Comments
bruce.armstrong wrote: Somebody just said it better than I did, and with more chops to say it: Open Letter to Mark Zuckerberg, Sheryl Sandberg & Facebook Mobile
Cloud Expo on Google News


2008 West
DIAMOND SPONSOR:
Data Direct
SOA, WOA and Cloud Computing: The New Frontier for Data Services
PLATINUM SPONSORS:
Red Hat
The Opening of Virtualization
GOLD SPONSORS:
Appsense
User Environment Management – The Third Layer of the Desktop
Cordys
Cloud Computing for Business Agility
EMC
CMIS: A Multi-Vendor Proposal for a Service-Based Content Management Interoperability Standard
Freedom OSS
Practical SOA” Max Yankelevich
Intel
Architecting an Enterprise Service Router (ESR) – A Cost-Effective Way to Scale SOA Across the Enterprise
Sensedia
Return on Assests: Bringing Visibility to your SOA Strategy
Symantec
Managing Hybrid Endpoint Environments
VMWare
Game-Changing Technology for Enterprise Clouds and Applications
Click For 2008 West
Event Webcasts

2008 West
PLATINUM SPONSORS:
Appcelerator
Get ‘Rich’ Quick: Rapid Prototyping for RIA with ZERO Server Code
Keynote Systems
Designing for and Managing Performance in the New Frontier of Rich Internet Applications
GOLD SPONSORS:
ICEsoft
How Can AJAX Improve Homeland Security?
Isomorphic
Beyond Widgets: What a RIA Platform Should Offer
Oracle
REAs: Rich Enterprise Applications
Click For 2008 Event Webcasts
SYS-CON.TV
Top Links You Must Click On


Is Cloud Computing Secure?
Asking the right questions

Obviously, the answer is it depends … on your security needs … on what you are comparing it with … on which cloud offering you are looking at.

Therefore, instead of providing a one word “Yes” or “No” answer let me ask you a set of questions that will help you answer the question for yourself. These questions will help you in identifying, for your given context, if the cloud application that you are evaluating is more or less secure compared to status quo or the alternatives that you are considering. The important point is to decide what threats are more significant than others and what can become a show stopper. In short:

  • What am I comparing?
  • What threats are relevant and I need to consider seriously?
  • Are there any show stoppers?
  • Do I have the necessary facts?
  • Is lack of knowledge clouding my perception?

The Questions

Q1. What are you comparing it with…?

  1. …in-premise infrastructure
  2. …data centre owned and managed by you
  3. …data centre owned by you but managed by third party
  4. …data centre hosted on a third party infrastructure but managed by you
  5. …data centre hosted on a third party infrastructure but managed by somebody else

Q2. What cloud services are you looking at…? (Here is a detailed discussion)

  1. …virtual machine instances (IaaS) like Amazon AWS or Rackspace Cloud Servers
  2. …cloud platform (PaaS) like Google GAE or Microsoft Azure
  3. …hosted Email like Gmail
  4. …hosted CRM like Salesforce.com
  5. …hosted ERP like SAP Business By Design
  6. …office suit in the cloud like Google Apps
  7. …any other

Q3. Which of the generic security threats do you consider very important? Threats that…

  1. …attempt to steal sensitive information
  2. …comes from inside, from disgruntled employee
  3. …exploit existing software bugs and vulnerabilities with the intent of crashing a system
  4. …are intended to overwhelm critical system resources such as CPU and RAM
  5. …convert compromised computers into a network of bot-nets in order to mount additional attacks

Q4. Is there any cloud specific security threat that needs to be considered? Threats like…

  1. …software bug leading to accidental exposure of information to other parties sharing the resources
  2. …sensitive data retrieved and leaked out from released resources
  3. …insecure interface and API exposed by the cloud provider
  4. …losing control over their ability to ensure strong authentication at the user level

Q5. Do you need to comply with any government regulation like…?

  1. …HIPAA
  2. …SOX
  3. …PCI
  4. …Data location restriction
  5. …others

You can see from this Google Trends chart how cloud security concerns are growing.

Read the original blog entry...

About Udayan Banerjee
Udayan Banerjee is CTO at NIIT Technologies Ltd, an IT industry veteran with more than 30 years' experience. He blogs at http://setandbma.wordpress.com.
The blog focuses on emerging technologies like cloud computing, mobile computing, social media aka web 2.0 etc. It also contains stuff about agile methodology and trends in architecture. It is a world view seen through the lens of a software service provider based out of Bangalore and serving clients across the world. The focus is mostly on...
  • Keep the hype out and project a realistic picture
  • Uncover trends not very apparent
  • Draw conclusion from real life experience
  • Point out fallacy & discrepancy when I see them
  • Talk about trends which I find interesting
Google

Enterprise Open Source Magazine Latest Stories . . .
In this CTO Power Panel at the 10th International Cloud Expo, moderated by Cloud Expo Conference Chair Jeremy Geelan, industry-leading CTOs & VPs of Technology will discuss such topics as: Which do you think is the most important cloud computing standard still to tackle? Who should...
Private clouds solve many problems for enterprises and bring unique operational challenges along with them. There are dozens of companies of all sizes that will build you a private cloud and turn over the keys – then what? Trying to convert a traditional enterprise IT operations team t...
The networking industry has gone through different waves over last 30+ years. In the ’80s, the first wave was all about connecting and sharing; how to connect a computer to other peripheral devices and other computers. There were many players who developed technology and services to ad...
The impact of Big Data is extremely broad for business, information management and technology. Being able to analyze your growing mountain of data can give you a distinct competitive advantage, but Big Data can be more than traditional tools can handle. In his session at the 10th Int...
Cloud computing is creating the new Wall Street boom, according to NIA. The only industry that is as bright as cloud computing on Wall Street is social networking, NIA said in a recent report. 2012 will be known as the year cloud computing became widely adopted worldwide. Cloud comput...
If your organization already uses virtualized infrastructure, you are well on your way to providing IT as a Service. But as businesses demand faster results in today’s competitive market, organizations look to gain more benefits from cloud computing than just virtualized infrastructure...
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021


SYS-CON Featured Whitepapers
ADS BY GOOGLE