The Macrosite for News, Analysis and Opinion about the Future of the Internet
DISCUSS   PRINT   Digg   Del.icio.us   Reddit   Email This   TWEET THIS

Cloud Security

Cloud Standards Are a Work in Progress
11/7/2009 1 comment
no ratings
1 saves

There’s general agreement that standards are needed for cloud computing – so much agreement, in fact, that at least eight different groups have stepped up and are trying to fill the void.

As the range of groups involved suggests, the work has just begun, including on standards related to security. “It will be about two years before a comprehensive set of standards for cloud computing will be available,” predicts Qualys's Puhlmann.

One challenge is that companies just don’t have a long-enough history with cloud computing to create firm standards, or they work with only one or two cloud vendors so it’s difficult to generalize from their experiences. “A lot of work still has to be done before the industry understands where the security holes will come from with cloud computing,” says Paul Simmonds of the Jericho Forum.

AREAS OF EMPHASIS
Jericho Forum and Cloud Security Alliance cite 14 areas that need standards:
  • Application security
  • Business continuity and disaster recovery
  • Compliance and audit
  • Data center operations management
  • E-discovery
  • Encryption and key management
  • Governance and enterprise risk management
  • Identity and access management
  • Incident response, notification, and remediation
  • Information life-cycle management
  • Physical security
  • Portability and interoperability
  • Storage
  • Virtualization

In May, the Jericho Forum said it would work with the vendor-led Cloud Security Alliance , to promote best security practices for the cloud. Jericho Forum members include AstraZeneca, Boeing, BP, Eli Lilly, and KLM, as well as IT vendors such as IBM, Qualys, Hewlett-Packard Co. (NYSE: HPQ), Motorola Inc. (NYSE: MOT), and Symantec Corp. (Nasdaq: SYMC).

The two groups are driving development of standards in a wide range of areas including audit, applications, cryptography, governance, network security, risk management, storage, and virtualization.

There are at least six other groups working on cloud computing standards: the Open Cloud Manifesto, the Cloud Computing Interoperability Forum, CloudCamp, the Cloud Computing Use Cases Group, the Distributed Management Task Force, and the Object Management Group.

At the Jericho Forum and Cloud Security Alliance, step one is identifying the differences between on-premises security and cloud security, and examining what existing standards mesh with cloud operations.

Eventually, they expect to drive standards that let companies securely integrate different vendors’ cloud computing services and be assured that their information is safe in the cloud. Says Puhlmann, “If we find existing standards that work for cloud security, we will use them.”

— Paul Korzeniowski

Next Page: All the Flavors of Cloud Computing

Channel:
Tags:
DISCUSS   PRINT   Digg   Del.icio.us   Reddit   Email This
< Previous Page 6 of 8 Next >
Current display:       newest comments first       display in chronological order
rjacksix
IQ Crew
Tuesday November 10, 2009 6:11:39 PM
no ratings

I fail to see how the issues around cloud security are any less (or more for that matter) than the concerns of outsourcing any aspect of IT.  Perhaps it's the name.  "Cloud" really doesn't sound stable does it?  And yet Amazon, Google and even Microsoft have far more experience in keeping their infrastructures running, and secure, than most other organizations, especially SMB's.

What is the hang up?  Granted, I think any organization should walk before they run into this arena, but we've been outsourcing computing resources and storing data on computers of such companies for years.  Certainly you have to make sure that the outsourcing company is reputable and that they have resonable hiring and security practices.   But who is more capable of doing this right, an organziation with the size and experience of Google or Amazon, or even a 200 person SMB (or 14,000 user state government for that matter)?

I'd put my money on the Google (who, if it isn't obvious by now, I do not think of as evil) Amazon or any other large well funded well managed IT innovation company.

I would be cautious about putting my data on Cloud-R-Us (can you say Internet bubble?) but I don't have any reservations about moving to the cloud, or the security of it.

The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
a moderated blogosphere of internet experts
Dan Cypra
Dan Cypra   11/20/2009   3 comments
A picture is worth a thousand words, or so the old saying goes. So understanding how to use images in e-newsletters effectively is quite important. Here are a few tips to ensure that your images in email newsletters work to your advantage.
Gordon Haff
Gordon Haff   11/20/2009   1 comment
Arms merchant or army? That's a fundamental question for vendors in the cloud computing space. Do they just sell their tooling to any and all comers, who then become the actual purveyors of hosted infrastructure, developer platforms, and software? Or do they offer their own cloud-based services, perhaps even keeping much of their technology in-house for competitive advantage?
Mary E. Shacklett
With the value of toxic assets on the rise, large U.S. and European banks face many challenges on the road to recovery. Sharing key information may help these firms effectively track the way forward.
Matthew Fraser
Matthew Fraser   11/19/2009   5 comments
Most of us go through life knowing that we’re expected to learn from our mistakes and improve. Those who are more conscientious about learning and personal improvement usually reap greater rewards.
Mike Moran
Mike Moran   11/19/2009   12 comments
Marketers are known for exaggerated claims and stretching the truth just a wee bit. But most marketers I know truly believe in what they sell. Their aggressiveness is based on a confidence that what they are promoting truly benefits the customer.
IETV: the thinkerNet on film
5
of
2pm EST
Tue
Dec 1st
an IBM information resource
sponsored content
big blue blog
Todd Watson
Todd Watson   11/20/2009   Post a comment
While Google introduces its new Chrome OS (which I'm hearing will be widely available in one year?  Did I mishear that?), IBM announced 10 new products today to help companies using IBM System z mainframe technology.
white papers & case studies
an IBM information resource
sponsored content
Smarter Collaboration: How to Thrive in a Challenging Business Environment
Market conditions are changing faster than ever, and organizations need to improve their agility and adaptability in order to provide better service and improve processes. The ability to work with customers, business partners, and employees as effectively as possible - while at the same time holding down costs - is a key to success.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Copyright © 2009 United Business Media Limited - All rights reserved.      About Us  |  Privacy Policy and Terms of Use  |  Contact Us
CMP Media LLC
Internet Evolution – not for thickies
what.the.ferraro
Facebook Lacks Social Skills

11|20|09   |   1:53   |   1 comment


Facebook's 'Suggestions' for users demonstrate how little social networking sites understand about true social relationships.
Singer at C-Level
Smart Grid Opportunities

11|20|09   |   2:49   |   No comments


Industry initiatives and government stimulus funds are giving enterprise software vendors a great opportunity to help build out and manage smart grid technologies.
Tom Nolle
Total Telephony Transcends Telepresence

11|20|09   |   2:11   |   2 comments


The problem with telepresence is that it's not universally accepted, because video calling isn't. While we can all do video calling, we also apparently worry too much about how we look. If we want HD telepresence in our future, we have to dress down, mess up our hair, and dive into our online life.
what.the.ferraro
ThinkerNet Wins Min's Award for Best Blogs!

11|19|09   |   1:13   |   4 comments


ThinkerNet wins the Min's award for 'Best Blogs' – Internet Evolution's fifth award this year!
Full Nelson
SanFran.gov

11|19|09   |   8:51   |   No comments


Fritz has an exclusive talk with the mayor and CTO of San Francisco about that city's latest e-government efforts.
Robert D. Atkinson
America Has Much to Learn About Digital Piracy

11|18|09   |   2:09   |   No comments


The US loses about $20 billion a year on pirated software, movies, and music. But public policy can help stem the tide of digital theft. For example, France has recently passed a 'three strikes and you’re out' law, whereby if after two warning letters an individual continues to download pirated software then his Internet access will be cut off. US policy makers should consider adopting similar policies.
Singer at C-Level
Connecting Stakeholders: Part 3

Part 3 of 3   |  
See complete series
11|18|09   |   2:09   |   No comments


Financial management planning does not need to include Voodoo economics, but it does help to tap into the knowledge base of your team through some sort of real-time system. We explore your options.
Reiter's Block
Tweeting for Customer Support

11|18|09   |   2:20   |   No comments


When Reiter gets incensed over incompetent Verizon FiOS order-taking and support, he broadcasts it via Twitter. Did it do any good? How should your company offer Twitter support? Watch this for all the answers.
what.the.ferraro
Dogster.com More Popular Than Gov 2.0

11|17|09   |   2:05   |   1 comment


A lot of attention is being paid to launching Gov 2.0 Websites, but these sites aren't attracting a lot of visitors.
Reiter's Block
Is the BlackBerry 9700 'Bold' Enough?

11|17|09   |   3:07   |   4 comments


The successor to the BlackBerry Bold 9000 – the Bold 9700 – will be available soon in the US. Is it worth upgrading? Reiter's got one, and offers advice.
TechWeb The Global Leader In Technology Media