Cutting Through the Fog of Cloud Security

As cloud computing's security gaps become more visible, users are finding ways to safeguard their data.

Daniel Flax, CIO at investment banking and financial services firm Cowen and Co., relies on cloud computing to automate his company's sales activities. While he's satisfied with cloud technology's potential to lower upfront costs, decrease downtime and support additional services, he admits that he has had to work hard to get a handle on the emerging technology's security weaknesses. "Security is one of the things we've had to come to grips with," he says.

Evan Jones, owner and IT chief of interactive production company Stitch Media, located in Toronto and Halifax, Nova Scotia, is also concerned about cloud security. "It's a scary concept when you just hand all of your important company data over to a third party," he says.

Like a growing number of IT managers, both Flax and Jones are beginning to realize that cloud computing doesn't offer companies a free ride when it comes to security . A Gartner report released last year identified concerns about risks in several areas, such as data privacy and integrity and compliance management, that should give pause to anyone thinking about rushing into cloud computing.

"Enterprises, particularly those in regulated industries, need to weigh both the business benefits and risks of cloud computing services," warns Jay Heiser, a Gartner analyst.

One of cloud computing's biggest risks arises from its very nature: It allows data to be sent and stored just about anywhere -- even divided among locations around the world. While data dispersion helps give cloud computing a cost and performance edge, the downside is that business information can land in storage systems in locales where privacy laws are loose or even nonexistent.

Flax, who is using Salesforce.com's Force.com platform to automate Cowen's global sales systems, says the best way to ensure that data steers clear of risky destinations is to work with a cloud vendor that is a public company and is therefore required by law to disclose how it manages information.

Salesforce.com is publicly traded, and "as a result, we have a sense of comfort that there are strict processes and guidelines around the management of their data centers," Flax says. "We know our data is in the US, and we have a report on the very data centers that we're talking about."

Agora Games, a company that builds Web communities for video game players, currently has no say on the matter of where its cloud computing provider, Terremark Worldwide, hosts its data and applications. But that will be changing in the near future, says Brian Corrigan, Agora's chief technology officer.

More about: Agora, Amazon, Amazon.com, Gartner, Logical, NetSuite, Rose, Salesforce.com, SAS, Terremark Worldwide
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the Computerworld comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: cloud computing
Whitepapers
All whitepapers
Sign up now to get free exclusive access to reports, research and invitation only events.
Featured Download
/downloads/product/15/angry-ip-scanner/

Angry IP Scanner

Angry IP Scanner (or simply ipscan) is an open-source and cross-platform network scanner designed to be fast and simple to use. It scans IP addresses ...

Computerworld newsletter

Join the most dedicated community for IT managers, leaders and professionals in Australia