Verizon Business is joining the Cloud Security Alliance http://www.networkworld.com/news/2009/033109-cloud-security-alliance.html , bringing another big corporate name to the group and, presumably, its expertise in actually providing cloud services.
Verizon Business’s stated intent in joining CSA is to promote discussion that leads to best practices in the industry.
The company says it has assigned a team of people to work in its contributions to the CSA.
Mainly the work will consist of refining CSAs initial document “Security Guidance for Critical Areas of Focus in Cloud Computing”, which sets down 15 areas of concern that should be addressed by best practices in order to secure data in the cloud.
Verizon has its own cloud service – Computing as a Service (CaaS) – from which it could draw useful experience.
The service collaborates with customers to make them aware of the unique security concerns with a cloud service vs. a private network, says Ken Biery, a professional services manager for the company.
Further, once customers have set up the security measures deemed necessary to go along with the service, Verizon gives them tools to verify that they are in place and working. For example, if customers want two-factor authentication for access to the service, the company can validate that it is actually being delivered.
CaaS is only a month old, but whatever real-world experience Verizon Business has gleaned and can share with the industry group – which has a large number of potential cloud-service customers – the better off the group’s work will be. The power of the group comes from the diversity of its members and their cooperation, so this new addition should help.




