CSA Official Press Release
Published 02/16/2022
New Cloud Security Alliance Report Highlights Factors to Consider When Designing Blockchain Solutions That Operate Within Critical Sectors
Paper provides insights into the three layers of distributed ledger technology and how they interact with enterprise security services to deliver specific security outcomes
SEATTLE – Feb. 16, 2022 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today released the Blockchain/Distributed Ledger Technology (DLT) Risk and Security Considerations report. Drafted by the CSA Blockchain/Distributed Ledger Working Group, the report encourages stakeholders to take a holistic view of blockchain/DLT network security by providing a reference security architecture to guide stakeholders' thinking around the why, what, and how aspects of Hyperledger Fabric security.
The paper explains the three layers of blockchain security (conceptual, component interaction, and technology) and their interaction with on-premises and cloud IT environments of organizations in critical sectors. It addresses both the value of security controls in terms of controlling an organization’s exposure to operational risk, but also how the security measures can enable organizations to exploit business opportunities.
“There is no shortage of guidance on how to design, configure, and deploy Hyperledger Fabric, but too few documents take a systematic approach to Fabric security that recognizes that durable security always starts with requirements,” said Dr. Frederick Wamala, the paper’s lead author. “Configuration-led fabric guidance, for instance, rarely explains why high assurance security controls are needed to obtain authorization to operate blockchain solutions in critical sectors. We wanted to close the information gap by highlighting the steps that should be considered when designing these types of blockchain solutions.”
The document offers guidance in helping:
- Business and government leaders understand the true risk balance of using blockchain and the resultant security, financial, regulatory, reputational, business, and consumer risks
- Chief Information Security Officers and enterprise security architects assess the risk of introducing DLT components into a corporate network while maintaining compliance
- Regulators and internal risk managers evaluate the potential risks associated with financial crime, consumer exposure, and espionage and devise appropriate policies in response
- Individuals gain high-level knowledge about blockchain security and reduce their exposure to fraudulent activity and unsuitable products
The Blockchain/Distributed Ledger Working Group works to produce useful content to educate different industries on blockchain and its proper use, as well as define blockchain security and compliance requirements based upon different industries and use cases. Individuals interested in becoming involved in Blockchain/Distributed Ledger future research and initiatives are invited to join the working group.
Download the full Blockchain/Distributed Ledger Technology (DLT) Risk and Security Considerations report.
About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, training, certification, events, and products. CSA's activities, knowledge, and extensive network benefit the entire community impacted by cloud — from providers and customers to governments, entrepreneurs, and the assurance industry — and provide a forum through which different parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.
About Cloud Security Alliance
The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, follow us on Twitter @cloudsa.
For press inquiries, email Zenobia Godschalk of ZAG Communications or reach her by phone at 650.269.8315.