Just as I finished writing the last issue (“SCIMing the provisioning landscape”) an interesting new study — about cloud computing providers — popped into my inbox.
Entitled “Security of Cloud Computing Providers Study,” it was commissioned by CA Technologies and compiled by the Ponemon Institute as a follow on to last year’s “Security of Cloud Computing Users.”
The study surveyed 103 cloud service providers in the U.S. and 24 in six European countries (for a total of 127 separate providers). Respondents from cloud provider organizations say software as a service (55 percent) is the most frequently offered cloud service, followed by identity as a service (34 percent) and platform as a service (11 percent). Fully 65% of cloud providers in this study deploy their IT resources in the public cloud environment, 18% deploy in the private cloud and 18% are hybrid. That does seem to be an all-encompassing cross-section.
ANALYSIS: Public vs. private clouds: Why not both?
From our perspective, a telling detail from the study shows that 50% of cloud users in comparison to 40% of cloud providers report identity and access management as a critical area of focus. The 50% of users is woefully low, but that only 40% of providers see IAM as critical — even as they hope to foist SCIM (simple cloud identity management) on us — is cause for pause in the headlong rush to move everything to the cloud.
Among other telling findings:
• The majority of cloud computing providers surveyed do not believe their organization views the security of their cloud services as a competitive advantage. Further, they do not consider cloud computing security as one of their most important responsibilities and do not believe their products or services substantially protect and secure the confidential or sensitive information of their customers.
• The majority of cloud providers believe it is their customers’ responsibility to secure the cloud and not their responsibility. They also say their systems and applications are not always evaluated for security threats prior to deployment to customers.
• The majority of cloud providers in our study admit they do not have dedicated security personnel to oversee the security of cloud applications, infrastructure or platforms.
The advice from here is that you need to work with your traditional IAM partners to secure your cloud resources, and don’t rely on the cloud providers to offer you any security. Read the entire study for yourself and be a better-informed buyer of cloud-based services.




