Welcome!

Cloud Expo Authors: Michael Meiner, Carmen Gonzalez, Elizabeth White, Liz McMillan, Pat Romanski

Related Topics: Virtualization, Cloud Expo, Security

Virtualization: Article

A New Approach to Cloud Computing Security

Arguably the greatest barrier to businesses taking full advantage of cloud computing is the issue of security

Security Pavillion at Cloud Expo

Arguably the greatest barrier to businesses taking full advantage of cloud computing is the issue of security. Recent high-profile breaches of the cloud (the attack on Twitter being perhaps the most publicized) have only served to heighten concerns.

It's true; the potential consequences of a breach of cloud security are catastrophic, and this knowledge has served to make the debate rage even more fiercely. A cloud security issue within an organization has the potential to be a major business crisis, and against a backdrop of heightened public awareness of data loss and privacy issues such as ID theft, it's understandable.

But there's no denying that cloud computing is gaining momentum and will continue to become more and more mainstream. This year, for example, the UK government announced that it would be developing a cloud infrastructure (the ‘G-Cloud'), and the offer of flexible, low-cost and easily scalable IT means that many businesses are relying more and more heavily on cloud-based applications, storage and security.

The result is that the industry must get to grips with the security concerns. Fast.

Concern...or Confusion?
One of the key questions is whether or not security concerns are justified. Is it the case that unnecessary fears are preventing organizations from getting the most from the wealth of benefits that cloud-based services can offer?

It's a bit of both in my opinion. First, there's certainly a lot of confusion. A recent report by Gartner [1] suggests that most organizations don't fully understand their business' existing security provision and therefore cannot accurately pinpoint exactly where the gaps are when it comes to working with a cloud-based provider.

Furthermore, a lot of the confusion - and concern - arises from the (largely incorrect) assumption that cloud security is a complex issue. Security of the cloud is not necessarily as complex as some would have you imagine.

Detached Data
One of the key ways in which cloud computing differs to other IT services is that the relationship between cloud service provider and client is detached, often with significant geographical separation between parties. In addition, the ‘on-demand' nature of the relationship means that the client has very little influence on the operational practices of the provider. The cloud business model has moved far away from nurturing long-term partnerships, focusing instead on ease of initiation (and termination!) of relationships.

Combine this with the often large numbers of potential cloud providers with whom an organization may have a relationship at any one time and the greater level of data sharing inherent in many cloud services, and the issues become clear.

One of the key issues that arises from a security perspective as a result is the greater transfer of data in and out of a company's own IT infrastructure. Cloud computing differs from other similar IT services by moving data further from its original owner. As data storage and email outsourcing become two of the most popular modern cloud-based services, security fears over the transfer of data, and later, over who has access to this data, remain significant concerns.

However the numbers of cloud providers involved and the level of sharing that is inherent with many cloud-based services may well prove to make the task of securing the cloud itself an almost impossible one.

The key problem is that by the time data has reached the cloud, it's normally too late. As soon as a company's data leaves the relatively safe confines of its own IT infrastructure, the potential is there for it to get into the wrong hands. For this reason, it's at the boundary between the organization and its external environment that security has to be the key priority for those looking to use cloud-based services.

Confidence in the Cloud
With all this talk of risk and security, it's easy to forget the rewards of cloud services. Cloud computing is responsible for offering some of the greatest efficiencies within IT for decades. Furthermore, cloud computing forms the basis for a range of cutting-edge communication tools that not only provide new ways to engage with customers and colleagues, but demonstrate that your business is agile and forward-thinking.

While security is an important consideration, let's not forget that security must essentially be about enablement. It's no good having security that operates by preventing access, clamping down etc.

Security in this day and age must be about giving businesses the confidence to take advantage of new technology. This in turn, will lead to better communication, connectivity and innovation.

For Your Eyes Only
The key premise on which the foundations for safe and effective use of the cloud is this: That there will always be data that is so sensitive that it simply cannot be allowed to leave the confines of your business.

In the case of highly sensitive material, the best course of action in most instances is to prevent it from leaving your organization in the first place. (It is classic psychology that sensitive or confidential material is considered less so the further away it gets from the original creator.) What is therefore needed is highly sophisticated automated checking of outbound data to ensure that data that shouldn't leave the organization does indeed remain there.

For this reason, the key priority for improving the security of cloud computing lies not in the security of the cloud itself but in the routes in to and out of the cloud. Consider the analogy of tangible security risks to homes and business premises; it's the access points that are always the weak point. Therefore it's vital to ensure the ‘windows' and ‘doors' of cloud computing are made as secure as possible. Addressing the security of your company's specific cloud entry and exit points is the best - and simplest - way to get a grip on the potential issues involved to enable businesses to take advantage of all that the cloud has to offer.

Inbound from the Cloud
Many believe that cloud-based email is the only way to attain the best levels of efficiency and cost reduction. Indeed, although cloud-based email offerings can be compelling, it isn't the only way of doing things. In fact, when you consider the often quite significant issues regarding trust of a third-party cloud provider, cloud-based email can lose its shine. Allowing a third party to have unfettered access to all your incoming mail has major security implications, and requires complete trust and reliance on the organization providing the service.

Advances in appliance-based technology now mean that non-cloud based email security applications are as effective at reducing spam and malware with similar efficiencies to cloud-based services, but without the risk of handing all email data to a third party.

Keeping It Simple
Security of the cloud does not need to cause concern, nor should it be a barrier to using cloud services. Businesses simply need to ensure they have fully understood the risks their particular organization faces through using cloud-based services, and ensure that their security will enable them to use cloud services with confidence.

Collaboration and openness (both key cloud computing premises) are great attributes for many types of technology, and security nowadays must shift to focus on enablement rather than prevention. But collaboration and sharing is one thing when it's just you and your home PC and you are taking individual responsibility for the potential consequences of your actions. The same is not true for a company IT system where this way of working and engaging with customers and suppliers, though often commercially advantageous, carries far greater risks and therefore needs a level of corporate governance.

While it's easy to assume, when looking to adopt cloud-based services, that a third party may be a safer pair of hands, the reality is that there are no guarantees, and even if there is someone else to blame, the potential damage to your business could be catastrophic The only way to ensure your data is not compromised by the cloud is to control what is going to and from it in the first place, and make sure your control over what goes to and from the cloud is watertight.

More Stories By Alf Pilgrim

Alf Pilgrim is CTO of content security company, Clearswift. He joined Clearswift in 2006 as vice president, engineering where he is responsible for the product portfolio and technology development strategy and leads Clearswift’s drive to deliver policy-based security solutions. He was previously chief technology officer and director of product development and support at Northgate Information Solutions plc, the premier supplier of software and services to the UK public sector and human resource markets. He was part of the team that oversaw a 400% increase in shareholder value and corporate entry into the FTSE250. Alf holds a Ph.D. from the University of Leeds, is a chartered engineer, chartered IT professional and a member of the British Computer Society.

Comments (1) View Comments

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


Most Recent Comments
rlebherz 11/20/09 03:42:00 PM EST

Alf,

Interesting article. I think the Cloud services and cloud infrastructure lines are a bit blurred, but I agree with most of what you are saying.

Dont underestimate the SLA's role in accountability. For companies that have dynamic requirements and no down time can be afforded, make sure you have very tight SLAs. For example, OpSource provides a 100% SLA in the cloud and 100%SLA around production application environments. Now 100% is ideally perfect, it comes down to accountability, you put you faith in us, we should do what we say we will do. And if something happens, you should be paid back. We also have 24x7 phone support where you can actually talk to a real person and you get account managers when you sign up who can help you work through business related issues. Imaging that, people in charge of the relationship and accountability.

Also, A New Approach To Cloud Security Is Already Her! From a Cloud Infrastructure and operations perspective
Check out OpSource.net and OpSourcecloud.net

If you want to move everything need for delivering your production environments into the cloud check out OpSource.net

If you want to move your infrastructure into the clouds, check out OpSourcecloud.net

Also, RLE01 will get you 20% off.

@CloudExpo Stories
The 4th International DevOps Summit, co-located with16th International Cloud Expo – being held June 9-11, 2015, at the Javits Center in New York City, NY – announces that its Call for Papers is now open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's large...
Verizon Enterprise Solutions is simplifying the cloud-purchasing experience for its clients, with the launch of Verizon Cloud Marketplace, a key foundational component of the company's robust ecosystem of enterprise-class technologies. The online storefront will initially feature pre-built cloud-based services from AppDynamics, Hitachi Data Systems, Juniper Networks, PfSense and Tervela. Available globally to enterprises using Verizon Cloud, Verizon Cloud Marketplace provides a one-stop shop fo...
Leysin American School is an exclusive, private boarding school located in Leysin, Switzerland. Leysin selected an OpenStack-powered, private cloud as a service to manage multiple applications and provide development environments for students across the institution. Seeking to meet rigid data sovereignty and data integrity requirements while offering flexible, on-demand cloud resources to users, Leysin identified OpenStack as the clear choice to round out the school's cloud strategy. Additional...
The major cloud platforms defy a simple, side-by-side analysis. Each of the major IaaS public-cloud platforms offers their own unique strengths and functionality. Options for on-site private cloud are diverse as well, and must be designed and deployed while taking existing legacy architecture and infrastructure into account. Then the reality is that most enterprises are embarking on a hybrid cloud strategy and programs. In this Power Panel at 15th Cloud Expo (http://www.CloudComputingExpo.com...
We are all here because we are sold on the transformative promise of The Cloud. But what good is all of this ephemeral, on-demand infrastructure if your usage doesn't actually improve the agility and speed of your business? How must Operations adapt in order to avoid stifling your Cloud initiative? In his session at DevOps Summit, Damon Edwards, co-founder and managing partner of the DTO Solutions, will highlight the successful organizational, process, and tooling patterns of high-performing c...
The definition of IoT is not new, in fact it’s been around for over a decade. What has changed is the public's awareness that the technology we use on a daily basis has caught up on the vision of an always on, always connected world. If you look into the details of what comprises the IoT, you’ll see that it includes everything from cloud computing, Big Data analytics, “Things,” Web communication, applications, network, storage, etc. It is essentially including everything connected online from ha...
Software-driven innovation is becoming a primary approach to how businesses create and deliver new value to customers. A survey of 400 business and IT executives by the IBM Institute for Business Value showed businesses that are more effective at software delivery are also more profitable than their peers nearly 70 percent of the time (1). DevOps provides a way for businesses to remain competitive, applying lean and agile principles to software development to speed the delivery of software that ...
Docker offers a new, lightweight approach to application portability. Applications are shipped using a common container format and managed with a high-level API. Their processes run within isolated namespaces that abstract the operating environment independently of the distribution, versions, network setup, and other details of this environment. This "containerization" has often been nicknamed "the new virtualization." But containers are more than lightweight virtual machines. Beyond their small...
The move in recent years to cloud computing services and architectures has added significant pace to the application development and deployment environment. When enterprise IT can spin up large computing instances in just minutes, developers can also design and deploy in small time frames that were unimaginable a few years ago. The consequent move toward lean, agile, and fast development leads to the need for the development and operations sides to work very closely together. Thus, DevOps become...
Cloud Expo 2014 TV commercials will feature @ThingsExpo, which was launched in June, 2014 at New York City's Javits Center as the largest 'Internet of Things' event in the world.

ARMONK, N.Y., Nov. 20, 2014 /PRNewswire/ --  IBM (NYSE: IBM) today announced that it is bringing a greater level of control, security and flexibility to cloud-based application development and delivery with a single-tenant version of Bluemix, IBM's

An entirely new security model is needed for the Internet of Things, or is it? Can we save some old and tested controls for this new and different environment? In his session at @ThingsExpo, New York's at the Javits Center, Davi Ottenheimer, EMC Senior Director of Trust, reviewed hands-on lessons with IoT devices and reveal a new risk balance you might not expect. Davi Ottenheimer, EMC Senior Director of Trust, has more than nineteen years' experience managing global security operations and asse...
Explosive growth in connected devices. Enormous amounts of data for collection and analysis. Critical use of data for split-second decision making and actionable information. All three are factors in making the Internet of Things a reality. Yet, any one factor would have an IT organization pondering its infrastructure strategy. How should your organization enhance its IT framework to enable an Internet of Things implementation? In his session at Internet of @ThingsExpo, James Kirkland, Chief Ar...
Technology is enabling a new approach to collecting and using data. This approach, commonly referred to as the "Internet of Things" (IoT), enables businesses to use real-time data from all sorts of things including machines, devices and sensors to make better decisions, improve customer service, and lower the risk in the creation of new revenue opportunities. In his General Session at Internet of @ThingsExpo, Dave Wagstaff, Vice President and Chief Architect at BSQUARE Corporation, discuss the ...
The security devil is always in the details of the attack: the ones you've endured, the ones you prepare yourself to fend off, and the ones that, you fear, will catch you completely unaware and defenseless. The Internet of Things (IoT) is nothing if not an endless proliferation of details. It's the vision of a world in which continuous Internet connectivity and addressability is embedded into a growing range of human artifacts, into the natural world, and even into our smartphones, appliances, a...
"BSQUARE is in the business of selling software solutions for smart connected devices. It's obvious that IoT has moved from being a technology to being a fundamental part of business, and in the last 18 months people have said let's figure out how to do it and let's put some focus on it, " explained Dave Wagstaff, VP & Chief Architect, at BSQUARE Corporation, in this SYS-CON.tv interview at @ThingsExpo, held Nov 4-6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
"Our premise is Docker is not enough. That's not a bad thing - we actually love Docker. At ActiveState all our products are based on open source technology and Docker is an up-and-coming piece of open source technology," explained Bart Copeland, President & CEO of ActiveState Software, in this SYS-CON.tv interview at DevOps Summit at Cloud Expo®, held Nov 4-6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
DevOps Summit 2015 New York, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that it is now accepting Keynote Proposals. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce software that is obsolete...
What do a firewall and a fortress have in common? They are no longer strong enough to protect the valuables housed inside. Like the walls of an old fortress, the cracks in the firewall are allowing the bad guys to slip in - unannounced and unnoticed. By the time these thieves get in, the damage is already done and the network is already compromised. Intellectual property is easily slipped out the back door leaving no trace of forced entry. If we want to reign in on these cybercriminals, it's hig...
Infor has announced a new feature Infor CloudSuite™ Aerospace & Defense (A&D) to aid compliance with International Traffic in Arms Regulations (ITAR). The ITAR function will serve as a complementary function for new or existing Infor CloudSuite A&D customers, to facilitate compliance for Infor customers that are creating a US defense article or performing a US defense service and wish to benefit from cloud-services. The ITAR regulation serves to manage handling and access requirements for dat...