Here’s How the Department of Homeland Security Is Promoting Cloud Security and Visibility

As an increasing number of organizations migrate their operations to the cloud, they are becoming empowered to deliver financial services faster and more effectively than has ever been possible before.
However, with all the convenience and service we enjoy as a result of cloud migration also comes a significantly higher risk of data breaches, theft, and other cyber-criminal activities. Breaches of this nature can cost financial brands millions of dollars in money stolen and fines and can result in reputational damage from which they may never recover.
With the cost of a lackadaisical attitude to cloud risk and security being so high, financial brands need to ensure that any cloud migration strategy is backed up by robust, appropriate, and evidence-based security protocols.
Department of Homeland Security
Due to the serious nature of the cybersecurity landscape today, the DHS has stepped in and empowered its Cybersecurity and Infrastructure Security Agency (CISA) to standardize the business of public cloud security in the United States.
The result of this commission is the Secure Cloud Business Applications Technical Reference Architecture (SCuBA TRA), a wide-reaching set of recommendations and guidelines which set out cloud security requirements civilian agencies will be required to adhere to and that have thus far fallen outside the existing Federal Risk and Authorization Management Program (FedRAMP) which only applies to Executive departments and agencies.
"The SCuBA project will address cybersecurity and visibility gaps in business applications hosted in the cloud and provide guidance to secure FCEB implementations,” says CISA in its for comment report. "These gaps impact each agency’s ability to manage cyber risk for its IT enterprise and CISA’s ability to adequately understand and manage cyber risk for the federal enterprise. The SCuBA project will provide architecture and security configurations that offer fundamental protections for cloud business applications and give FCEB agencies and CISA the visibility necessary to identify and detect adversarial activity in their cloud environments.”
The SCuBA TRA will enable government agencies and businesses to better understand the current threat landscape and build on existing knowledge to develop solutions which drastically reduce the chances of a breach occurring. CISA will establish baselines which will form the bedrock of security protocols developed using the framework and enable a feedback loop which allows for the continued refinement of engineering solutions and improved guidance on configuring SaaS offerings.
"Get ready for the semi-nationalization of public cloud security in the US,” reports Forrester. "The proposed changes — expected after a public comment period — will have a ripple effect across cloud vendor offerings and raise expectations among regulators in all key industries around cloud security.”
Extensible Visibility
The second thrust of the CISA strategy to shore up the defenses of cloud enabled businesses is the Extensible Visibility Reference Framework (eVRF), a framework designed to empower organizations to identify visibility data which can then be leveraged to mitigate threats, understand the extent to which specific products and services provide necessary visibility data, and identify potential visibility gaps.
"In order to achieve its mission and strengthen cybersecurity across the Federal Government, the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) requires visibility across various Federal Civilian Executive Branch (FCEB) agency domains,” says the CISA for comment report on the framework. "This visibility enables CISA to develop insights that can be shared across the FCEB, ensuring that CISA can identify threats, protect against potential attacks, and perform hunt, incident response, and analysis activities.”
The eVRF will:
- Communicate requirements for FCEB agencies to provide CISA with the necessary data to protect agency networks, devices, cloud-based environments, data, and systems.
- Enable agencies to evaluate their ability to collect relevant visibility data and model their coverage of CISA’s visibility requirements.
- Promote partners’ ability to incorporate key visibility concepts into their own cyber practices.
- Provide a framework for agencies to evaluate visibility products’ capabilities and features and to characterize the visibility gaps that various products can fill.
As with the SCuBA TRA, the eVRF may be mainly focused on government and civilian agencies but will almost certainly have a knock-on effect which sees these frameworks and regulations filter down to our industry.
Final Thoughts
With the DHS and its relevant departments taking the threats associated with cloud security so seriously it only serves to highlight the scale of the problem. Cloud computing offers financial brands significant advantages when it comes to serving their customers, but security must be prioritized and assigned the appropriate level of time and resources to mitigate these risks.
You can hear Senior Cyber Security Advisor, Cybersecurity and Infrastructure Security Agency (CISA), US Department of Homeland Security, Michael Kingsley speak at InfoSec Finance Connect 2023, being held in March at the Rancho Bernardo Inn, San Diego CA.
Download the agenda today for more information and insights.