When it comes to cloud platforms, there are many elements to a good security posture, grouped into the broad categories of technology, process, and people. These areas need to be thought about hard and carefully by the most senior architects, IT leaders, and senior executives at a modern company. Let’s face it, security is critical to any company, and must be treated in a thoughtful and earnest manner, not as a checkbox on an RFP or something to be accomplished as cheaply as possible.
Let’s now talk about each of these broad categories in turn.
Technology aspects of security includes hardening servers, tightly constraining firewalls, having file integrity checks, and intrusion monitoring. But it doesn't just mean "protecting the perimeter." Good security means locking down internal attack surfaces so that if someone does get into an internal network, they still can't easily compromise systems or access information.
To effectively protect the telecom network and sensitive customer data, a key process is the operations of a 24x7 Security Operations Centre with AI-based monitoring on syslogs, net flows, system access, and other system events. Such systems are known in the industry as “SIEM”, and can be built and operated internally or outsourced, but regardless represent a foundational aspect of security. Processes also must consist of solid and documented change management, periodic scanning and penetration testing, keeping operating systems and networking devices current with vendor security patches, and comprehensive reviews and audits.
But proper telecom company security also means "people" by designing an architecture that differentiates roles, permits the most possible work to be done with the least amount of access, and allows a company to closely vet, restrict, and monitor those that access sensitive data and systems. It also means frequently training staff on proper security practices and simplifying and automating as many maintenance and administrative activities as possible, reducing the need for human access to critical systems and the concomitant opportunity for human error, the weak link in many security breaches.
Lastly, end-to-end encryption of communication paths, combined with disciplined and stringent management of cryptographic keys, remains the most reliable way to protect communications while in transit and at rest.
Data privacy is a closely related topic. Data privacy requires good security but also encompasses issues surrounding where data is stored, how it is tracked, whether it can be obfuscated, redacted, or removed; and for what purposes the data can be used. Various data standards such as HIPAA for U.S. healthcare and GDPR, CCPA, and NY Shield all spell out the legal requirements for those managing patient and/or consumer data.




