infoTECH Feature

March 14, 2012

Security Watch: Cloud is No Less Secure Than a Dedicated Environment

Without a doubt, one of the biggest obstacles toward widespread adoption of cloud computing is the issue of security. Cloud has opened up several IT strategy considerations for businesses, with security top of mind for chief information officers as they evaluate the potential benefits of shifting to the cloud.

The way in which CIOs think about cloud security needs to transform in order to be able to adequately address the technology, layers of security, transparency and auditability – and defend against potential attacks, according to Chris Hinkley, network and systems security engineer at FireHost.

There is no evidence that specifically proves the cloud is any more or less secure than a dedicated environment.

“It’s more about giving up control of our assets and data (and not controlling the associated risk) than any technology specific to the cloud,” according to the 2011 Data Breach Investigations Report, a study conducted by the Verizon (News - Alert) RISK Team, which Hinkley cites in this blog post.

“Depending on your goals, there are essentially two key ingredients for true security in the cloud,” wrote Hinkley. “The first and most important is separation. This is absolutely essential – not only should your data be segregated from other tenants on the infrastructure, your network traffic, virtual machines and even security policies should be separate.”

Transparency is also imperative in allowing CIOs to keep tabs on their cloud-hosting provider.  

“Being able to see behind the curtain should allow you to see exactly how your environment is being protected. Not only does it give you peace of mind, but it’s required to perform regulatory compliance audits,” said Hinkley.

Over the past year, there has been an increase in cloud security awareness and bringing cloud security into workforce management. The Cloud Security Alliance recently announced initiatives such as examining ways to better secure mobile devices through cloud computing, looking at ways to drive more security innovation, and a push into the Asia-Pacific region, TMCnet reported.

According to the CSA, the open market has produced inadequate information security for cloud computing. Security solutions have been developed by an inefficient system of investors that are more interested in developing technologies that manage the problems enterprises face, not actually solve them. The group hopes to identify key structural issues related to trust and security that inhibit the adoption of next-generation information technology.




Edited by Tammy Wolf
FOLLOW US

Subscribe to InfoTECH Spotlight eNews

InfoTECH Spotlight eNews delivers the latest news impacting technology in the IT industry each week. Sign up to receive FREE breaking news today!
FREE eNewsletter

infoTECH Whitepapers