EU Security Agency Highlights Cloud Computing Risks

Cloud computing users face problems including loss of control over data, difficulties proving compliance, and additional legal risks as data moves from one legal jurisdiction to another, according to a assessement of cloud computing risks from the European Network and Information Security Agency (ENISA).

By Mikael Ricknäs
Fri, November 20, 2009

IDG News Service — Cloud computing users face problems including loss of control over data, difficulties proving compliance, and additional legal risks as data moves from one legal jurisdiction to another, according to a assessement of cloud computing risks from the European Network and Information Security Agency (ENISA).

The agency highlighted those problems as having the most serious consequences and being among the most likely for companies using cloud computing services, according to ENISA.

ENISA examined the assets that companies put at risk when they turn to cloud computing, including customer data and their own reputation; the vulnerabilities that exist in cloud computing systems; the risks to which those vulnerabilities expose businesses, and the probabilities that those risks will occur.

When moving to cloud-based computing services, companies have to hand over control to the cloud provider on a number of issues, which may affect security negatively. For example, the provider's terms of use may not allow port scans, vulnerability assessment and penetration testing. At the same time, service level agreements (SLAs) may not include those services. The result is a gap in defenses, ENISA said in the report.

Compliance could also prove to be a big problem if the provider can't offer the right levels of certification or the certification scheme hasn't been adapted for cloud services, the report said.

One of the advantages of cloud services is that data can be stored in multiple locations, which could save the day in the event of an incident in one of the data centers. However, it could also be a big risk if the data centers are located in countries with a shaky legal system, according to the report.

Other areas of concern are vendor lock-in, failure of mechanisms separating different companies, management interfaces that get accessed by hackers, data not deleted properly and malicious insiders.

To minimize these risks the report proposes a list of questions that a company needs to ask potential cloud providers. For example, what guarantees does the provider offer that customer resources are fully isolated, what security education program does it run for staff, what measures are taken to ensure third-party service levels are met, and so on.

In the end a good contract can lessen the risks, according to the report. Companies should especially pay attention to their rights and obligations related to data transfers, access to data by law enforcement and notifications of breaches in security, it said.

ENISA's report isn't all doom and gloom, though. Using cloud computing services can result in more robust, scalable and cost-effective defenses against certain kinds of attack, according to the report. For example, the ability to dynamically allocate resources could provide better protection against DDoS (distributed denial-of-service) attacks, ENISA said.

Europe Network and Information Security Agency

Get up to speed on mobile security.

Learn More »
Loading...
Most Recent Security Stories
This whitepaper by Marc Staimer, Dragon Slayer Consulting, reviews urgent issues facing organizations such as the inability to recover and restore data when required and mounting financial and legal risks. It also covers an on-demand approach that instantly and cost-effectively solves these issues.
Managing the security and availability of email is complex. This paper will discuss the wide variety of challenges associated with email security and availability and illustrate how integral email is to the operations of any organization.
Based on a survey of 273 IT managers, we reveal the top ten web threats to business and outline a solution that uses MessageLabs Security Safeguard.
Online spam campaigns have become more sophisticated and precisely targeted. Spammers routinely disseminate millions of fraudulent emails which sap bandwidth and productivity. Learn how a hosted anti-spam service provides multi-layered protection against spam, improves employee productivity and lowers costs.
Users are increasing influencing IT security decisions, according to new research from IDG Research Services, and IT is somewhat ill-prepared to embrace this trend. Workers are flocking to mobile devices and are becoming increasing vocal about the types of devices they want to use in the corporate world.
Discover how Citrix Delivery Center provides an efficient and secure architecture for virtual workforce success.
Enterprises are adopting cloud technologies for speed to market, business flexibility and cost control. But serious questions still abound on the security vulnerabilities of cloud deployment. Midsized to large enterprises face entirely different issues than smaller companies when considering cloud technology.
This virtual meeting for IT managers and CIOs is based on a new IBM study. Senior Vice Presidents and a Chief Technology Officer provide guidance on business resiliency, security and cloud computing. What steps should you take to achieve a more pro-active, comprehensive approach to risk management?
With almost everything now connected through the Internet, organizations become more vulnerable to cyber intrusion. As a result, cyber security is a senior management issue, not just a technical problem. Join Accenture and Forrester to explore the current global cyber security situation and learn how your organization can adopt a proactive cyber security approach.
The economic downtown has forced many companies to rethink the way they approach IT. CIOs are increasingly being asked how they can drive competitive advantage through technology. Many organizations have recognized that workforce mobility and collaboration are important drivers of increased productivity. These forces are creating a new challenge: the need for dynamic security.

In this webcast, Phil Go, CIO of Barton Malow, discusses how this leading national construction firm is tackling these issues, along with the technology he is adopting to ensure mobile security.
Learn how RSA, the Security Division of EMC helps companies create the intersection of IT operations and Security o...
Moderated by CSO Publisher, Bob Bragdon, hear from this esteemed panel as they share practical approaches to simpli...
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Resource Center