Tuesday | 2 December, 2008
The dangers of cloud computing
On-demand apps and services have several security risks that IT should address up front
Ephraim Schwartz (InfoWorld) 08/07/2008 10:35:45

A best practice guideline for cloud computing

Ultimately, the consumer of the services is responsible for maintaining the confidentiality, integrity, and availability of data, agrees Kristin Lovejoy, director of IBM's security, governance, and risk management division.

Lovejoy cites by way of example the fact that the HIPAA (US Health Insurance Portability and Accountability Act) makes no specific statements regarding outsourcing or offshoring. Instead, the act's sections 164.308 and 164.314 simply require that a company get assurance from any third parties handling its data that the data will be safeguarded, she notes.

As far as placing limitations on when to deploy the cloud, Lovejoy advises that companies adhere to Geoffrey Moore's consideration of "context versus core." (Moore is a business strategist and managing partner of TCG Advisors.)

Core business practices provide competitive differentiation. Context practices deliver business activities that are typically internal, such as HR services and payroll. Both core and context can be divided into mission-critical applications and non-mission-critical ones. "If a non-mission-critical application goes offline, the company can survive," Lovejoy says.

The rule of thumb Moore comes up with, notes Lovejoy, is this: If the business practice is context and non-mission-critical, then always put it in the cloud. If it is context and mission-critical, it is likely you should make it cloud-enabled. However, if it is core and non-mission-critical, you may want to think about keeping it behind the firewall; if it is core and mission-critical, then definitely keep it behind the firewall, she says.

Good security takes time

The cloud approach doesn't map naturally to how good security is typically designed, says John Pescatore, Gartner's chief security analyst and a man whose resume reads like it came from a James Bond movie, including a stint with the FBI, the National Security Agency, and the Secret Service.

The area that worries Pescatore most is how quickly cloud-based services are updated and changed. He cites Microsoft's painstaking development of the SDLC (Software Development Life Cycle) initiative that assumes mission-critical software will have a three- to five-year period in which it will not substantially change.

"In the cloud, every two weeks we add a new feature, changing the app all the time. But the secure SDLC is not built to do that. We are going back to the old Netscape days of pushing out new features real quick, and nobody has a security cycle that moves that fast," Pescatore says.

What makes matters even worse is that the business user can't say he wants to stay on the old version. "In the cloud you have to accept the next version, possibly nullifying any security that was built into the old application or assumed through integration at the customer site.

Computerworld Buyer's Guide - Vendors Matched to this Article
Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds
Market Place

 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Taking On Demand CRM Integration to the Next Level

Discover the current integration challenges facing businesses attempting to deploy on demand CRM systems. Learn how to create comprehensive integration of your data, user interface and business process levels and transform a portfolio of disparate applications into a unified, virtual application suite.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links