Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Securing Your Data when Migrating to the Cloud
News & Analysis

Securing Your Data when Migrating to the Cloud

ISBuzz TeamBy ISBuzz TeamNovember 3, 2014Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
cloud
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

More organizations are moving applications and databases to IaaS/PaaS environments to enjoy the benefits of cloud computing while preserving application flexibility and control.

However, many IT departments have serious concerns about moving sensitive servers and data to the cloud.

Featured Download: Social media access at work. Do your employees know the rules?

They have good reason for concern: industry experts, such as Cloud Security Alliance and IBM Security Services, agree that moving sensitive data into the hands of third-party cloud providers expands and complicates the risk landscape.

Reports from these experts are reinforced by a stream of news stories about hacked data from companies including eBay, Target, LinkedIn, Subway, Sony, JPMorgan, AT&T, and more.

Before migrating a database to the cloud, it is critical to understand the scope of this action:

– What data are you moving?

Understand the content and context of the data as it moves to the cloud. Migrating PII and other regulated data may affect regulatory compliance. Tools that provide eDiscovery options can help to identify sensitive database content, understand the regulatory aspects, and assist in classification of the data.

– Who is accessing the database?

Examine who is accessing the database and for what purposes, thinking beyond regular user access. For example, map out administrative tasks to ensure granular access controls are maintained after moving to the cloud.

– Where is the data moving?

Understand the different security capabilities from IaaS/PaaS providers. When weighing cloud provider options, know the security aspects involved, including the physical and network security infrastructures, who has administration access to the database, and to what granular extent you can specify access rights.

Once you have a clear picture of the required security policies and how to achieve them, plan the security controls. One of the biggest challenges is understanding who is responsible for what – between you and your service provider. In IaaS, the borders are clear, but in PaaS they are blurred. As a rule of thumb, your provider is responsible for protecting the infrastructure components, but all instance and application security is up to you. If you are using a managed database environment, your provider will be responsible for the availability of the database. They will not be responsible for protection against confidentiality and integrity threats – that is up to you.

Areas that you must address – or make sure that your cloud provider is addressing – include:

– Data-in-motion encryption – Use SSL or a VPN to protect the data as it moves in and out of the cloud. Also, encrypt the traffic between application servers and database servers.

– Hardening instances – Secure the operating system, including hardening best practices, OS patches and security software installation. Make sure to follow your database vendor’s security guidelines.

– Protect management console access –Use best practices such as multi-factor authentication and role-based access to dashboard functions to protect IaaS management consoles.

– Account for application security – Review all components of the Security Development Lifecycle (SDLC) and include cloud-specific threats in your threat modeling.

– Prepare plans for availability, backups, Disaster Recover (DR) and Business Continuity – Most IaaS vendors provide tools for creating an adequate backup and DR strategy within the boundaries of the provider. However, you are responsible for deploying the tools.

By David Maman, Co-founder and CTO, GreenSQL

About GreenSQL

GreenSQL_logoFounded in 2009, GreenSQL provides unified database security and compliance solutions for enterprises running their databases on premises or in the cloud. The company’s all-in-one approach to database security helps organizations by discovering their sensitive data location, protecting databases from SQL injection attacks (the most common data breach method today), securing sensitive information from unauthorized database access, enforcing separation-of-duties and meeting regulatory compliance requirements. With more than 150,000 copies downloaded in 198 countries, GreenSQL is the most-used product for eliminating database vulnerabilities in the face of modern day cyber-attacks. The company, based in Tel Aviv, is backed by leading venture capital firms Jerusalem Venture Partners, Magma Venture Capital and Rhodium.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Tenable warns AI adoption is outpacing governance as cloud exposure risks surge

May 15, 20264 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

AppSec is dead, long live AI security

April 29, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}