The Jericho Forum and the Cloud Security Alliance have made a formal commitment to jointly develop and promote best security practices in cloud computing.
Their first step together will be working on version two of CSA’s major document “Security Guidance for Critical Areas of Focus in Cloud Computing.” The paper sets down 15 areas of concern that should be addressed by best practices in order to secure data in the cloud.
CSA and Jericho forum say they hope version two will be ready at the end of October. Participation in the work is not limited to group members and others can volunteer by e-mailing info@cloudsecurityalliance.org.
CSA plans to announce its version two kickoff next week.
One goal of the version two work will be to incorporate Jericho Forum’s “cloud cube” model of security and risk assessment in the CSA document, says Jim Reavis, the executive director of CSA. Jericho Forum and CSA have signed a memo of understanding with the broad goal of working together, but that otherwise has few specifics, he says.
The two groups have scheduled “lots of meetings together” and Jericho Forum has seats on CSA committees and CSA members participate in Jericho Forum working groups, he says.
The two groups flirted with each other at the RSA conference in San Francisco earlier this year, with
individual members acknowledging the similarity of each other’s work and suggesting that cooperation would serve the goals of both groups.
Jericho Forum is made up mostly of European IT executives, while CSA has a larger membership and includes more vendors.




