By Harold Moss LinuxInsider Part of the ECT News Network
10/09/08 4:00 AM PT
Richard Stallman famously voiced his mistrust of cloud computing as "marketing hype," while Larry Ellison dismissed it as simply a fashionable name for stuff we already do. IBM's Harold Moss seems to agree more with Ellison, saying it's an evolution of existing technologies, and companies should be mindful of just what they're putting up there.
Success is just a matter of knowing the right "secrets." Download the free eBook, "The Edge of Success: 9 Building Blocks to Double Your Sales." You will discover the fastest, most effective ways to grow your business and still have time to live your life.
Regardless of all its hype, security in cloud computing is not a revolution; rather it's an evolution of the age-old business model of outsourcing. The concept of cloud computing has evolved from the concepts of grid, utility, and SaaS (Software as a Service), and these models evolved from the application service provider in the mid-early '90s. The emerging model of cloud computing allows people to tap into a vast network of computers scattered around the world using any type of connected device to analyze an abundance of information on demand. The information resides in massively scalable data centers, provided by an outsourcer, which are enabled by the maturity and progression of virtualization technology.
With any outsourcing model, business owners, not service providers, are ultimately responsible for maintaining the confidentiality, integrity and availability of their data. Before embracing any type of outsourcing model, be it cloud or traditional, businesses must exercise best practices to ensure they are working with a trusted service provider who will be gaining access to and helping protect sensitive company data. It is also important to note that cloud computing is fundamentally an extension of an organization's environment, and similar vigilance needs to be in place as it relates to periodic assessments of what information is deemed "safe for the cloud."
Security and Communication
This new era of computing is as much about the need for security as it is about the need for communication. Businesses must not only trust their service provider, but also, during the information-gathering process, enable open communication to ensure proper oversight and control of the information being accessed. A security risk assessment always should be conducted by checking the provider's credentials, from where the service is operated, and to which external assessments the supplier adheres. Moreover, service providers should provide informational assets and mechanisms that allow for real-time understanding of the security posture. In addition to a security risk assessment, proper security measures must be in place at the customer's premise to ensure secure transactions with the cloud. This is accomplished through implementation of traditional in-depth defense practices such as network and endpoint protection technologies, coupled with managed security services for real-time monitoring and response.
While the majority of businesses remain completely unaware of everyday in-house security controls and protections, the act of extending their business out to the cloud amplifies the need to increase understanding of current security models. A cloud model implementation must offer adequate or better security and management than what currently is in place. By focusing full attention on the data involved, there are several questions businesses can ask themselves to help understand the outsourcing process. Questions such as "Is this data mission critical?" and "Does this data represent private customer information?" enable businesses to determine the level of security they need and if the data is appropriate for the cloud.
What Is Cloud-Safe Data?
Not all business data is appropriate for the cloud model -- as would be the case for any outsourcing. When considering data security, information that has external facing attributes and is not considered mission critical should be considered safe for the cloud. Also, internal-only data that is non-mission critical is also considered safe. Regardless, the appropriate levels of security should always be applied to each classification of information while minimizing the likelihood of creating security or business exposures. Keep in mind though that if the data is competitive and mission-critical, it might be most secure behind a company's own firewall. More importantly, for data that is both competitive and mission-critical, companies can best control risk by looking to manage it themselves.
While security risks may always be a concern in the information technology industry, businesses that embrace new technologies while maintaining strategic focus on core IT and business initiatives will be successful in the emerging technology landscape and will have the tools to better leverage existing resource investments. In order to satisfy today's challenges in the explosion of data, the need for businesses to move to the next generation of computing, cloud computing, is imminent.
Harold Moss is a security architect for IBM (NYSE: IBM) Software Group.
Astaro: Tapping the Channel for Security Revenue August 28, 2008
Offering a free version of an open source security product might get you plenty of attention, but catching paying customers takes a little more work. Astaro learned that lesson and adapted, steering toward a channel sales model under which it's grown to 165 employees. Its latest mission: Gunning for larger competitors' dissatisfied customers.
Related Stories
IBM Enlarges Sphere of Influence in the Cloud October 06, 2008
IBM is moving deeper into the cloud, and its relentless march could make it difficult for any competitor to gain purchase, despite the newness of the space. On Monday, Big Blue debuted a new cloud service dubbed "Bluehouse," which facilitates social networking and collaboration among different organizations.
Cloud Computing: Perilous Pitfall or Panacea? October 06, 2008
Open source guru Richard Stallman came down big on cloud computing last week, calling it a major risk for proprietary system lock-in. Some Linux bloggers agreed wholeheartedly. Other still see some silver lining -- if it's used for sensible purposes. "Cloud computing as a concept isn't idiocy," Gerhard Mack said. "It's just been extended to idiotic lengths."
Cloud Storage, Part 1: The Business Data Warehouse October 01, 2008
Companies of all sizes have to war with two competing goals when it comes to management of their mission-critical data: 1) protecting their data in the event of disaster; and 2) maintaining the highest level of data security. The first requires letting go, while the second demands holding fast.