SlideShare una empresa de Scribd logo
1 de 16
Descargar para leer sin conexión
CLOUD SECURITY:
A GOVERNMENT STEP
CHANGE
With TONY RICHARDS
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
G-CLOUD
WE HAVE VERY RELEVANT EXPERIENCESuppliers offer commodity cloud services
Published via www.gov.uk/digital-marketplace
UK Government buyers select and purchase
best fit services
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
OLD RULES – BAD BADGES
WE HAVE VERY RELEVANT EXPERIENCE
Suppliers submitted services to a Pan
Government Accreditation service
In 3 years, out of 19000 services, only 200
were Pan Government Accredited
Buyers were biased towards the PGA badged
services
A PGA badged service may not have been
appropriate or proportional
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
USER SECURTY NEEDS
WE HAVE VERY RELEVANT EXPERIENCE
Move away from centralised compliance to
Principles based Risk Management
Align security with the commercial offerings
of commodity services
Simplified - Offer a service, state the security
Buyers select what is relevant and
proportional
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
G-CLOUD SECURITY APPROACH
1. Data in transit protection
2. Asset protection and resilience
3. Separation between consumers
4. Governance framework
5. Operational security
6. Personnel security
7. Secure development
8. Supply chain security
9. Secure consumer management
10. Identity and authentication
11. External interface protection
12. Secure service administration
13. Audit information provision to consumers
14. Secure use of the service by the consumer
CLOUD SECURITY PRINCIPLES
51 SECURITY ASSERTIONS
SELECT APPROPRIATE ANSWERS
STATE APPROPRIATE EVIDENCE
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
G-CLOUD SECURITY APPROACH
Suppliers security information published as
part of their service description on the UK
Digital Marketplace
Buyers can assess Suppliers services
relevant to business needs and make
pragmatic risk management decisions from a
position of knowledge
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
TRANSPARENCY
WE HAVE VERY RELEVANT EXPERIENCE
Suppliers state what security they currently
have in place
No wrong answer, No minimum baseline
Suppliers can update the security information
at any time, for any change
Transparency, not compliance
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
MANAGE THE RISK
Buyers should develop a minimum
Security Profile for the service:
1. Identify any legal or regulatory
requirements or constraints
2. Agree with the business any
security or Risk “Red Lines”
3. Identify applicable security
questions
4. Determine the minimum security
assertions that meet your security
requirements
5. Select the minimum supporting
approaches that meet your Risk
Appetite
MINIMUM SECURITY PROFILE
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
SERVICE SELECTON
Using the assertions in the Security Profile,
Buyers can incorporate security into the
selection criteria for filtering the Digital
Marketplace to create the Supplier Long List
Buyers can also utilise the supporting
assurance mechanisms to develop a set of
criteria for filtering the Long List to create the
Supplier Short List selection
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
SUPPLIER DISCUSSIONS
WE HAVE VERY RELEVANT EXPERIENCE
On request, Suppliers should provide further
details supporting their security assertions
And additional information about their Supporting
Approach’s with references where relevant
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
SERVICE ASSURANCE
The consuming organisations Security Team
can compare the Supplier’s Security
Assertions and stated supporting approaches
evidence, against the Security Profile
The consuming organisations Security Team
can then identify any gaps, or areas which
require additional assurance activities
A winning G-Cloud service should be BEST FIT,
and does not need to be 100% perfect
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
USEFUL LINKS
https://www.gov.uk/government/collections/cloud-security-guidance
https://digitalmarketplace.blog.gov.uk/2014/11/04/the-g-cloud-6-security-
questions/
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
WHO ARE IACS?
• WE ARE SECURITY EXPERTS that
understand business.
• WE ARE DIFFERENT. We thrive on solving
challenges pragmatically at low costs.
• WE BRING BIG 4 EXPERIENCE. Low
overheads enable us to flexible and value
driven.
• GROWING UK SME WITH CREDIBILITY.
Working with UK Government, European
and Asian FS Clients and Partners.
• WE INVEST IN OUR PEOPLE. We are
ISO27001 LAs, ex-CLAS, CCP, CISSP, CSA
CCSK, CSA STAR Advanced Auditors,
TOGAF and Cyber Essential certified.
CLOUD SECURITY
CYBER SECURITY
SECURITY and COMPLIANCE
THREAT and VULNERABILITY
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
UK GOVERNMENT EXPERIENCE
CLOUD SECURITY
CYBER SECURITY
• Carried out a discovery exercise and then re-architected and assured a
government departments applications, including full audit and accreditation.
• Provided advice and guidance on cyber security and secure architecture to a
government agency.
• Providing an outsourced & managed security service to a government agency.
• Non-government organisation's key applications secured and assured as part
of the implementation of cloud based, corporate services.
• Architected and assured a government agency’s key applications migration to
cloud infrastructure.
• Developed UK government’s security approach for cloud services.
THREAT and VULNERABILITY
• Government agency’s applications penetration tested and assured annually as
part of a managed security service, including cloud services.
• Conducted penetration testing and IT health checks on a range of secure
systems across a number of prisons.
WHO WE ARE
THE EXPERT
SECURITY ADVISORS
WWW.IACS-LLP.COM
CONTACT US
• Information Assurance Consulting
Services LLP
• Unit 7 Park Farm, Tyringham, Newport
Pagnell, MK16 9ES
• See our G-Cloud 7 services on the Digital
Marketplace:
• Cloud Security Architecture Service – G-Cloud
ID: 7795260587117876
• Certified Cyber Security Consultancy and Cloud
Assurance – G-Cloud ID: 7126790914748078
• Cloud IT Health Check Services – G-Cloud ID:
7262973877382092
• Cloud Security Managed Services – G-Cloud ID:
7731390423841686
EMAIL: g-cloud@iacs-llp.com
WEB: www.iacs-llp.com
TEL: 0845 519 6138
TWITTER: @IACSLLP
ANY QUESTIONS?
WWW.IACS-LLP.COM

Más contenido relacionado

Similar a Government Cloud Security: Transparency, Risk Management and Best Fit Services

Alcumus ISOQAR India Pvt. Ltd. Presentation
Alcumus ISOQAR India Pvt. Ltd.  PresentationAlcumus ISOQAR India Pvt. Ltd.  Presentation
Alcumus ISOQAR India Pvt. Ltd. PresentationPalvi Shah
 
Alcumus ISOQAR India Pvt. Ltd. Presentation
Alcumus ISOQAR India Pvt. Ltd.  PresentationAlcumus ISOQAR India Pvt. Ltd.  Presentation
Alcumus ISOQAR India Pvt. Ltd. PresentationPalvi Shah
 
Hipora company profile
Hipora company profileHipora company profile
Hipora company profileVivien Wamalwa
 
Introducing Veriserv
Introducing VeriservIntroducing Veriserv
Introducing VeriservDavid Quarmby
 
John Godwin's Presentation at Digital Leaders Conference 2015
John Godwin's Presentation at Digital Leaders Conference 2015John Godwin's Presentation at Digital Leaders Conference 2015
John Godwin's Presentation at Digital Leaders Conference 2015Digital Leaders
 
PIPL Practice Area Trusted Advisory
PIPL Practice Area Trusted AdvisoryPIPL Practice Area Trusted Advisory
PIPL Practice Area Trusted AdvisoryDr. Sanjeev B Ahuja
 
NQA Your Risk Assurance Partner
NQA Your Risk Assurance PartnerNQA Your Risk Assurance Partner
NQA Your Risk Assurance PartnerNQA
 
AutoProtect Product Presentation
AutoProtect Product PresentationAutoProtect Product Presentation
AutoProtect Product PresentationAutoProtect
 
How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?PECB
 
Securium Solutions: Empowering Online Certification Training in Cyber Securit...
Securium Solutions: Empowering Online Certification Training in Cyber Securit...Securium Solutions: Empowering Online Certification Training in Cyber Securit...
Securium Solutions: Empowering Online Certification Training in Cyber Securit...Securium Solutions
 
SECURIUM-SOLUTIONS Best VAPT Security Company
SECURIUM-SOLUTIONS Best VAPT Security CompanySECURIUM-SOLUTIONS Best VAPT Security Company
SECURIUM-SOLUTIONS Best VAPT Security Companykeshavsecurium
 
Best Vapt Security Company Securium Solu
Best Vapt Security Company Securium SoluBest Vapt Security Company Securium Solu
Best Vapt Security Company Securium Solukeshavsecurium
 
An introduction to Alcumus Sypol
An introduction to Alcumus SypolAn introduction to Alcumus Sypol
An introduction to Alcumus SypolCecil Cruickshank
 
Feb20 Webinar - Managing Risk and Pain of Vendor Management
Feb20 Webinar - Managing Risk and Pain of Vendor ManagementFeb20 Webinar - Managing Risk and Pain of Vendor Management
Feb20 Webinar - Managing Risk and Pain of Vendor ManagementTrustArc
 

Similar a Government Cloud Security: Transparency, Risk Management and Best Fit Services (20)

Alcumus ISOQAR India Pvt. Ltd. Presentation
Alcumus ISOQAR India Pvt. Ltd.  PresentationAlcumus ISOQAR India Pvt. Ltd.  Presentation
Alcumus ISOQAR India Pvt. Ltd. Presentation
 
Alcumus ISOQAR India Pvt. Ltd. Presentation
Alcumus ISOQAR India Pvt. Ltd.  PresentationAlcumus ISOQAR India Pvt. Ltd.  Presentation
Alcumus ISOQAR India Pvt. Ltd. Presentation
 
Hipora company profile
Hipora company profileHipora company profile
Hipora company profile
 
Introducing Veriserv
Introducing VeriservIntroducing Veriserv
Introducing Veriserv
 
Introducing Veriserv
Introducing VeriservIntroducing Veriserv
Introducing Veriserv
 
John Godwin's Presentation at Digital Leaders Conference 2015
John Godwin's Presentation at Digital Leaders Conference 2015John Godwin's Presentation at Digital Leaders Conference 2015
John Godwin's Presentation at Digital Leaders Conference 2015
 
PIPL Practice Area Trusted Advisory
PIPL Practice Area Trusted AdvisoryPIPL Practice Area Trusted Advisory
PIPL Practice Area Trusted Advisory
 
AWS Cloud Security Fundamentals
AWS Cloud Security FundamentalsAWS Cloud Security Fundamentals
AWS Cloud Security Fundamentals
 
NQA Your Risk Assurance Partner
NQA Your Risk Assurance PartnerNQA Your Risk Assurance Partner
NQA Your Risk Assurance Partner
 
Smart Contract Audit and Development
Smart Contract Audit and DevelopmentSmart Contract Audit and Development
Smart Contract Audit and Development
 
AutoProtect Product Presentation
AutoProtect Product PresentationAutoProtect Product Presentation
AutoProtect Product Presentation
 
Kantara Overview June 2013
Kantara Overview June 2013Kantara Overview June 2013
Kantara Overview June 2013
 
How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?
 
Securium Solutions: Empowering Online Certification Training in Cyber Securit...
Securium Solutions: Empowering Online Certification Training in Cyber Securit...Securium Solutions: Empowering Online Certification Training in Cyber Securit...
Securium Solutions: Empowering Online Certification Training in Cyber Securit...
 
Securim Solutions Pvt Ltd
Securim Solutions Pvt LtdSecurim Solutions Pvt Ltd
Securim Solutions Pvt Ltd
 
SECURIUM-SOLUTIONS Best VAPT Security Company
SECURIUM-SOLUTIONS Best VAPT Security CompanySECURIUM-SOLUTIONS Best VAPT Security Company
SECURIUM-SOLUTIONS Best VAPT Security Company
 
Best Vapt Security Company Securium Solu
Best Vapt Security Company Securium SoluBest Vapt Security Company Securium Solu
Best Vapt Security Company Securium Solu
 
An introduction to Alcumus Sypol
An introduction to Alcumus SypolAn introduction to Alcumus Sypol
An introduction to Alcumus Sypol
 
WP-Governance-Digital
WP-Governance-DigitalWP-Governance-Digital
WP-Governance-Digital
 
Feb20 Webinar - Managing Risk and Pain of Vendor Management
Feb20 Webinar - Managing Risk and Pain of Vendor ManagementFeb20 Webinar - Managing Risk and Pain of Vendor Management
Feb20 Webinar - Managing Risk and Pain of Vendor Management
 

Último

##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up NumberMs Riya
 
EDUROOT SME_ Performance upto March-2024.pptx
EDUROOT SME_ Performance upto March-2024.pptxEDUROOT SME_ Performance upto March-2024.pptx
EDUROOT SME_ Performance upto March-2024.pptxaaryamanorathofficia
 
Item # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdfItem # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdfahcitycouncil
 
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Bookingroncy bisnoi
 
(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service
(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service
(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Serviceranjana rawat
 
Artificial Intelligence in Philippine Local Governance: Challenges and Opport...
Artificial Intelligence in Philippine Local Governance: Challenges and Opport...Artificial Intelligence in Philippine Local Governance: Challenges and Opport...
Artificial Intelligence in Philippine Local Governance: Challenges and Opport...CedZabala
 
The Economic and Organised Crime Office (EOCO) has been advised by the Office...
The Economic and Organised Crime Office (EOCO) has been advised by the Office...The Economic and Organised Crime Office (EOCO) has been advised by the Office...
The Economic and Organised Crime Office (EOCO) has been advised by the Office...nservice241
 
Top Rated Pune Call Girls Bhosari ⟟ 6297143586 ⟟ Call Me For Genuine Sex Ser...
Top Rated  Pune Call Girls Bhosari ⟟ 6297143586 ⟟ Call Me For Genuine Sex Ser...Top Rated  Pune Call Girls Bhosari ⟟ 6297143586 ⟟ Call Me For Genuine Sex Ser...
Top Rated Pune Call Girls Bhosari ⟟ 6297143586 ⟟ Call Me For Genuine Sex Ser...Call Girls in Nagpur High Profile
 
Climate change and safety and health at work
Climate change and safety and health at workClimate change and safety and health at work
Climate change and safety and health at workChristina Parmionova
 
Call Girls Chakan Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Chakan Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Chakan Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Chakan Call Me 7737669865 Budget Friendly No Advance Bookingroncy bisnoi
 
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...tanu pandey
 
Expressive clarity oral presentation.pptx
Expressive clarity oral presentation.pptxExpressive clarity oral presentation.pptx
Expressive clarity oral presentation.pptxtsionhagos36
 
CBO’s Recent Appeals for New Research on Health-Related Topics
CBO’s Recent Appeals for New Research on Health-Related TopicsCBO’s Recent Appeals for New Research on Health-Related Topics
CBO’s Recent Appeals for New Research on Health-Related TopicsCongressional Budget Office
 
2024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 282024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 28JSchaus & Associates
 
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxxIncident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxxPeter Miles
 
Fair Trash Reduction - West Hartford, CT
Fair Trash Reduction - West Hartford, CTFair Trash Reduction - West Hartford, CT
Fair Trash Reduction - West Hartford, CTaccounts329278
 
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escortsranjana rawat
 

Último (20)

##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up Number
 
EDUROOT SME_ Performance upto March-2024.pptx
EDUROOT SME_ Performance upto March-2024.pptxEDUROOT SME_ Performance upto March-2024.pptx
EDUROOT SME_ Performance upto March-2024.pptx
 
Item # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdfItem # 4 - 231 Encino Ave (Significance Only).pdf
Item # 4 - 231 Encino Ave (Significance Only).pdf
 
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
 
(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service
(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service
(PRIYA) Call Girls Rajgurunagar ( 7001035870 ) HI-Fi Pune Escorts Service
 
Artificial Intelligence in Philippine Local Governance: Challenges and Opport...
Artificial Intelligence in Philippine Local Governance: Challenges and Opport...Artificial Intelligence in Philippine Local Governance: Challenges and Opport...
Artificial Intelligence in Philippine Local Governance: Challenges and Opport...
 
The Economic and Organised Crime Office (EOCO) has been advised by the Office...
The Economic and Organised Crime Office (EOCO) has been advised by the Office...The Economic and Organised Crime Office (EOCO) has been advised by the Office...
The Economic and Organised Crime Office (EOCO) has been advised by the Office...
 
Top Rated Pune Call Girls Bhosari ⟟ 6297143586 ⟟ Call Me For Genuine Sex Ser...
Top Rated  Pune Call Girls Bhosari ⟟ 6297143586 ⟟ Call Me For Genuine Sex Ser...Top Rated  Pune Call Girls Bhosari ⟟ 6297143586 ⟟ Call Me For Genuine Sex Ser...
Top Rated Pune Call Girls Bhosari ⟟ 6297143586 ⟟ Call Me For Genuine Sex Ser...
 
The Federal Budget and Health Care Policy
The Federal Budget and Health Care PolicyThe Federal Budget and Health Care Policy
The Federal Budget and Health Care Policy
 
Climate change and safety and health at work
Climate change and safety and health at workClimate change and safety and health at work
Climate change and safety and health at work
 
Call Girls Chakan Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Chakan Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Chakan Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Chakan Call Me 7737669865 Budget Friendly No Advance Booking
 
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
 
Expressive clarity oral presentation.pptx
Expressive clarity oral presentation.pptxExpressive clarity oral presentation.pptx
Expressive clarity oral presentation.pptx
 
CBO’s Recent Appeals for New Research on Health-Related Topics
CBO’s Recent Appeals for New Research on Health-Related TopicsCBO’s Recent Appeals for New Research on Health-Related Topics
CBO’s Recent Appeals for New Research on Health-Related Topics
 
Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance VVIP 🍎 SER...
Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance  VVIP 🍎 SER...Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance  VVIP 🍎 SER...
Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance VVIP 🍎 SER...
 
2024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 282024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 28
 
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxxIncident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
 
Fair Trash Reduction - West Hartford, CT
Fair Trash Reduction - West Hartford, CTFair Trash Reduction - West Hartford, CT
Fair Trash Reduction - West Hartford, CT
 
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
 
Call Girls In Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
Call Girls In  Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCeCall Girls In  Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
Call Girls In Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
 

Government Cloud Security: Transparency, Risk Management and Best Fit Services

  • 1. CLOUD SECURITY: A GOVERNMENT STEP CHANGE With TONY RICHARDS
  • 2. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM G-CLOUD WE HAVE VERY RELEVANT EXPERIENCESuppliers offer commodity cloud services Published via www.gov.uk/digital-marketplace UK Government buyers select and purchase best fit services
  • 3. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM OLD RULES – BAD BADGES WE HAVE VERY RELEVANT EXPERIENCE Suppliers submitted services to a Pan Government Accreditation service In 3 years, out of 19000 services, only 200 were Pan Government Accredited Buyers were biased towards the PGA badged services A PGA badged service may not have been appropriate or proportional
  • 4. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM USER SECURTY NEEDS WE HAVE VERY RELEVANT EXPERIENCE Move away from centralised compliance to Principles based Risk Management Align security with the commercial offerings of commodity services Simplified - Offer a service, state the security Buyers select what is relevant and proportional
  • 5. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM G-CLOUD SECURITY APPROACH 1. Data in transit protection 2. Asset protection and resilience 3. Separation between consumers 4. Governance framework 5. Operational security 6. Personnel security 7. Secure development 8. Supply chain security 9. Secure consumer management 10. Identity and authentication 11. External interface protection 12. Secure service administration 13. Audit information provision to consumers 14. Secure use of the service by the consumer CLOUD SECURITY PRINCIPLES 51 SECURITY ASSERTIONS SELECT APPROPRIATE ANSWERS STATE APPROPRIATE EVIDENCE
  • 6. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM G-CLOUD SECURITY APPROACH Suppliers security information published as part of their service description on the UK Digital Marketplace Buyers can assess Suppliers services relevant to business needs and make pragmatic risk management decisions from a position of knowledge
  • 7. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM TRANSPARENCY WE HAVE VERY RELEVANT EXPERIENCE Suppliers state what security they currently have in place No wrong answer, No minimum baseline Suppliers can update the security information at any time, for any change Transparency, not compliance
  • 8. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM MANAGE THE RISK Buyers should develop a minimum Security Profile for the service: 1. Identify any legal or regulatory requirements or constraints 2. Agree with the business any security or Risk “Red Lines” 3. Identify applicable security questions 4. Determine the minimum security assertions that meet your security requirements 5. Select the minimum supporting approaches that meet your Risk Appetite MINIMUM SECURITY PROFILE
  • 9. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM SERVICE SELECTON Using the assertions in the Security Profile, Buyers can incorporate security into the selection criteria for filtering the Digital Marketplace to create the Supplier Long List Buyers can also utilise the supporting assurance mechanisms to develop a set of criteria for filtering the Long List to create the Supplier Short List selection
  • 10. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM SUPPLIER DISCUSSIONS WE HAVE VERY RELEVANT EXPERIENCE On request, Suppliers should provide further details supporting their security assertions And additional information about their Supporting Approach’s with references where relevant
  • 11. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM SERVICE ASSURANCE The consuming organisations Security Team can compare the Supplier’s Security Assertions and stated supporting approaches evidence, against the Security Profile The consuming organisations Security Team can then identify any gaps, or areas which require additional assurance activities A winning G-Cloud service should be BEST FIT, and does not need to be 100% perfect
  • 12. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM USEFUL LINKS https://www.gov.uk/government/collections/cloud-security-guidance https://digitalmarketplace.blog.gov.uk/2014/11/04/the-g-cloud-6-security- questions/
  • 13. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM WHO ARE IACS? • WE ARE SECURITY EXPERTS that understand business. • WE ARE DIFFERENT. We thrive on solving challenges pragmatically at low costs. • WE BRING BIG 4 EXPERIENCE. Low overheads enable us to flexible and value driven. • GROWING UK SME WITH CREDIBILITY. Working with UK Government, European and Asian FS Clients and Partners. • WE INVEST IN OUR PEOPLE. We are ISO27001 LAs, ex-CLAS, CCP, CISSP, CSA CCSK, CSA STAR Advanced Auditors, TOGAF and Cyber Essential certified. CLOUD SECURITY CYBER SECURITY SECURITY and COMPLIANCE THREAT and VULNERABILITY
  • 14. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM UK GOVERNMENT EXPERIENCE CLOUD SECURITY CYBER SECURITY • Carried out a discovery exercise and then re-architected and assured a government departments applications, including full audit and accreditation. • Provided advice and guidance on cyber security and secure architecture to a government agency. • Providing an outsourced & managed security service to a government agency. • Non-government organisation's key applications secured and assured as part of the implementation of cloud based, corporate services. • Architected and assured a government agency’s key applications migration to cloud infrastructure. • Developed UK government’s security approach for cloud services. THREAT and VULNERABILITY • Government agency’s applications penetration tested and assured annually as part of a managed security service, including cloud services. • Conducted penetration testing and IT health checks on a range of secure systems across a number of prisons.
  • 15. WHO WE ARE THE EXPERT SECURITY ADVISORS WWW.IACS-LLP.COM CONTACT US • Information Assurance Consulting Services LLP • Unit 7 Park Farm, Tyringham, Newport Pagnell, MK16 9ES • See our G-Cloud 7 services on the Digital Marketplace: • Cloud Security Architecture Service – G-Cloud ID: 7795260587117876 • Certified Cyber Security Consultancy and Cloud Assurance – G-Cloud ID: 7126790914748078 • Cloud IT Health Check Services – G-Cloud ID: 7262973877382092 • Cloud Security Managed Services – G-Cloud ID: 7731390423841686 EMAIL: g-cloud@iacs-llp.com WEB: www.iacs-llp.com TEL: 0845 519 6138 TWITTER: @IACSLLP