DEV Community

Cover image for Who Has Access to Your Cloud? Why It Matters for Security
EzSecure
EzSecure

Posted on

Who Has Access to Your Cloud? Why It Matters for Security

The cloud platforms have made it very convenient for businesses to store files, work with teams and get information from almost anywhere. Share a document with a colleague in seconds, add a new employee to a workspace quickly and teams can work together without being in the same office.

But this convenience can also lead to a simple problem: too many people may have access to more information than they actually need.

An employee can change roles and retain their former permissions. A former employee’s account may stay active. A file can be shared with the whole team but only 2 people need it. External users can also have access to folders containing confidential business information.

The bigger problem is that access can change all the time. Without regular visibility and review, businesses may not know who is accessing their cloud data.

Why Cloud Access Matters

Cloud security is about more than just securing the cloud platform itself. It’s also about who can access the information stored there, and what they can do with it.

Think of a shared folder with customer data. If you need 10 employees to have access, you are exposing yourself unnecessarily by giving access to 50. The same can be said for financial documents, employee records, contracts, business plans, and other confidential information.

The more accessible information is , the more difficult it is to control where that information can go.

This is the reason why access management is a key aspect in keeping a secure cloud environment.

Employees Should Only Have the Access They Need

Access management is based on a simple principle: people should have access to the information they need to do their jobs, and not much more.

For example, a member of the marketing team may require access to campaign documents and brand assets. They probably don’t need access to payroll or sensitive HR files, for example.

Similarly, a finance employee may require financial reports but may not need access to all the customer support folders.

This limits the exposure to only what is necessary for the user to do.

This approach is often referred to as least privilege.

It sounds simple, but it can become difficult to stay on top as organisations grow.

Employee Roles Change

People don’t remain in the same job forever.

A person might switch from sales to marketing, take on management responsibilities or transfer to another department. They may require different access for their new role but sometimes their old permissions can be grand-fathered in.

This can accumulate permissions over time.

Permissions are often never reviewed, so an employee who initially needed access to five folders may end up with access to twenty.

That’s why access should be reviewed when employees change roles, not just when they join or leave the company.

Former Employees Can Leave Access Behind

Another key area is offboarding employees.

When someone leaves an organization, their account should be disabled and their access reviewed as part of the offboarding process.

The problem is compounded when employees have access to multiple cloud applications, shared folders, documents or outside collaboration spaces.

An abandoned account can be an unnecessary access point for company information.

Therefore, businesses should include cloud access in their employee onboarding and offboarding processes.

External Sharing Can Create Another Risk

Cloud collaboration enables the effortless sharing of information with people outside the company.

A document can be shared with:

  • Customers
  • Consultants
  • Business partners
  • Contractors
  • Suppliers
  • Different external email addresses

Sharing to external entities is great, but should also be kept track of!

The document holding secrets might have the external person as its viewer, still be active and available long after the initial work has been completed.

Regular external sharing checkups should take place and access removal done if no permission is granted.

Not All Data Needs the Same Level of Access

Yet another critical aspect is the necessity for access rules to be decided by the nature of information.

Public marketing brochures do not require the same degree of access controls that employee payroll records do for instance).

So the first thing is that you really need to know what information you’ve got stored in the cloud.

Businesses should therefore be able to identify and classify types of information such as:

  • Customer data
  • Employee personnel files
  • Company financial statements
  • Identity details
  • Legal agreements
  • Future company strategies
  • Creative materials
  • Secret documents that are only shared internally

With the sensitive data identified it is possible for access reviews to be directed at the data that is most important.

Shared Folders Can Become Difficult to Manage

Shared folders are quite nice to have, especially for teams working on shared projects.

However, after a certain point folders can become messy, having lots of files, users

groups and settings.

If a folder has originally been

set up for a project, the folder can continue to survive in the years to come.

The workers of the initial project can still have permission to use it

even though they may have

changed teams.

As a consequence, you end up with a situation in which it is impossible for anyone to know completely who has access to which resources.

Frequent access

reviews will allow companies identify users or roles that no longer need permission and

miscellaneous or obsolete sharing agreements.

Cloud Access Should Be Reviewed Regularly

Access management is never a once and done job.

If companies are to maintain effective access control, they need to set up a process of periodically reviewing who has got how:

  • Who is granted access?
  • What kind of access are they allowed?
  • Has this level of access become unnecessary?
  • Do people outside of the organization need to have their access reviewed?
  • Has there been an instance where the former employees are still listed as having access?
  • Do privileged accounts still get the right level of control?
  • Do sensitive files get unnecessarily widespread sharing?

The interval at which these reviews will be conducted can vary from one organization to another and can be influenced in part by the latter’s size, the type of data being managed, and the compliance with regulations.

The most important thing is that the reviews should be made an integral part of the normal business activity rather than be reserved for the time when an incident has occurred.

Visibility Comes Before Better Access Control

One of the biggest issues is that organizations are unable to evaluate that which is hidden from view.

Knowledge of the cloud platform that the organization is using, for example, cannot help if confidential business data, sensitive customer information or intellectual property have already been copied or uploaded into various storage locations, such as cloud storage, shared folders, documents, spreadsheets or any other business applications.

Organizations need the ability to see what sensitive data they have, how is it protected, and who can view or modify it.

If that is not possible or is difficult, then they will never really understand the risk, nor will they be able to control it, especially in a digital world where sensitive digital assets are becoming more and more common and the threat of loss or misuse has a devastating impact.

By way of illustration, if a folder is discovered that contains customer information, it will be up to the company to decide if all the employees with access to the folder need access in fact or whether access should only be permitted through special procedures.

Sometimes even in the most secure IT environments you may come across information that should not have been left there by accident or intentionally.

A Simple Cloud Access Checklist

Organizations can start with a basic review:

☐ Identify all major cloud platforms used by the business

☐ Review user accounts and access permissions

☐ Remove access that is no longer required

☐ Review former employee accounts

☐ Check permissions when employees change roles

☐ Review external users and shared links

☐ Identify folders containing sensitive information

☐ Classify important information based on sensitivity

☐ Review privileged accounts

☐ Schedule regular access reviews

☐ Monitor changes to access and sharing permissions

The Goal Is Not to Remove Access

Good cloud security does not mean making information difficult for employees to access.

People need access to information to do their jobs.

The goal is to make sure the right people have access to the right information for the right reasons.

That requires more than simply creating user accounts and assigning permissions. Organizations need ongoing visibility into their cloud environment, the information stored within it, and how access changes over time.

As businesses continue moving more information to cloud platforms, understanding who can access that information becomes increasingly important.

The question is not simply “Is our data in the cloud?”

It is:

“Do we know who can access it, what they can access, and whether they still need that access?”

That visibility can make it much easier to identify unnecessary exposure and maintain better control over sensitive information.

Top comments (0)