SYS-CON Events announced today that The Open Data Center Alliance, an independent organization that gives stakeholders a voice in shaping the future of cloud computing, has been named “Bronze Sponsor” of SYS-CON's 10th International Cloud Expo, which will take place on June 11–14, 2012, at the Javits Center in New York City, New York.
The Open Data Center Alliance was formed in 2010 as a unique consortium of leading global IT organizations. The Alliance is led by a steering committee of senior ...| By Philip Lieberman | Article Rating: |
|
| March 29, 2010 05:00 PM EDT | Reads: |
4,072 |
Cloud Security on Ulitzer
Safeguarding a cloud infrastructure from unmonitored access, malware and intruder attacks grows more challenging for service providers as their operations evolve. And as a cloud infrastructure grows, so too does the presence of unsecured privileged identities – those so-called super-user accounts that hold elevated permission to access sensitive data, run programs, and change configuration settings on virtually every IT component. Privileged identities exist on all physical and virtual operating systems, on network devices such as routers, switches, and firewalls, and in programs and services including databases, line-of-business applications, Web services, middleware, VM hypervisors and more.
Left unsecured, privileged accounts leave an organization vulnerable to IT staff members who have unmonitored access to sensitive customer data and can change configuration settings on critical components of your infrastructure through anonymous, unaudited access. Unsecured privileged accounts can also lead to financial loss from failed regulatory audits such as PCI-DSS, HIPAA, SOX and other standards that require privileged identity controls.
One of the largest challenges for consumers of cloud services is attaining transparency into how a public cloud provider is securing its infrastructure. For example, how are identities being managed and secured? Many cloud providers won’t give their customers much more of an answer than a SAS 70 certification. How can we trust in the cloud if the vendors of cloud-based infrastructures neglect to implement both the process and technology to assure that segregation of duties are enforced, and customer and vendor identities are secured?
The Cloud Vendor’s Challenge: Accountability
Cloud computing has the potential to transform business technology, but it brings security issues that IT organizations should consider before trusting their sensitive data to the cloud. These issues should cause security experts and auditors to rethink many fundamental assumptions about Privileged Identity Management in terms of who is responsible for managing these powerful privileged accounts, how they manage them, and who exactly is in control.
Historically, IT data centers have always been in secured physical locations. Now, with cloud computing, those locations are no longer maintained directly by the IT organization. So the questions are these: how do you get accountability for management of physical assets that are no longer under your physical control, and exactly what control mechanisms are in place? Can you trust your cloud vendor to secure your most sensitive data? Moreover, if there’s a security breach in the cloud, who is to blame? Is it the cloud vendor that disclaims all legal liability in its contract, or an enterprise that relinquishes control of its sensitive data in the first place?
Cloud computing promises to make IT more efficient and deliver more consistent service levels. However, there’s a paradox that when it comes to security (and control over privileged identities in particular) cloud services are often among the least efficient. Many cloud service providers’ processes – based on ad-hoc techniques like scripting of password changes – are slow, expensive and unreliable. And that’s dangerous.
Fortunately the industry is starting to move beyond paralyzing discussions about the security and compliance problems that arise from cloud computing to address them head on. One example is the Trusted Cloud Initiative, which was launched at RSA Security Conference 2010. The goal of the initiative is “to help cloud providers develop industry-recommended, secure and interoperable identity, access and compliance management configurations, and practices.” However, only time will tell if it will help standardize cloud computing or turn out to be a technology certification of little use.
Several major cloud vendors and ISPs have begun the task of integrating security solutions that are capable of managing the large number of privileged identities that make up their infrastructure (hardware, VM hosts, VM Image OS, application stacks). This has really broken the fundamental model of IT being in control of security and has started to blur the lines between vendor and customer when it comes to the management of security.
Today, some privileged identity management frameworks are capable of managing “from iron to application,” giving cloud customers a full measure of control over credentials used in each physical and virtual layer of the stack and the potential to gain full visibility into who has access. In contrast, scripts and other ad-hoc methods to manage privileged identities can no longer keep pace or meet regulatory requirements in fast-changing and highly virtualized cloud computing environments.
In addition, cloud vendors must move to become identity providers of authentication services, multi-tenancy control, and X.509 certificate issuance for applications, end-points, users, and encrypted sessions. It is inappropriate for cloud vendors to expect their customers to use disconnected and third party providers of certificate services for what should be an inherent and integrated feature of every cloud vendor’s offering.
The End User’s Challenge: Transparency
In my opinion, the cloud is a really good, compelling idea. It can reduce the cost of IT dramatically. Given that cloud computing is available, the idea of building new data centers these days seems like a last-century way of doing things. And since many organizations lack the appropriate personnel to manage the IT resources they have, they’re willing to forego seeing and touching their own systems in their secured data centers – and the corresponding feeling of control – and have turned to outsourcing. Cloud computing is essentially the next generation of outsourcing, so we’re not only reducing manpower but also getting rid of our hard assets entirely. By moving these services to data centers anywhere on the planet we’re offered the potential for service delivery that costs far less than the alternatives. And the idea of outsourcing security and liability is extraordinarily compelling.
However, enterprises should ask the right questions of their cloud providers before taking the leap into the cloud and blindly assuming that their data is safe there. You should ask your cloud service provider to meet every point of compliance that your IT organization is required to meet, and should ask your cloud service provider every question that your IT auditors ask you.
Auditors, too, share a responsibility to verify that client organizations are able to track the usage and control of their data and resources inside the cloud. In keeping with major regulatory mandates, auditors are obligated to confirm segregation of duties and the enforcement of “need to know” and “need to access” policies. And, potential cloud customers should ask what provisions have been made to provide the required trail of access to the user’s auditors on demand – and what provisions are in place to allow the sharing of privileged control between cloud vendor and user for appropriate reporting and verification.
Because today’s cloud vendors offer literally no transparency and little information, don’t be surprised if you don’t like the answers you get. Most cloud vendors would say that for security purposes, it’s on a “need to know” basis and you don’t need to know. Others state that they’re SAS 70 compliant, but that’s really just a self-certification. And because each measure of security adds to cloud vendor costs, it is appropriate for consumers of cloud services to demand to know precisely what measures are in place – and what auditing processes are supported – as part of the service agreement.
Be persistent. What kind of security does the cloud service provider have in place to protect your privileged accounts and most sensitive data? Do they have Privileged Identity Management technology in place? How do they control privileged accounts used in cloud infrastructure to manage sensitive systems and data? How do they manage cloud stacks at the physical layer and application stack layers ? What is your access to audit records?
Whatever regulatory standards your organization must meet, so too must your cloud vendor. So if you think that by venturing into the cloud you’re saving yourself from regulatory headaches, think again.
Conclusion
Security is the greatest barrier towards adoption of the cloud, and it’s no great surprise that cloud security was a major theme at this year’s RSA Conference. Unfortunately, improvements in cloud security won’t be seen as a priority until a major breach has a significant impact on one or more cloud service vendors and their customers. This needs to change. When it comes to cloud security, it is the end-user’s duty to understand what processes and methodologies the cloud vendor is using to protect the customer’s most sensitive assets.
Published March 29, 2010 Reads 4,072
Copyright © 2010 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Philip Lieberman
Philip Lieberman is President & CEO of Lieberman Software. You can reach him and learn more about Privileged Identity Management in the cloud by contacting Lieberman Software
![]() |
douglas.barbin 03/31/10 06:09:00 PM EDT | |||
Philip, Very good article and very comprehensive view of the assurance issues surrounding identity management in the cloud. One clarification (and I could see what you were getting at so its not as if you misconstrued) but I wanted to clarify that SAS 70 is not a self-certification. First, SAS 70 is not a certification at all although I agree with you that technology marketers love to issue press releases saying that it is. Second, you are correct in that there are no prescriptive standards and that what is being tested are the control activities and objectives set by the provider. That said, the two do have to interrelate for a CPA to render an unqualified opinion. For instance, if the (high-level) control objective provides reasonable assurance against unauthorized access and the (detailed) control activities tested by the auditor were only paper-based (policies) with no technical preventive or detective controls, the result would likely be a qualified or adverse opinion on that objective if not the broader controls. The bottom line is while yes, the cloud provider dictates what the objectives and activities are, you won't get an unqualified (some refer to as clean) opinion if the controls are not suitably designed and/or fairly presented. Best Regards, |
||||
SYS-CON Events announced today that The Open Data Center Alliance, an independent organization that gives stakeholders a voice in shaping the future of cloud computing, has been named “Bronze Sponsor” of SYS-CON's 10th International Cloud Expo, which will take place on June 11–14, 2012, at the Javits Center in New York City, New York.
The Open Data Center Alliance was formed in 2010 as a unique consortium of leading global IT organizations. The Alliance is led by a steering committee of senior ...Feb. 3, 2012 12:21 PM EST Reads: 483 |
By Liz McMillan Big Data has become very popular as what can probably best be described as “loosely structured large scale data”, i.e., data sets of relatively small files.
In his session at the 10th International Cloud Expo, Tom Leyden, Director of Alliances and Marketing at Amplidata, will explain what Big Unstructured Data is (lots of large, unstructured files) and how you build scalable storage infrastructures that can handle such volumes of data. The focus will be on Object Storage, which is the future s...Feb. 2, 2012 07:00 AM EST Reads: 1,086 |
By Elizabeth White SYS-CON Events announced today that the Open Data Center Alliance, an independent organization that gives stakeholders a voice in shaping the future of cloud computing, will co-locate its one-day event “Forecast 2012: Shaping the Future of Cloud Computing” on June 12 at SYS-CON's 10th International Cloud Expo, which will take place on June 11–14, 2012, at the Javits Center in New York City, New York.
“Forecast 2012: Shaping the Future of Cloud Computing” will be open to Alliance members, partne...Feb. 1, 2012 09:54 AM EST Reads: 772 |
By Elizabeth White SYS-CON Events announced today that UShareSoft, provider of a cloud template factory, will exhibit at SYS-CON's 10th International Cloud Expo, which will take place on June 11–14, 2012, at the Javits Center in New York City, New York.
UShareSoft offers a cloud server template factory and enterprise app store platform for self-service software onboarding to cloud. UShareSoft's UForge enables customers to automate the creation and management of cloud images and server templates, with full softwar...Feb. 1, 2012 08:45 AM EST Reads: 836 |
By Liz McMillan In her general session at the 9th International Cloud Expo, Jill Tummler Singer, CIO for the National Reconnaissance Office (NRO), discussed the key elements needed for a triumphant enterprise cloud computing migration and highlighted strategies (including security advantages found in the cloud) to ensure you don't crash and get caught in the riptide of this rapidly emerging technology.
Jill Tummler Singer is CIO for the National Reconnaissance Office (NRO)- which as part of the 16-member Intel...Feb. 1, 2012 08:30 AM EST Reads: 1,004 |
By Pat Romanski Cloud computing has gained momentum and is increasingly being embraced by enterprises of all sizes for application delivery. But the cloud itself is often its own worst enemy as performance, reliability, and the lack of enterprise level capabilities have led to obstacles in growth and adoption of this still promising infrastructure methodology. This is only exacerbated by an increasingly mobile and global world, one that is plagued with security concerns.
In his Day 3 Keynote at the 9th Interna...Feb. 1, 2012 07:45 AM EST Reads: 1,449 |
By Liz McMillan As more enterprises are adopting clouds, the nature of cloud computing is changing. Previously, clouds were used to test applications or for non-mission critical applications. Today, enterprises are using clouds for cost-saving advantages and launching more mission critical applications that have defined performance needs.
In his session at the 10th International Cloud Expo, Eric Shepcaro, CEO and Chairman of the Board of Telx, will discuss how distributed computing has many advantages. It wou...Feb. 1, 2012 06:00 AM EST Reads: 1,313 |
By Elizabeth White What are the legal implications and consequences of cloud computing in the healthcare and high-tech sectors? What are the potential legal protections and solutions from the point of view of providers, suppliers and consumers?
In his session at the 10th International Cloud Expo, Paul Rubell, a Partner at Meltzer Lippe, will discuss the federal mandates that will encourage “meaningful use” of EHR technology by 2015, and what those mandates will require executives to understand about cloud comput...Jan. 31, 2012 10:00 AM EST Reads: 1,018 |
By Pat Romanski Hadoop, MapReduce, Hive, Hbase, Lucene, Solr? The only thing growing faster than enterprise data these days is the landscape of big data tools. These tools, which are designed to help organizations turn big data into opportunities, are gaining deeper insight into massive volumes of information. A recent Gartner report predicts that enterprise data will increase by 650% over the next five years, which means that the time is now for IT decision makers to determine which big data tools are the best...Jan. 31, 2012 07:30 AM EST Reads: 1,209 |
By Pat Romanski SYS-CON Events announced today that CodeFutures Corporation, the company behind dbShards, will exhibit at SYS-CON's 10th International Cloud Expo, which will take place on June 11–14, 2012, at the Javits Center in New York City, New York.
CodeFutures Corporation, the company behind dbShards, is a leading supplier of database performance and reliability tools that reduce the time and effort required to dramatically increase database scalability and performance. With dbShards, production environm...Jan. 30, 2012 05:30 AM EST Reads: 978 |
- Gartner Hype Cycle for Emerging Technologies 2011
- How Are You Building Your Cloud?
- Big Data in Telecom: The Need for Analytics
- Microsoft Tries Hadoop on Azure
- Big Data Gold Mine in Cloud Governance and Automation
- Thoughts on Big Data and Data Virtualization
- What Motivates Open Standards in the Cloud?
- StorSimple Supports OpenStack
- What to Expect in 2012: Cloud Computing and Open Source Software
- Australia's Lunatic NBN OK for Cloud (Update)
- Will PaaS Finally Bring Open Source Love to the Enterprise?
- Ten Hot Trends in Cloud Data for 2012
- The Future of Cloud Computing: Industry Predictions for 2012
- SYS-CON Events Announces Cloud Expo 2012 New York Venue
- HP Puts Activist Shareholder on Board
- 9th Cloud Expo | Speaker Faculty A–Z
- Cloud Expo Day 4 Keynote Speaker Profile: Jill T. Singer - NRO
- Ericsson: Leaders to discuss how ICT can shape future education at NEST
- Amazon Tipped to Buy webOS
- Make Customer On-Boarding Easy as Paint-by-Numbers for Cloud Services
- Cloud Expo Speaker Profile: Rich Wolski - Eucalyptus Systems
- Gartner Hype Cycle for Emerging Technologies 2011
- How Are You Building Your Cloud?
- Cloud Expo Speaker Profile: Greg O'Connor - AppZero
- What is Cloud Computing?
- The Top 150 Players in Cloud Computing
- Six Benefits of Cloud Computing
- Virtualization Conference Keynote Webcast Live on SYS-CON.TV
- GDS International: Global Warming Scam?
- What's the Difference Between Cloud Computing and SaaS?
- Twenty-One Experts Define Cloud Computing
- The Future of Cloud Computing
- The Top 250 Players in the Cloud Computing Ecosystem
- SOA 2 Point Oh No!
- Cloud Expo Europe 2009 in Prague: Themes & Topics
- A Brief History of Cloud Computing: Is the Cloud There Yet?









Big Data has become very popular as what can probably best be described as “loosely structured large scale data”, i.e., data sets of relatively small files.
In his session at the 10th International Cloud Expo, Tom Leyden, Director of Alliances and Marketing at Amplidata, will explain what Big Unstructured Data is (lots of large, unstructured files) and how you build scalable storage infrastructures that can handle such volumes of data. The focus will be on Object Storage, which is the future s...
SYS-CON Events announced today that the Open Data Center Alliance, an independent organization that gives stakeholders a voice in shaping the future of cloud computing, will co-locate its one-day event “Forecast 2012: Shaping the Future of Cloud Computing” on June 12 at SYS-CON's 10th International Cloud Expo, which will take place on June 11–14, 2012, at the Javits Center in New York City, New York.
“Forecast 2012: Shaping the Future of Cloud Computing” will be open to Alliance members, partne...
SYS-CON Events announced today that UShareSoft, provider of a cloud template factory, will exhibit at SYS-CON's 10th International Cloud Expo, which will take place on June 11–14, 2012, at the Javits Center in New York City, New York.
UShareSoft offers a cloud server template factory and enterprise app store platform for self-service software onboarding to cloud. UShareSoft's UForge enables customers to automate the creation and management of cloud images and server templates, with full softwar...
In her general session at the 9th International Cloud Expo, Jill Tummler Singer, CIO for the National Reconnaissance Office (NRO), discussed the key elements needed for a triumphant enterprise cloud computing migration and highlighted strategies (including security advantages found in the cloud) to ensure you don't crash and get caught in the riptide of this rapidly emerging technology.
Jill Tummler Singer is CIO for the National Reconnaissance Office (NRO)- which as part of the 16-member Intel...
Cloud computing has gained momentum and is increasingly being embraced by enterprises of all sizes for application delivery. But the cloud itself is often its own worst enemy as performance, reliability, and the lack of enterprise level capabilities have led to obstacles in growth and adoption of this still promising infrastructure methodology. This is only exacerbated by an increasingly mobile and global world, one that is plagued with security concerns.
In his Day 3 Keynote at the 9th Interna...
As more enterprises are adopting clouds, the nature of cloud computing is changing. Previously, clouds were used to test applications or for non-mission critical applications. Today, enterprises are using clouds for cost-saving advantages and launching more mission critical applications that have defined performance needs.
In his session at the 10th International Cloud Expo, Eric Shepcaro, CEO and Chairman of the Board of Telx, will discuss how distributed computing has many advantages. It wou...
What are the legal implications and consequences of cloud computing in the healthcare and high-tech sectors? What are the potential legal protections and solutions from the point of view of providers, suppliers and consumers?
In his session at the 10th International Cloud Expo, Paul Rubell, a Partner at Meltzer Lippe, will discuss the federal mandates that will encourage “meaningful use” of EHR technology by 2015, and what those mandates will require executives to understand about cloud comput...
Hadoop, MapReduce, Hive, Hbase, Lucene, Solr? The only thing growing faster than enterprise data these days is the landscape of big data tools. These tools, which are designed to help organizations turn big data into opportunities, are gaining deeper insight into massive volumes of information. A recent Gartner report predicts that enterprise data will increase by 650% over the next five years, which means that the time is now for IT decision makers to determine which big data tools are the best...
SYS-CON Events announced today that CodeFutures Corporation, the company behind dbShards, will exhibit at SYS-CON's 10th International Cloud Expo, which will take place on June 11–14, 2012, at the Javits Center in New York City, New York.
CodeFutures Corporation, the company behind dbShards, is a leading supplier of database performance and reliability tools that reduce the time and effort required to dramatically increase database scalability and performance. With dbShards, production environm...
There’s an excellent discussion going on over on the Cloud Computing Google Group about the pace of migration of traditional software to a SaaS model.
Here I recently went into some of the very real reasons why the migration is slower than some would like, but didn’t really talk about the pace of a...
Application development has been moving in the direction of platform abstraction. That is, the need for developers to have detailed knowledge of the infrastructure that the application was being deployed on was becoming less important with increasing sophistication of the application platform for wh...
In compliment to Jon’s headline focus on Enterprise Cloud Computing, my key specialism is where this technology overlaps with social media aka ‘Enterprise 2.0′.
Although it can feel like you’re playing an intense game of Buzzword Bingo, the key way to approach new technologies like Cloud Computing ...
Every year, our friends at ESG post results of their annual Spending Intentions Survey, indicating where many businesses are likely to spend their IT dollars over the coming year. Recently Steve Duplessie posted an article on his blog entitled Cloud – The Cost Containment Strategy that concludes clo...
Explore why not just revenue streams and business models are slowing the demise of installed software. And see how independent software vendors and their customers are leveraging the cloud....
Cloud computing is a pretty big deal. It's one of the top priorities for many CIOs. So, it should be a pretty easy process to build a B2B content strategy that helps CIOs make a purchasing decision.
Or is it?
I subscribe to a lot of newsletters and have a ton of Google Alerts to help me mine for i...
The automation of processes is a key enabler of the Cloud phenomena – without process the Cloud remains a passive environment that undoubtedly saves you money and removes some of the operational headaches, but does little else.
The Cloud without process cannot deliver on the promise of Business Tec...
One of the benefits of web applications is that they are generally transported via TCP, which is a connection-oriented protocol designed to assure delivery. TCP has a variety of native mechanisms through which delivery issues can be addressed – from window sizes to selective acks to idle time specif...
Every once in a while, as the number of people following me grows (thank you, each and every one), I like to revisit something that is fundamental to the high-tech industry but is often overlooked or not given the attention it deserves. This is one of those times, and the many-faceted nature of any ...
In most cases, the use of the term “consolidation” implies the aggregation (and subsequently elimination) of like devices. Application delivery consolidation, for example, is used to describe a process of scaling up infrastructure that often occurs during upgrade cycles. Many little boxes are exchan...















