RSA Interview (c/o Tripwire) On the State Of Information Security In Virtualized/Cloud Environments.
David Sparks (c/o Tripwire) interviewed me on the state of Information Security in virtualized/cloud environments. It’s another reminder about Information Centricity.
Direct Link here.
Emedded below:
Related articles by Zemanta
- Six Year Old Rationalizes the Cloud (rationalsurvivability.com)
- Cloud Computing Security: (Orchestral) Maneuvers In the Dark? (rationalsurvivability.com)
- From the X-Files – The Cloud in Context: Evolution from Gadgetry to Popular Culture (rationalsurvivability.com)
- ENISA launches Cloud Computing Security Risk Assessment Document (rationalsurvivability.com)
- Cloud: Security Doesn’t Matter (Or, In Cloud, Nobody Can Hear You Scream) (rationalsurvivability.com)
- Mark Masterson’s Brilliant Cloud Security Presentation (rationalsurvivability.com)
Categories: Cloud Computing, Cloud Security, Cloud Security Alliance, Compliance, Information Centricity, Information Security, Information Survivability, Risk Management, Virtualization, Virtualization Security Cloud Computing, Computer security, Information Centricity, Information Security, Risk Management
Great point about getting back to the basics of classifying your data to better understand how it needs to be protected, no matter where it is. This simple exercise allows for clear protection requirements on which to act. It also allows for a risk management based approach to applying data protection for different classes of data. The combination provides a means to push protection requirements into applications and infrastructure with extremely clear goals. If you apply this process inside the firewall, it doesn't change for the cloud save for some additional location based needs that you may not consider inside your walls but can be easily added to the mix. What may change is your ability to effectively push the requirements into the applications and infrastructure.