I got an interesting tweet sent to me today that asked a great question:
I thought about this and it occurred to me that while I would have liked to have answered that the Cloud Security Alliance Guidance was my first choice, I think the most appropriate answer is actually the following:
“Cloud Security and Privacy: An Enterprise Perspective on Risks and Compliance” by Tim Mather, Subra Kumaraswamy, and Shahed Latif is an excellent overview of the issues (and approaches to solutions) for Cloud Security and privacy. Pair it with the CSA and ENISA guidance and you’ve got a fantastic set of resources. I’d also suggest George Reese’s excellent book “Cloud Application Architectures: Building Applications and Infrastructure in the Cloud”
I suppose it’s only fair to disclose that I played a small part in reviewing/commenting on both of these books prior to being published 😉
/Hoff
Here are the slides from my Cloud Security Alliance (CSA) keynote from the Cloud Security Summit at the 2010 RSA Security Conference.
The punchline is as follows:
All this iteration and debate on the future of the “back-end” of Cloud Computing — the provider side of the equation — is ultimately less interesting than how the applications and content served up will be consumed.
Cloud Computing provides for the mass re-centralization of applications and data in mega-datacenters while simultaneously incredibly powerful mobile computing platforms provide for the mass re-distribution of (in many cases the same) applications and data. We’re fixated on the security of the former but ignoring that of the latter — at our peril.
People worry about how Cloud Computing puts their applications and data in other people’s hands. The reality is that mobile computing — and the clouds that are here already and will form because of them — already put, quite literally, those applications and data in other people’s hands.
If we want to “secure” the things that matter most, we must focus BACK on information centricity and building survivable systems if we are to be successful in our approach. I’ve written about the topics above many times, but this post from 2009 is quite apropos: The Quandary Of the Cloud: Centralized Compute But Distributed Data You can find other posts on Information Centricity here.
Slideshare direct link here (embedded below.)
Categories: A6, Cloud Computing, Cloud Security, Cloud Security Alliance, CloudAudit, Data-Centric Security, De-Perimeterization, Disruptive Innovation, Information Centricity, Information Security, Information Survivability Tags: Application Service Providers, Business, Business-to-Business, Cloud, Cloud Computing, Cloud Networking, Cloud Security, Cloud Security Alliance, CSA, E-Commerce, Security, Virtualization Security
Recent Comments