Comments
Matt McLarty wrote: For more info... Follow me on Twitter See our website
Cloud Computing
Conference & Expo
November 2-4, 2009 NYC
Register Today and SAVE !..

2008 West
DIAMOND SPONSOR:
Data Direct
SOA, WOA and Cloud Computing: The New Frontier for Data Services
PLATINUM SPONSORS:
Red Hat
The Opening of Virtualization
GOLD SPONSORS:
Appsense
User Environment Management – The Third Layer of the Desktop
Cordys
Cloud Computing for Business Agility
EMC
CMIS: A Multi-Vendor Proposal for a Service-Based Content Management Interoperability Standard
Freedom OSS
Practical SOA” Max Yankelevich
Intel
Architecting an Enterprise Service Router (ESR) – A Cost-Effective Way to Scale SOA Across the Enterprise
Sensedia
Return on Assests: Bringing Visibility to your SOA Strategy
Symantec
Managing Hybrid Endpoint Environments
VMWare
Game-Changing Technology for Enterprise Clouds and Applications
Click For 2008 West
Event Webcasts

2008 West
PLATINUM SPONSORS:
Appcelerator
Get ‘Rich’ Quick: Rapid Prototyping for RIA with ZERO Server Code
Keynote Systems
Designing for and Managing Performance in the New Frontier of Rich Internet Applications
GOLD SPONSORS:
ICEsoft
How Can AJAX Improve Homeland Security?
Isomorphic
Beyond Widgets: What a RIA Platform Should Offer
Oracle
REAs: Rich Enterprise Applications
Click For 2008 Event Webcasts
In many cases, the end of the year gives you time to step back and take stock of the last 12 months. This is when many of us take a hard look at what worked and what did not, complete performance reviews, and formulate plans for the coming year. For me, it is all of those things plus a time when I u...
SYS-CON.TV
Good Governance Controls Risk in the Cloud
Adopting cloud computing can save money, but good governance is essential to manage the risk

Cloud computing provides organizations with an alternative way of obtaining IT services and offers many benefits including increased flexibility and cost reduction. However, many organizations are reluctant to adopt the cloud because of concerns over information security and a loss of control over the way IT service is delivered. These fears have been exacerbated by recent events reported in the press including outages by Amazon[1] and the three day loss of BlackBerry services from RIM[2]. What approach can an organization take to ensure that the benefits of the cloud outweigh the risks?

To understand the risks involved it's important to understand that the cloud is not a single model. The cloud covers a wide spectrum of services and delivery models ranging from in-house virtual servers to software accessed by multiple organizations over the Internet. A clear explanation of this range is described by NIST[3]. This document describes the five essential characteristics that define the cloud, the three service models, and the four deployment models. The risks of the cloud depend on both the service model and the delivery model adopted.

When moving to the cloud it's important that the business requirements for the move are understood and that the cloud service selected meets these needs. Taking a good governance approach, such as COBIT[4], is the key to safely embracing the cloud and the benefits that it provides:

  • Identify the business requirements for the cloud-based solution. This seems obvious but many organizations are using the cloud without knowing it.
  • Determine the cloud service needs based on the business requirements. Some applications will be more business-critical than others.
  • Develop scenarios to understand the security threats and weaknesses. Use these to determine the response to these risks in terms of requirements for controls and questions to be answered. Considering these risks may lead to the conclusion that the risk of moving to the cloud is too high.
  • Understand what the accreditations and audit reports offered by the cloud provider mean and actually cover.

The risks associated with cloud computing depend on both the service model and the delivery model adopted. The common security concerns are ensuring the confidentiality, integrity, and availability of the services and data delivered through the cloud environment. Particular issues that need attention when adopting the cloud include ensuring compliance and avoiding lock-in.

To manage risk, an organization moving to the cloud should make a risk assessment using one of the several methodologies available. An independent risk assessment of cloud computing[5] was undertaken by ENISA (the European Network Information and Security Agency). This identifies 35 risks that are classified according to their probability and their impact. When the risks important to your organization have been identified, these lead to the questions you need to ask the cloud provider. I propose the following top 10 questions:

  1. How is legal and regulatory compliance assured?
  2. Where will my data be geographically located?
  3. How securely is my data handled?
  4. How is service availability assured?
  5. How is identity and access managed?
  6. How is my data protected against privileged user abuse?
  7. What levels of isolation are supported?
  8. How are the systems protected against Internet threats?
  9. How are activities monitored and logged?
  10. What certification does your service have?

The cloud service provider may respond to these questions with reports from auditors and certifications. It's important to understand what these reports cover.

There are two common types of report that are offered: SOC 1 and SOC 2. SOC stands for "Service Organization Controls" and the reports are based on the auditing standard SSAE[6] no. 16 (Statement on Standards for Attestation Engagements which became effective in June 2011):

  • SOC 1 report: Provides the auditor's opinion on whether or not the description of the service is fair (it does exist) and whether or not the controls are appropriate. Appropriate controls could achieve their objectives if they were operating effectively.
  • SOC 2 Report: It's similar to a type 1 report but includes further information on whether or not the controls were actually working effectively. It includes how the auditor tested the effectiveness of the controls and the results of these test.

Note that these reports are based on the statement of the service that the organization claims to provide - they are not an assessment against best practice.

A service organization may also provide an auditor's report based on established criteria such as Trust Services (including WebTrust and SysTrust). The Trust Services Principles and Criteria[7] were established by the AICPA and cover security, availability, processing integrity, privacy, and confidentiality. A typical auditor's report[8] on a cloud service will simply refer to which of the five areas are covered by the report and it's up to the customer to evaluate whether the Trust Principle and criteria are appropriate for their needs. In addition ISACA have recently published a set of IT Control Objectives for Cloud Computing[9].

Cloud computing can reduce costs by providing alternative models for the procurement and delivery of IT services. However, organizations need to consider the risks involved in a move to the cloud. The information security risks associated with cloud computing depend on both the service model and the delivery model adopted. The common security concerns of a cloud computing approach are maintaining the confidentiality, integrity, and availability of data. The best approach to managing risk in the cloud is one of good IT governance covering both cloud and internal IT services.

References

  1. PCWorld
  2. http://www.bbc.co.uk/news/technology-15287072
  3. http://csrc.nist.gov/publications/nistpubs/800-145/SP800-145.pdf
  4. http://www.isaca.org/cobit
  5. http://www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing-risk-assessment
  6. http://ssae16.com/
  7. http://www.webtrust.org/principles-and-criteria/item27818.pdf
  8. https://trust.salesforce.com/trust/assets/pdf/Misc_SysTrust.pdf
  9. http://www.isaca.org
About Mike Small
Mike Small is a Fellow of the BCS and a Senior Analyst at KuppingerCole and a member of the London Chapter of ISACA. Until 2009, Small worked for CA where he developed CA’s identity and access management product strategy. He is a frequent speaker at IT security events around EMEA.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

SOA World Latest Stories
Facebook sold off again Tuesday scrapping the bottom at $30.98 after Reuters reported that Scott Devitt, a research analyst at the IPO’s lead underwriter Morgan Stanley, unexpectedly cut his revenue estimates on the company during the roadshow leading up to it going public last Friday....
As a Silver Sponsor of Cloud Expo New York, CloudPassage is offering special passes to SYS-CON's 10th International Cloud Expo, which will take place on June 11–14, 2012, at the Javits Center in New York City, New York. CloudPassage is the leading cloud server security provider, and c...
Private clouds solve many problems for enterprises and bring unique operational challenges along with them. There are dozens of companies of all sizes that will build you a private cloud and turn over the keys – then what? Trying to convert a traditional enterprise IT operations team t...
Cloud computing is becoming an integral part of every enterprise IT environment. With multiple cloud deployment models to choose from, understanding the essential components to any cloud solution will help ensure your success. In his session at the 10th International Cloud Expo, Ores...
The International Trade Commission’s six-member board of commissioners has issued an import ban against Motorola Mobility’s Android gear that the agency’s administrative law judge found in December infringes Microsoft’s patent on “generating meeting requests and group scheduling from a...
As a Platinum Sponsor of Cloud Expo New York, Intel is offering special passes to SYS-CON's 10th International Cloud Expo, which will take place on June 11–14, 2012, at the Javits Center in New York City, New York. Intel is a world leader in computing innovation. The company designs a...
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021


SYS-CON Featured Whitepapers
ADS BY GOOGLE