Defining cloud computing
I’m amazed how many companies now offer “cloud services.” Anything that comes down the pipe is a “cloud” service. This explosion of cloudness complicates the security discussion since it’s very tough to protect what you can’t define. I believe the best work on cloud definition is being done by Peter Mell and his team at the National Institute of Standards and Technology (NIST).
“Cloud computing is a model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.”
Its value is in its simplicity. For example, cloud computing is a model, not a service. This lets us focus on defining a more general security model that addresses the unique characteristics of the cloud as opposed to a different defense for each service.
This definition also exemplifies agility flexibility and scalability. Fifty-four percent of organizations participating in Nemertes benchmark research list agility and flexibility as one of their top virtualization drivers. Virtualization is the foundation of the cloud model, and virtualization security is a foundation of a cloud defense.
The NIST definition ends with “This cloud model promotes availability and is composed of five essential characteristics, three service models, and four deployment models.” We can use this definition to differentiate cloud computing from cloud-like services. In the coming weeks we’ll discuss the essential characteristics, models and deployment in relation to a security model for cloud computing.




