Cloud Security: Ten Questions to Ask Before You Jump In

From regulations to liability, CA cloud security expert Tim Brown outlines the key security issues you should explore while preparing for a cloud deployment.

By Tim Brown, Chief Security Architect, CA
Tue, January 26, 2010

CIO

The hype around cloud computing would make you think mass adoption will happen tomorrow. But recent studies by a number of sources have shown that security is the biggest barrier to cloud adoption. The reality is cloud computing is simply another step in technology evolution following the path of mainframe, client server and Web applications, all of which had — and still have — their own security issues.

Cloud Computing Definitions and Solutions

Security concerns did not stop those technologies from being deployed and they will not stop the adoption of cloud applications that solve real business needs. To secure the cloud, it needs to be treated as the next evolution in technology not a revolution that requires broad based changes to your security model. Security policies and procedures need to be adapted to include cloud models in order to prepare for the adoption of cloud-based services. Like other technologies, we're seeing early adopters take the lead and instill confidence in the cloud model by deploying private clouds or by experimenting with less-critical information in public clouds.

Defining Cloud Security: Six Perspectives
Cloud Security: Danger (and Opportunity) Ahead

Organizations are asking many questions and weighing the pros and cons of utilizing cloud solutions. Security, availability and management all need to be considered. As part of that process, here are 10 security-related questions organizations should consider to help them determine if a cloud deployment is right for them, and if so, which cloud model — private, public or hybrid.

1. How does a cloud deployment change my risk profile?
A cloud computing deployment — whether private or public — means you are no longer in complete control of the environment, the data, or the people. A change in control creates a change in risk — sometimes an increase in risk and in some cases a decrease in risk. Some cloud applications give you full transparency, advanced reporting, and integration with your existing systems. This can help lower your risk. Other cloud applications may be unable to modify their security profiles, they may not fit with your existing security measures, and may increase your risk. Ultimately the data and its sensitivity level will dictate what type of cloud is used or if a cloud model makes sense at all.

2. What do I need to do to ensure my existing security policy accommodates the cloud model?
A shift to a cloud paradigm is an opportunity to improve your overall security posture and your security policies. Early adopters of cloud applications will have influence and can help drive the security models implemented by the cloud providers. You should not create a new security policy for the cloud, but instead extend you existing security policies to accommodate this additional platform. To modify your policies for cloud, you need to consider similar factors: where the data is stored, how the data is protected, who has access to the data, compliance with regulations, and service level agreements.

Continue Reading

Whether your data center is large or small, it faces a similar set of roadblocks to efficiency, uptime, and ROI. This white paper reveals the six most common and intractable problems facing the data center and explains how to rectify them while improving efficiency and uptime.
In an IDC White Paper sponsored by HP, IDC covers how cloud computing is one of the prevailing IT trends today and how HP is helping organizations address this trend. By providing greater levels of provisioning and automation, cloud computing can help organizations become more nimble, reduce operating costs, improve application performance, and efficiently allocate their compute resources.
To understand infrastructure and operations (I&O) perceptions of converged infrastructure (CI), Forrester Consulting surveyed 200 I&O decision-makers from six different countries. Decision-makers were asked about their expectations of benefits and barriers to implementation of CI and those who have implemented CI were questioned on their actual experiences. This white paper reveals the results of this study and explains why Forrester believes that CI should be considered for any major infrastructure refresh or net new investment.
Public Platform as a Service (PaaS), for a variety of reasons, is not accessible to a majority of enterprise IT use cases. PaaS, however, provides significant value ranging from the automation of typically mundane and long running tasks such as application deployment, to providing a foundational architecture for guest application scalability. The ability to deploy a PaaS within your enterprise IT infrastructure, a "private PaaS", allows for your enterprise developers to access PaaS value without the accessibility problems of public PaaS. Find out more, and download the whitepaper today!
As you know, everything is mobile, connected, interactive, and immediate. This is exactly why organizations need a highly agile IT infrastructure in order to keep pace with extreme fluctuations in business demand. This book will help you understand why infrastructure convergence has been widely accepted as the optimal approach for simplifying and accelerating your IT to deliver services at the speed of business while also shifting significantly more IT resources from operations to innovation.
This solution brief will help you understand the benefits of the HP CloudSystem Matrix which provides a unified solotion for physical and virtual environments that's perfectly suited as an IT consolidation platform.
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and enterprise campus network infrastructures for the Cloud, and identify ways to better allocate network resources, reduce operating costs and improve application performance.
VMware recently announced VMware vFabric™ Data Director, a new database deployment and operations platform that enables enterprise IT organizations to offer database as a private cloud service. Built on top of VMware vSphere 5, vFabric Data Director enables IT organizations to ontrol database sprawl through automation and consistent policy enforcement and accelerate application development cycles with self-service database management. Attend this webcast to learn how vFabric Data Director can help you build database-as-a-service in your datacenter.
InfoWorld contributing editor and consultant David Linthicum offers expert advice about choosing services to outsource to the public cloud providers, cloud data security and identity, integrating public cloud services, and how to avoid provider lock-in.
In this exclusive Virtual Briefing Center session from Microsoft and IDG, you'll discover how deploying Windows 7 Enterprise now will help you take advantage of this new environment. Learn through a series of videos, audio webinars and rich downloadable resources how to power today's flexible workstyles with Windows 7 Enterprise.
Cloud deployments are playing a critical role in propelling innovation for many companies. At the same time security has become the #1 one of the top concerns for IT and business leaders as they migrate into the cloud. In this webinar, learn from Accenture discusses how to recast the cloud as a "fresh chance to rethink your approach to security."
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Sponsored Links

Eliminate storage boundaries with HP.View the on-demand webinar to learn more

HP Enterprise Security recognized as leader in Gartner's DAST Magic Quadrant - get it now!

Push the limits of virtualization with HP. Get the tech dossiers and learn how you can put an end to runaway virtual sprawl.

Splunk translates machine data into "aha" moments for IT and the business.

Evolving Your Data Center for the Cloud

Get Ethernet speeds from 1 Mbps to 10 Gbps - Comcast Business Class

Gain cutting-edge insights at MIT in 2-5 day executive programs.

Converge your infrastructure with HP. Access a valuable case study in the CI Resource Center now.

Redefine Software support with HP

Click to see how Accenture has delivered high performance to clients

Learn how Accenture helps clients become high-performing businesses.

Join the Conversation. Follow Oracle EPM & BI on Twitter Today.

Check Point Trusted by the Global 100

BlackBerry® Mobile Fusion. Different mobile devices. One platform.

It's time to Be Bold. See what's new at BlackBerry World 2012.

Customized information views & Twitter events at New Fulcrum Point

ShoreTel UC cuts costs like no other. Mobilize your business today.

E-book: Discover Business-Ready Storage Systems For Oracle Environments

Managed Hosting Buyer's Guide - Benefits to key considerations

Discover how integration of operations mgmt and service mgmt enhances productivity.

Converge your infrastructure with HP. Access white papers, case studies, videos and more.

High performance. Delivered. Click to see Accenture's client successes

See how Accenture helps clients perform at the highest levels

Compare risk and TCO in single and multivendor networks on Feb 23.

Connect with global CIOs now at Enterprise CIO Forum

Resource Center