Wednesday, March 8, 2017

Cloud Computing Forensics Readiness

Photo credit: Shuterstock

In today’s globally connected world, data security breaches are bound to occur. This, in turn, increases the importance of digital forensic readiness, or the ability to access and trust computer log data in the identification of a breach and the determination of what datasets may have been compromised. As organizations rapidly move into the cloud, the complexities of this multi-jurisdictional and multi-tenancy environment has made the importance of cloud forensics even more pronounced. This reality has also drastically heightened the legal risk associated with information technology operations. Cloud and digital forensics readiness are therefore critical to business disaster recovery, continuity of business services and cloud ecosystem management.

  • Reducing the cost of cyber investigations;
  • Quick determination of relevant attack vector;
  • Reduction in the cost for data disclosure;
  • Faster restoration from damage; and
  • Cyber insurance discounts.


Forensic readiness will also help your organization regain control after any sort of data breach. It will help limit the damage and costs from just about any digital incident. When forensics readiness is taken into account, post breach digital investigation often become simpler in that retrieval of digital evidence can occur without running into some of the better known challenges. Even more important is when forensics is part of the business continuity plan, digital evidence is actually acquired and stored before an incident occurs without interrupting business operations.




Cloud and digital forensics should be looked at across three separate dimensions: technical, organizational, and legal. The technical dimension is mainly focused onL
  • Forensics data collection;
  • Elastic, static and live forensics;
  • Evidence segregation;
  • Investigations in virtualized environments; and
  • Pro-active preparations.

The organization dimension is strongly influenced by the roles played by the relevant cloud service provider and the cloud service consumer. To establish a forensic capability, these organizations must define a staffing structure that fulfills the following critical roles:

  •  Investigators: Responsible for collaborative investigation allegations of misconduct in the Cloud and working with external assistance or law enforcement when needed.
  • IT Professionals: System, network, and security administrators, ethical hackers, cloud security architect, and technical support staff in the cloud organization.
  • Incident Handlers: The team that responds to a variety of specific security incidents, such as unauthorized data access, accidental data leakage and data loss, breach of tenant confidentiality, inappropriate system usage, malicious code infections, malicious insider attack, (distributed) denial of service attacks, etc.
  • Legal Advisors: Staff familiar with multi-jurisdiction and multi-tenant issues in the Cloud that will ensure that any forensic activities will not violate regulations under respective jurisdiction(s) or confidentialities of other tenant(s) sharing the same resource(s).
  •  External Assistance: Typically, it is wise for the cloud organizations to rely on a combination of its own staff and external parties to perform forensic tasks such as e-discovery, investigations on civil cases, investigations on external chain of dependencies. The responsibility of any external party should be determined in advance and made clear relevant policies, guidelines and agreements.

The legal dimension primarily revolves around multi-jurisdiction and multi-tenancy challenges and the terms of use as specified in the CSP Service Level Agreement (SLA). Specific topics that should always be addressed within the SLA include:
·         Service provided, techniques supported and access granted by the CSP to the customer regarding forensic investigation;
·         Trust boundaries, roles and responsibilities between the CSP and the cloud customer regarding forensic investigation;
·         How forensic investigations are secured in a multi-jurisdictional environment in terms of legal regulations, confidentiality of customer data, and privacy policies; and
·         How forensic investigations are secured in a multi-tenant environment in terms of legal regulations, confidentiality of customer data and privacy policies

Experts recommend a focus in three primary aspects:

  • Preparation: Create and maintain the conditions that enable you to respond timely and effectively to any digital incident.
  • Partnering: Forge relations with and external specialists and stakeholders when it comes to dealing with digital incidents before a crisis occurs.
  • Evolving: Periodically rehearse, evaluate and update your response plan.


Forensics is a core requirement of good organizational hygiene, alongside business continuity and disaster recovery and should always be specified in standard contract clauses. Businesses without forensic readiness planning and testing in place are just as negligent as those that fail to plan for business continuity or disaster recovery. By implementing and testing their forensic readiness, a business can prepare itself to be in a much better position when – not if – a security incident occurs.

This post was brought to you by IBM Global Technology Services. For more content like this, visit ITBizAdvisor.com



Cloud Musings
( Thank you. If you enjoyed this article, get free updates by email or RSS - © Copyright Kevin L. Jackson 2016)



36 comments:

silakarim said...


Thanks for sharing this post. It is very helpful for me to develop my skills in a right way.
Ethical Hacking Course in Velachery
Ethical Hacking Course in T Nagar
Ethical Hacking Course in Tambaram
Ethical Hacking Course in Anna Nagar
Ethical Hacking Course in Porur
Ethical Hacking Course in Vadapalani
Ethical Hacking Course in Thiruvanmiyur
Ethical Hacking Course in Adyar
Ethical Hacking Course in OMR

Jobi Johnson said...

The great website and information shared are also very appreciable. Kanye West Donda Vest

Application Development said...

"This information really helped me a lot. It was very informative.
Cloud Advisory Services
cloud advisory companies
cloud advisory process
cloud consultation services
cloud consulting companies
cloud services consulting
cloud service consultant
cloud consult and advisory services
Cloud Consulting services"

eddielydon said...

Statistics students and professor are worried to find the deviation calculator because their work depends on it. Dreamer Biker Jacket

George Mark said...

I must say that you are my favourite author. You always bring surprised things for me everytime I see your articles. Great efforts!! Biker Boyz Jacket

data science course in gorakhpur said...

In this article, I will let you know about data mining and data analysis. You need to learn these concepts because if you are working on some data-driven project, you cannot deny their importance.

john said...

Cloud Musings yellowstone season 4 coat this is a very nice post.

niklola said...

Awesome Blog! Your blog is very informative. It is nice to read such high-quality content john dutton brown vest

Divya said...

Thank you for sharing, keep up the good work.
Digital marketing courses in Noida

apeksha said...

nice article Web Designing Courses in Pune

kritikan krishna said...

It is nice to read such high-quality content.
Keep up the good work! Digital Marketing Institute in Pune

FMC Kenya said...

I like this page! You have selected a good topic to discuss with us. I appreciate for brining this blog in front of us. thank you. Keep updating!
financial modelling course in kenya

Pooja Patil said...

Thanks for sharing this info,it is very helpful. Check Out Digital Marketing Courses in Pune

divy said...

good article to read
do read:Teamcenter Training in Pune

Insta Info said...

You may tweak your profile to increase engagement and attract more followers by using pertinent keywords, captivating photographs, and an engaging bio. A sense of community and brand loyalty can be cultivated through interesting captions, direct messaging, and other frequent interactions with your audience. Last but not least, in order to keep your audience interested and develop an organic Instagram following, you must consistently produce high-quality content that is relevant to your audience.

Read more

aiemoo

Android13,Mark R baum

Official arrival of Android 13

Pencil Guide said...

The paper, which was posted on the website SemiAnalysis, stressed the necessity of continual innovation and investment in order to maintain a leading position in the rapidly expanding AI field. To be competitive in the quick-paced world of AI, businesses must adapt as the market shifts and take advantage of the opportunities and challenges presented by new technology.



Readmore

advantage of large tech companies

Star Wars

collaboration with Star Wars

Snab Info said...

We'll look at eight iPhone emojis in this post that set them apart from their Android equivalents. With the help of these particular emojis, iPhone users can express themselves in original and innovative ways and experience a sense of exclusivity. Let's take a closer look at the world of iPhone emojis to learn more about its unique beauty and allure.



Learn more.



Brian Graham
Microsoft retires its keyboards and mice
Microsoft Retires Keyboards and Mice

Insta Info said...

Google announced that it deleted more than 20,000 YouTube channels in the first quarter of 2023. According to Google’s Threat Analysis Group (TAG) blog, these channels were part of an investigation into “coordinated influence operation campaigns” involving multiple countries, with 6,930 channels featuring Chinese-language spam content about music, entertainment, and lifestyle.



Read more

Motorolla

- MARK R. BAUM

Instagram tips and tricks

Pencil Guide said...


Google has recently unveiled the Android 14 Beta 2, marking yet another significant step in the evolution of its flagship operating system. This latest offering was announced during the keynote at Google I/O 2023 and brings with it an array of intriguing enhancements.

Readmore

collaboration with Star Wars

fortnite has launched

Star Wars characters to Fortnite

The veganist said...

The best snacks for on-the-go munching are energy bars and bite-sized snacks. They provide convenience and are nutrient-rich to keep you nourished all day. Making your own energy bars is simple if you combine nuts, seeds, dried fruits, and oats.

Readmore...

avegan sweet potato casserole recipe

This article explores the negative impact

warm and comforting tomato soup on a chilly day

Vegan line said...



"New Meat" has dishes by Korteweg and contributions from eleven prominent chefs, including Michelin-starred cooks Asimakis Chaniotis, James Goodyear, and Ricky

Readmore...

Babybel

demand for plant-based alternatives grew,

ban that prohibits imports of food products linked to deforestation

playerpulse said...

In the universe of Elden Ring, Diallos is a legendary place cloaked in danger. According to legend, there is a dangerous environment full with hidden treasures that can only be found by those who have the courage to explore it.

Readmore...

enigmatic NPC in Elden Ring

“Maidenless”

Elden Ring

Dhananjay Bhuyan said...

Great Piece of the article got lots of insight , i would like to draw attention to Best Software Testing Courses in Pune up-sacling the skills.

Pelorus Technologies said...

"Great article! The information you shared here is really valuable and well-researched. I appreciate the effort you put into creating such high-quality content."
For any digital investigation services, you can contact us.
Drone Forensics
Cloud Forensics

DMtools said...

Very informative post! Thanks for sharing your insights on this topic.
To facilitate your journey as a Digital marketer, refer to this article which provides information on the core digital marketing tools.
 Free digital marketing tools 

Aperture2 said...

Great blog! Keep posting! Thank you! Digital marketing courses in Albania 

Cmolds Creativity said...

Cmolds is a leading mobile application development company san francisco, specializing in creating innovative and customized mobile solutions that drive businesses forward. With a team of skilled professionals, Cmolds transforms ideas into exceptional mobile applications that redefine user experiences.

Ramma Foundation Repair said...

Ramma Foundation Repair is your trusted partner for Foundation Repair Edmonton solutions, ensuring the stability and longevity of your property's foundation. Experience top-notch expertise and quality service with Ramma Foundation Repair.

coworkista said...

Your Artical is really interesting.
I recently had the privilege of experiencing the fantastic coworking space in Pune, and I must say, it exceeded all my expectations. The vibrant atmosphere, state-of-the-art facilities, and attentive staff made it an ideal place to boost my productivity and creativity.

Filmsjackets said...

Great Article. You have beautifully articulated it. Readers revisit only if they found something useful. Halloween Jackets

hattie said...

Good blog. I appreciate you sharing with us. Such fascinating details. Dinwiddie Conducción imprudente

sopfiaa said...

You made a very interesting post regarding the price of a divorce in New York. We appreciate you deconstructing the many elements and giving us an accurate picture of what to anticipate. Your insightful observations show how committed you are to supporting people going through this process.
¿Cuánto es para un Divorcio en Nueva York?

Sdivesh said...

Very informative post, thanks for your piece.

investment banking courses in Canada

Stelena675 said...

Indulge in the epitome of luxury with Cabo San Lucas Villas, your premier choice for unparalleled vacations. Our exquisite collection of cabo house rentals with chef promises a perfect blend of opulence and comfort. Experience the pinnacle of hospitality in the most sought-after destination.

abigailuna said...

"Cloud Computing Forensics Readiness" is a guide for businesses addressing cloud technology and forensic preparedness, emphasizing proactive security measures. It provides insights into mitigating risks and ensuring accountability, making it a must-read for cloud computing era success. Statement of Net Worth Divorce New York

Monster Rabbit said...

Indulge in the exquisite world of Monster Rabbit, where luxury meets sensuality with our royal performance honey. Experience the epitome of pleasure and vitality with our premium products, crafted to elevate your intimate experiences to new heights.