Forrester: Need for scrutiny heightened in cloud security

May 12, 2009, 08:30 AM —  Network World — 

The security gaps in cloud computing demand greater scrutiny than traditional IT outsourcing models, a new Forrester report says.

With traditional outsourcing models, a customer places its own servers in someone else's data center, or a service provider manages devices dedicated to that customer. But multi-tenancy rules the day in cloud computing, and customers may not know where their data is stored or how it's replicated, Forrester analyst Chenxi Wang writes in a report titled "How secure is your cloud?

"Cloud computing decouples data from infrastructure and obscures low-level operational details, such as where your data is and how it's replicated," Wang writes. "Multi-tenancy, while it is rarely used in traditional IT outsourcing, is almost a given in cloud computing services. These differences give rise to a unique set of security and privacy issues that not only impact your risk management practices, but have also stimulated a fresh evaluation of legal issues in areas such as compliance, auditing, and eDiscovery."

The rise of software-as-a-service, http://www.networkworld.com/topics/saas.html along with Web-based platforms for building applications and hosting server or storage capacity have many industry watchers examining the benefits and pitfalls of cloud computing.

Wang notes that the Electronic Privacy Information Center recently filed a complaint against Google with the U.S. Federal Trade Commission, alleging that its security and privacy controls are inadequate.

Wang quotes Boeing chief security architect Steve Whitlock as saying: "Like many others, we see huge potential and benefits for moving into 'the cloud,' but we see risks, security issues, and interoperability issues. The community has much work to do to make the cloud a safe place to collaborate." Whitlock is also on the board of the Jericho Forum, an industry group that examines the erosion of the network perimeter. While securing applications and data in the cloud is difficult because of the lack of visibility and control, customers must make the effort to evaluate vendors' security and privacy practices, Wang says.

"Companies must consider these aspects: data protection, identity management, vulnerability management, physical and personnel security, application security, incident response, and privacy measures," she writes.

For example, customers should seek information about the vendor's encryption system; how the vendor protects data at rest and in motion; the vendor's documentation available to auditors; authentication and access control procedures; and whether the vendor has proper data segregation and data leak prevention measures.

There are still numerous questions to be worked out regarding not just security in the cloud but also liability. To avoid pitfalls, customers need service-level agreements that specify a set of "detailed liability conditions and consequences," Wang writes.

"The fact that the laws do not treat data in the cloud the same as data on-premise leads to complicated liability discussions," she writes.

Network World

Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world

I like it!
Close

On Twitter now

cloud computing

Powered by Twitter
You are logged in | Sign out
Sign in and post to Twitter

What are you thinking?

Cancel Tweet sent

On Twitter now

Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
peer-to-peer

Esther Schindler
If the comments are ugly, the code is ugly

claird
SVG a graphics format for 21st century

pasmith
Take Chrome OS for a test spin

Sandra Henry-Stocker
Solaris Tip: Have Your Files Changed Since Installation?

sjvn
64-bits of protection?

jfruh
Android fragments vs. the iPhone monolith

mikelgan
What Gizmodo missed about the Pro WX Wireless USB disk drive

 

Where Google Chrome security fails: the password
I heard mention that the Chrome OS will have some sort of encryption available a la bitlocker. If it's possible to encrypt personal data using another password or key, then it may have potential for very secure data.... And Ubuntu has an 'encrypt home directory' option, perhaps google should follow suit.
- Dann

Join the conversation here

The Daily Tip

The Daily TipQuick, practical advice for IT pros. Made fresh daily.

Hot tips:

Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.

Newsletters

Subscribe to ITWORLD TODAY and receive the latest IT news and analysis.

I would like to receive offers via email from ITworld partners.
By clicking submit you agree to the terms and conditions outlined in ITworld's privacy policy.
Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

Marketplace