tgreene
Executive Editor

The Cloud Security Alliance looks to standardize security for cloud computing

Opinion
Apr 28, 20092 mins

* CSA releases an 83-page document detailing 15 areas of concern for cloud-computing security

A wide ranging group has set down principles for cloud security and is seeking help advancing them.

The Cloud Security Alliance (CSA) made its formal debut at RSA Conference 2009 last week by releasing a white paper on how customers of cloud services can go about ensuring they are secure.

The goal of the paper is to help these customers come to agreement with providers about the security they want. Its intent is also to help providers figure out how to deliver what customers need more efficiently.

Cooperation between customers and providers is essential, especially now, while cloud services are developing, says David Cullinane, the CISO of eBay and who is a founding member of CSA. “I strongly feel that the most cost effective way to secure the cloud is to do it right the first time,” he says in an introduction to the paper.

In its paper, CSA sets down 15 domains or areas of concern about cloud-computing security and recommends best practices in each area.

CSA wants to develop and coordinate a broad group of corporate consumers of cloud computing to influence vendors of security products as well as providers. If they speak with a unified voice, vendors and providers will have a better idea of what they need to do to meet demand.

To that end, CSA is planning a series of regional meetings to discuss its initial white paper and prepare revisions. Information about CSA plans are here. A discussion forum is here.