This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Improving Data Lake Security

Download resources

About this session

Ron Bennatan of Imperva explains why data lakes, especially those assembled from cloud services, are hard to secure and what a workable programme looks like. Using a redacted customer architecture on AWS (S3 at the core, Athena, EMR, Redshift, RDS, plus Snowflake and on-premises Hadoop), he shows how every optimisation copies or transforms data into a new store with its own security language, so controls do not follow the data and entitlements become impossible to reason about. Security teams can no longer dictate platforms, so controls must be universal across on-premises and every cloud. He orders the work: automated, continuous discovery of assets through cloud APIs; AI-driven classification into a master catalogue that makes data-subject access requests routine; long retention of audit data, cheaply tiered on cloud storage; machine-learning baselines of who touches what, so a data scientist behaving differently stands out; automated response playbooks that change security groups or repository settings; scheduled posture checks against CIS and STIG benchmarks under the shared-responsibility model; and finally a single entitlement view with just-in-time, least-privilege access provisioned for a bounded period.

Data lakes are a strategy for data storage that has received a lot of hype of late. The term has been used to describe any storage repository that holds a vast amount of raw data in its native format until it is needed. Ron can explain why
security, compliance and privacy are the biggest "threats" to
everyone's Data Lake projects and how leaders are addressing these needs. He can speak to the fact that the hardest challenges today for big data projects, data lakes and especially data lakes o the cloud are good security controls, addressing privacy and compliance requirements etc., what to do about it, and what are the world's best organizations doing in the field.  

Key takeaways

  • Automate discovery through the cloud provider's APIs and rerun it on a schedule; any process that relies on teams documenting new stores or instances will fail within months.
  • Build an AI-driven classification catalogue first; it is what turns data-subject access and deletion requests from a crisis into a routine lookup.
  • Apply the same controls everywhere data lands, on-premises and in every cloud, because copies, aggregates and transforms inherit the sensitivity of their source.
  • Retain audit and access data for the 13 months to three years regulations demand, tiering it on cheap storage, and use that history to baseline behaviour per constituency.
  • Replace static access rules with a single entitlement view and just-in-time, least-privilege grants scoped to a task and a time window.

Speakers

Ron Bennatan
Ron Bennatan
SVP & GM, Data Security · Impreva
Ron joined Imperva through the acquisition of jSonar where he served as CTO and co-founder. He has been a “data security guy” for 25 years and has worked at companies such as J.P. Morgan, Merrill Lynch, Intel, IBM and AT&T Bell Labs. He was… Read moreRead less

Ron joined Imperva through the acquisition of jSonar where he served as CTO and co-founder. He has been a “data security guy” for 25 years and has worked at companies such as J.P. Morgan, Merrill Lynch, Intel, IBM and AT&T Bell Labs. He was co-founder and CTO at Guardium which was acquired by IBM where he later served as a Distinguished Engineer and the CTO for Data Security and Governance. He has a Ph.D. in Computer Science and has authored 11 technical books. Previous Speaking Experience: Ron has spoken at the Nashville Cybersecurity Summit; Brightalk Virtual fireside chat: The state of data security; and CyberSummit USA.

Resources

Tags

More from GoSec 2021

Also from Ron Bennatan

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.