Are your cloud services secure?

Opinion
Aug 18, 20102 mins

Cloud computing and virtualization are rapidly changing the normal mode of operations for most companies. But this move also means that techniques used to secure your corporate information assets must evolve drastically. In particular, there is no longer a physical “perimeter” to guard. Instead, the information is distributed, and the security must be likewise distributed.

IT managers must adapt by implementing faster, smarter security measures that monitor the constantly changing global landscape. It’s not exactly news, but it bears repeating that while guarding and authenticating physical boundaries was formerly sufficient, the new level of virtualization must be extremely concerned about access authentication and control.

Two recent papers by Cisco and Juniper do an excellent job of examining these new challenges in depth. In the paper by Juniper, “Dynamic Security for the New Network Data Center,” the most appropriate point is made that “To date, security in data centers has been applied primarily at the perimeter using firewalls, and at the server level by installing host-based intrusion detection, identity enforcement, antivirus, and other software agents. With virtualization, applications on the same host can communicate without accessing the physical network, thereby circumventing traditional firewalls and breaking zones of trust. Server-based security isn’t scalable, doesn’t encompass the range of network-attached devices in the data center, and presents major operational challenges. To protect today’s data center, enterprises need a unified security layer operating dynamically across the heterogeneous and ever changing data center infrastructure.”

Likewise, Cisco is offering a security architecture for “borderless networking.” In its paper, they examine the threats, the access points that are particularly vulnerable, and (of course) a series of steps for remediation.

As observed in the Cisco paper, “The threat landscape has changed. IT and security operations teams must combat an array of threats to the network infrastructure and simultaneously assure network access for all who need it. Many current and emerging threats take advantage of existing vulnerabilities, even though organizations can become distracted by emerging threats. It is important to focus time, energy, and resources on what is strategically, financially, and competitively most important to safeguard your organization and that means taking a close look at your entire security system.”

We couldn’t agree more with the information in these papers, and together they form an excellent tutorial. We recommend the papers and welcome your comments.

Jim has a broad background in the IT industry. This includes serving as a software engineer, an engineering manager for high-speed data services for a major network service provider, a product manager for network hardware, a network manager at two Fortune 500 companies, and the principal of a consulting organization. In addition, Jim has created software tools for designing customer networks for a major network service provider and directed and performed market research at a major industry analyst firm. Jim’s current interests include both cloud networking and application and service delivery. Jim has a Ph.D. in Mathematics from Boston University.

More from this author