- Microsoft Windows chief decries standards grandstanding
- The 5 best, and 5 worst, features of Google Chrome OS
- Federal government using PS3 to crack pedophile passwords
- 10G Ethernet cheat sheet
- Top 10 free Windows tools for IT pros, at a glance
A group calling itself the Cloud Security Alliance announced its formation Tuesday, with eBay and ING as founding members.
The alliance, which plans to make its first big splash at the upcoming RSA Conference, was formed to promote security best practices in a cloud computing environment.
The on-demand cloud computing model is putting new demand on security, according to statements from Dave Cullinane, CISO at eBay. "The very nature of how businesses use information technology is being transformed by the on-demand cloud computing model," he said. "It is imperative that information security leaders are engaged at this early stage to help assure that the rapid adoption of cloud computing builds in information security best practices without impeding the business."
"Enterprises need pragmatic advice to qualify and engage with cloud providers in a way that is in alignment with organizational risk tolerances," says Alan Boehme, Cloud Security Alliance founding member and senior vice president of IT strategy and architecture at ING, a large global financial-service firm.
Chris Hoff, technical advisor to the Cloud Security Alliance, says the group, which includes a mix of user companies and vendors (PGP, Qualys and zScaler are among those announced) wants to sort out issues coming up in the cloud computing environment today.
"These companies, large and small, are struggling to make cloud computing relevant to their business," Hoff says. "The cloud means many things to many people." The group will seek not to define standards but set a common baseline for understanding security for cloud computing.
The group will likely tackle recommendations about security for cloud computing, and according to the group's Web site, it will be examining "15 domains of concern."
These include areas such as governance and enterprise risk, information and life-cycle management, compliance and audit, eDiscovery, encryption and key management, application security, identity and access management and incident response.
In related news, a document called the Open Cloud Manifesto, signed by dozens of vendors in support of cloud computing interoperability, was released Monday.
This document, issued by a group said to include IBM, Sun Microsystems, VMware and several others, tackles issues surrounding security, integration, interoperability, portability, governance/management and metering/monitoring in a cloud environment. But at least for the moment, it is mired in some controversy.
"The debacle stems from how the document was put together," Hoff explains. Some believe the document was too top-heavy with input from IBM and not open enough. Others criticize it as missing support from some of the major cloud computing heavyweights, such as Google.
Hoff says debate about it all is ongoing at the Cloud Computing Expo in New York City this week.
Partner Content
www.bmc.com
Gartner 2009 Magic Quadrant for Job Scheduling
Gartner has positioned BMC CONTROL-M in the Leaders Quadrant of their "2009 Magic Quadrant for Job Scheduling." The report assesses the ability to execute and completeness of vision of key vendors in the marketplace. Read a full copy today, courtesy of BMC Software.
Download whitepaper
Dell's SMART Approach to Workload Automation
Read a compelling case study by EMA, Inc. to learn how Dell uses BMC CONTROL-M to cut cost and increase productivity with workload automation.
Download whitepaper
Workload Automation Cost Savings 2 Minute Video
A major computer manufacturer uses BMC CONTROL-M and just four people to schedule and run over 85,000 jobs every month. By switching to BMC CONTROL-M, they more than quadrupled the workload without adding a single staff member. See how in this 2-minute video overview.
Go to video
Comments (1)
Cloud securityBy BobP/CEO on April 29, 2009, 12:11 pmLet's get back to security basics based on NSA & Common Criteria Standards. S/W only won't hasn't and will not do it alone. Just purchase our Trustworthy Platform...
Reply | Read entire comment
View all comments