Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cloud
    • Cloud
    • IT Management
    • Networking
    • Storage

    Is Cloud Computing Secure? Prove It

    Written by

    Wayne Rash
    Published September 16, 2009
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The buzz around cloud computing is intense, but that buzz rarely addresses the question of whether cloud computing is safe-or whether you can prove that it’s safe.

      “Is cloud computing ready for prime time?” asked Amy DeCarlo, principal analyst for managed IT services at Current Analysis. “I would say no. There’s not a lot of transparency; there’s not a lot of confidence.”

      And, even if your data really is secure in the cloud, you may not be able to prove it, said DeCarlo.

      “[Public cloud providers] don’t have the pieces to meet the regulatory requirements; they don’t have the means to meet the compliance issues related to security,” she said. “That’s not to say there won’t be a time, or that cloud service providers can’t provide something useful to the enterprise.”

      The issue, according to DeCarlo, is that cloud providers don’t meet current compliance rules. What’s more, some of those providers, such as Amazon.com, have said that they don’t intend to meet those rules and that they won’t allow compliance auditors on-site. This pretty much eliminates any chance of using public cloud providers for anything that must meet any of the government regulations involving protected data either in the United States or the European Union.

      And it gets more complex.

      “Any client using the public cloud that collects personally identifiable information is subject to the regulations of each state where they are,” explained IBM Director of Corporate Security Strategy Kris Lovejoy. This means that every place in which the data may reside, or through which the data must pass, can regulate how the data is protected. “How can you ask a company to respond to the requirements of every state, not to mention cross-border situations?” asked Lovejoy.

      The use of the public cloud also implies the use of virtualization to move data and compute requirements to the place that’s cheapest and/or most suitable. You have no good way of knowing where your data is, how it’s protected, or what other data and processing are going on in the same infrastructure. In fact, your provider probably doesn’t know, and neither does your auditor.

      So, what can you do?

      Right now, the public cloud is probably out of the question for any data that’s subject to government or industry compliance rules. But that doesn’t mean you can’t use the public cloud. “There are a lot of use cases for testing, development, beta testing and overflow for applications that don’t require compliance,” said Lori MacVittie, technical marketing manager for F5 Networks. “Workflows, data entry that’s not covered by compliance-things covered by best practices. There are plenty of applications that can go in the cloud.”

      Applications that work well in the cloud typically have security designed into them from the beginning.

      “Web apps have moved very well to the cloud,” said Scott Morrison, chief architect and vice president of engineering at Layer 7 Technologies. “The important thing is that you have to take lessons from good service-oriented architecture and good Web architecture. You have to put security into the architecture. You have to make applications secure; then they can move to the cloud.”

      Morrison adds that it’s up to each enterprise to figure out what can be moved to the cloud. “Every application is different, and every application has something that will determine whether they can run in the cloud,” he explained. “You need to do an inventory. The cloud is shared, and you don’t have the physical demarcation between applications. A lot of security comes down to rigorous ideas that systems have physical boundaries. You can’t do that if you don’t own the whole show.”

      Private Clouds

      Private Clouds

      One way to balance security with the efficiency of the cloud is to deploy a private cloud. A private cloud is similar to the public cloud, except that it resides behind a corporate firewall to ensure that security and compliance needs are met. The Department of Defense, said Level 7’s Morrison, uses one of the largest private clouds in the world.

      Of course, before you can make a decision on whether to use the public cloud, a private cloud or no cloud at all, you have to know what you have and how it needs to be secured.

      “Do people really know what their requirements are?” asked Dan Kusnetzky, vice president of research operations for The 451 Group. “Have they looked at the regulations and the implications on the ground for their data center?”

      No matter where your data goes, said Kusnetzky, security can’t be taken for granted.

      “Security is not a product that can be purchased,” he said. “It’s a way of life, an implementation of the proper architecture, and the proper selection of tools, programs and procedures. No product that I know of is either secure or insecure. The same is true of the cloud computing environment.”

      More to Come

      Right now, it’s unlikely that you can move your most critical information to the public cloud. However, that could soon change.

      “I think the horse is out of the barn,” said Current Analysis’ DeCarlo. “This is something that’s going to go forward. We’ll see some stumbling. We’ve seen this with Google outages and Amazon. We’ve seen plenty of issues there already. But the concept is so appealing, there’s no reason this won’t take off. But I don’t think every application will be there or mission-critical applications will ever be there.”

      Industry experts say providers will have to move quickly to satisfy customers’ pent-up desire for cloud computing options-and security.

      “Hospitals are dying to put their data in the cloud,” said Joel Smith, CTO of AppRiver, a provider of systems for cloud computing. “There needs to be some sort of meet-in-the-middle agreement. They’re going to have to have providers who will allow auditors to visit the data center. Or the regulation folks will have to make some subset of rules for specific regulations.”

      Kusnetzky suggests that companies will start with small steps toward the cloud. “There will be people who might take some ancillary operations of their systems and try them out,” he said.

      Lovejoy thinks that, ultimately, cloud providers that want business from large companies will have no choice but to offer secure, compliant systems: “We’re going to be evolving to the point where cloud providers aren’t going to say, -I’m not going to do it.’ They’ll have to do it.”

      Contributing Analyst Wayne Rash can be reached at wayne.rash@ziffdavisenterprise.com.

      Wayne Rash
      Wayne Rash
      https://www.eweek.com/author/wayne-rash/
      Wayne Rash is a content writer and editor with a 35-year history covering technology. He’s a frequent speaker on business, technology issues and enterprise computing. He is the author of five books, including his most recent, "Politics on the Nets." Rash is a former Executive Editor of eWEEK and a former analyst in the eWEEK Test Center. He was also an analyst in the InfoWorld Test Center and editor of InternetWeek. He's a retired naval officer, a former principal at American Management Systems and a long-time columnist for Byte Magazine.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×