Alexis
Hi, everyone. Welcome to another episode of Talk Tech with Data Dave. I am Alexis. Not Data Dave, obviously, and I’m here with Data Dave to talk about a cloud question. I’m super excited. How are you this morning? Well, it’s not morning anymore, is it?
Data Dave
It’s not morning, but we’ll go with it.
Alexis
I’m just messing up this intro completely.
Before we get started, Dave, I always like to start these episodes by reminding our listeners that you can always submit a question to Data Dave by emailing us at talktech@d3clarity.com. You can also submit a question right on our website or connect with either one of us on LinkedIn. We would love to chat with you more.
So, Dave, that cloud question that I messed up in our intro, let me talk a little bit about it. Here’s the question. How can businesses tackle compliance in the cloud? Now, we’re taking a weird path here. As you and I both have talked about previously and even in previous podcasts, those two things might not always go hand in hand, the way this question is implying. Let’s try to answer it anyway. How can businesses tackle compliance in the cloud?
Data Dave
That is an interesting question. It’s an interesting way that it’s worded. I’m going to separate it for a moment and then we’ll try and pull it together. How’s that?
Alexis
I like that idea.
Data Dave
I’m going to separate the idea of compliance and the idea of the cloud and then try and bring together what compliance and cloud might mean together. Compliance, to me, is compliance to policy and process. How do you comply with a documented policy or a documented procedure that is published? Whether it comes from regulatory or from internal, you’re still complying with something.
So, from an external compliance perspective, there’s that kind of compliance. There’s SOC compliance that we’re all familiar with. You’re very familiar with SOC2 and so on. So from a compliance point of view, it’s about making sure your procedures and policies are documented and that you are appropriately policing those procedures and policies to ensure that you comply with them, that you are following them. Now, there are various aspects to that, right? We can talk about finance policies and procedures. We can talk about regulatory ones. Right? Like we can talk about security ones. We can talk about physical access ones we can talk about. There’s various laptop management ones. The cloud doesn’t necessarily apply to all of these procedures and policies to which you’re complying.
Alexis
So, one of the SOC2 compliance regulations, one of the SOC2 controls is actually that we are required to do annual performance evaluations on our employees every year. That has nothing to do with whether or not we’re in the cloud, but it is part of the SoC two controls. So to your point, those two things definitely there don’t really match or matter.
Data Dave
Now, do we use the cloud to do that? Yes, we do. We store all our performance reviews in OneDrive and wherever else, so they’re stored in the cloud and they’re secure and whatever else around the cloud. So we do use the cloud technologies, but the cloud technologies does not really impact that side of compliance.
Alexis
That policy would be the same if we were on the cloud or on-prem.
Data Dave
Right, exactly. Now, to a certain extent, we do use the cloud to affect compliance quite significantly, because, as you well know, we’ve got data access policies within D3Clarity, and we’ve got laptop control policies and things like that. As one of the people who does work with a lot of our secure data and proprietary data, I do all that in the cloud. I actually build myself cloud-based desktops and remote desktops into them to avoid having any data on my laptop at any time. So, my laptop becomes just a window into the cloud because it is easier to then comply with not having any data in my laptop. And if my laptop did get stolen, yes, my laptop is encrypted. You know that because you police that. So my laptop is encrypted, but all my data, I actually have almost a virtual machine per client in the cloud that I then log into specifically to keep them separated, isolated, secured, et cetera, and work that way quite frequently.
So, the cloud does help in that regard. The policy is that we’ve got strict controls, overdose, allowing data onto our own laptops, because it is often sensitive information. So, we don’t do that. We’ve got a policy that says you shouldn’t do that, therefore we don’t. One of the ways I comply with that is by using the cloud, and I advise other people in the organization to do the same thing when we’re not logging onto our client’s site and equipment. So, we do do that. The cloud, to a certain extent, does make it easier to comply in that way using that technology applied to the policy and procedure that we have, that we have to comply with. So, the way I look at it, I separate the cloud as a technology platform from the compliance as a policing policy and procedure structure. You still want people to want to comply with the policies. It shouldn’t all be about policing the fact that we require HIPAA training, the fact that we require security training, et cetera, once a year. That’s a policy and a procedure. It may or may not be delivered in the cloud.
Alexis
Right.
Data Dave
Right. Now, the cloud does help. If you look at the socks stuff, it has physical access requirements and things like that, where everything has to be locked and things like that. To a certain extent, the cloud does help there because I don’t own any hardware, really. It’s owned by somebody else, and I rent it, so it’s up to them to make it secure.
Alexis
Yeah, and we’re in kind of an interesting boat there because we’re a remote organization. When I was going through all of our policies for the annual policy review this year, our Rhymetec team member was like, “Hey, notice you have a lot of stuff not in your physical access policy. That seems kind of weird.” And I was like, “Oh, but we don’t have an office.”
Like, we’re a remote organization. We have a physical access policy that says, yes, we need to lock our computers whenever we walk away from them. And we have a physical access policy that says, “Don’t leave your computer sitting in public,” but we don’t have one that says, “Make sure that the on premise server is locked or make sure that the office is locked whenever you leave.” Because we’re in the cloud. I mean, we’re consistently in the cloud.
Data Dave
Yeah, we don’t have any. Right. We don’t have any data centers. We are exclusively in the cloud from our operating system. So, even our laptop policies are pretty benign because, like I said, we use laptops as a window, as a glass into the cloud, and let the cloud lock it all up.
Alexis
So, for us, it’s very inherently blended, or it makes a little bit more sense for us because we’re a remote organization. But even non-remote organizations still work in the cloud.
Data Dave
Yes, but the policies and procedures aren’t written necessarily with cloud in mind. They’re written with the data or the behavior in mind. And the cloud may or may not make it easier. If you are an on-premise organization or you have policies that have grown up on-premise, then moving to the cloud can affect those procedures and policies.
So that’s an interesting way to look at it as well, because when we were at IBM, we did have all the procedures and policies. We owned the whole shooting match when we’re at other organizations where we did require physical access and various things. The other thing that is interesting is that the paradigm of least privilege that is prevalent in the cloud and never was on premise does make it easier to police things, right? Because when you’re working in the cloud, you have to explicitly turn on access to a particular application. So if we put an application in the cloud, we have to explicitly grant access to people, rather than it being you have access and people get turned off. So that actually makes it easier because fewer things are just natively available.
Alexis
You just said something that sparked something in my brain. I’m our M365 admin, you know that, Dave, but maybe our listeners don’t know that. The other day, Patrick asked me to assign a couple of people to a specific cloud application within our active directory to give us access to a specific part of AWS. That is the principle of least privilege at what you’re explaining at its core, right. It’s saying you guys can’t access it right now until I give you access to it, and then when I give you access, you can get there.
Data Dave
That’s right, exactly. And because you’ve granted access, you can audit that access, right? Because it’s written down. It’s written down that you granted. It’s in the audit trail. You explicitly granted access to the cloud natively. Now, people don’t always set it up this way, but the cloud natively has the idea of least privilege. You can do nothing until you grant it. Now we find places where that’s violated and so on all the time, as you’ve heard the horror stories of it. But you have to explicitly grant access. So sometimes people do explicitly grant access to everybody.
That’s a foul. You shouldn’t do that. Right. That’s a non-compliant policy, certainly with it for us. But are you being asked to explicitly grant access within AWS to those people for that application is exactly that. Which now, there’s an audit trail that says Patrick asked for it and the admin granted it on this date for these people. And if those people leave, it will get automatically terminated. Yep, that’s exactly what that means. So it makes it easier. But what we’re really saying there is the principle of least privilege affects the policing of policy. The principle of least privilege is often inherent within the cloud. The cloud doesn’t necessarily give you that, but it is a tool that you can absolutely use to help with compliance and help with getting visibility and auditability and compliance to policy and procedure.
Alexis
Yes. Okay. I love it when things like that can click in my brain when we’re talking. It maybe isn’t helpful for any of our listeners, but for me, things like that click into place. I’m like, oh my gosh, I understand stuff a little bit more now. That was awesome. Thank you for letting me go on that tangent.
Data Dave
The other example that I would use for that, which is one we discussed earlier, is our friend from Rhymetec, who was mentioning penetration testing and the fact that when he was doing penetration testing on-premise, he would get hundreds of violations and hundreds of vulnerabilities that all had to be remediated. But when he does penetration testing against cloud-based applications, he gets far, far, far fewer.
That is, again, this idea of least privilege, which is only the ports that are necessary for this to run have been opened in the cloud. Because the default in the cloud is to close everything and only open it. What you need versus the default on-premise is everything is open, and you close what you can’t have. That’s a fundamental shift. But you can build an on-premise system with a point of view of least privilege. Like I want to separate those. I’m not sure whether that quite answers the question, which is, I can’t remember the question.
Alexis
Yeah. So how can businesses tackle compliance in the cloud? I’ll take it a step further, and I’ll ask it to you a little bit of a different way, Dave.
Let’s say I’m a business. We’ll call it, I don’t know, AOK Enterprises and AOK Enterprises runs on-prem, but I’ve decided I want to move to the cloud, but I need to still maintain my compliance with my policies, my compliance with my SoC, two policies with my ISO 27 101 whatever policies. How is moving to the cloud going to impact my compliance as it sits? And when I get to the cloud.
Data Dave
It will impact it somewhat in the manner that you comply because you still have the same policies and procedures. So, as part of moving to the cloud, you would have to ensure that the procedures and policies that are relevant for that application are still complied with within that cloud movement. Therefore, the principle of least privilege might well apply in making sure that only the right people have access to it and that it is appropriately locked down. The risk of failure is greater because if it is in the cloud, you might accidentally open it up to the entire world, not just your employee base. So, you do want to make sure you comply with the policy that you have, which is this audience should have access to it.
You might also need to make sure you comply with backup policies, retention policies, and various other things that are built into your on-premise pieces. Now the nice thing is that the cloud often has these pieces built into it as well. So if you want a seven-year retention policy or a backup policy or a failover policy, a high availability policy, et cetera, for these systems as part of your process and structure, the cloud has that ability to do that and that ability to play in that space. And often some of this is something you don’t have to invent. You can just inherit from AWS or Azure or Google or wherever you go as a cloud provider. So some of them have that built in, but you still need to make sure that your application is compliant with your policies and procedures. And you’ve got the right audit trail that is contiguous across your on-premise behaviors and in-cloud behaviors that are on you, that you can’t offload that to the cloud provider.
Now there are some things that you do offload to the cloud provider. We just talked about the idea that we, as a company, don’t own, I think, any servers yet. We’re a data company. We don’t own any service because everything is in the cloud. We’re a virtual organization. Everything is cloud. While we have to comply with the physical security policies as written in the SOC2 documents. And we have to validate that we’re doing that. One of the ways we validate that we’re doing that is that we simply read the AWS and Azure, Microsoft Azure service levels, and then they say oh, we guarantee that every server is behind a locked door and it’s got power and its safe, bombproof environment and whatever else. So we just say, oh yeah, they’re contractually committed to supplying that to us. So yes, we’ve got it. Right?
Data Dave
Yeah.
Alexis
And I mean a step further, we, we sometimes just pull their SOC2s and we attach it to ours. I mean, I just made a stapler, there’s no stapling, we don’t have any papers, but yeah, that’s what we do.
Data Dave
Exactly. We just attach it and have a nice life. Right. So, there’s an element where the use of that technology can make it easier to comply, but the policies and procedures are still yours. You made a key point, which is you pull theirs and you attach them to ours.
We still have to comply with the policies and procedures of SOC 2 that we are following, and we use theirs to help demonstrate that because we use their services, we are compliant, and we’ve got a pass-through to where our servers live. Now if we configure those cloud servers to not be secure, or we don’t have the backups built or the various things built in the cloud. It’s us that’s noncompliant, not the cloud provider because they’ve got the ability to provide that. We have to take responsibility to make sure we use it in order to be compliant.
Alexis
I’m going to ask last question I asked you one more time, and let’s make sure that we’ve got a kind of a solid answer here. If I was an on prem organization and I’m deciding I’m going to move to the cloud, how is that going to impact my compliance?
From what you just said, it won’t impact your policies. It might impact how you implement those policies. Does that sound about right?
Data Dave
That’s exactly what I would probably say. Now, you might decide that you can change those policies, but you need to look at the policies and procedures that you are complying to and make sure that you are completely covered in a manner that is appropriate for where you’re placing that application, that data. Right. So, it might impact how you do it, but it doesn’t impact your responsibility to do it.
Alexis
There we go.
Data Dave
And that, I think, is the crucial piece.
Alexis
Very good. I hope we answered that question the way it was posed to us. I think we did. I think we got to the heart of it. If you’re out there and you’re like, “Alexis, Dave, you missed the mark here; I need you to try again.” Reach out to us. Give us a little bit more context. We’ll try again.
Data Dave
Yeah, we’ll try again. We’re not against trying again. Not against somebody adding more color to it, because this is our thinking. And the question, like I say, I’m not sure we completely answered it.
Alexis
I think that’s okay, though. I learned in this conversation, and that’s really what I care about, which is awful because this podcast is supposed to not be for me, but it really is. Like, let’s be honest. Everyone out there, please, please send us your questions. You can reach out to us at talktech@d3clarity.com or right on the D3Clarity website. We would be happy to answer your questions on the podcast. Dave, thank you so much for talking with me today. I really, really appreciate it, and I hope everyone has a fantastic day.
Data Dave
Yes, thank you. Thank you, everybody. And thank you, Alexis.