<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.trendmicro.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" version="2.0">

<channel>
	<title>Trend Cloud Security Blog - Cloud Computing Experts</title>
	
	<link>http://cloud.trendmicro.com</link>
	<description>Securing Your Journey to the Cloud</description>
	<lastBuildDate>Tue, 30 Apr 2013 16:33:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.trendmicro.com/cloud-security" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="cloud-security" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">cloud-security</feedburner:emailServiceId><feedburner:feedburnerHostname xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Why It’s Time to Manage Your Networking and Security from the Cloud</title>
		<link>http://cloud.trendmicro.com/why-its-time-to-manage-your-networking-and-security-from-the-cloud/</link>
		<comments>http://cloud.trendmicro.com/why-its-time-to-manage-your-networking-and-security-from-the-cloud/#comments</comments>
		<pubDate>Tue, 30 Apr 2013 15:34:21 +0000</pubDate>
		<dc:creator>Dave Asprey</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cloud management]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[Deep Security as a Service]]></category>
		<category><![CDATA[IT management]]></category>
		<category><![CDATA[Meraki]]></category>
		<category><![CDATA[saas]]></category>
		<category><![CDATA[systems management]]></category>

		<guid isPermaLink="false">http://cloud.trendmicro.com/?p=2998</guid>
		<description><![CDATA[If you still believe that your systems management consoles should be running on servers in your data center, you’re definitely from the pre-cloud era. Even if you believe your systems management and security consoles should be running on infrastructure as a service instances you control, you’re also out of date. The evidence is in, and [...]]]></description>
			<content:encoded><![CDATA[<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-its-time-to-manage-your-networking-and-security-from-the-cloud%2F&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=recommend&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px;height:30px;margin-top:5px;"></iframe><p>If you still believe that your systems management consoles should be running on servers in your data center, you’re definitely from the pre-cloud era. Even if you believe your systems management and security consoles should be running on infrastructure as a service instances you control, you’re also out of date.</p>
<p>The evidence is in, and your control systems should absolutely reside in the cloud, even if the systems they control are not in the cloud. Cisco’s recent acquisitions are a reminder, and so is this week’s launch of Trend Micro’s new <a href="http://deepsecurity.trendmicro.com/">Deep Security as a Service</a> that secures AWS instances.</p>
<p>Cisco just provided a reminder about the growth of  cloud management in the enterprise by recently reporting their second quarter fiscal 2013 earnings, which showed a massive push to grow their data center business. One of the unique highlights of the quarter for Cisco was their <a href="http://news.cnet.com/8301-1001_3-57551605-92/cisco-nabs-cloud-networking-start-up-meraki-for-$1.2-billion/">$1.2 billion acquisition of midmarket networking vendor Meraki</a> (they build cloud managed wireless and wired access points as well as provide network acceleration and security capabilities) <a href="http://techcrunch.com/2012/11/18/cisco-acquires-enterprise-wi-fi-startup-meraki-for-1-2-billion-in-cash/">which was first announced in November of 2012</a>.</p>
<p>Meraki developed an incredibly compelling cloud managed networking solution &#8211; enough to be named a Gartner Magic Quadrant Visionary &#8211; that will greatly aid Cisco in its exit from the home networking market and its intention to increase its presence in the networking mid-market. With Meraki’s product, an enterprise has the ability to centrally manage everything related to their network in the cloud from a single portal. This gives the enterprise complete control over all users, applications, and devices and means that there is <em>no longer any controller hardware or management software to install and maintain</em>. This secure cloud infrastructure can scale to million-user deployments and eliminates the need for administrators to configure devices by logging in to each one directly.</p>
<p>If a trend is big enough to be worth a billion dollar acquisition, it’s beyond the early days. Since I joined Trend Micro almost 3 years ago as its cloud technology evangelist, I’ve been pushing the idea that control systems are safer and higher availability when you put them in the cloud, compared to where most of them sit today in enterprises. This is doubly true for security systems.</p>
<p>That’s why I’m incredibly excited that this week Trend Micro is formally announcing <a href="http://deepsecurity.trendmicro.com/">Deep Security as a Service</a>. It protects Amazon Web Services instances with a security console that is hosted, managed, and updated in real-time by Trend Micro.</p>
<p>Security and management control systems work exceptionally well in the cloud, as <a href="https://www.infoworld.com/d/cloud-computing/cloud-control-systems-tame-ether-878">we have heard for years</a>, and with Cisco’s Meraki deal and Trend Micro’s announcement, we are seeing the next stage of the evolution.</p>
<p>Remote management is something, you may recall, that Cisco had some <a href="http://www.wired.com/wiredenterprise/2012/07/cisco-router/">very significant, and very public issues</a> with &#8211; the company’s customer base erupted when Cisco chose to update its home Wi-Fi routers to use a web-based service, which in turn stoked privacy fears.  People revolted because Cisco owned the portal and gave its users no local option to update the firmware.</p>
<p>Unwarranted cloud fear, I say. Cisco just didn’t handle the communication very well. Had they explained to end-users that they would get a faster, more responsive, and better service, people would have adopted the service in droves. The very same people who complained about managing their routers from the clouds are already using email that runs in the cloud, which represents a much greater privacy risk.</p>
<p>This was such an issue that it gave Cisco cause to pull back and reevaluate just how they were going to deploy their cloud based service that integrated into its residential/home routers. Obviously, bringing Meraki into the fold has been part of the strategy to not only be a major player in the enterprise business market, but also have the technology and capability in house to prevent such fiascos in the future.</p>
<p>Furthermore, Meraki’s technology far transcends just a plug for Cisco. The new acquisition has been transformed into Cisco&#8217;s new Cloud Networking Group and will serve as the foundation for the its planned, larger cloud networking offers, and <a href="https://slashdot.org/topic/cloud/cisco-acquires-meraki-to-strengthen-cloud-networking/">an aid to ‘cloudify’ numerous products</a> already in Cisco’s enterprise networking portfolio.</p>
<p>There is no question in my mind that in the very near future, we will see Software as a Service networking management tools like Meraki’s, and security tools like Trend Micro’s, quickly evolve into the <em>only</em> way we manage our networks and security. Yes. <em>The only.</em> It just makes too much sense from every perspective of systems management.</p>
<p>Management systems for devices are subject to release cycles that are slow, whereas Software as a Service offerings deliver weekly release cycles. By deploying a SaaS service in your enterprise, you are assured to get a regularly updated system, and your networking and security vendors will deploy their development assets to their core functions, rather than supporting ancient versions of their management tools on random platforms.</p>
<p>Meraki’s (now Cisco’s) tools are transformative in how they will revolutionize the work of the network administrator. The new Deep Security as a Service offering will revolutionize the work of securing the cloud.</p>
<p>As an IT professional, you should be deploying your time and attention to maintaining and securing systems in the cloud, not to maintaining and securing the control systems for systems in the cloud. It is not worth your time, and it significantly slows your vendors ability to create responsive systems that actually protect your assets in the cloud.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://cloud.trendmicro.com/why-its-time-to-manage-your-networking-and-security-from-the-cloud/" data-text="Why It&#8217;s Time to Manage Your Networking and Security from the Cloud"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/why-its-time-to-manage-your-networking-and-security-from-the-cloud/"></a><a class="a2a_button_google_plus_share addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/why-its-time-to-manage-your-networking-and-security-from-the-cloud/"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-its-time-to-manage-your-networking-and-security-from-the-cloud%2F&amp;linkname=Why%20It%E2%80%99s%20Time%20to%20Manage%20Your%20Networking%20and%20Security%20from%20the%20Cloud" title="Facebook" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-its-time-to-manage-your-networking-and-security-from-the-cloud%2F&amp;linkname=Why%20It%E2%80%99s%20Time%20to%20Manage%20Your%20Networking%20and%20Security%20from%20the%20Cloud" title="Email" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-its-time-to-manage-your-networking-and-security-from-the-cloud%2F&amp;linkname=Why%20It%E2%80%99s%20Time%20to%20Manage%20Your%20Networking%20and%20Security%20from%20the%20Cloud" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_pinterest" href="http://www.addtoany.com/add_to/pinterest?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-its-time-to-manage-your-networking-and-security-from-the-cloud%2F&amp;linkname=Why%20It%E2%80%99s%20Time%20to%20Manage%20Your%20Networking%20and%20Security%20from%20the%20Cloud" title="Pinterest" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/pinterest.png" width="16" height="16" alt="Pinterest"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-its-time-to-manage-your-networking-and-security-from-the-cloud%2F&amp;linkname=Why%20It%E2%80%99s%20Time%20to%20Manage%20Your%20Networking%20and%20Security%20from%20the%20Cloud" title="Reddit" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-its-time-to-manage-your-networking-and-security-from-the-cloud%2F&amp;linkname=Why%20It%E2%80%99s%20Time%20to%20Manage%20Your%20Networking%20and%20Security%20from%20the%20Cloud" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-its-time-to-manage-your-networking-and-security-from-the-cloud%2F&amp;linkname=Why%20It%E2%80%99s%20Time%20to%20Manage%20Your%20Networking%20and%20Security%20from%20the%20Cloud" title="Slashdot" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-its-time-to-manage-your-networking-and-security-from-the-cloud%2F&amp;linkname=Why%20It%E2%80%99s%20Time%20to%20Manage%20Your%20Networking%20and%20Security%20from%20the%20Cloud" title="Tumblr" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-its-time-to-manage-your-networking-and-security-from-the-cloud%2F&amp;title=Why%20It%E2%80%99s%20Time%20to%20Manage%20Your%20Networking%20and%20Security%20from%20the%20Cloud" id="wpa2a_4">Share/Bookmark</a></p><div class="feedflare">
<a href="http://feeds.trendmicro.com/~ff/cloud-security?a=C5vWT3HFy1o:d1JTcOu1B-o:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=C5vWT3HFy1o:d1JTcOu1B-o:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=C5vWT3HFy1o:d1JTcOu1B-o:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=C5vWT3HFy1o:d1JTcOu1B-o:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=C5vWT3HFy1o:d1JTcOu1B-o:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=C5vWT3HFy1o:d1JTcOu1B-o:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=C5vWT3HFy1o:d1JTcOu1B-o:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=C5vWT3HFy1o:d1JTcOu1B-o:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/cloud-security/~4/C5vWT3HFy1o" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://cloud.trendmicro.com/why-its-time-to-manage-your-networking-and-security-from-the-cloud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5 Questions to Ask Your Security Vendor about AWS</title>
		<link>http://cloud.trendmicro.com/5-questions-aws/</link>
		<comments>http://cloud.trendmicro.com/5-questions-aws/#comments</comments>
		<pubDate>Tue, 30 Apr 2013 13:00:51 +0000</pubDate>
		<dc:creator>Justin Foster</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[Amazon EC2]]></category>
		<category><![CDATA[amazon machine image]]></category>
		<category><![CDATA[amazon web services]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[Chef]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[CloudFormation]]></category>
		<category><![CDATA[Deep Security]]></category>
		<category><![CDATA[Deep Security as a Service]]></category>
		<category><![CDATA[how to secure AWS]]></category>
		<category><![CDATA[iaas]]></category>
		<category><![CDATA[product]]></category>
		<category><![CDATA[Puppet]]></category>
		<category><![CDATA[RightScale]]></category>
		<category><![CDATA[securing AWS]]></category>
		<category><![CDATA[trend micro]]></category>

		<guid isPermaLink="false">http://cloud.trendmicro.com/?p=2978</guid>
		<description><![CDATA[Over the past weeks we have been reviewing the top 10 tips for securing instances running on Amazon Web Services. We walked through the critical controls as part of the AWS shared security model. As noted in these tips, host-based security capabilities such as intrusion detection and prevention, anti-malware, and integrity monitoring are critical for [...]]]></description>
			<content:encoded><![CDATA[<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-aws%2F&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=recommend&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px;height:30px;margin-top:5px;"></iframe><p>Over the past weeks we have been reviewing the <a href="http://cloud.trendmicro.com/tag/how-to-secure-aws/">top 10 tips for securing instances running on Amazon Web Services</a>. We walked through the critical controls as part of the AWS shared security model. As noted in these tips, host-based security capabilities such as intrusion detection and prevention, anti-malware, and integrity monitoring are critical for protecting your applications and data.</p>
<p>While some of these recommended tips involve configuring and tuning AWS itself, some require the use of third-party tools. So when looking for candidates for securing your cloud projects, here are five questions to ask potential vendors:</p>
<ol>
<li><strong>Are newly created instances automatically recognized?</strong> One of the benefits of the cloud is also one of its biggest challenges: elasticity. Often instances are automatically created, for example, in response to increased load. If those automatic instances are not also automatically protected, you can be left vulnerable.</li>
<li><strong>Does your policy speak AWS?</strong> All instances are not the same, and the security policy may vary depending on the type and purpose of the instance (for example, database versus web server). The policy engine needs to understand the information being served through AWS, and apply appropriate policies accordingly.</li>
<li><strong>Will I need to change my deployment process?</strong> A variety of commercial and open source deployment tools are used in managing today’s AWS deployments (<a href="http://www.rightscale.com">RightScale</a>, <a href="http://www.opscode.com/chef/">Chef</a>, <a href="https://puppetlabs.com/puppet/what-is-puppet/">Puppet</a>, <a href="http://aws.amazon.com/cloudformation/">CloudFormation</a>, to name a few). Being required to change those processes to fit security solutions means time, expense, and the potential for something to go wrong in the deployment process.</li>
<li><strong>Can I manage my security in one place?</strong> Having to manage multiple security policies, alerts, dashboards, etc… is both time-consuming and complicated – and increases the risk of missing key information that can impact the security of your deployment.</li>
<li><strong>Am I considered to be on the &#8216;bleeding edge&#8217;?</strong> It is great to be an early adopter, but not if doing so risks the security of your cloud deployment. Make sure the technology being used to secure your instances is established, and that the policy templates provided have already been proven in real-world deployments.</li>
</ol>
<p><strong>What challenges are you seeing in securing AWS? Let us know in the comments!</strong></p>
<hr />
<p><a href="http://deepsecurity.trendmicro.com"><img class="alignright size-full wp-image-2982" title="dsaaslogo" src="http://cloud.trendmicro.com/wp-content/uploads/2013/04/dsaaslogo.png" alt="" width="356" height="109" /></a>These questions highlight one of the challenges in securing AWS deployments: finding proven technology delivered in a way that takes full advantage AWS. That’s why we are so excited to announce that our <a href="http://deepsecurity.trendmicro.com">Deep Security as a Service for AWS</a> is now available. Based on Trend Micro’s proven <a href="http://www.trendmicro.com/us/enterprise/cloud-solutions/deep-security/index.html">Deep Security product</a>, the service runs on AWS and is specifically designed to provide the range of security capabilities to protect AWS instances. So you can set up your account and secure your AWS instances, literally in minutes.</p>
<p>You can check out and explore Deep Security as a Service by <strong>signing up now for a full, free trial at <a href="http://deepsecurity.trendmicro.com">deepsecurity.trendmicro.com</a>.</strong></p>
<p><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://cloud.trendmicro.com/5-questions-aws/" data-text="5 Questions to Ask Your Security Vendor about AWS"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/5-questions-aws/"></a><a class="a2a_button_google_plus_share addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/5-questions-aws/"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-aws%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20Security%20Vendor%20about%20AWS" title="Facebook" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-aws%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20Security%20Vendor%20about%20AWS" title="Email" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-aws%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20Security%20Vendor%20about%20AWS" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_pinterest" href="http://www.addtoany.com/add_to/pinterest?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-aws%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20Security%20Vendor%20about%20AWS" title="Pinterest" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/pinterest.png" width="16" height="16" alt="Pinterest"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-aws%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20Security%20Vendor%20about%20AWS" title="Reddit" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-aws%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20Security%20Vendor%20about%20AWS" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-aws%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20Security%20Vendor%20about%20AWS" title="Slashdot" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-aws%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20Security%20Vendor%20about%20AWS" title="Tumblr" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-aws%2F&amp;title=5%20Questions%20to%20Ask%20Your%20Security%20Vendor%20about%20AWS" id="wpa2a_8">Share/Bookmark</a></p><div class="feedflare">
<a href="http://feeds.trendmicro.com/~ff/cloud-security?a=osBAHdjShq0:QupQ_sOVMoQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=osBAHdjShq0:QupQ_sOVMoQ:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=osBAHdjShq0:QupQ_sOVMoQ:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=osBAHdjShq0:QupQ_sOVMoQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=osBAHdjShq0:QupQ_sOVMoQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=osBAHdjShq0:QupQ_sOVMoQ:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=osBAHdjShq0:QupQ_sOVMoQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=osBAHdjShq0:QupQ_sOVMoQ:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/cloud-security/~4/osBAHdjShq0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://cloud.trendmicro.com/5-questions-aws/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AWS OpsWorks: Targeting PaaS with Chef?</title>
		<link>http://cloud.trendmicro.com/aws-opsworks-targeting-paas-with-chef/</link>
		<comments>http://cloud.trendmicro.com/aws-opsworks-targeting-paas-with-chef/#comments</comments>
		<pubDate>Mon, 29 Apr 2013 18:04:56 +0000</pubDate>
		<dc:creator>Dave Asprey</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[amazon web services]]></category>
		<category><![CDATA[application management]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[Chef]]></category>
		<category><![CDATA[cloud development]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[how to secure AWS]]></category>
		<category><![CDATA[OpsCode Chef framework]]></category>
		<category><![CDATA[OpsWorks]]></category>
		<category><![CDATA[OpsWorks API]]></category>
		<category><![CDATA[paas]]></category>
		<category><![CDATA[Peritor]]></category>
		<category><![CDATA[platform as a service]]></category>

		<guid isPermaLink="false">http://cloud.trendmicro.com/?p=2959</guid>
		<description><![CDATA[Amazon Web Services did it again. Its new service, OpsWorks, is an application management service with the ability to manage applications of any scale or complexity in the AWS cloud. This integrated system manages resource provisioning, configuration management, application deployment, software updates, and monitoring and access control. The service is another offering from the leader in [...]]]></description>
			<content:encoded><![CDATA[<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fcloud.trendmicro.com%2Faws-opsworks-targeting-paas-with-chef%2F&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=recommend&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px;height:30px;margin-top:5px;"></iframe><p><a href="https://aws.amazon.com/">Amazon Web Services</a> did it again. Its new service, <a href="https://aws.amazon.com/opsworks/">OpsWorks</a>, is an application management service with the ability to manage applications of any scale or complexity in the AWS cloud. This integrated system manages resource provisioning, configuration management, application deployment, software updates, and monitoring and access control.</p>
<p>The service is another offering from the leader in cloud computing poised to disrupt a market, in this case, Platform as a Service (PaaS). OpsWorks will compete directly with PaaS mainstays Heroku, Engine Yard and AppFog. Given the speculation that AWS is working on a graphical interface to ease complex deployments, systems integrators and consultants, who traditionally worked with administrators on such deployments, may also be affected.</p>
<p>Functionally, AWS OpsWorks enables developers to use ‘<a href="http://docs.aws.amazon.com/opsworks/latest/userguide/workinglayers-basics.html">layers’</a> which serve as structures for whatever instance a developer deploys. Every instance deployed by AWS OpsWorks “must be a member of at least one layer, which define an instance&#8217;s role in the stack and manage the details of setting up and configuring the instance, deploying applications, and so on.”</p>
<p>While the AWS OpsWorks console only permits an instance to be a member of one layer, using the AWS OpsWorks API gives the option of letting instances optionally be a member of multiple compatible layers. For example, if you wanted to use on of your application servers for administration, you could create a custom administrative layer and add one of the application server instances to that layer. The administrative layer&#8217;s recipes configure that application server instance to perform administrative tasks, and install any additional required software. The other application server instances are just application servers.</p>
<p>Operational control, automation, and flexibility are central to the OpsWorks offering. For a developer to define and deploy apps, all he has to do is instruct OpsWorks where the code resides and the service takes it from there, handling deployment tasks such as database configuration. Because OpsWorks uses the <a href="http://www.opscode.com/blog/2013/02/20/aws-opsworks-uses-opscode-chef-as-default-automation-engine/">Opscode Chef framework</a>, developers can use existing recipes or choose from an extensive offering of community-built configurations.</p>
<p>Did I mention that Trend Micro’s <a href="https://deepsecurity.trendmicro.com/trial">Deep Security</a> service runs on AWS and is best set to be deployed automatically by Chef, which works with OpsWorks?</p>
<p>Werner Vogels has <a href="http://www.allthingsdistributed.com/2013/02/aws-opsworks.html">a detailed post</a> that outlines both OpsWorks and the general AWS strategy. Amazon first rolled out its core services of storage database and computing and then added advance offerings such as DNS, messaging, etc., and now receiving management tools. OpsWorks is an important next step in revealing the AWS approach to the development of their service offerings. OpsWorks is a solid management tool that increases user options significantly, and adds to AWS’ growing number of different <a href="https://aws.amazon.com/application-management/">Application Management Services</a>. It looks like part of a greater push to garner wider enterprise adoption, as confirmed by <a href="http://www.businessinsider.com/amazon-enterprise-hires-2013-3">this recent article</a>.</p>
<p>Old Cloud gurus know that OpsWorks was invented in Germany and is based on the Scalarium technology of <a href="http://www.peritor.com/">Peritor</a>. Scalarium was bought in 2012 by Amazon.</p>
<p><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://cloud.trendmicro.com/aws-opsworks-targeting-paas-with-chef/" data-text="AWS OpsWorks: Targeting PaaS with Chef?"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/aws-opsworks-targeting-paas-with-chef/"></a><a class="a2a_button_google_plus_share addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/aws-opsworks-targeting-paas-with-chef/"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Faws-opsworks-targeting-paas-with-chef%2F&amp;linkname=AWS%20OpsWorks%3A%20Targeting%20PaaS%20with%20Chef%3F" title="Facebook" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Faws-opsworks-targeting-paas-with-chef%2F&amp;linkname=AWS%20OpsWorks%3A%20Targeting%20PaaS%20with%20Chef%3F" title="Email" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Faws-opsworks-targeting-paas-with-chef%2F&amp;linkname=AWS%20OpsWorks%3A%20Targeting%20PaaS%20with%20Chef%3F" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_pinterest" href="http://www.addtoany.com/add_to/pinterest?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Faws-opsworks-targeting-paas-with-chef%2F&amp;linkname=AWS%20OpsWorks%3A%20Targeting%20PaaS%20with%20Chef%3F" title="Pinterest" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/pinterest.png" width="16" height="16" alt="Pinterest"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Faws-opsworks-targeting-paas-with-chef%2F&amp;linkname=AWS%20OpsWorks%3A%20Targeting%20PaaS%20with%20Chef%3F" title="Reddit" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Faws-opsworks-targeting-paas-with-chef%2F&amp;linkname=AWS%20OpsWorks%3A%20Targeting%20PaaS%20with%20Chef%3F" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Faws-opsworks-targeting-paas-with-chef%2F&amp;linkname=AWS%20OpsWorks%3A%20Targeting%20PaaS%20with%20Chef%3F" title="Slashdot" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Faws-opsworks-targeting-paas-with-chef%2F&amp;linkname=AWS%20OpsWorks%3A%20Targeting%20PaaS%20with%20Chef%3F" title="Tumblr" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcloud.trendmicro.com%2Faws-opsworks-targeting-paas-with-chef%2F&amp;title=AWS%20OpsWorks%3A%20Targeting%20PaaS%20with%20Chef%3F" id="wpa2a_12">Share/Bookmark</a></p><div class="feedflare">
<a href="http://feeds.trendmicro.com/~ff/cloud-security?a=RgJD3lyLdFs:7I8HSaSfmls:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=RgJD3lyLdFs:7I8HSaSfmls:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=RgJD3lyLdFs:7I8HSaSfmls:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=RgJD3lyLdFs:7I8HSaSfmls:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=RgJD3lyLdFs:7I8HSaSfmls:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=RgJD3lyLdFs:7I8HSaSfmls:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=RgJD3lyLdFs:7I8HSaSfmls:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=RgJD3lyLdFs:7I8HSaSfmls:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/cloud-security/~4/RgJD3lyLdFs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://cloud.trendmicro.com/aws-opsworks-targeting-paas-with-chef/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 AWS Security Tips: #10 Penetration Testing</title>
		<link>http://cloud.trendmicro.com/top-10-aws-security-tips-10-penetration-testing/</link>
		<comments>http://cloud.trendmicro.com/top-10-aws-security-tips-10-penetration-testing/#comments</comments>
		<pubDate>Wed, 17 Apr 2013 13:58:11 +0000</pubDate>
		<dc:creator>Mark Nunnikhoven</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[AWS best practices]]></category>
		<category><![CDATA[aws security]]></category>
		<category><![CDATA[cloud application security]]></category>
		<category><![CDATA[cloud penetration testing]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Deep Security as a Service]]></category>
		<category><![CDATA[how to do penetration testing]]></category>
		<category><![CDATA[how to run a penetration test]]></category>
		<category><![CDATA[how to run a pentest]]></category>
		<category><![CDATA[how to secure AWS]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[pen test]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[pentesting in the cloud]]></category>
		<category><![CDATA[securing AWS]]></category>
		<category><![CDATA[site operation security]]></category>
		<category><![CDATA[site operations]]></category>
		<category><![CDATA[siteops]]></category>
		<category><![CDATA[top AWS tips]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://cloud.trendmicro.com/?p=2965</guid>
		<description><![CDATA[In last week&#8217;s post, we gave a high level overview of vulnerability assessments. This type of assessment results in a prioritized list of vulnerabilities in your deployment. It&#8217;s an excellent first step in knowing the state of your deployment. The next step you should take is to conduct a penetration test. The Test A penetration [...]]]></description>
			<content:encoded><![CDATA[<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-10-penetration-testing%2F&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=recommend&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px;height:30px;margin-top:5px;"></iframe><p><span style="font-size: 13px;">In <a href="http://cloud.trendmicro.com/top-10-aws-security-tips-9-conduct-vulnerability-assessments/">last week&#8217;s post</a>, we gave a high level overview of vulnerability assessments. This type of assessment results in a prioritized list of vulnerabilities in your deployment. It&#8217;s an excellent first step in knowing the state of your deployment.</span></p>
<p>The next step you should take is to conduct a penetration test.</p>
<h3>The Test</h3>
<p>A <a href="http://en.wikipedia.org/wiki/Penetration_test">penetration test</a> (or simply, pentest) is an active test of your defenses. You&#8217;re hiring a trusted 3rd party to attack your deployment in order to find exploitable vulnerabilities. The theory is that it&#8217;s better to have someone working with you do this before a malicious attacker can.</p>
<p>The test report is going to provide detailed information on how the attacks were conducted, what was successful, how defenses could be improved, etc.</p>
<h3>Setting up a Test</h3>
<p>Pentests can vary greatly depending on their goals, your deployment, timelines, etc. A few key tips for organizing a pentest on AWS include:</p>
<ol>
<li>Use a trusted 3rd party to conduct the test</li>
<li>Give AWS a heads up</li>
<li>Establish a time frame but not a testing time</li>
</ol>
<h4>Trusted 3rd Party</h4>
<p>While you might have the skill set on your security team, it&#8217;s usually best to have a trusted 3rd party conduct the penetration test. Penetration testing is as much an art as a science. A good penetration tester is going to be able to ferret out issues with your deployment that you never saw coming.</p>
<p>If you use an internal resource, they will approach the test with a biased mindset. The most typical issue that surfaces is that an internal resource will either attack the most common&#8211;and well known&#8211;weak spot or avoid that option entirely. Either way, that type of test is not a close enough simulation of a real attack.</p>
<p>A trusted 3rd party will approach the test methodically. Working through your exposed attack surface gradually finding issues with your deployment and mapping your exploitable vulnerabilities.</p>
<h4>Give AWS a Heads Up</h4>
<p>AWS requests that your provide them with notification <strong>before</strong> any vulnerability scanning or penetration testing is done. They provide a <a href="https://aws.amazon.com/security/penetration-testing/">convenient form</a> to help make that process as easy as possible.</p>
<p>As part of the form, AWS requires:</p>
<ul>
<li><span style="font-size: 13px;">information about the instances to be tested</span></li>
<li><span style="font-size: 13px;">the time frame for the testing</span></li>
<li><span style="font-size: 13px;">agreement with their terms &amp; conditions</span></li>
<li><span style="font-size: 13px;">appropriate use of the tool set used during the test</span></li>
</ul>
<p>Completing the form only takes a few minutes and will save a lot of headaches. Be sure to take the time to fill it in with the details of your test.</p>
<h4>Establish a Time Frame</h4>
<p>The first time you have a pentest done, it&#8217;s extremely tempting to provide a specific time at which the test will be conducted. In fact, that&#8217;s one the pieces of information that AWS requests up front.</p>
<p>Within reason, keep this information compartmentalized. Don&#8217;t tell your security team, your ops teams, or support.</p>
<p>Why not? Because if any of the teams normally involved in incident response knows about the test ahead of time you won&#8217;t be testing the right things.</p>
<p>The ideas behind the pentest is to measure you current security posture at any given time. If everyone knows ahead of time that they&#8217;re going to be tested, they are going to prepare ahead of time. While you may look better on the test report, you&#8217;re doing yourself a disservice.</p>
<p>When a real attack happens, no one calls ahead.</p>
<h3>The Report</h3>
<p>So your &#8220;attacker&#8221; has tested your defenses and found a few holes. Maybe they&#8217;ve even been able to breach all of your defenses and gain access to key customer data. <strong>Don&#8217;t panic</strong>. That&#8217;s OK. This is the whole reason you run a pentest. It&#8217;s much better to have <strong>your</strong> known testing attacker reach your customer data than an unplanned attacker with actual malicious intent.</p>
<p>At the end of the test, you should receive a comprehensive report detailing the results. This should include:</p>
<ul>
<li><span style="font-size: 13px;">how far the tester was able to breach your </span>defences</li>
<li><span style="font-size: 13px;">details of the vulnerabilities exploited</span></li>
<li><span style="font-size: 13px;">suggestions for mitigating these issues</span></li>
<li><span style="font-size: 13px;">another other issues found or observations of the tester</span></li>
</ul>
<p>Even though it may be hard to read the results, take them to heart. Work through each of the issues raised in turn and <strong>fix the problem</strong>. This is the crucial step. You have to take action on the results.</p>
<h3>Stronger Than Before</h3>
<p>After you&#8217;ve worked through the issues raised in the report, your defenses should be stronger than ever. Better yet, you know your defenses work. They&#8217;ve been actively tested.</p>
<p>While no security is perfect, by following the tips in this series you can be confident that you&#8217;ve taken reasonable steps to ensure that only the most determined attackers are going to have a chance at breaching your defenses.</p>
<hr />
<p><strong>How do you handle penetration testing in the cloud? Please share your tips in the comments!</strong> And if you’re interested in securing your EC2 or VPC instances, check out our new <a href="https://deepsecurity.trendmicro.com/trial">Deep Security as a Service</a> for cloud servers, currently in free Beta.</p>
<p><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://cloud.trendmicro.com/top-10-aws-security-tips-10-penetration-testing/" data-text="Top 10 AWS Security Tips: #10 Penetration Testing"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/top-10-aws-security-tips-10-penetration-testing/"></a><a class="a2a_button_google_plus_share addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/top-10-aws-security-tips-10-penetration-testing/"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-10-penetration-testing%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%2310%20Penetration%20Testing" title="Facebook" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-10-penetration-testing%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%2310%20Penetration%20Testing" title="Email" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-10-penetration-testing%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%2310%20Penetration%20Testing" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_pinterest" href="http://www.addtoany.com/add_to/pinterest?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-10-penetration-testing%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%2310%20Penetration%20Testing" title="Pinterest" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/pinterest.png" width="16" height="16" alt="Pinterest"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-10-penetration-testing%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%2310%20Penetration%20Testing" title="Reddit" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-10-penetration-testing%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%2310%20Penetration%20Testing" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-10-penetration-testing%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%2310%20Penetration%20Testing" title="Slashdot" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-10-penetration-testing%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%2310%20Penetration%20Testing" title="Tumblr" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-10-penetration-testing%2F&amp;title=Top%2010%20AWS%20Security%20Tips%3A%20%2310%20Penetration%20Testing" id="wpa2a_16">Share/Bookmark</a></p><div class="feedflare">
<a href="http://feeds.trendmicro.com/~ff/cloud-security?a=Aychs_kg_BQ:JNIIgkERDMY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=Aychs_kg_BQ:JNIIgkERDMY:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=Aychs_kg_BQ:JNIIgkERDMY:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=Aychs_kg_BQ:JNIIgkERDMY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=Aychs_kg_BQ:JNIIgkERDMY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=Aychs_kg_BQ:JNIIgkERDMY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=Aychs_kg_BQ:JNIIgkERDMY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=Aychs_kg_BQ:JNIIgkERDMY:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/cloud-security/~4/Aychs_kg_BQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://cloud.trendmicro.com/top-10-aws-security-tips-10-penetration-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why are you scared of the cloud?</title>
		<link>http://cloud.trendmicro.com/why-are-you-scared-of-the-cloud/</link>
		<comments>http://cloud.trendmicro.com/why-are-you-scared-of-the-cloud/#comments</comments>
		<pubDate>Mon, 15 Apr 2013 13:15:07 +0000</pubDate>
		<dc:creator>Ryan Delany</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[client]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[cloud storage]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[IT management]]></category>
		<category><![CDATA[Netflix]]></category>
		<category><![CDATA[scared of the cloud]]></category>
		<category><![CDATA[secure cloud]]></category>
		<category><![CDATA[small business cloud]]></category>

		<guid isPermaLink="false">http://cloud.trendmicro.com/?p=2905</guid>
		<description><![CDATA[As a Product Marketing Manager for Trend Micro™ Worry-Free™ Business Security Services, I hear a lot of objections about the product, and in particular, a lot of cloud-related fears. Some examples of things I hear from customers and partners are: “I wouldn’t be secure if my Internet connection went down.” “I don’t want to put [...]]]></description>
			<content:encoded><![CDATA[<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-are-you-scared-of-the-cloud%2F&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=recommend&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px;height:30px;margin-top:5px;"></iframe><p>As a Product Marketing Manager for Trend Micro™ <a href="http://www.trendmicro.com/us/small-business/product-security/worry-free-services/index.html">Worry-Free™ Business Security Services</a>, I hear a lot of objections about the product, and in particular, a lot of cloud-related fears. Some examples of things I hear from customers and partners are:</p>
<p>“I wouldn’t be secure if my Internet connection went down.”</p>
<p>“I don’t want to put all my data in the cloud.”</p>
<p>“I don’t want to waste all my bandwidth, uploading everything to the cloud to be scanned.”</p>
<p>The cloud is becoming better understood by the average person these days, thanks to companies like <a href="http://www.google.com">Google</a>, <a href="http://www.apple.com">Apple</a>, <a href="http://www.netflix.com">Netflix</a>, and other consumer-oriented companies that have spent a lot of marketing dollars. They are helping their customers understand cloud-related products, and how those products are delivered. Fortunately, this knowledge spills over nicely to small business owners and employees who are consumers of these cloud-based services at home.</p>
<p>I don’t want to get in to a deep technical explanation, but for the purposes of this article, it will help you to understand the architecture of Worry-Free Business Security Services. It is an endpoint security solution, purpose built for small and medium businesses (SMBs) to protect you and your data on these three types of devices: Windows, Mac, and Android. There are two components that make up this solution.</p>
<p>The first component is what I call the management console. It is what you would use as an administrator to manage the product, configure policies, review log files, run reports, and do any day-to-day tasks related to the product. The management console physically resides in a highly-secure Trend Micro data center.</p>
<p>The second component is called the client. It is what gets installed on each device (Windows, Mac, Android) and is responsible for providing the actual protection of the device. This component handles the scanning of files, blocking of malware found, and reporting of results to the management console.</p>
<h3>“I wouldn’t be secure if my Internet connection went down”</h3>
<p>Now that you understand the architecture, it should be pretty easy to see why this objection is not a valid one. Logically speaking, if all the security is provided by the client that resides physically on the device, how can you possibly be less secure without an Internet connection? The answer is, you aren’t less secure. Everything the product needs to protect your device is on the device, no Internet connection required.</p>
<h3>“I don’t want to put all my data in the cloud”</h3>
<p>Since the management console is physically located in the cloud, there is a minimal amount of information residing in the cloud. So on the surface this may seem like a valid objection, depending on how you define “all my data.” The only information that does get saved in the cloud is log data generated by the client, and any additional comments/notes added to the console by you, the administrator.</p>
<p>The product does not copy any of your existing items, such as documents, spreadsheets, files, etc. and move them to the cloud. Bottom line, none of your stuff is moved to the cloud. We only store data about detected malware such as time stamp, computer name, virus name, and other relevant metadata in the cloud.</p>
<h3>“I don’t want to waste all my bandwidth uploading everything to the cloud to be scanned”</h3>
<p>Going back to the architecture discussion, I mentioned that all of the protection is provided by the second component, the client, which is physically located on the device. All the scanning, analyzing, and remediation are done on the device so this objection is not valid.</p>
<p>The product does have some innovative technologies such as Smart Scan that leverages updates delivered from the cloud. However, ironically, these features actually result in less bandwidth utilization, not more. Files that are being scanned never leave the device and are never uploaded anywhere, including the cloud.</p>
<h3>Are you still scared?</h3>
<p>In summary, there is really no reason to be scared of the cloud as it relates to a security solution like Worry-Free Business Security Services. It does not depend on an active Internet connection to provide maximum security, nor is your data “taken” from you and stored in the cloud.  And it doesn’t shuttle your files out to the cloud and back to scan them because it is all done locally.</p>
<p><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://cloud.trendmicro.com/why-are-you-scared-of-the-cloud/" data-text="Why are you scared of the cloud?"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/why-are-you-scared-of-the-cloud/"></a><a class="a2a_button_google_plus_share addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/why-are-you-scared-of-the-cloud/"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-are-you-scared-of-the-cloud%2F&amp;linkname=Why%20are%20you%20scared%20of%20the%20cloud%3F" title="Facebook" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-are-you-scared-of-the-cloud%2F&amp;linkname=Why%20are%20you%20scared%20of%20the%20cloud%3F" title="Email" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-are-you-scared-of-the-cloud%2F&amp;linkname=Why%20are%20you%20scared%20of%20the%20cloud%3F" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_pinterest" href="http://www.addtoany.com/add_to/pinterest?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-are-you-scared-of-the-cloud%2F&amp;linkname=Why%20are%20you%20scared%20of%20the%20cloud%3F" title="Pinterest" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/pinterest.png" width="16" height="16" alt="Pinterest"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-are-you-scared-of-the-cloud%2F&amp;linkname=Why%20are%20you%20scared%20of%20the%20cloud%3F" title="Reddit" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-are-you-scared-of-the-cloud%2F&amp;linkname=Why%20are%20you%20scared%20of%20the%20cloud%3F" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-are-you-scared-of-the-cloud%2F&amp;linkname=Why%20are%20you%20scared%20of%20the%20cloud%3F" title="Slashdot" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-are-you-scared-of-the-cloud%2F&amp;linkname=Why%20are%20you%20scared%20of%20the%20cloud%3F" title="Tumblr" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcloud.trendmicro.com%2Fwhy-are-you-scared-of-the-cloud%2F&amp;title=Why%20are%20you%20scared%20of%20the%20cloud%3F" id="wpa2a_20">Share/Bookmark</a></p><div class="feedflare">
<a href="http://feeds.trendmicro.com/~ff/cloud-security?a=wLSwwdqz0i0:E8uuM17EKIw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=wLSwwdqz0i0:E8uuM17EKIw:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=wLSwwdqz0i0:E8uuM17EKIw:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=wLSwwdqz0i0:E8uuM17EKIw:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=wLSwwdqz0i0:E8uuM17EKIw:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=wLSwwdqz0i0:E8uuM17EKIw:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=wLSwwdqz0i0:E8uuM17EKIw:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=wLSwwdqz0i0:E8uuM17EKIw:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/cloud-security/~4/wLSwwdqz0i0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://cloud.trendmicro.com/why-are-you-scared-of-the-cloud/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Top 10 AWS Security Tips: #9 Conduct Vulnerability Assessments</title>
		<link>http://cloud.trendmicro.com/top-10-aws-security-tips-9-conduct-vulnerability-assessments/</link>
		<comments>http://cloud.trendmicro.com/top-10-aws-security-tips-9-conduct-vulnerability-assessments/#comments</comments>
		<pubDate>Wed, 10 Apr 2013 13:00:02 +0000</pubDate>
		<dc:creator>Justin Foster</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[Amazon EC2]]></category>
		<category><![CDATA[amazon machine image]]></category>
		<category><![CDATA[amazon web services]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[how to secure AWS]]></category>
		<category><![CDATA[iaas]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://cloud.trendmicro.com/?p=2951</guid>
		<description><![CDATA[In this series, Mark and I have talked about hardening your AWS resources (both inside and outside of your instances) and preforming ongoing monitoring. The last two tips are around measuring your overall security so that you can understand your risks and measure your progress. It may be an old adage but it still rings true&#8230; [...]]]></description>
			<content:encoded><![CDATA[<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-9-conduct-vulnerability-assessments%2F&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=recommend&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px;height:30px;margin-top:5px;"></iframe><p>In this <a href="http://cloud.trendmicro.com/tag/how-to-secure-aws/" target="_blank">series</a>, <a href="http://twitter.com/marknca" target="_blank">Mark</a> and I have talked about hardening your AWS resources (both inside and outside of your instances) and preforming ongoing monitoring. The last two tips are around measuring your overall security so that you can understand your risks and measure your progress.</p>
<p>It may be an old adage but it still rings true&#8230; You can&#8217;t manage what you can&#8217;t measure. You may have layer upon layer of defense, but unless you conduct a vulnerability assessment you don&#8217;t really know where you stand.</p>
<h3>Assess Your IaaS</h3>
<p><img style="float: right;" src="http://cloud.trendmicro.com/wp-content/uploads/2013/04/blog_vmlc.png" alt="" width="410" height="450" />Conducting a vulnerability assessment includes identifying and prioritizing vulnerabilities in all areas of your system. You start by cataloging the vulnerabilities through a mixtures of tools, services and manual evaluation. Then you move on to prioritizing the vulnerabilities and evaluating ways of mitigating.</p>
<p><a href="http://en.wikipedia.org/wiki/Vulnerability_scanner" target="_blank">Tools</a> and services often take two forms, network scanners or host-based. Within these two forms there are passive and active scanners. Some vulnerabilities can only be detected on the instance or with privileged network access.</p>
<p>If you are running a network scan against your AWS instances, you need to fill out the <a href="https://aws.amazon.com/security/penetration-testing/" target="_blank">AWS Vulnerability / Penetration Testing Request Form</a>. This way, AWS knows you will be conducting a scan and your connectivity won&#8217;t be disrupted.</p>
<h3>Feeling Vulnerable?</h3>
<p>Once you know where you stand, its time to work towards improving your security posture. You start with the most serious vulnerabilities and work your way down the list.</p>
<p>Remediation can take many different forms. It may be as simple as closing a port, or turning off a service. In other cases it requires a software patch or a rule from an intrusion prevention system. No matter how you remediate, it is important to verify that remediation is in place and protecting the vulnerability.</p>
<p>The number of unmitigated vulnerabilities in your application makes a great metric to track over time in order to understand if you are continually improving.</p>
<p>&nbsp;</p>
<p>Stay tuned for the next (and final) tip where we look at another important way to evaluate your security.</p>
<hr />
<p><strong>Have any tips for how you conduct vulnerability assessments on AWS? Please share them in the comments!</strong> And if you’re interested in securing your EC2 or VPC instances, check out our new <a href="https://deepsecurity.trendmicro.com/">Deep Security as a Service</a> for cloud servers, currently in free Beta.</p>
<p><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://cloud.trendmicro.com/top-10-aws-security-tips-9-conduct-vulnerability-assessments/" data-text="Top 10 AWS Security Tips: #9 Conduct Vulnerability Assessments"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/top-10-aws-security-tips-9-conduct-vulnerability-assessments/"></a><a class="a2a_button_google_plus_share addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/top-10-aws-security-tips-9-conduct-vulnerability-assessments/"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-9-conduct-vulnerability-assessments%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%239%20Conduct%20Vulnerability%20Assessments" title="Facebook" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-9-conduct-vulnerability-assessments%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%239%20Conduct%20Vulnerability%20Assessments" title="Email" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-9-conduct-vulnerability-assessments%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%239%20Conduct%20Vulnerability%20Assessments" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_pinterest" href="http://www.addtoany.com/add_to/pinterest?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-9-conduct-vulnerability-assessments%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%239%20Conduct%20Vulnerability%20Assessments" title="Pinterest" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/pinterest.png" width="16" height="16" alt="Pinterest"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-9-conduct-vulnerability-assessments%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%239%20Conduct%20Vulnerability%20Assessments" title="Reddit" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-9-conduct-vulnerability-assessments%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%239%20Conduct%20Vulnerability%20Assessments" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-9-conduct-vulnerability-assessments%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%239%20Conduct%20Vulnerability%20Assessments" title="Slashdot" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-9-conduct-vulnerability-assessments%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%239%20Conduct%20Vulnerability%20Assessments" title="Tumblr" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-9-conduct-vulnerability-assessments%2F&amp;title=Top%2010%20AWS%20Security%20Tips%3A%20%239%20Conduct%20Vulnerability%20Assessments" id="wpa2a_24">Share/Bookmark</a></p><div class="feedflare">
<a href="http://feeds.trendmicro.com/~ff/cloud-security?a=6ZhXuI5tJgc:O6LkM8y1wPc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=6ZhXuI5tJgc:O6LkM8y1wPc:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=6ZhXuI5tJgc:O6LkM8y1wPc:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=6ZhXuI5tJgc:O6LkM8y1wPc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=6ZhXuI5tJgc:O6LkM8y1wPc:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=6ZhXuI5tJgc:O6LkM8y1wPc:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=6ZhXuI5tJgc:O6LkM8y1wPc:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=6ZhXuI5tJgc:O6LkM8y1wPc:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/cloud-security/~4/6ZhXuI5tJgc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://cloud.trendmicro.com/top-10-aws-security-tips-9-conduct-vulnerability-assessments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5 More Questions to Ask Your RMM Vendor about Integrated Security Solutions</title>
		<link>http://cloud.trendmicro.com/5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions/</link>
		<comments>http://cloud.trendmicro.com/5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions/#comments</comments>
		<pubDate>Mon, 08 Apr 2013 13:03:19 +0000</pubDate>
		<dc:creator>Ryan Delany</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[5 things to ask your RMM vendor]]></category>
		<category><![CDATA[choosing security solution]]></category>
		<category><![CDATA[integrated security]]></category>
		<category><![CDATA[more integrated security questions]]></category>
		<category><![CDATA[more questions]]></category>
		<category><![CDATA[questions to ask]]></category>
		<category><![CDATA[RMM vendor]]></category>
		<category><![CDATA[security solution]]></category>
		<category><![CDATA[vendor questions]]></category>
		<category><![CDATA[what to ask]]></category>

		<guid isPermaLink="false">http://cloud.trendmicro.com/?p=2909</guid>
		<description><![CDATA[Remote management module (RMM) vendors frequently offer an integrated security solution with their core product. But how does the security featured in these integrated products compare? In a previous blog, I wrote about the five questions to ask your RMM vendor about integrated security offerings. Now, here are five more questions to make sure you [...]]]></description>
			<content:encoded><![CDATA[<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fcloud.trendmicro.com%2F5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=recommend&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px;height:30px;margin-top:5px;"></iframe><p>Remote management module (RMM) vendors frequently offer an integrated security solution with their core product. But how does the security featured in these integrated products compare? In a previous blog, I wrote about the <a href="http://cloud.trendmicro.com/?p=2907">five questions to ask your RMM vendor</a> about integrated security offerings. Now, here are five more questions to make sure you know what’s covered and what isn’t in these solutions.</p>
<h3>What is the process for acquiring licenses for an integrated security solution?</h3>
<p>Sometimes you are required to make significant up-front purchases of security solution licenses in order to get specific pricing, or simply because they are sold in blocks and you don’t have the flexibility to increase and decrease your license count on-the-fly to match your business needs.</p>
<p>Separate from the pricing and any up-front costs, how do you obtain those licenses? Do you have to place an order through your RMM vendor and then wait a period of time until they can supply those licenses, because they &#8211; in turn &#8211; have to request them from the security solution vendor? What happens if you are doing a new roll-out on the weekend and you didn’t initiate that process in time? Can you get licenses on demand, 24x7x365?</p>
<h3>What is the process for obtaining support for the integrated security solution?</h3>
<p>RMM vendors aren’t the most qualified to support a security solution due to their lack of knowledge and expertise (which is expected since they didn’t build the security solutions). So how do you get support? Can you contact the security solution vendor directly? Or do you have to submit tickets/cases through your RMM vendor and wait for the escalation process to get to the security solution vendor? What is the average response time you can expect when you open a case? And more importantly, how long will your customers have to wait?</p>
<h3>How long is your contract with the security solution vendor? And what happens when that contract expires?</h3>
<p>Just like in your business, where you negotiate term-based contracts with your customers, RMM vendors negotiate contracts with security solution vendors that have a term associated with them. It’s important to be aware of the implications if that term happens to expire and the RMM vendor decides not to renew it, and switches to another security solution.</p>
<p>Will they renew the contract with no impact to you? Or will they decide to partner with another vendor? And what does that mean for you and your customers?</p>
<h3>If you change the integrated security solution, how does that impact me?</h3>
<p>Unfortunately for you, if your RMM vendor decides to switch security solutions, you will most likely be forced to follow suit. This means despite all the effort you spent deploying the security solution in the first place, you will have to do it again.</p>
<p>Don’t expect any help from the outgoing security solution vendor either, as they have no incentive or motivation to make that process easier for you. There’s also the challenge of re-training your entire staff on the new solution. How much time is that going to take? And what impact will that have on your bottom line? What will the RMM vendor do to mitigate that impact?</p>
<h3>What happens if you get acquired, consolidate, or go out of business?  Are my customers still protected?</h3>
<p>The RMM market is extremely crowded, with at least 30 different companies offering a similar product with similar functionality. All are vying for a piece of the MSP market that is on a rapid upward trajectory.  These are ripe conditions for consolidation, acquisition, and &#8211; in some cases &#8211; closing up shop.</p>
<p>If your RMM vendor is the victim of one of these events, the integrated security solution they offered may become a casualty.  Contracts may not carry over or be honored by the acquiring entity, or the acquiring entity may have a relationship with a different security solution, forcing you to rip out and replace everything.</p>
<p>If your RMM vendor goes out of business, don’t expect the integrated security solution vendor to keep providing the security solution at the same price, or at all. What assurances does the RMM vendor have in place for this situation?</p>
<p>&nbsp;</p>
<p>With these questions in hand, you should be prepared to learn all you need to know about the integrated security in RMM solutions. <strong>Have others that we should add to this list? Let us know in the comment section below!</strong></p>
<p><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://cloud.trendmicro.com/5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions/" data-text="5 More Questions to Ask Your RMM Vendor about Integrated Security Solutions"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions/"></a><a class="a2a_button_google_plus_share addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions/"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20More%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="Facebook" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20More%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="Email" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20More%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_pinterest" href="http://www.addtoany.com/add_to/pinterest?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20More%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="Pinterest" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/pinterest.png" width="16" height="16" alt="Pinterest"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20More%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="Reddit" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20More%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20More%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="Slashdot" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20More%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="Tumblr" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcloud.trendmicro.com%2F5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;title=5%20More%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" id="wpa2a_28">Share/Bookmark</a></p><div class="feedflare">
<a href="http://feeds.trendmicro.com/~ff/cloud-security?a=FUG-N773WPU:KPP8hsvRVhU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=FUG-N773WPU:KPP8hsvRVhU:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=FUG-N773WPU:KPP8hsvRVhU:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=FUG-N773WPU:KPP8hsvRVhU:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=FUG-N773WPU:KPP8hsvRVhU:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=FUG-N773WPU:KPP8hsvRVhU:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=FUG-N773WPU:KPP8hsvRVhU:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=FUG-N773WPU:KPP8hsvRVhU:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/cloud-security/~4/FUG-N773WPU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://cloud.trendmicro.com/5-more-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Software Defined Software: The History of “Software Defined”</title>
		<link>http://cloud.trendmicro.com/software-defined-software-the-history-of-software-defined/</link>
		<comments>http://cloud.trendmicro.com/software-defined-software-the-history-of-software-defined/#comments</comments>
		<pubDate>Thu, 04 Apr 2013 13:43:35 +0000</pubDate>
		<dc:creator>Dave Asprey</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Akami]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[CASE]]></category>
		<category><![CDATA[cloud networking]]></category>
		<category><![CDATA[cloudwashing]]></category>
		<category><![CDATA[Dave Asprey]]></category>
		<category><![CDATA[Deep Security]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[software defined]]></category>
		<category><![CDATA[software defined cloud networking]]></category>
		<category><![CDATA[software defined data center]]></category>
		<category><![CDATA[software defined storage]]></category>
		<category><![CDATA[vCloud]]></category>
		<category><![CDATA[vCloud Director]]></category>
		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://cloud.trendmicro.com/?p=2936</guid>
		<description><![CDATA[“Software defined” is the latest buzzword in IT and cloud. Some people hate it because marketers are jumping on ”software defined” almost as fast as they jumped on the word “cloud” years before they had real cloud products. Cloudwashing was a real phenomenon, and it was easy to say. “Software Defined Washing” just doesn’t roll [...]]]></description>
			<content:encoded><![CDATA[<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fcloud.trendmicro.com%2Fsoftware-defined-software-the-history-of-software-defined%2F&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=recommend&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px;height:30px;margin-top:5px;"></iframe><p><a href="http://cloud.trendmicro.com/wp-content/uploads/2013/04/software-defined-software1.jpg"><img class=" wp-image-2944 alignright" src="http://cloud.trendmicro.com/wp-content/uploads/2013/04/software-defined-software1.jpg" alt="" width="405" height="300" /></a></p>
<p>“Software defined” is the latest <a href="http://www.networkcomputing.com/data-center/the-software-defined-data-center-dissect/240006848">buzzword</a> in IT and cloud. Some people hate it because marketers are jumping on ”software defined” almost as fast as they jumped on the word “cloud” years before they had real cloud products. <a href="http://cloud.trendmicro.com/the-top-eight-most-annoying-cloud-marketing-mistakes/">Cloudwashing</a> was a real phenomenon, and it was easy to say. “Software Defined Washing” just doesn’t roll off the tongue the same way, and it implies IP-enabled virtual laundry.</p>
<p>Here is an explanation of why you should embrace the term (I like it even more than cloud) and a view what we called it before “software defined” became in vogue.</p>
<p>In vogue it is. VMware likes “software defined” so much that they <a href="http://blogs.vmware.com/console/2012/07/vmware-and-nicira-advancing-the-software-defined-datacenter.html">bought</a> SDN vendor Nicira for the<a href="http://blogs.vmware.com/vcloud/tag/software-defined-datacenter"> Software Defined Data Center</a>. EMC is <a href="http://chucksblog.emc.com/chucks_blog/2013/04/going-to-emc-world-interested-in-software-defined-storage.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+emc%2FYkrh+%28Chuck%27s+Blog%29">all over</a> Software Defined Storage. My friends at Arista Networks talk about <a href="http://www.aristanetworks.com/en/blogs/?p=582">Software defined cloud networking</a> and may well have been the originators of the SDN term. (If I’m wrong and you know who invented the term, please tell me &#8211; <a href="http://www.twitter.com/daveasprey">@daveasprey</a>)</p>
<p>The truth is that the idea is not new. Here’s what we used to call “software defined”.</p>
<p><strong>Policy based whatever</strong></p>
<p>In 1999, I co-wrote a 350 page book called “Business Class Internet” for Prentice-Hall that never got published thanks to the dotcom bust. In it, I wrote extensively about how policy-based and policy-driven architecture was required for the Internet to reach the levels of availability and security that enterprises expect. Network engineers have been talking about policy and policy-based architecture for more than a decade now. VLAN policies are even today a fundamental part of keeping cloud networks segmented.</p>
<p>The difference between software defined and policy-based is… marketing. Then again, marketing matters enormously. The proto-cloud service I created years ago at Speedera (now <a href="http://www.akamai.com/">Akamai</a>) was called “flex computing” because I didn’t have the marketing smarts to think of the word “cloud.” At the end of the day, it did exactly what infrastructure as a service clouds do: provision new instances based on rules or policies. But it had the wrong name!</p>
<p>In the current software defined world, no one has a nausea reaction when they hear software defined, but at some level the word “policy” is neurologically linked to unthinking, inflexible bureaucracies and slow-moving systems. The truth of the matter is that policies are amazing, as long as you are the one who gets to write them. But let’s wisely discard that term, as Arista has, because it doesn’t work. Software-defined it is.</p>
<p><strong>Software Defined Software</strong></p>
<p>Back in the day (i.e. 1994), <a href="http://en.wikipedia.org/wiki/Computer-aided_software_engineering">CASE tools</a> were all the rage (Computer Aided Software Engineering). If you ever had the displeasure of working with such tools, they allowed you to define very high level software policies, which the systems would then (hopefully, if you wrote very careful policies) compile into high-quality, defect-free, and maintainable software products.</p>
<p>Look at Opscode Chef, which <a href="http://www.opscode.com/blog/2013/02/20/aws-opsworks-uses-opscode-chef-as-default-automation-engine/">AWS is uses for automation</a>, and <a href="http://www.opscode.com/blog/2013/02/04/facebook-likes-opscode-and-private-chef/">Facebook also uses</a>. It reminds me of computer-aided software engineering. You simply define cloud deployment policies, and the systems get deployed as high quality, defect-free, maintainable cloud services. The difference between automatically deploying a complex system across tens of thousands of instances and automatically creating and then compiling code to work with millions of logic gates is not large. Orchestration offerings like VMware’s <a href="http://www.vmware.com/products/vcloud-director/overview.html">vCloud Director</a> are another example – you can set policies to configure virtualized compute, networking, storage, and security automatically.</p>
<p>As Trend Micro’s cloud security guy, I feel obligated to point out that my company’s <a href="http://www.trendmicro.com/us/enterprise/cloud-solutions/deep-security/index.html">Deep Security</a> ties in to vCloud and Chef so you can automatically build security into cloud environments as they are provisioned in a software defined world.</p>
<p>As long as it’s easy to create policies, manage policies, and enforce policies in the system, it doesn’t matter if you call it “software defined,” cloud, orchestrated, policy based, CASE, or something else. Just don’t create extra security and availability problems caused by human error or waste time doing things manually, and it will be a better IT system.</p>
<p>In all these cases, you need a system to manage the system. And that is the essence of “software defined.”</p>
<p><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://cloud.trendmicro.com/software-defined-software-the-history-of-software-defined/" data-text="Software Defined Software: The History of &#8220;Software Defined&#8221;"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/software-defined-software-the-history-of-software-defined/"></a><a class="a2a_button_google_plus_share addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/software-defined-software-the-history-of-software-defined/"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fsoftware-defined-software-the-history-of-software-defined%2F&amp;linkname=Software%20Defined%20Software%3A%20The%20History%20of%20%E2%80%9CSoftware%20Defined%E2%80%9D" title="Facebook" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fsoftware-defined-software-the-history-of-software-defined%2F&amp;linkname=Software%20Defined%20Software%3A%20The%20History%20of%20%E2%80%9CSoftware%20Defined%E2%80%9D" title="Email" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fsoftware-defined-software-the-history-of-software-defined%2F&amp;linkname=Software%20Defined%20Software%3A%20The%20History%20of%20%E2%80%9CSoftware%20Defined%E2%80%9D" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_pinterest" href="http://www.addtoany.com/add_to/pinterest?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fsoftware-defined-software-the-history-of-software-defined%2F&amp;linkname=Software%20Defined%20Software%3A%20The%20History%20of%20%E2%80%9CSoftware%20Defined%E2%80%9D" title="Pinterest" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/pinterest.png" width="16" height="16" alt="Pinterest"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fsoftware-defined-software-the-history-of-software-defined%2F&amp;linkname=Software%20Defined%20Software%3A%20The%20History%20of%20%E2%80%9CSoftware%20Defined%E2%80%9D" title="Reddit" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fsoftware-defined-software-the-history-of-software-defined%2F&amp;linkname=Software%20Defined%20Software%3A%20The%20History%20of%20%E2%80%9CSoftware%20Defined%E2%80%9D" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fsoftware-defined-software-the-history-of-software-defined%2F&amp;linkname=Software%20Defined%20Software%3A%20The%20History%20of%20%E2%80%9CSoftware%20Defined%E2%80%9D" title="Slashdot" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Fsoftware-defined-software-the-history-of-software-defined%2F&amp;linkname=Software%20Defined%20Software%3A%20The%20History%20of%20%E2%80%9CSoftware%20Defined%E2%80%9D" title="Tumblr" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcloud.trendmicro.com%2Fsoftware-defined-software-the-history-of-software-defined%2F&amp;title=Software%20Defined%20Software%3A%20The%20History%20of%20%E2%80%9CSoftware%20Defined%E2%80%9D" id="wpa2a_32">Share/Bookmark</a></p><div class="feedflare">
<a href="http://feeds.trendmicro.com/~ff/cloud-security?a=0Rm69RpqrTY:TrTBc1709uY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=0Rm69RpqrTY:TrTBc1709uY:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=0Rm69RpqrTY:TrTBc1709uY:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=0Rm69RpqrTY:TrTBc1709uY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=0Rm69RpqrTY:TrTBc1709uY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=0Rm69RpqrTY:TrTBc1709uY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=0Rm69RpqrTY:TrTBc1709uY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=0Rm69RpqrTY:TrTBc1709uY:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/cloud-security/~4/0Rm69RpqrTY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://cloud.trendmicro.com/software-defined-software-the-history-of-software-defined/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 AWS Security Tips: #8 Encrypt Sensitive Data</title>
		<link>http://cloud.trendmicro.com/top-10-aws-security-tips-8-encrypt-sensitive-data/</link>
		<comments>http://cloud.trendmicro.com/top-10-aws-security-tips-8-encrypt-sensitive-data/#comments</comments>
		<pubDate>Wed, 03 Apr 2013 13:35:19 +0000</pubDate>
		<dc:creator>Mark Nunnikhoven</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[AWS best practices]]></category>
		<category><![CDATA[AWS encryption]]></category>
		<category><![CDATA[aws security]]></category>
		<category><![CDATA[AWS security best practices]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[database encryption]]></category>
		<category><![CDATA[database security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[file security]]></category>
		<category><![CDATA[how to secure AWS]]></category>
		<category><![CDATA[Mark Nunnikhoven]]></category>
		<category><![CDATA[public cloud]]></category>
		<category><![CDATA[securing AWS]]></category>
		<category><![CDATA[top AWS tips]]></category>

		<guid isPermaLink="false">http://cloud.trendmicro.com/?p=2925</guid>
		<description><![CDATA[Last week, we tackled the basics of monitoring your AWS deployment. This week we&#8217;re going to shift gears and take a look at encryption. Data Drives Your Business Your business runs on data and information. One of the biggest concerns about moving to the public cloud is the safety of that data. With a little due [...]]]></description>
			<content:encoded><![CDATA[<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-8-encrypt-sensitive-data%2F&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=recommend&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px;height:30px;margin-top:5px;"></iframe><p><span style="font-size: 13px">Last week, we tackled <a href="http://cloud.trendmicro.com/top-10-aws-security-tips-7-monitor/">the basics of monitoring</a> your AWS deployment. This week we&#8217;re going to shift gears and take a look at encryption.</span></p>
<h3>Data Drives Your Business</h3>
<p>Your business runs on data and information. One of the biggest concerns about moving to the public cloud is the safety of that data. With a little due diligence, you can put those concerns to bed.</p>
<p>There are three key steps to protections your data in the cloud:</p>
<ol>
<li>Identify and classify your data</li>
<li>Protect your data at rest</li>
<li>Protect your data in motion</li>
</ol>
<h3>Identify &amp; Classify</h3>
<p>You can&#8217;t take steps to protect your data until you understand what you have, what it&#8217;s worth to you and your customers, and where it&#8217;s stored and processed.</p>
<p>Looking at your network, what type of customer data do you store? Any intellectual property that gives you a competitive advantage? Access credentials for your systems?</p>
<p>Start by taking an inventory of your data.</p>
<p>Now, go through that inventory and try to prioritze the data. How important is it to your customers? Your business operations? Your reputation? You don&#8217;t need hard values for the data, just a rough idea of what&#8217;s important to your business.</p>
<p>Once you have that list, track down where and how you store that data and where it is processed. These are the areas you should focus on securing first.</p>
<h3>Protect Your Data At Rest</h3>
<p>How you protect your data at rest depends heavily on where you store it. If you&#8217;re storing your data as files on a drive, you can either encrypt the entire drive or encrypt file-by-file. If your data is stored in a database, you can either encrypt the entire database or encrypt value-by-value.</p>
<p>In both scenarios&#8211;file or database&#8211;your choice really boils down to:</p>
<ol>
<li>Encrypt the underlying storage so everything get encrypted automatically</li>
<li>Encrypt each piece of data as it&#8217;s stored</li>
</ol>
<p>From a usability perspective, the less you need to worry about encryption for day-to-day operations, the better. This usually leads to the encryption of the underlying storage. However this can also impose a performance penalty on your deployment.</p>
<p>A quick note for S3 users; you can either either use <a href="http://aws.typepad.com/aws/2011/10/new-amazon-s3-server-side-encryption.html">S3 server-side encryption</a> or AWS&#8217; <a href="http://aws.amazon.com/articles/2850096021478074">envelope encryption</a> feature to help encrypt your data.</p>
<p>Regardless of the solution you choose, it&#8217;s important to test which ever method you choose to ensure that it meets both your security and performance requirements.</p>
<h3>Protect Your Data In Motion</h3>
<p>While protecting your data at rest involves some performance testing and hard decisions, protecting data in motion doesn&#8217;t. Use encrypted communication channels throughout your deployment.</p>
<p>Use <a href="http://en.wikipedia.org/wiki/Transport_Layer_Security">SSL/TLS</a> for any HTTP traffic (that&#8217;s the &#8220;S&#8221; in &#8220;HTTPS&#8221;) with a validate certificate from a trusted 3rd party<sup>1</sup>. If you&#8217;re deployment isn&#8217;t using HTTP as a transport, find the encrypted equivalent for the protocol you use.</p>
<p>The performance impact of an all encrypted communications channel in negligible. There is no reason not to use an encrypted transport.</p>
<h3>Protect Your Data Everywhere</h3>
<p>Encryption can be a tricky subject to address but there&#8217;s no need to be intimidated. Take an inventory of your data, prioritize it by value. Work through the inventory applying the appropriate level of encryption to each data store in turn. Make sure that all communications within your deployment are encrypted.</p>
<p>Taking these simple steps will greatly increase the security of your data at rest and in motion.</p>
<hr />
<p><strong>What do you do to protect your sensitive data in the cloud? Please share your tips in the comments!</strong> And if you’re interested in securing your EC2 or VPC instances, check out our new <a href="https://deepsecurity.trendmicro.com/trial">Deep Security as a Service</a> for cloud servers, currently in free Beta.</p>
<p><span style="color: #c0c0c0"><em><sup>1</sup>Full disclosure, Trend Micro is in the SSL certificate business but a certificate from any trusted 3rd party will get the job done. A quick search for &#8220;<a href="https://www.google.com/search?q=ssl+certificate+vendors&amp;aq=f&amp;oq=ssl+certificate+vendors"><span style="color: #c0c0c0">SSL certificate vendors</span></a>&#8221; will turn up quite a few possibilities.</em></span></p>
<p><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://cloud.trendmicro.com/top-10-aws-security-tips-8-encrypt-sensitive-data/" data-text="Top 10 AWS Security Tips: #8 Encrypt Sensitive Data"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/top-10-aws-security-tips-8-encrypt-sensitive-data/"></a><a class="a2a_button_google_plus_share addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/top-10-aws-security-tips-8-encrypt-sensitive-data/"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-8-encrypt-sensitive-data%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%238%20Encrypt%20Sensitive%20Data" title="Facebook" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-8-encrypt-sensitive-data%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%238%20Encrypt%20Sensitive%20Data" title="Email" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-8-encrypt-sensitive-data%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%238%20Encrypt%20Sensitive%20Data" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_pinterest" href="http://www.addtoany.com/add_to/pinterest?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-8-encrypt-sensitive-data%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%238%20Encrypt%20Sensitive%20Data" title="Pinterest" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/pinterest.png" width="16" height="16" alt="Pinterest"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-8-encrypt-sensitive-data%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%238%20Encrypt%20Sensitive%20Data" title="Reddit" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-8-encrypt-sensitive-data%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%238%20Encrypt%20Sensitive%20Data" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-8-encrypt-sensitive-data%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%238%20Encrypt%20Sensitive%20Data" title="Slashdot" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-8-encrypt-sensitive-data%2F&amp;linkname=Top%2010%20AWS%20Security%20Tips%3A%20%238%20Encrypt%20Sensitive%20Data" title="Tumblr" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcloud.trendmicro.com%2Ftop-10-aws-security-tips-8-encrypt-sensitive-data%2F&amp;title=Top%2010%20AWS%20Security%20Tips%3A%20%238%20Encrypt%20Sensitive%20Data" id="wpa2a_36">Share/Bookmark</a></p><div class="feedflare">
<a href="http://feeds.trendmicro.com/~ff/cloud-security?a=jyIqy1b5Mk0:TO6aYgTqhlo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=jyIqy1b5Mk0:TO6aYgTqhlo:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=jyIqy1b5Mk0:TO6aYgTqhlo:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=jyIqy1b5Mk0:TO6aYgTqhlo:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=jyIqy1b5Mk0:TO6aYgTqhlo:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=jyIqy1b5Mk0:TO6aYgTqhlo:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=jyIqy1b5Mk0:TO6aYgTqhlo:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=jyIqy1b5Mk0:TO6aYgTqhlo:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/cloud-security/~4/jyIqy1b5Mk0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://cloud.trendmicro.com/top-10-aws-security-tips-8-encrypt-sensitive-data/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5 Questions to Ask Your RMM Vendor about Integrated Security Solutions</title>
		<link>http://cloud.trendmicro.com/5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions/</link>
		<comments>http://cloud.trendmicro.com/5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions/#comments</comments>
		<pubDate>Fri, 29 Mar 2013 18:57:37 +0000</pubDate>
		<dc:creator>Ryan Delany</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[antisypware]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[ask your vendor]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[choosing security solution]]></category>
		<category><![CDATA[free security]]></category>
		<category><![CDATA[integrated security]]></category>
		<category><![CDATA[remote management]]></category>
		<category><![CDATA[RMM]]></category>
		<category><![CDATA[security selection]]></category>
		<category><![CDATA[security solution]]></category>
		<category><![CDATA[selecting security]]></category>
		<category><![CDATA[vendor]]></category>
		<category><![CDATA[what to ask]]></category>

		<guid isPermaLink="false">http://cloud.trendmicro.com/?p=2907</guid>
		<description><![CDATA[Remote management and monitoring (RMM) vendors often offer an integrated security solution with their core product. But how does the security offered by these integrated options compare? Below are the questions to ask your RMM vendor to make sure you get the full picture of the security being offered. 1. Is the security solution included [...]]]></description>
			<content:encoded><![CDATA[<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=recommend&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px;height:30px;margin-top:5px;"></iframe><p>Remote management and monitoring (RMM) vendors often offer an integrated security solution with their core product. But how does the security offered by these integrated options compare? Below are the questions to ask your RMM vendor to make sure you get the full picture of the security being offered.</p>
<h3>1. Is the security solution included with the RMM platform <em>really </em>free?</h3>
<p>RMM vendors and security solution vendors are for-profit businesses and are not going to make money by giving something away for free. While the security solution may be advertised as free, the most likely scenario is that the cost is baked into the total price of the RMM platform &#8211; and you are paying for it, whether you use it or not.  Don’t be surprised if your RMM vendor gives you a lower price for the RMM platform if you ask them to remove the security solution from your license.</p>
<h3>2. Does the security solution have all the same features as the standalone solution? What is missing/different?</h3>
<p>Contrary to popular opinion, security solutions integrated in to an RMM platform are not the same as the product you could buy directly from the security solution vendor. In most cases, the “integration” is a complex set of scripts combined with some HTML/CSS that acts as a wrapper around the security solution that leverages limited command-line functionality built into the core product.</p>
<p>What this means is that you are either managing a solution with stripped-down functionality (because they don’t make every single option available via the command-line), or the security solution vendor had to purpose-build a different version/product specifically for the integration, which means it won’t have all the same features as the standalone product because that’s too much work for them.</p>
<p>This also means that it probably won’t have the same priority for patches/hotfixes/upgrades as the standalone version, since a lot more customers use the standalone products than the ones integrated in to your RMM platform.</p>
<p>With five new threats discovered every second of every day, make sure you know if your security solution may make you wait days, weeks, or months for an integrated solution fix/update/upgrade to provide the same timely coverage as the standalone product.</p>
<h3>3. Does the integrated security solution work on all the devices I manage (servers, workstations, laptops, Macs, Androids)?</h3>
<p>Some security solutions that integrate with RMM platforms may lack the broad platform support provided by more robust security solutions. There have been instances in the past where an integrated security solution only worked on workstations/laptops and not on servers. This meant you went without coverage (bad idea) or you had to use a separate security solution, thus completely negating the “single pane of glass” benefit you signed up for in the first place!</p>
<p>Additionally, the technology landscape is changing quickly. You need a security solution that can protect all the devices your customers are allowing their employees to bring into their work environment (aka <a href="http://consumerization.trendmicro.com/tag/byod/">BYOD</a>), such as Mac laptops and Android devices, along with traditional Windows servers and workstations. It’s important to make sure the integrated security solution can protect all of these devices, or else you once again lose the “single pane of glass” benefit.</p>
<h3>4. What features does the integrated security solution offer? And how does it compare to industry-leading standalone security solutions?</h3>
<p>It may surprise you to learn that when security solutions were originally integrated in to RMM platforms, they were usually the free options available on the market at the time. Financially speaking, this makes sense in a low-margin, fixed-fee business model where it is important to find every way to save that you can to maximize profit. However, RMM vendors and MSPs quickly realized the truth in the old adage, “you get what you pay for.” Soon they moved away from integrating the free options towards the low-cost options.</p>
<p>Today, the integrated security solutions in RMM platforms are a broad spectrum of the low-cost options on the market. This generally means they lack the features found in the industry-leading products. It is important to understand:</p>
<ol>
<li>What’s missing</li>
<li>What you are going to have to pay extra for</li>
<li>That you’re going to need to augment with another tool from another vendor (and use another management console for) to provide the maximum level of protection your customers demand</li>
</ol>
<p>It is no longer good enough to just offer basic <a href="http://www.antivirus.com">antivirus</a>. Does the integrated solution offer advanced reputation-based protection? And do they provide additional integrated features like URL Filtering, Behavior Monitoring, POP3 scanning, Firewall, Mac, and Android protection?</p>
<h3>5. Why do you offer both an antivirus solution AND a separate anti-malware/spyware solution? And do I have to pay for both of them separately?</h3>
<p>A number of RMM vendors have been forced to add secondary security solutions to their platform because the primary one may be lacking in some way or another. These products are generally divided between antivirus functionality and anti-malware/antispyware functionality. Don’t expect to get both of these for the same low price you were originally quoted, and make sure you ask how much it will cost you for both solutions.</p>
<p>If two solutions are offered, there is a reason for it (read: the first solution isn’t good enough on its own). So consider it a warning that your costs will go up or your security coverage will suffer.</p>
<p>If you don’t buy that second solution, expect to be rolling trucks to your customer sites to clean up those nasty infections that can’t be cleaned remotely because you have to boot in to Safe Mode to clean them up. Expect to lose some customers too when they are either crippled to the point that they go out of business, or they get tired of your technicians coming onsite to clean up what the first security solution missed.</p>
<p><strong>What are your concerns with integrated security in RMM solutions? Let us know in the comments!</strong></p>
<p><strong> </strong><strong> </strong></p>
<p>&nbsp;</p>
<p><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://cloud.trendmicro.com/5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions/" data-text="5 Questions to Ask Your RMM Vendor about Integrated Security Solutions"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions/"></a><a class="a2a_button_google_plus_share addtoany_special_service" data-annotation="none" data-href="http://cloud.trendmicro.com/5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions/"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="Facebook" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="Email" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_pinterest" href="http://www.addtoany.com/add_to/pinterest?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="Pinterest" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/pinterest.png" width="16" height="16" alt="Pinterest"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="Reddit" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="Slashdot" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;linkname=5%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" title="Tumblr" rel="nofollow" target="_blank"><img src="http://cloud.trendmicro.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcloud.trendmicro.com%2F5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions%2F&amp;title=5%20Questions%20to%20Ask%20Your%20RMM%20Vendor%20about%20Integrated%20Security%20Solutions" id="wpa2a_40">Share/Bookmark</a></p><div class="feedflare">
<a href="http://feeds.trendmicro.com/~ff/cloud-security?a=iG3CNkIjUnY:wxMW6taz9-Q:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=iG3CNkIjUnY:wxMW6taz9-Q:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=iG3CNkIjUnY:wxMW6taz9-Q:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=iG3CNkIjUnY:wxMW6taz9-Q:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=iG3CNkIjUnY:wxMW6taz9-Q:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=iG3CNkIjUnY:wxMW6taz9-Q:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cloud-security?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.trendmicro.com/~ff/cloud-security?a=iG3CNkIjUnY:wxMW6taz9-Q:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cloud-security?i=iG3CNkIjUnY:wxMW6taz9-Q:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/cloud-security/~4/iG3CNkIjUnY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://cloud.trendmicro.com/5-questions-to-ask-your-rmm-vendor-about-integrated-security-solutions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
