This page was machine-translated and may differ from the original. View original

'Secret Sprawl' Phenomenon Frequent…Security and Management Solutions Necessary

Google 우선 소스Published2022.07.07 09:33
HashiCorp, "Vault Provides Vendor-Agnostic Secret Management Solution"

As development environments in the IT industry increasingly shift toward software-centric approaches, distributed environments through multi-cloud are becoming common. In the process of operating development organizations, security management becomes complex and security data is not properly managed, sometimes resulting in large-scale data breaches.

HashiCorp held a press briefing on the 6th to introduce ways to flexibly and securely operate increasingly diverse Korean enterprise infrastructure.

HashiCorp, which provides infrastructure automation software for multi and hybrid cloud environments, identified five essential elements for successfully adopting new cloud technologies in enterprise business. These are: workflow standardization, infrastructure integrated management, security strengthening from the development stage, automation, and cost optimization. To achieve this, HashiCorp supports a vendor-agnostic cloud operating model through Terraform, VaultTM, Consul, and NomadTM.

At the press briefing, Kim Jung-hun, Senior Executive Vice President of Technology, said, "As the Korean IT environment has shifted from hardware-centric to software-centric, static traditional data centers have transformed into dynamic self-service-based modernized data centers. As the paradigm of the entire IT organization changes, we are contemplating 'vendor-agnostic' infrastructure operating methods, and Vault supports vendor-agnostic secret management," he explained.
▲Eight representative methods to utilize Vault (Source - HashiCorp)

The 'secrets' mentioned here refer to important information that functions as a key to unlock protected resources or sensitive information such as passwords, certificates, tokens, SSH keys, and API keys. Over the past 10 years, 20 enterprises have experienced large-scale data breaches exceeding approximately 1 billion won, and it was explained that 90% of them are already using Vault for secret management.

HashiCorp Vault is a solution that sets effective secret policies based on who accesses where and how, and provides automation for a more effective authentication environment. Vault manages trillions of sensitive data annually, demonstrates annual downloads exceeding 160 million, and is also a solution in use by the top 20 banks in the United States.

Vault's secret issuance process is similar to a hotel's card key issuance process. Assuming the hotel reception is Vault, to enter a hotel room, identity verification through identification cards or passports is first performed. Vault similarly authenticates each user centrally according to policies and grants permissions. Once authentication is complete, a card key is used to enter the room, but access is permitted only temporarily. Vault similarly allows tokens and policies to be used temporarily, issuing secrets that only approved targets can access according to policies. Ultimately, by allowing only authorized users to access targets such as cloud, databases, and servers, security vulnerabilities are minimized.

As infrastructure diversifies, the phenomenon where secret information is scattered in many places is called 'secret sprawl,' and in such environments, secrets can be easily leaked, becoming a security vulnerability. With Vault, instead of users knowing actual secrets or entering them into systems (applications), all secrets can be centrally stored in Vault and issued effectively.

Additionally, users are issued dynamic secrets that change periodically, and systems can have APIs registered to obtain secret information from Vault.

Vault is provided in two models: a data center installation Enterprise version and a cloud SaaS-based HCP (HashiCorp Cloud Platform) model. Recently, multi-factor authentication (MFA) for Vault, which was previously available only in the Vault Enterprise version, extended zero-trust security implementation to HCP Vault.

Kim Jong-deok, Country Manager for Korea, said, "We are progressing through mainframe, virtualization, private cloud, and public cloud toward 'multi-cloud,'" and added, "All industries are actively leveraging the advantages of multiple clouds to create new customer experiences, and Korean enterprises are already enhancing customer experience through innovation."
To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.
명세환 기자
명세환 Reporter