The Macrosite for News, Analysis and Opinion about the Future of the Internet
DISCUSS   PRINT   Digg   Del.icio.us   Reddit   Email This   TWEET THIS

Cloud Security

Introduction
11/7/2009 Post a comment
no ratings

Before the Los Angeles City Council gave Google (Nasdaq: GOOG) a $7.25 million contract to provide email as an online service for the city’s 30,000 employees, it put Google through the wringer over information security.

The Los Angeles Police Department and the city attorney’s office were concerned that any confidential information in email messages might be exposed if it were stored in the cloud, meaning on Google’s servers instead of the city’s own data center. The City Council echoed a concern heard in business boardrooms around the country as they consider cloud computing: “Security was one of the leading issues,” says Eduardo Hewitt, legislative deputy for City Councilman Tony Cardenas.

To win over the council, Google had to meet a laundry list of special security provisions, including:

  • Fingerprinting all employees working on the project for Google and Computer Sciences Corp., which will set up and manage the service for Los Angeles
  • Encrypting data in transit
  • “Sharding” the data at rest, with pieces stored on separate drives, so someone needs an application and encryption key to put the pieces into a readable format
  • Storing all of Los Angeles’s data within the United States
  • Limiting access to the data to Google and CSC employees who meet the city’s clearance requirements

Google also is offering minimum damage payments for various mishaps, including a confidentiality breach, faults in the network resulting from the actions of Google or CSC, or the personal injury of a city employee or contractor caused by Google or CSC. The amount of the damages payable in such instances is still being worked out, says Kevin Crawford, LA’s assistant general manager of IT.

Why did the city need such measures, some of which exceed enterprise cloud computing deployments? “It was because of the newness of the product for the public sector,” says Crawford. Various city agencies and constituents simply weren’t convinced of the safety of cloud computing, so they demanded the additional stipulations. But Crawford says the city didn’t pay extra for them, and in fact negotiated discounts off Google’s list prices. “We’re still getting 40 percent off retail,” he says.

Jitters over the security of cloud computing, including concerns about its “newness,” are by no means limited to the government sector. When InformationWeek Analytics asked 547 business technology pros what worries them about cloud computing, security concerns grabbed the top three spots, far outpacing issues of performance, disaster recovery, or vendor lock-in:

Cloud computing is getting considered because companies and government agencies are keenly interested in the lower licensing and staff support costs that cloud services promise. Faster deployment also works in cloud computing’s favor. Yet security plays the foil to cost savings, and for many companies, security concerns end up sinking any move to the cloud.

Gartner Inc. predicts companies will spend about $10 billion this year on two types of cloud computing: infrastructure as a service, where companies buy raw computing power as needed, and software as a service, where they pay a subscription for online access to software, ranging from email to CRM to business intelligence.

While companies can subscribe to an ever-widening array of cloud services, IT departments don’t have the same long history that they do with on-premises software, so they aren’t as confident of where pain points such as security flaws may be. What new intrusion points are introduced? How can a company be sure that its data sitting in the vendor’s data center is safe? When should information be encrypted? In our survey, 57 percent cited “security defects in the technology itself” as a top concern with cloud computing, more than any other concern.

Standards and best practices for cloud security are just emerging. “Security is and always should be a top consideration when companies are examining cloud services,” says Steve Cakebread, former president and chief strategy officer at Salesforce.com, who’s now on the board of eHealth, an online health insurance reseller, and Solarwinds, a network management vendor.

To understand potential security risks, companies must complete a thorough examination of a cloud service – beginning with the networking layer, checking out the provider’s operations, and working up to the cloud application.

While there isn’t the same kind of well established, best-practices security checklist for cloud computing that there is for on-premises IT systems, here’s one concept to bank on: It’s still the user organization, meaning the IT teams that contract for cloud computing, that will be held responsible for the security of the data and apps they put in the cloud. “In the end, regulators will come after our IT department, not the cloud service provider, if security problems arise with our data,” says Ash Patel, global CIO at Aon Consulting, one of three business units within Aon Corp., a $7.4 billion-a-year insurance consulting and service provider.

Table of contents:

— Paul Korzeniowski is a freelance writer who has been dissecting technology and business issues for two decades.

— Mary Jander, ThinkerNet Editor, Internet Evolution

Next Page: Lower Costs, Simpler Operations

Channel:
Tags:
DISCUSS   PRINT   Digg   Del.icio.us   Reddit   Email This
Page 1 of 8 Next >
Current display:       newest comments first       display in chronological order
Be the first to post a comment regarding this story.
The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
a moderated blogosphere of internet experts
Mary E. Shacklett
Does the Internet threaten relationship-building and families by compromising the quality and quantity of communications?
Alan Reiter
Alan Reiter   11/6/2009   19 comments
When government officials talk about information “transparency,” they don't mean augmented reality (AR). But AR will play a major role in enhancing government transparency, although it won't be welcomed by many officials.
Dan Cypra
Dan Cypra   11/5/2009   8 comments
You can’t judge a book by its cover, unless you’re the recipient of an email newsletter, in which case hitting the “Delete” button can be done with ease. Having an effective layout is essential to increasing the open and click-through rates of your mailer. Let’s take a look at a few basics of e-newsletter layout.
Ross M. Greenberg
Setting up a corporate Website is truly a juggling act: One tries to balance corporate needs with the ever-changing needs and desires of the seemingly random Webpage visitor. Something that worked perfectly yesterday doesn’t work or is out of fashion today.
IETV: the thinkerNet on film
5
of
2pm EST
Tue
Dec 1st
an IBM information resource
sponsored content
an IBM information resource
sponsored content
Smarter Collaboration: How to Thrive in a Challenging Business Environment
Market conditions are changing faster than ever, and organizations need to improve their agility and adaptability in order to provide better service and improve processes. The ability to work with customers, business partners, and employees as effectively as possible - while at the same time holding down costs - is a key to success.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Copyright © 2009 United Business Media Limited - All rights reserved.      About Us  |  Privacy Policy and Terms of Use  |  Contact Us
CMP Media LLC
Internet Evolution – not for thickies
Augmented Reality Meets Government Transparency
Alan Reiter
When government officials talk about information “
transparency,” they don't mean augmented reality (AR). But AR will play a major role in enhancing government transparency, although it won't be welcomed by many officials.

CLICK FOR MORE
Jart Armin
Methods From the Dark Side: RFI Attacks

11|6|09   |   2:22   |   No comments


Exploring methods from the 'Dark Side' of the Internet – in this case 'Remote File Inclusion.'
John Soat
Internet Anonymity: A Gray Area

11|6|09   |   2:45   |   2 comments


Is there such a thing as complete anonymity on the Internet? It is something of a philosophical question, but the consensus among experts seems to be 'No.' However, there are degrees of anonymity, which might be more practical for most people – and more necessary than ever before.
Steve Saunders' Outernet
The New Information Divide: Part 3

Part 3 of 3   |  
See complete series
11|6|09   |   1:46   |   No comments


A digital content market is emerging. Only two things are known about it: the first is that at some point the Internet will primarily become a paid network. The second known factor is that there are innumerable variables in the digital content market that have yet to be worked out. It’s not known, for example, exactly how users will pay for content (micropayments, subscriptions, bartering of farm animals, other).
what.the.ferraro
Developers Take Google to Task

11|5|09   |   1:53   |   1 comment


The Google backlash continues. After seeing their Project 10^100 submissions disappear into the bowels of a Google server farm, a group of irate developers has started their own site to re-collect and vote on the ideas.
Tom Nolle
Net Neutrality & UFOs

11|5|09   |   2:20   |   2 comments


The government secrets of UFOs are hidden in Area 51, so where are the secrets of net neutrality hidden, Area 52? Nope, they're hidden in Paragraph 148 – and they're a lot more substantive than UFOs!
Steven Peterson
iPhone App Makes Sense of Public Transport

11|5|09   |   1:19   |   No comments


Routesy is an iPhone application that uses the phone’s GPS to let the user know where and when the next train or bus is coming. The application’s developer, Steven Peterson, talks about why a mobile application makes sense, especially given that this transportation information is already available on the Web.
Singer at C-Level
Connecting Stakeholders: Part 2

Part 2 of 3   |  
See complete series
11|4|09   |   2:22   |   No comments


Executives from all backgrounds are modifying their best practices to connect stakeholders to all points of their businesses. In this section, we will explore how the supply chain industry is changing with the times.
Reiter's Block
Slobbering Over the N900

11|4|09   |   2:41   |   9 comments


Techies have been going crazy over the pending release of Nokia's N900 cellular phone, which incorporates a newly revised touch-screen operating system. Reiter's got one. Is the craziness justified?
Steve Saunders' Outernet
The New Information Divide: Part 2

Part 2 of 3   |  
See complete series
11|4|09   |   2:19   |   4 comments


Bad news! By eliminating the world’s digital divide we’re likely to create a new divide: the information divide, where we end up creating a two-tier Internet where access to 'quality' content is controlled and charged for by mega-corporations, and the gulf between information haves and have-nots is entirely dependent on how much money they have. This is, of course, an almost exact inversion of the current situation on the Internet – where access is expensive and content is free.
The Incredible Hultquist
Web 2.0 – Just Being There Isn't Enough

11|3|09   |   2:15   |   4 comments


As enterprises leap into the Web 2.0 world of blogging, commenting, and social networking, just 'being there' won't deliver ROI. You may want a 'Web Evangelist' to systematically harvest the feedback in order to polish your product or service.
TechWeb The Global Leader In Technology Media