Cloud Security
Is Cloud Computing Secure?
Asking the right questions
Feb. 17, 2011 07:00 AM
Obviously, the answer is it depends … on your security needs … on what you are comparing it with … on which cloud offering you are looking at.
Therefore, instead of providing a one word “Yes” or “No” answer let me ask you a set of questions that will help you answer the question for yourself. These questions will help you in identifying, for your given context, if the cloud application that you are evaluating is more or less secure compared to status quo or the alternatives that you are considering. The important point is to decide what threats are more significant than others and what can become a show stopper. In short:
- What am I comparing?
- What threats are relevant and I need to consider seriously?
- Are there any show stoppers?
- Do I have the necessary facts?
- Is lack of knowledge clouding my perception?

The Questions
Q1. What are you comparing it with…?
- …in-premise infrastructure
- …data centre owned and managed by you
- …data centre owned by you but managed by third party
- …data centre hosted on a third party infrastructure but managed by you
- …data centre hosted on a third party infrastructure but managed by somebody else
Q2. What cloud services are you looking at…? (Here is a detailed discussion)
- …virtual machine instances (IaaS) like Amazon AWS or Rackspace Cloud Servers
- …cloud platform (PaaS) like Google GAE or Microsoft Azure
- …hosted Email like Gmail
- …hosted CRM like Salesforce.com
- …hosted ERP like SAP Business By Design
- …office suit in the cloud like Google Apps
- …any other
Q3. Which of the generic security threats do you consider very important? Threats that…
- …attempt to steal sensitive information
- …comes from inside, from disgruntled employee
- …exploit existing software bugs and vulnerabilities with the intent of crashing a system
- …are intended to overwhelm critical system resources such as CPU and RAM
- …convert compromised computers into a network of bot-nets in order to mount additional attacks
Q4. Is there any cloud specific security threat that needs to be considered? Threats like…
- …software bug leading to accidental exposure of information to other parties sharing the resources
- …sensitive data retrieved and leaked out from released resources
- …insecure interface and API exposed by the cloud provider
- …losing control over their ability to ensure strong authentication at the user level
Q5. Do you need to comply with any government regulation like…?
- …HIPAA
- …SOX
- …PCI
- …Data location restriction
- …others
You can see from this Google Trends chart how cloud security concerns are growing.

Read the original blog entry...
About Udayan BanerjeeUdayan Banerjee is CTO at NIIT Technologies Ltd, an IT industry veteran with more than 30 years' experience. He blogs at
http://setandbma.wordpress.com.
The blog focuses on emerging technologies like cloud computing, mobile computing, social media aka web 2.0 etc. It also contains stuff about agile methodology and trends in architecture. It is a world view seen through the lens of a software service provider based out of Bangalore and serving clients across the world.
The focus is mostly on...
- Keep the hype out and project a realistic picture
- Uncover trends not very apparent
- Draw conclusion from real life experience
- Point out fallacy & discrepancy when I see them
- Talk about trends which I find interesting
Google