Compliance is Only the Tip of the Cloud Security Iceberg

By David Den Bleyker
We’ve all seen beautiful pictures of icebergs. We also know that 7/8ths of the iceberg is below the surface – hidden danger. 

This is a lot like many conversations I’ve had over the past few months about compliance and security. Many people and companies believe that if they are in compliance with the relative regulations for their industry, they will also be secure. This couldn’t be further from the truth.

Think of compliance as the 1/8th of the iceberg you can see. Security and governance are the other 7/8ths you are unable to see. HIPAA, PCI DSS, GDPR, SOC 2, NIST, NIST 800-53, ISO 27001, FedRAMP CCM 3.0.1 CIS for (GCP, AWS, Kubernetes, Microsoft Azure) CSA Cloud Controls are just some of the regulations your company is subject to. 

What about the next one that is still emerging from the regulatory ooze?
Most companies are lacking the holistic or circular solution to their security, compliance and governance issues. A solutions should 1) Harvest the current cloud configuration, 2) Unify the multi-cloud configuration data into a standardized model, 3) Analyze the unified data and identify changes in the cloud infrastructure that represent security, compliance or governance issues, 4) Take action: automated remediation and or notification and recording the event and resolution.

This may seem like a distant dream, but it isn’t. DivvyCloud had delivered continuous cloud compliance to a broad section of enterprise clients: 3M, GE, AutoDesk, Fannie Mae, Twilio and Pizza Hut. We have many more that we can discuss under NDA. Why NDA? These clients have found DivvyCloud to part of their strategic competitive advantage.

