infoTECH Feature

May 14, 2012

Organizations Must Weigh Risks Before Moving to the Cloud

While much is being written about the potential security risks involved with cloud computing, organizations need to increase their awareness of the conceivable hazards involved before adopting the cloud, according to insurance brokerage Marsh.

The New York City-based broker has launched its Cloud Risk Framework, which outlines a five-stage process that helps businesses evaluate the risks and the potential financial impact of any change in risk profile involved in a shift to the cloud.

A comprehensive risk assessment must be the starting point for the debate concerning the adoption of cloud technology, according to Fredrik Motzfeldt, leader of Marsh’s communications, media and technology practice in EMEA.

“Moving information technology services to the cloud presents a conundrum to many businesses,” said Motzfeldt. “Although it promises greater financial efficiency and productivity, the cloud brings an increased dependence on technology infrastructures housed outside an organization’s immediate control.”

The Cloud Risk Framework is the result of a year-long collaboration by the Cloud Risk Forum, a Marsh-led group of international legal, insurance, risk and technology experts.

The Cloud Risk Framework’s five-stage process is comprised of the following steps:

  • Identify key categories of risk for IT services clients.
  • Categorize potential types of loss and costs typically linked to IT service failure.
  • Quantify areas of financial impact.
  • Allocate the cost of a risk event between the customer and cloud provider.
  • Determine the likelihood of a risk event occurring

“The ability to adopt cloud computing models that reduce complexity should bring competitive advantages,” added Motzfeldt. “A structured and simplified approach to assessing the risks of moving to the cloud, as evidenced by the Cloud Risk Framework, is a vital first step to achieving this goal.”

The way in which CIOs think about cloud security needs to transform in order to be able to adequately address the technology, layers of security, transparency and auditability – and defend against potential attacks, according to Chris Hinkley, network and systems security engineer at FireHost.

There is no evidence that specifically proves the cloud is any more or less secure than a dedicated environment, TMCnet recently reported.

“It’s more about giving up control of our assets and data (and not controlling the associated risk) than any technology specific to the cloud,” according to the 2011 Data Breach Investigations Report, a study conducted by the Verizon (News - Alert) RISK Team, which Hinkley cited in this blog post.

“Depending on your goals, there are essentially two key ingredients for true security in the cloud,” wrote Hinkley. “The first and most important is separation. This is absolutely essential – not only should your data be segregated from other tenants on the infrastructure, your network traffic, virtual machines and even security policies should be separate.”




Edited by Braden Becker
FOLLOW US

Subscribe to InfoTECH Spotlight eNews

InfoTECH Spotlight eNews delivers the latest news impacting technology in the IT industry each week. Sign up to receive FREE breaking news today!
FREE eNewsletter

infoTECH Whitepapers