Welcome!

Cloud Expo Authors: Maureen O'Gara, Elizabeth White, Liz McMillan, Salvatore Genovese, Pat Romanski

Related Topics: Cloud Expo, Security

Cloud Expo: Press Release

Cloud Security Alliance Sets Industry Standard with New User Certification

Certificate of Cloud Security Knowledge (CCSK) Aimed at Promoting Secure Cloud Computing for All

The Cloud Security Alliance on Wednesday unveiled the industry's first user certification program for secure cloud computing. The Certificate of Cloud Security Knowledge (CCSK) is designed to ensure that a broad range of professionals with a responsibility related to cloud computing have a demonstrated awareness of the security threats and best practices for securing the cloud.

Cloud computing is being aggressively adopted on a global basis as businesses seek to reduce costs and improve their agility.  Among the critical needs of the industry is to provide training and certification of professionals to assure that cloud computing is implemented responsibly with the appropriate security controls.  The Cloud Security Alliance has developed a widely adopted catalogue of security best practices, the Security Guidance for Critical Areas of Focus in Cloud Computing, V2.1.  In addition, the European Network and Information Security Agency (ENISA) whitepaper "Cloud Computing: Benefits, Risks and Recommendations for Information Security" is an important contribution to the cloud security body of knowledge.  The Certificate of Cloud Security Knowledge (CCSK) provides evidence that an individual has successfully completed an examination covering the key concepts of the CSA guidance and ENISA whitepaper.   More information is available at www.cloudsecurityalliance.org/certifyme.

"Cloud represents the shift to compute as a utility and is ushering in a new generation of information technology.  Critical services are now being provided via the cloud, which is creating a mandate for cloud security skills across the spectrum of IT-related professions," said Jim Reavis, CSA executive director.  "The CSA is providing a low cost certification that establishes a robust baseline of cloud security knowledge.  When combined with existing professional certifications, the CCSK helps provide necessary assurance of user competency in this important time of transition.  We are also thrilled to have ENISA's support and their agreement to join our certification board."

"We have already been leveraging the CSA's ‘Security Guidance for Critical Areas in Cloud Computing' as a best practices manual for our information security staff," said Dave Cullinane, CISO and VP for eBay, Inc.  "We now plan to make this certification a requirement for our staff, to ensure they have a solid baseline of understanding of the best practices for securing data and applications in the cloud."

"Security has been identified as the most significant issue associated with cloud computing adoption," said Melvin Greer, Chief Strategist, Cloud Computing, for Lockheed Martin. "The CSA Certificate of Cloud Security Knowledge (CCSK) will provide a consistent way of developing cloud security competency and provide both organizations and agencies the confidence they need to adopt secure cloud solutions."

"Cloud computing will undoubtedly have a profound effect on information security.  Educating and developing talented thought-leaders is a key challenge in solving cloud security issues," said Jerry Archer, CSO for Sallie Mae. "The CSA, in providing a set of goals through the CCSK, is challenging security practitioners to become the cloud thought-leaders we need today and tomorrow to ensure safe and secure cloud environments.  In developing the CCSK, CSA is "setting the bar" for security professionals and providing business executives a means to gauge the opinions and rhetoric associated with security in the cloud."

eBay, Lockheed Martin and Sallie Mae join many other companies, including ING, Symantec, CA, Trend Micro and Zynga in their commitment to adoption of the CCSK. Online testing will be available starting Sept 1st 2010. The CSA will offer discount pricing of $195 through Dec 31; regular pricing at $295 begins January 1.

More Stories By Liz McMillan

Liz is Associate Online Editor at Ulitzer.com, where she covers emerging technologies including Cloud Computing and Virtualization, as well as mergers and acquisitions and "new-media" strategies as described under the Ulitzer Live! umbrella. You can forward your press releases by email lizmcmillan.ulitzer.com.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


Cloud Expo Breaking News
SYS-CON Events announced today that Red Hat, the world's leading provider of open source solutions, has been named “Platinum Sponsor” of SYS-CON’s 7th International Cloud Expo, which will take place on November 1–4, 2010, at the Santa Clara Convention Center in Santa Clara, CA. Red Hat, an S&P 500 company, is headquartered in Raleigh, NC, with over 65 offices spanning the globe. The company provides high-quality, affordable technology with its operating system platform, Red Hat Enterprise Linux...
SYS-CON Events announced today that Webroot, a leading provider in Web and Email Security, will exhibit at SYS-CON's 7th International Cloud Expo, which will take place on November 1–4, 2010, at the Santa Clara Convention Center in Santa Clara, CA. Webroot provides industry-leading security solutions businesses worldwide. Webroot products consistently receive top review ratings by respected third parties and have been adopted by millions globally. With a wide range of security services for busi...
What is the Enterprise Cloud Living Blueprint? In his session at the 7th International Cloud Expo, Brian Sledge, SVP Solution Architecture and Field Engineering for Adaptivity, will walk delegates through the creation and linkage of a living blueprint concept and how it helps firms realize a cloud delivery model. Brian Sledge is the SVP Solution Architecture and Field Engineering for Adaptivity. He is responsible for both the creative side of the business and for the development of all product...
What are small, high-growth companies experiencing as they make their move to on demand applications and how they are dealing with concerns around security, integration, business disruption? In his session at the 7th International Cloud Expo, Shawn Reynolds, Director at SAP, will discuss what benefits they are actually seeing versus what they expected and what advice they are giving software companies to help them achieve long-term growth and profitability.
Public cloud adoption by an enterprise may have numerous barriers and challenges surrounding data privacy, residency, and security. Transitioning from on-premise solutions to the cloud means ceding data governance to the cloud vendor. This may impact your enterprise regulatory compliance, adherence to industry standards, and internal data management standards. Depending on your jurisdiction, you may be subject the EU Data Protection Directive, or cope with a patchwork of disparate and overlappin...
Moving to the cloud raises lots of questions, mostly about security. Providers worthy of your business should answer them clearly and honestly. Amazon Web Services has built an infrastructure and established processes to mitigate common vulnerabilities and offer a safe compute and storage environment. In his session at the 7th International Cloud Expo, Steve Riley, an evangelist and strategist for cloud computing at Amazon Web Services, will discuss common cloud security concerns, show how AWS...