forensic capability, these organizations must define a staffing structure that fulfills the following critical roles:

  •  Investigators: Responsible for collaborative investigation allegations of misconduct in the Cloud and working with external assistance or law enforcement when needed.
  • IT Professionals: System, network, and security administrators, ethical hackers, cloud security architect, and technical support staff in the cloud organization.
  • Incident Handlers: The team that responds to a variety of specific security incidents, such as unauthorized data access, accidental data leakage and data loss, breach of tenant confidentiality, inappropriate system usage, malicious code infections, malicious insider attack, (distributed) denial of service attacks, etc.
  • Legal Advisors: Staff familiar with multi-jurisdiction and multi-tenant issues in the Cloud that will ensure that any forensic activities will not violate regulations under respective jurisdiction(s) or confidentialities of other tenant(s) sharing the same resource(s).
  •  External Assistance: Typically, it is wise for the cloud organizations to rely on a combination of its own staff and external parties to perform forensic tasks such as e-discovery, investigations on civil cases, investigations on external chain of dependencies. The responsibility of any external party should be determined in advance and made clear relevant policies, guidelines and agreements.

The legal dimension primarily revolves around multi-jurisdiction and multi-tenancy challenges and the terms of use as specified in the CSP Service Level Agreement (SLA). Specific topics that should always be addressed within the SLA include:
·         Service provided, techniques supported and access granted by the CSP to the customer regarding forensic investigation;
·         Trust boundaries, roles and responsibilities between the CSP and the cloud customer regarding forensic investigation;
·         How forensic investigations are secured in a multi-jurisdictional environment in terms of legal regulations, confidentiality of customer data, and privacy policies; and
·         How forensic investigations are secured in a multi-tenant environment in terms of legal regulations, confidentiality of customer data and privacy policies

Experts recommend a focus in three primary aspects:

  • Preparation: Create and maintain the conditions that enable you to respond timely and effectively to any digital incident.
  • Partnering: Forge relations with and external specialists and stakeholders when it comes to dealing with digital incidents before a crisis occurs.
  • Evolving: Periodically rehearse, evaluate and update your response plan.


Forensics is a core requirement of good organizational hygiene, alongside business continuity and disaster recovery and should always be specified in standard contract clauses. Businesses without forensic readiness planning and testing in place are just as negligent as those that fail to plan for business continuity or disaster recovery. By implementing and testing their forensic readiness, a business can prepare itself to be in a much better position when – not if – a security incident occurs.

This post was brought to you by IBM Global Technology Services. For more content like this, visit ITBizAdvisor.com



Cloud Musings
( Thank you. If you enjoyed this article, get free updates by email or RSS - © Copyright Kevin L. Jackson 2016)



37 comments:

  1. The great website and information shared are also very appreciable. Kanye West Donda Vest

    ReplyDelete
  2. Statistics students and professor are worried to find the deviation calculator because their work depends on it. Dreamer Biker Jacket

    ReplyDelete
  3. I must say that you are my favourite author. You always bring surprised things for me everytime I see your articles. Great efforts!! Biker Boyz Jacket

    ReplyDelete
  4. In this article, I will let you know about data mining and data analysis. You need to learn these concepts because if you are working on some data-driven project, you cannot deny their importance.

    ReplyDelete
  5. Awesome Blog! Your blog is very informative. It is nice to read such high-quality content john dutton brown vest

    ReplyDelete
  6. It is nice to read such high-quality content.
    Keep up the good work! Digital Marketing Institute in Pune

    ReplyDelete
  7. I like this page! You have selected a good topic to discuss with us. I appreciate for brining this blog in front of us. thank you. Keep updating!
    financial modelling course in kenya

    ReplyDelete
  8. Thanks for sharing this info,it is very helpful. Check Out Digital Marketing Courses in Pune

    ReplyDelete
  9. You may tweak your profile to increase engagement and attract more followers by using pertinent keywords, captivating photographs, and an engaging bio. A sense of community and brand loyalty can be cultivated through interesting captions, direct messaging, and other frequent interactions with your audience. Last but not least, in order to keep your audience interested and develop an organic Instagram following, you must consistently produce high-quality content that is relevant to your audience.

    Read more

    aiemoo

    Android13,Mark R baum

    Official arrival of Android 13

    ReplyDelete
  10. The paper, which was posted on the website SemiAnalysis, stressed the necessity of continual innovation and investment in order to maintain a leading position in the rapidly expanding AI field. To be competitive in the quick-paced world of AI, businesses must adapt as the market shifts and take advantage of the opportunities and challenges presented by new technology.



    Readmore

    advantage of large tech companies

    Star Wars

    collaboration with Star Wars

    ReplyDelete
  11. We'll look at eight iPhone emojis in this post that set them apart from their Android equivalents. With the help of these particular emojis, iPhone users can express themselves in original and innovative ways and experience a sense of exclusivity. Let's take a closer look at the world of iPhone emojis to learn more about its unique beauty and allure.



    Learn more.



    Brian Graham
    Microsoft retires its keyboards and mice
    Microsoft Retires Keyboards and Mice

    ReplyDelete
  12. Google announced that it deleted more than 20,000 YouTube channels in the first quarter of 2023. According to Google’s Threat Analysis Group (TAG) blog, these channels were part of an investigation into “coordinated influence operation campaigns” involving multiple countries, with 6,930 channels featuring Chinese-language spam content about music, entertainment, and lifestyle.



    Read more

    Motorolla

    - MARK R. BAUM

    Instagram tips and tricks

    ReplyDelete

  13. Google has recently unveiled the Android 14 Beta 2, marking yet another significant step in the evolution of its flagship operating system. This latest offering was announced during the keynote at Google I/O 2023 and brings with it an array of intriguing enhancements.

    Readmore

    collaboration with Star Wars

    fortnite has launched

    Star Wars characters to Fortnite

    ReplyDelete
  14. The best snacks for on-the-go munching are energy bars and bite-sized snacks. They provide convenience and are nutrient-rich to keep you nourished all day. Making your own energy bars is simple if you combine nuts, seeds, dried fruits, and oats.

    Readmore...

    avegan sweet potato casserole recipe

    This article explores the negative impact

    warm and comforting tomato soup on a chilly day

    ReplyDelete


  15. "New Meat" has dishes by Korteweg and contributions from eleven prominent chefs, including Michelin-starred cooks Asimakis Chaniotis, James Goodyear, and Ricky

    Readmore...

    Babybel

    demand for plant-based alternatives grew,

    ban that prohibits imports of food products linked to deforestation

    ReplyDelete
  16. In the universe of Elden Ring, Diallos is a legendary place cloaked in danger. According to legend, there is a dangerous environment full with hidden treasures that can only be found by those who have the courage to explore it.

    Readmore...

    enigmatic NPC in Elden Ring

    “Maidenless”

    Elden Ring

    ReplyDelete
  17. Great Piece of the article got lots of insight , i would like to draw attention to Best Software Testing Courses in Pune up-sacling the skills.

    ReplyDelete
  18. "Great article! The information you shared here is really valuable and well-researched. I appreciate the effort you put into creating such high-quality content."
    For any digital investigation services, you can contact us.
    Drone Forensics
    Cloud Forensics

    ReplyDelete
  19. Very informative post! Thanks for sharing your insights on this topic.
    To facilitate your journey as a Digital marketer, refer to this article which provides information on the core digital marketing tools.
     Free digital marketing tools 

    ReplyDelete
  20. Cmolds is a leading mobile application development company san francisco, specializing in creating innovative and customized mobile solutions that drive businesses forward. With a team of skilled professionals, Cmolds transforms ideas into exceptional mobile applications that redefine user experiences.

    ReplyDelete
  21. Ramma Foundation Repair is your trusted partner for Foundation Repair Edmonton solutions, ensuring the stability and longevity of your property's foundation. Experience top-notch expertise and quality service with Ramma Foundation Repair.

    ReplyDelete
  22. Your Artical is really interesting.
    I recently had the privilege of experiencing the fantastic coworking space in Pune, and I must say, it exceeded all my expectations. The vibrant atmosphere, state-of-the-art facilities, and attentive staff made it an ideal place to boost my productivity and creativity.

    ReplyDelete
  23. Great Article. You have beautifully articulated it. Readers revisit only if they found something useful. Halloween Jackets

    ReplyDelete
  24. Good blog. I appreciate you sharing with us. Such fascinating details. Dinwiddie Conducción imprudente

    ReplyDelete
  25. You made a very interesting post regarding the price of a divorce in New York. We appreciate you deconstructing the many elements and giving us an accurate picture of what to anticipate. Your insightful observations show how committed you are to supporting people going through this process.
    ¿Cuánto es para un Divorcio en Nueva York?

    ReplyDelete
  26. Indulge in the epitome of luxury with Cabo San Lucas Villas, your premier choice for unparalleled vacations. Our exquisite collection of cabo house rentals with chef promises a perfect blend of opulence and comfort. Experience the pinnacle of hospitality in the most sought-after destination.

    ReplyDelete
  27. "Cloud Computing Forensics Readiness" is a guide for businesses addressing cloud technology and forensic preparedness, emphasizing proactive security measures. It provides insights into mitigating risks and ensuring accountability, making it a must-read for cloud computing era success. Statement of Net Worth Divorce New York

    ReplyDelete
  28. Indulge in the exquisite world of Monster Rabbit, where luxury meets sensuality with our royal performance honey. Experience the epitome of pleasure and vitality with our premium products, crafted to elevate your intimate experiences to new heights.

    ReplyDelete
  29. CMOLDS leads as one of the premier mobile app development companies in uae, offering bespoke solutions tailored to your business needs. Our expertise ensures cutting-edge, user-centric mobile applications that elevate your brand in the competitive UAE market.

    ReplyDelete