Welcome!

Microservices Expo Authors: Pat Romanski, Liz McMillan, Elizabeth White, Mehdi Daoudi, Flint Brenton

Related Topics: Microservices Expo, Java IoT, Agile Computing, Cloud Security

Microservices Expo: Blog Post

Casting Light on Shadow IT and ID

Watching vulnerability cracks in your network widen via unauthorized application usage

It's not a new term or concept. You probably recognize that it’s happening within your own organization. Shadow IT is the appropriation and use of IT assets and applications without organizational approval.  And it happens more than you know. Sally the sales rep gets a label template design application, Marco from HR downloads software that manages inbound resumes. Kelsey in marketing signs up for a WordPress page and social media accounts. All too often, employees are not going through corporate channels to get what they need to achieve their goals.

And every time they do, the vulnerability cracks in your network widen.

Now on top of the obvious issues with unauthorized applications is the creation of Shadow Identities. For all of these applications there are user names and passwords. Across an enterprise that could mean thousands and thousands of identities. And, because some are even using their personal commercial mail accounts to create these new IDs, you now have your corporate data going out through an external service with which you have no control.

The world of SaaS has exacerbated the security problem, but the cloud also provides the solution.

To understand how to best approach the quandary, you must realize that traditional concepts of IT are out of date.  At one time you just built a wall around everything. However, with SaaS, mobile users, customers, partners, the perimeter has been erased—you simply can’t open an LDAP query from your directory and plug in applications to your enterprise infrastructure.

Identity Management is the new Network Perimeter. And identity management from the cloud centralizes, ordains, and automates your corporate policies. The idea is when you can’t pull your curtain of protection around where the data resides, your only point of control is identity credentialing and authorization. You create the rules for access and entrance and then pass the user along to the specific resource.

In any organization this can mean dozens of applications for a variety of departments and niche users.  This means managing potentially thousands of passwords...and that’s not a place most IT professionals wish to spend their time. But rather than belabor the problem, let’s highlight the solution broken down by type:

Data has two general directions: inbound and outbound. The key is to create federated relationships. You need to ensure that those who you invite to access or add data to your network are properly vetted. And these can be broken into two very general categories: high and low risk. Lower risk would include partners and customers because you can automatically provision them to see just a small part of your network. Customers don’t need to access production, they simply want to process an order or maybe query the help desk…and that’s all they should be given.  For something like this all you really need is cloud identity management to control the reach and scope of their access. The same holds true with partners like VARs or suppliers.

Then there are higher risk transactions. These are usually driven by your mobile users and internal employees. They obviously need more access to things like payroll or benefit packages. For these, in the scope of identity management, you would be best served by using a multi-factor authorization.

It is obviously more complex than a 750 word blog can delve into but, the ability to automatically provision and deprovision, to manage countless passwords, to federate access to your data is easily handled by cloud-based security. If the goal is to rethink how IT works in order to make it more cost-effective and asset protective, then IT departments must evolve from a developer of stacks to brokers and facilitators of service. The mission is still to keep the data safe, but you are now analyzing where you once were building. You are now acquiring and integrating in concert with enterprise business needs and goals.  When that is the case, then security-as-a-service must be a consideration for your enterprise.

Now let’s also consider outbound data. Federation is not only important. It is the driving need to ensure the safety of this nebulous enterprise perimeter. Your users are accessing third-party applications like salesforce.com or ADP, Webex, SharePoint, etc and you must provide the access in support of business needs.  Whereas much of inbound can be federated using cloud-based identity management as a baseline, anything outbound must be SAML-aware.  You need to insist on SAML-based federation before you approve any outside program. If not, you better think twice about including it as an option.

If there is one takeaway from this, it is that unless you decide to evolve with the changing demands of business, your architecture will be compromised by an expanding creep of Shadow IT and their accompanying Shadow Identities. If you realize that now your data can be anywhere, you must centralize the access to that data. By taking full advantage of cloud-based security, you not only benefit from the cost-efficiencies, but your gain all the built-in federations and integrated resources, as well as best-of-breed password management and single-sign on.  Then there are the compliance and reporting needs and how a strong security-as-a-service offering effectively addresses that pressing requirement…but we’ll leave that for another day.

Kevin Nikkhoo
www.cloudaccess.com

More Stories By Kevin Nikkhoo

With more than 32 years of experience in information technology, and an extensive and successful entrepreneurial background, Kevin Nikkhoo is the CEO of the dynamic security-as-a-service startup Cloud Access. CloudAccess is at the forefront of the latest evolution of IT asset protection--the cloud.

Kevin holds a Bachelor of Science in Computer Engineering from McGill University, Master of Computer Engineering at California State University, Los Angeles, and an MBA from the University of Southern California with emphasis in entrepreneurial studies.

@MicroservicesExpo Stories
With the rise of DevOps, containers are at the brink of becoming a pervasive technology in Enterprise IT to accelerate application delivery for the business. When it comes to adopting containers in the enterprise, security is the highest adoption barrier. Is your organization ready to address the security risks with containers for your DevOps environment? In his session at @DevOpsSummit at 21st Cloud Expo, Chris Van Tuin, Chief Technologist, NA West at Red Hat, will discuss: The top security r...
DevOps at Cloud Expo – being held October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's largest enterprises – and delivering real r...
The “Digital Era” is forcing us to engage with new methods to build, operate and maintain applications. This transformation also implies an evolution to more and more intelligent applications to better engage with the customers, while creating significant market differentiators. In both cases, the cloud has become a key enabler to embrace this digital revolution. So, moving to the cloud is no longer the question; the new questions are HOW and WHEN. To make this equation even more complex, most ...
The last two years has seen discussions about cloud computing evolve from the public / private / hybrid split to the reality that most enterprises will be creating a complex, multi-cloud strategy. Companies are wary of committing all of their resources to a single cloud, and instead are choosing to spread the risk – and the benefits – of cloud computing across multiple providers and internal infrastructures, as they follow their business needs. Will this approach be successful? How large is the ...
21st International Cloud Expo, taking place October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy. Me...
Many organizations adopt DevOps to reduce cycle times and deliver software faster; some take on DevOps to drive higher quality and better end-user experience; others look to DevOps for a clearer line-of-sight to customers to drive better business impacts. In truth, these three foundations go together. In this power panel at @DevOpsSummit 21st Cloud Expo, moderated by DevOps Conference Co-Chair Andi Mann, industry experts will discuss how leading organizations build application success from all...
You know you need the cloud, but you’re hesitant to simply dump everything at Amazon since you know that not all workloads are suitable for cloud. You know that you want the kind of ease of use and scalability that you get with public cloud, but your applications are architected in a way that makes the public cloud a non-starter. You’re looking at private cloud solutions based on hyperconverged infrastructure, but you’re concerned with the limits inherent in those technologies.
‘Trend’ is a pretty common business term, but its definition tends to vary by industry. In performance monitoring, trend, or trend shift, is a key metric that is used to indicate change. Change is inevitable. Today’s websites must frequently update and change to keep up with competition and attract new users, but such changes can have a negative impact on the user experience if not managed properly. The dynamic nature of the Internet makes it necessary to constantly monitor different metrics. O...
Today companies are looking to achieve cloud-first digital agility to reduce time-to-market, optimize utilization of resources, and rapidly deliver disruptive business solutions. However, leveraging the benefits of cloud deployments can be complicated for companies with extensive legacy computing environments. In his session at 21st Cloud Expo, Craig Sproule, founder and CEO of Metavine, will outline the challenges enterprises face in migrating legacy solutions to the cloud. He will also prese...
Enterprises are moving to the cloud faster than most of us in security expected. CIOs are going from 0 to 100 in cloud adoption and leaving security teams in the dust. Once cloud is part of an enterprise stack, it’s unclear who has responsibility for the protection of applications, services, and data. When cloud breaches occur, whether active compromise or a publicly accessible database, the blame must fall on both service providers and users. In his session at 21st Cloud Expo, Ben Johnson, C...
Agile has finally jumped the technology shark, expanding outside the software world. Enterprises are now increasingly adopting Agile practices across their organizations in order to successfully navigate the disruptive waters that threaten to drown them. In our quest for establishing change as a core competency in our organizations, this business-centric notion of Agile is an essential component of Agile Digital Transformation. In the years since the publication of the Agile Manifesto, the conn...
As DevOps methodologies expand their reach across the enterprise, organizations face the daunting challenge of adapting related cloud strategies to ensure optimal alignment, from managing complexity to ensuring proper governance. How can culture, automation, legacy apps and even budget be reexamined to enable this ongoing shift within the modern software factory?
The nature of the technology business is forward-thinking. It focuses on the future and what’s coming next. Innovations and creativity in our world of software development strive to improve the status quo and increase customer satisfaction through speed and increased connectivity. Yet, while it's exciting to see enterprises embrace new ways of thinking and advance their processes with cutting edge technology, it rarely happens rapidly or even simultaneously across all industries.
These days, APIs have become an integral part of the digital transformation journey for all enterprises. Every digital innovation story is connected to APIs . But have you ever pondered over to know what are the source of these APIs? Let me explain - APIs sources can be varied, internal or external, solving different purposes, but mostly categorized into the following two categories. Data lakes is a term used to represent disconnected but relevant data that are used by various business units wit...
"When we talk about cloud without compromise what we're talking about is that when people think about 'I need the flexibility of the cloud' - it's the ability to create applications and run them in a cloud environment that's far more flexible,” explained Matthew Finnie, CTO of Interoute, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
"NetApp's vision is how we help organizations manage data - delivering the right data in the right place, in the right time, to the people who need it, and doing it agnostic to what the platform is," explained Josh Atwell, Developer Advocate for NetApp, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
One of the biggest challenges with adopting a DevOps mentality is: new applications are easily adapted to cloud-native, microservice-based, or containerized architectures - they can be built for them - but old applications need complex refactoring. On the other hand, these new technologies can require relearning or adapting new, oftentimes more complex, methodologies and tools to be ready for production. In his general session at @DevOpsSummit at 20th Cloud Expo, Chris Brown, Solutions Marketi...
Leading companies, from the Global Fortune 500 to the smallest companies, are adopting hybrid cloud as the path to business advantage. Hybrid cloud depends on cloud services and on-premises infrastructure working in unison. Successful implementations require new levels of data mobility, enabled by an automated and seamless flow across on-premises and cloud resources. In his general session at 21st Cloud Expo, Greg Tevis, an IBM Storage Software Technical Strategist and Customer Solution Architec...
Most of the time there is a lot of work involved to move to the cloud, and most of that isn't really related to AWS or Azure or Google Cloud. Before we talk about public cloud vendors and DevOps tools, there are usually several technical and non-technical challenges that are connected to it and that every company needs to solve to move to the cloud. In his session at 21st Cloud Expo, Stefano Bellasio, CEO and founder of Cloud Academy Inc., will discuss what the tools, disciplines, and cultural...
DevOps is often described as a combination of technology and culture. Without both, DevOps isn't complete. However, applying the culture to outdated technology is a recipe for disaster; as response times grow and connections between teams are delayed by technology, the culture will die. A Nutanix Enterprise Cloud has many benefits that provide the needed base for a true DevOps paradigm. In their Day 3 Keynote at 20th Cloud Expo, Chris Brown, a Solutions Marketing Manager at Nutanix, and Mark Lav...