BLOG
Security in the M&E Landscape (ISO 27017)
Cyber Security

Date

By Julián Fernández-Campón, CTO TEDIAL

In today’s rapidly evolving digital landscape, cybersecurity resilience underscores the critical importance of adapting and fortifying your organization’s defenses against an array of cyber threats.

According to Google, “Cloud security is the set of cybersecurity measures used to protect cloud-based applications, data, and infrastructure. This includes applying security policies, practices, controls, and other technologies like identity and access management and data loss prevention tools to help secure cloud environments against unauthorized access, online attacks, and insider threats.”

AWS identifies security as one of the pillars of a well-architected framework, reinforcing a shared responsibility model. While AWS manages security of the cloud, the customer is responsible for security IN the cloud. This means that customers retain control over the security they implement to protect their content, platforms, applications, systems, and networks, just as they would in an on-site data center. The latest technology in building security is useless if you leave the windows open!

The M&E Landscape

Security encompasses many aspects and layers and can be viewed from different angles; it’s impossible to find a ‘one-size-fits-all’ solution. Managing media has several implications, one of which is securing unauthorized access to sensitive media and unreleased content. While access to a single asset might not be critical in other markets, in M&E, unauthorized access to certain images can result in losses amounting to hundreds of thousands of dollars.

This is why companies must pay special attention when dealing with media and ensure an infrastructure specifically designed for media management is implemented.

MovieLabs has defined the Common Security Architecture for Production (CSAP), a zero-trust architecture specifically designed for media creation. It is a zero-trust implementation similar to those used in non-media organizations, with additional functionality tailored for media production.

At TEDIAL, we align with this vision by implementing a zero-trust methodology governed by software-defined workflows and software-defined storage. This NoCode approach simplifies the application and propagation of security across all services and applications.

We address different security levels:

  • Assets: Data and metadata that are created, processed, and output.
  • Processes: Software services and user-interacting applications that process assets, including automated tasks.
  • Workflows: Orchestrated sets of processes acting on a set of assets.

smartWork, TEDIAL’s cloud native media integration platform (iPaaS), guarantees that media is protected and accessible only by explicit requests through tasks in a software defined workflow. Signed URLs provide access to media that is not exposed and is managed by smartWork | AST, abstracting the physical location of the file as a software defined storage.

Processes run in a secured environment, following best practices such as network segregation (public/private), middleware to expose only specific endpoints, firewalls, and cloud-specific services during deployment. Finally, software defined workflows managed by smartWork ensure media is not exposed until required as part of the process.

Backend services are secured with encrypted information to prevent malicious manipulation and unauthorized access to APIs.

Secure the Foundations

The best way to ensure security is to develop software with security embedded from the foundation. Whether deployed in the cloud, on-premises, or in hybrid environments, core services and applications must be secure to mitigate risks from attacks or breaches.

Security must be integrated into the entire development process, involving several aspects. Firstly, ensure the application follows best practices for software development. TEDIAL adheres to OWASP (Open Worldwide Application Security Project) standards, an online community that produces freely available articles, methodologies, documentation, tools, and technologies in IoT, system software, and web application security.

At TEDIAL, our secure software development approach includes:

  • Static code analysis to detect risks and ensure secure, quality software.
  • Keeping frameworks and libraries up to date to prevent vulnerabilities.
  • Scanning Docker images to ensure no vulnerabilities are present.

Certifications: Ensuring Commitment

There are vendors who say that their cloud applications are secure because public cloud providers meet all security standards, evading their own security responsibilities and compliances. This represents a serious risk for customers.

Even some people think certifications are merely for show, but they can be a robust way to follow best practices and implement necessary procedures. The International Organization for Standardization (ISO) is an independent, non-governmental organization with an international membership of 163 national standards bodies.

ISO/IEC 27017 provides guidelines for information security controls applicable to cloud services, offering additional implementation guidance for relevant controls specified in ISO/IEC 27001, as well as new cloud-specific controls.

Following our commitment to security, TEDIAL is one of the few companies with ISO/IEC 27017 certification. TEDIAL has also been certified in ISO/IEC 27001 since 2006 and holds certifications like ENS (National Security Schema) and GDPR (General Data Protection Regulation) in the EU.

Security is not a one-time task but a continuous process. To maintain a secure platform, controls, audit logs, alerts, and contingency plans must be defined and regularly reviewed to mitigate risks. Penetration testing is also crucial to detect vulnerabilities and keep the platform updated.

Conclusion

Security is essential for modern platforms and must be taken seriously from development through continuous implementation. It should be embedded within the platform and easy to configure. Following recommendations from market prescriptors like MovieLabs and other specialized organizations is the only way to ensure guaranteed security.

Strong cloud security at the center of an M&E organization enables digital transformation and innovation. To achieve this, it is essential to follow security standards to safeguard content in the cloud.

Although public cloud providers meet all security standards, it is the responsibility of the cloud application and services vendor to complement and obtain their own certifications, guaranteeing customers that their assets are well safeguarded.

Security
Share Post

More
articles