{"id":3433,"date":"2016-02-18T10:05:25","date_gmt":"2016-02-18T10:05:25","guid":{"rendered":"https:\/\/www.happiestminds.com\/blogs\/?p=3433"},"modified":"2024-04-10T07:29:10","modified_gmt":"2024-04-10T07:29:10","slug":"best-security-practices-in-it-infrastructure-implementation","status":"publish","type":"post","link":"https:\/\/www.happiestminds.com\/blogs\/best-security-practices-in-it-infrastructure-implementation\/","title":{"rendered":"Best Security Practices in IT Infrastructure Implementation"},"content":{"rendered":"<div id=\"bsf_rt_marker\"><\/div><p style=\"text-align: justify;\">The structure of <a title=\"IT infrastructure\" href=\"https:\/\/www.happiestminds.com\/services\/managed-infrastructure-and-security-services\/\" target=\"_blank\" rel=\"noopener\">IT infrastructure<\/a> is changing and with it, its security aspects. Gartner in its \u2018Top Predictions for IT Organizations and Users for 2016 and Beyond\u2019 [<a href=\"http:\/\/www.gartner.com\/newsroom\/id\/3143718\" target=\"_blank\" rel=\"noopener\">1<\/a>] reveals, \u2018By 2018, 50 percent of enterprises with more than 1,000 users will use cloud access security broker products to monitor and manage their use of SaaS and other forms of public cloud\u2026\u2019 Yet, the security of the virtualized environment and the responsibility of ensuring regulatory compliance lie with the enterprise.<\/p>\n<p style=\"text-align: justify;\">So, how do enterprises ensure <a title=\"security control\" href=\"https:\/\/www.happiestminds.com\/IT-security-services\/\" target=\"_blank\" rel=\"noopener\">security control<\/a> over cloud data \u2014 its collection, storage, access, usage, transfer, and disposal? How can they ensure compliance with regulatory requirements?<\/p>\n<p style=\"text-align: justify;\">Best practices dictate:<\/p>\n<p style=\"text-align: justify;\"><strong>Control of input and access <\/strong>\u2014 Opt for cloud encryption CRM gateways, firewalls, inputs of only encrypted data. In parallel, put in place strict <a title=\"Identity and Access Management\" href=\"https:\/\/www.happiestminds.com\/IT-security-services\/identity-and-access-management\/\" target=\"_blank\" rel=\"noopener\">Identity and Access Management<\/a> (IAM) protocols to address possible human-related vulnerabilities. Allow only vetted, authorized personnel both within the enterprise and in the cloud service provider organization, access to the enterprise cloud data. Also, check that data collected and uploaded follows defined standards and complies with applicable laws.Enterprises that have access to highly restricted and regulated data such as CJIS (Criminal Justice Information System Database) and HITECH (Health Information Technology for Economic and Clinical Health Act) and so on have stringent regulatory requirements to safeguard data.<\/p>\n<p style=\"text-align: justify;\"><strong>Control of storage<\/strong> \u2014 ISO 27001 is a widely accepted certification to check the security of a physical <a title=\"data center\" href=\"https:\/\/www.happiestminds.com\/services\/infrastructure-management-Services\/cloud-management-services\/\" target=\"_blank\" rel=\"noopener\">data center<\/a>. Conformance would mean that business threats are assessed and managed; physical security processes such as restricted\/named access are consistently enforced; and, audits are conducted regularly at each site, including tests of security and CCTV planning andmonitoring. Adhere to similar high standards in assessment, management and audit of cloud data centers as well. Enterprises that fall under regulatory data residency requirements need to ensure that their <a title=\"cloud service provider\" href=\"https:\/\/www.happiestminds.com\/services\/infrastructure-management-Services\/cloud-management-services\/\" target=\"_blank\" rel=\"noopener\">cloud service provider<\/a> is not offloading storage to overseas data centers according to traffic.<\/p>\n<p style=\"text-align: justify;\"><strong>Control of use and transfer <\/strong>\u2014 Ensure checks at all points. Data from a protected server can lose its security layer by an inadvertent unchecked transfer into an unprotected server. Track data even within a private cloud, to safeguard against data exposure to unauthorized, possibly malicious insiders. Keep <a title=\"access control\" href=\"https:\/\/www.happiestminds.com\/IT-security-services\/identity-and-access-management\/\" target=\"_blank\" rel=\"noopener\">access control<\/a> protection of all used servers active and patched up to date. Also, ensure compliance with applicable regulations. An EU directive currently places restrictions on the export of crucial data like Personally Identifiable Information (PII) outside the European Economic Area.<\/p>\n<p style=\"text-align: justify;\"><strong>Control of disposal<\/strong> \u2014 The problem of data remnants arises from factors like the dynamic movement of data and shared apps\/platforms. While regulatory bodies like the Health Insurance Portability and Accountability Act (HIPAA) have rules for the safe disposal of their digital media, the problem of residual data on the cloud is yet unregulated. Where possible, use crypto-shredding \u2014 the destruction of the encryption protocol to ensure that the data cannot be used. Else, work with the provider to wipe free space and ensure that the SLA with the provider covers this.<\/p>\n<p style=\"text-align: justify;\">With the inevitability of cloud adoption for cost and convenience, enterprises need to understand the critical nature of <a title=\"cloud security\" href=\"https:\/\/www.happiestminds.com\/IT-security-services\/\" target=\"_blank\" rel=\"noopener\">cloud security<\/a> issues and put in place appropriate strategies to address them.<\/p>\n<p style=\"text-align: justify;\">[1]Gartner, Inc., Gartner Reveals Top Predictions for IT Organizations and Users for 2016 and Beyond, 2015 October, accessed 2015 December, <a href=\"http:\/\/www.gartner.com\/newsroom\/id\/3143718\">http:\/\/www.gartner.com\/newsroom\/id\/3143718<\/a><\/p>\n<p style=\"text-align: justify;\">\n<div class=\"pld-like-dislike-wrap pld-template-2\">\r\n    <div class=\"pld-like-wrap  pld-common-wrap\">\r\n    <a href=\"javascript:void(0)\" class=\"pld-like-trigger pld-like-dislike-trigger  \" title=\"Like\" data-post-id=\"3433\" data-trigger-type=\"like\" data-restriction=\"cookie\" data-already-liked=\"0\">\r\n                        <i class=\"fas fa-heart\"><\/i>\r\n                <\/a>\r\n    <span class=\"pld-like-count-wrap pld-count-wrap\">0    <\/span>\r\n<\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>The structure of IT infrastructure is changing and with it, its security aspects. Gartner in its \u2018Top Predictions for IT Organizations and Users for 2016 and Beyond\u2019 [1] reveals, \u2018By 2018, 50 percent of enterprises with more than 1,000 users will use cloud access security broker products to monitor and manage their use of SaaS [&hellip;]<\/p>\n","protected":false},"author":124,"featured_media":1262,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[472,252,369,139],"tags":[673,845,847,929,1153,1243,1527],"class_list":["post-3433","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-access-governance","category-identity-access-governance","category-infrastructure","category-security","tag-access-control","tag-cloud-security","tag-cloud-service-provider","tag-data-center","tag-identity-and-access-management","tag-it-infrastructure","tag-security-control"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/posts\/3433","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/users\/124"}],"replies":[{"embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/comments?post=3433"}],"version-history":[{"count":1,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/posts\/3433\/revisions"}],"predecessor-version":[{"id":12049,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/posts\/3433\/revisions\/12049"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/media\/1262"}],"wp:attachment":[{"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/media?parent=3433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/categories?post=3433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.happiestminds.com\/blogs\/wp-json\/wp\/v2\/tags?post=3433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}