The i-Technology Media!
Register | Log in
   
 
.NET  ·  AJAX  ·  CLOUD  ·  ECLIPSE  ·  FLEX  ·  OPEN WEB  ·  iPHONE  ·  JAVA  ·  LINUX  ·  OPEN SOURCE  ·  ORACLE  ·  PBDJ  ·  SEARCH  ·  SILVERLIGHT  ·  SOA  ·  VIRTUALIZATION  ·  WEB 2.0  ·  WIRELESS  ·  XML
Comments
Drool, Britannia? Is the UK Failing the Cloud?
By Roger Strukhoff
Richard Davies wrote: The UK has a good crop of technology pioneers in cloud computing - for example ElasticHosts, FlexiScale, Flexiant, OnApp - and also some strong government initiatives such as G-Cloud. We will have to see whether this kind of technical leadership converts into swift mass-market adoption or not.
Jan. 8, 2012 11:38 AM EST
read more & respond »
Cloud Expo on Google News
Did you read today's front page stories & breaking news?

Cloud Expo & Virtualization 2011 West
Keynotes
Oracle
Opening Keynote | An Enterprise Cloud for Business-Critical Applications
Abiquo
Day 2 Keynote | The Enterprise Cloud Tightrope - Balancing for Success
Akamai
Day 3 Keynote | The DNA of an Enterprise Cloud
DIAMOND SPONSOR:
Oracle
Many Clouds, Many Choices'Cloud
PLATINUM PLUS SPONSORS:
Abiquo
Enterprise Cloud Best Practices - Town Hall - Join the discussion…
PLATINUM SPONSORS:
Intel
Progressing Toward the Federated, Automated and Client-Aware Cloud
New Relic
How to build an app with Twitter-like throughput
Rackspace
Computing in the Cloud Era
GOLD SPONSORS:
Gale Technologies
Practical Cloud Migration
IBM
Re-think IT. Re-inventing Business.
Intel/McAfee
Identity Driven Security in the Cloud
PerspecSys
Hackers Hackers Everywhere, Is My Public Cloud That Safe?
Red Hat
Unlock the Value of the Cloud
SHI
Mission Critical Applications and the Cloud - Myth or Reality?
SoftLayer
Not Your Grandpa's Cloud
Terremark
Integrating Enterprise Clouds
VMware
Upgrade to a vCloud
POWER PANELS:
Cloud Expo Silicon Valley: CTO Power Panel
Cloud Expo Silicon Valley: CEO Power Panel
Cloud Expo Silicon Valley: Cloud SuperStars Panel
Cloud Expo Silicon Valley: CloudNOW Panel
Click For 2010 West
Event Webcasts
Cloud Expo & Virtualization 2011 East
DIAMOND SPONSOR:
Dell
Dell & VMware Deliver the Enterprise Hybrid Cloud
PLATINUM PLUS SPONSORS:
Abiquo
Are Financial Services Organizations Risking Security by Avoiding Cloud Computing?
Oracle
From Consolidation to Enterprise Private PaaS
PLATINUM SPONSORS:
Intel
Driving the Transformation to Next Generation Cloud Data Centers
Rackspace
The Inevitability of an Open Cloud
GOLD SPONSORS:
CA Technologies
Follow YOUR path to Cloud Computing
Interxion
Who Keeps the Cloud in the Air?
Microsoft
Patterns for Cloud Computing
PerspecSys
War in the Clouds: Are you ready?
ServiceMesh
The Big Win: Stop Playing Small-Ball with Your Cloud Strategy
Terremark
Evaluating Enterprise Clouds
Xiotech
Cloud Storage: Myths and Realities
POWER PANELS:
Cloud Expo New York: CTO Power Panel
Cloud Expo New York: CEO Power Panel
Cloud Expo New York: CMO Power Panel
Cloud Expo New York: Wrap-Up Power Panel
Click For 2010 West
Event Webcasts
Live Google News by SYS-CON!
Top Three Links You Must Click On


Cloud Security
It's Time to Stop Fearing Change and Learn About Cloud Computing
Cloud Computing is Scary - But the FUD Has to Stop

By: Dan Morrill
Oct. 28, 2008 03:45 AM

The Cloud Ave Blog

When headlines like “RMS hates cloud computing; says you should too”, “Cloud Computing a Trap” or “Cloud computing puts your health data at risk” show up on the Internet, it looks like the same old FUD (Fear Uncertainty and Doubt) that have been the inevitable response from the security community or from people who do not accommodate change well.

It is time to start embracing where business is going, and trying to make sure that they are doing it in the safest way possible.

It is one thing to create FUD, it is quite another to offer no solutions or pointers to the solutions for the problems we are seeing. To remain credible security professionals have to provide solutions to go along with what we are talking about.

The problem is also that we are not providing answers back to the security community that needs support and guidance. There are very few information security experts in cloud computing. It is hard to have your average IDS watcher, or network security engineer understand that cloud computing offers benefits and risks, just as much as virtualization, or even the iPhone.

What security professionals need to be doing rather than creating their own FUD is work out ways to make it safer. It is time to stop fearing change and learn about cloud computing technology and what it can and cannot do for the business. Work through a risk matrix, work through measures and counter measures, do all those good things that security engineers should be doing.

What I am seeing in the community, on blogs, and in private communications is the same earnest viewpoint of proposing a six million dollar security solution for a 15-minute wireless test by insisting that a Faraday cage had to be built around the two buildings we wanted to use in the test. That the Faraday cage would have invalidated the test because we never would have been able to go point-to-point wireless as the test protocol asked for.

While we might struggle with new technology, it is time for information security folks to step up to the plate and get smart on how the technology works, what the risks are, and how those risks can be reasonably addressed by good security solutions.

There are tricks to cloud computing that will remind you of a SAN, there are things that will annoy you like logging, there are things that will make you happy like automatically having an MD5 has on every object on the system if you use Amazon AWS or S3. Or using the power of the cloud to acquire and digest computer images for forensics. Let alone the power that the cloud represents in actually meeting C2 logging levels for databases, or the raw log crunching power of the system. Or the ability to test patching routines for systems by building instances against images and regression testing there instead of on a thrown together test bed. There is a lot of love when it comes to cloud computing.

There are things to worry about, privacy, control of objects, legal discovery, who has access to what questions that arise anyways in a corporate environment, e-mail security, database security, what about the provider going out of business, or a host of other legitimate concerns about the security, privacy, access, and availability of the data or the objects.

There is also very little usable information from the security viewpoint on these issues, some of this is addressable, some of it will mean that information security professionals learn as they go using the best practices. They will also have to fall back on what they know, what they are legally responsible for, and what the real issues are to help management make the best decision that they can. They will not make a decision that security folks will like, because many data points are going to move off the local networks, and go to reside somewhere else in the world.

There are some great resources for good information, Cloud Ave is one of them, but Trend Micro, IBM, Google, Amazon, Microsoft, Oracle and others who have all figured out that this can be a very neat technology and help companies expand and contract according to business need and market conditions.

While it is not ‘inevitable’, it is probable that companies are going to move some operations off the local network and into the cloud. The best bet right now for the security engineer is to work through the process, and get smart now so that management can benefit from what you have learned.


[This post appeared originally here and is republished in full by kind permission of the editor-in-chief of CloudAve.com.]

Creative Commons License Attribution to http://www.cloudave.com

Published Oct. 28, 2008— Reads 10,936
Copyright © 2008 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
Related Stories
▪ Opinion: Cloud Computing in 2008 - Not For the Faint-Hearted
▪ Viewpoint: Seven Technical Security Benefits of Cloud Computing
▪ A Brief History of Cloud Computing: Is the Cloud There Yet?
▪ SYS-CON's Cloud Computing Expo Will Be Larger Than Any Recent Gartner Event
▪ SYS-CON's November "Cloud Computing Bootcamp" Expected to be Sold-Out
▪ Five Key Challenges of Enterprise Cloud Computing
▪ The Future of Cloud Computing: Let's Not Fret About Definitions
About Dan Morrill
Dan Morrill has been blogging since 2003, writing about technology like Nutch, Hadoop, management, and the ways that people, politics, and technology intersect. He's a globally syndicated blogger across 27 major internet news sites. His focus is on information security in all its forms, needs, and educational requirements.


Add Your Feedback

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON Featured Whitepapers

ADS BY GOOGLE

Breaking Java News
JCM Global Names Payam Zadeh General Manager, Nobuyuki Sato Managing Director of Its EMEA Operations
Vicksburg CVB Announces Online Sweepstakes
FDA CONSUMER HEALTH INFORMATION - Giving Medicine to Children and Teaching Kids About Using Medicine Safely
Sherwin-Williams Boosts Dividend 7%
kuMobile Launches Commercial Trial of SuperWiFi Service in Kamloops
Mark Basten Joins Pragmatek Consulting Group to Lead Software Sales of IBM/Cognos Products
IT Service Management Salary Survey Results Released
PeaceHealth Saves Millions With RTLS Asset Tracking From Versus
CORRECTING and REPLACING Konarka’s Next Generation Organic Photovoltaic Cells First OPV Technology to Pass Set of Individual Critical Lifetime Aging Tests According to IEC 61646 Performed by TÜV Rheinland
IssueTrak Version 9.7 Streamlines Workflow, Debuts New Process Management Options, Enhances Asset Management

ADVERTISE   |   MAGAZINE SUBSCRIPTIONS   |   FREE BREAKING-NEWSLETTERS!   |   SYS-CON.TV   |   BLOG-N-PLAY!   |   WEBCAST   |   EDUCATION   |   RESEARCH

.NET Developer's Journal - .NETDJ   |   ColdFusion Developer's Journal - CFDJ   |   Eclipse Developer's Journal - EDJ   |   Enterprise Open Source Magazine - EOS
Open Web Developer's Journal - OPENWEB   |   iPhone Developer's Journal - iPHONE   |   Virtualization - Virtualization   |   Java Developer's Journal - JDJ   |   Linux.SYS-CON.com
PowerBuilder Developer's Journal - PBDJ   |   SEO / SEM Journal - SJ   |   SOAWorld Magazine - SOAWM   |   IT Solutions Guide - ITSG   |   Symbian Developer's Journal - SDJ
WebLogic Developer's Journal - WLDJ   |   WebSphere Journal - WJ   |   Wireless Business & Technology - WBT   |   XML-Journal - XMLJ   |   Internet Video - iTV
Flex Developer's Journal - Flex   |   AJAXWorld Magazine - AWM   |   Silverlight Developer's Journal - SLDJ   |   PHP.SYS-CON.com   |   Web 2.0 Journal - WEB2
Apache   |   CMS   |   CRM   |   HP   |   Oracle Journal   |   Perl   |   Python   |   Red Hat   |   Ruby on Rails   |   SAP   |   SaaS

SYS-CON MEDIA:   ABOUT US   |   CONTACT US   |   COMPANY NEWS   |   CAREERS   |   SITE MAP
SYS-CON EVENTS:   |  AJAXWorld Conference & Expo  |  iPhone Developer Summit  |  Cloud Computing Conference & Expo  |  SOA World Conference & Expo  |  Virtualization Conference & Expo
INTERNATIONAL SITES:   India  |  U.K.  |  Canada  |  Germany  |  France  |  Australia  |  Italy  |  Spain  |  Netherlands  |  Brazil  |  Belgium
 Terms of Use & Our Privacy Statement     About Newsfeeds / Video Feeds
Copyright ©1994-2008 SYS-CON Publications, Inc. All Rights Reserved. All marks are trademarks of SYS-CON Media.
Reproduction in whole or in part in any form or medium without express written permission of SYS-CON Publications, Inc. is prohibited.
 
close this window