Obtén el informe: Como lograr alinear a CIOs y CEOs en la era de la IA

cerrar
cerrar
Su red del mañana
Su red del mañana
Planifique su camino hacia una red más rápida, más segura y más resistente diseñada para las aplicaciones y los usuarios a los que da soporte.
Descubra Netskope
Ponte manos a la obra con la plataforma Netskope
Esta es su oportunidad de experimentar de primera mano la Netskope One plataforma de una sola nube. Regístrese para participar en laboratorios prácticos a su propio ritmo, únase a nosotros para una demostración mensual del producto en vivo, realice una prueba de manejo gratuita de Netskope Private Accesso únase a nosotros para talleres en vivo dirigidos por instructores.
Líder en SSE. Ahora es líder en SASE de un solo proveedor.
Netskope ha sido reconocido como Líder con mayor visión tanto en plataformas SSE como SASE
2X líder en el Cuadrante Mágico de Gartner® para SASE Plataforma
Una plataforma unificada creada para tu viaje
Protección de la IA generativa para principiantes
Protección de la IA generativa para principiantes
Descubra cómo su organización puede equilibrar el potencial innovador de la IA generativa con sólidas prácticas de seguridad de Datos.
Prevención de pérdida de datos (DLP) moderna para dummies eBook
Prevención moderna de pérdida de datos (DLP) para Dummies
Obtenga consejos y trucos para la transición a una DLP entregada en la nube.
Libro SD-WAN moderno para principiantes de SASE
SD-WAN moderna para maniquíes SASE
Deje de ponerse al día con su arquitectura de red
Entendiendo dónde está el riesgo
Advanced Analytics transforma la forma en que los equipos de operaciones de seguridad aplican los conocimientos basados en datos para implementar una mejor política. Con Advanced Analytics, puede identificar tendencias, concentrarse en las áreas de preocupación y usar los datos para tomar medidas.
Soporte técnico Netskope
Soporte técnico Netskope
Nuestros ingenieros de soporte cualificados ubicados en todo el mundo y con distintos ámbitos de conocimiento sobre seguridad en la nube, redes, virtualización, entrega de contenidos y desarrollo de software, garantizan una asistencia técnica de calidad en todo momento
Vídeo de Netskope
Netskope Training
La formación de Netskope le ayudará a convertirse en un experto en seguridad en la nube. Estamos aquí para ayudarle a proteger su proceso de transformación digital y aprovechar al máximo sus aplicaciones cloud, web y privadas.

Activities in the Cloud, and What They Mean

Nov 05 2015
Tags
Cloud Best Practices
Cloud Security
Netskope Cloud Report
Tools and Tips

Each quarter we report on aggregated, anonymized findings such as top used apps, top activities, and top policy violations from across our customers using the Netskope Active Platform.

While this season’s report highlights industry usage, especially data violations in industries like healthcare and retail, an important area we dug into was activities. Unlike perimeter solutions that articulate activity in cloud services in “gets” and “posts” and measure them in bytes up or down, we can tell the actual activity, like “share,” “upload,” “create,” “post,” “edit,” “download,” “approve,” and so on. Because we normalize these activities, we can see usage in aggregate, for example, all “shares” whether they’re in Cloud Storage, CRM, Business Intelligence, or Finance apps. This gives our customers a sense for where the non-compliant or risky activities are likely to be, what constitutes real data movement (versus just a chatty app), and potential data exposure, as well as enables our customers to know where to set granular, activity-level policies that address real risk (versus taking a coarse-grained, allow-or-block approach).

With that in mind, here are some activity-level aggregate findings (and my attempt at interpreting them!) that, when put into the context of their cloud app categories, are unexpected or at least put risk into stark relief. Here goes…

We start with Cloud Storage (apps like Dropbox, Box, Microsoft 365, and Google Workspace):

  • “Share” is the most common activity
  • For every “login,” there are four “shares”
  • For every “upload,” there are two “downloads”

Why do we care about “downloads” and “shares?” These are activities associated with data leakage and exposure. When IT doesn’t always have visibility into what apps are in use, much less what content is housed in them, data-exposing activities take on new meaning. Is that file that’s being shared a photo or a non-public draft of your quarterly earnings release?

Another category we looked at is HR (apps like SuccessFactors, Workday, Taleo, and Cornerstone OnDemand):

  • “Download” is the fourth most common activity
  • There are nearly as many “downloads” as “uploads”
  • “Share” is a top-ten activity

Why do we care about “downloads” in HR? Unlike apps that we hear a lot about, such as Dropbox and Evernote, HR apps are often not on IT’s radar. This means organizations often don’t know the extent of HR apps in their environment, who’s administering them, and whether the apps have proper access and data controls in place. With this lack of visibility as a backdrop, “download” of information can signal a policy violation and potentially exposure of sensitive employee information. What if the downloader is not in HR? What if they’re a former HR director who left the company two weeks ago?

Finally, we looked at Business Intelligence apps (apps like Qualtrics, Birst, or Tableau):

  • “Share” is the most common activity
  • For every data “upload,” there are two “shares”
  • There are as many “downloads” as there are “views”

Why do we care about “shares” in Business Intelligence apps? These apps often house confidential corporate information such as line-of-business performance metrics. While many such apps will have controls in place that prevent inadvertent sharing outside of the company, sometimes it is possible to share with unauthorized individuals within the company.

In short, activities can say a lot about the nature of the app, how and whether people are deriving value from it, and how risky it may be in an organization. Activities can signal out-of-compliant behaviors and, when taken with other data, such as our compromised account intelligence, can indicate external threats. Activities are essential!

Which combination of apps and activities are you most interested in?

Conéctese con Netskope

Subscribe to the Netskope Blog

Sign up to receive a roundup of the latest Netskope content delivered directly in your inbox every month.