Share


Share

Share it !



share/bookmark
Showing posts with label Cloud. Show all posts
Showing posts with label Cloud. Show all posts

Federal Cyber Security and Trusting the Cloud - Data Hosting and Virtualization


It seems that the security risk to federal cyber security introduced by a new or emerging technology is inversely proportional to the convenience it offers to industry. Every few years a hot capability comes along that instantly has businesses clamoring to adopt it, while security professionals scramble to discover and address its vulnerabilities. Wireless networking fell into this category, and the rise of Cloud computing over the last few years appears to be just the leading edge in a massive migration towards virtualization and out-sourced data hosting.

An industry unfortunately lacking standardization and oversight, where the uninformed essentially gamble one of their most valuable assets on a table marked with confusing, and sometimes risky, bets. The "valuable asset" in this analogy is, of course, proprietary data. Businesses, and even governments, frequently fail to comprehend the true value their data and intellectual property represent to their organization-much less the value that information might have to others: "Value" cannot always be measured in monetary terms, and oftentimes the value of an object comes not in its positive potential, but in the negative consequences it might produce in the hands of a competitor, criminal, or wary public.

The attraction to the Cloud is undeniable. Cost savings are frequently realized through the outsourcing of infrastructure, software, technical support, and security controls-assuming those services are effective and reliable. In fact, a service provider may be able to offer a computing capability far beyond what many companies might otherwise be able to afford: An outsourced solution is easily scalable, providing a partial or total solution with ready-made growth capability, and it may also offer increased accessibility to data if that is desirable. With respect to security, for a small or mid-sized company with marginal security to begin with, even a service provider with only modest security features may offer an improvement over the existing system.

When deciding whether or not to outsource it is important for an organization to fully understand and quantify their risk in utilizing the Cloud, starting with a comprehensive assessment of the true value of the data and intellectual property being entrusted to a potential service provider. In an outsourced solution, an organization is relinquishing direct control of their data, and possibly business processes as well, to an entity for which the element of trust may be unknown or at least undeveloped. Significant effort should be expended in understanding the details of the service being provided and defining the level of trust obligated by the contractual relationship. Be wary of Service Level Agreements (SLA) containing contractual elements granting the provider wide latitude and limited liability for the storage or confidentiality of data: For instance, some SLAs include provisions for sharing data with third parties or rights for marketing.

Key information to collect and consider when comparing service providers will include:

• Governance, Oversight, and Liability: When was the service provider's last assessment, and have they had citations or security breaches in the past? Is the service provider compliant with applicable regulatory requirements in handling your data? Are you in compliance with applicable regulatory requirements in outsourcing your data? What is the provider's liability and obligation in case of data loss or compromise?

• Physical and Logical Geography: Where are the data centers physically located that will be hosting your information, and how will your data be partitioned on the server(s) relative to other data stored by the provider?

• Security Controls: How is your data secured, both in transit and in storage? How, when, and where is your data replicated, and how long is it retained? How will various security measures impact advertised access and performance characteristics for the service?

• Physical and Logical Access: What security policies are in place for access to, and modification of, the data center and your data? Who will have access to your data? Possibilities include service-provider employees or administrators, third-party vendors, contractors, as well as officials from governmental, compliance, or oversight bodies.

• Balance Risk versus Trust: Evaluate the costs and consequences in the event your data were lost or compromised, and consider maintaining internal control or heightened security measures for that portion of information critical to the organization or the conduct of business. Such sensitive data might concern proprietary products or processes, intellectual property, privacy information regarding employees or customers, or company financial's.

Although various initiatives are underway for establishing uniform standards and oversight bodies for the virtual sector, many such efforts have failed in the past and effective legal and industry standards for Cloud computing appear to be years away from realization. As tighter security and control requirements do come into play in the industry, it will be interesting to see whether outsourcing remains a cost-efficient and attractive proposition for businesses when weighed against the relative risks.




Jon M. Stout is Chief Executive Officer of Aspiration Software LLC. Aspiration Software LLC is an Information Technology/Cyber Security services provider focused on the Intelligence Community (IC). For more information about Cyber Security and Information Assurance and Employment Opportunities in the Intelligence Community go to http://aspirationsoftware.com




Cloud Computing And How It Can Impact Your Business


Successful business is done by groups, not individuals. It takes an entire team of people to efficiently create, test, and distribute products and services. So why are so many business programs on the computer designed to be only used by one person? Wouldn't it make sense to provide all the workers on a team with an option for real-time collaboration and the ability to access to the same set of resources and tools related to the project they're working on? Cloud computing allows the storage of information on a server that can be accessed by multiple users. There's many benefits to this system of computing. Some of these benefits include improved worker productivity, decreased expenses for users, and the ability to work from any device with Internet access.

Workers can save time using cloud computing therefore increase their productivity. Instead of working on documents and spreadsheets individually and then e-mailing them to coworkers asking for comments and criticisms, members on the cloud can receive real-time input and assistance from their peers who are working in tandem with them on the same file.

Hard drive space is both essential and expensive, and cloud computing can save its users a significant amount of money by freeing up room on users' computers. Large, important documents that once needed to be kept in a folder on a user's personal computer can now be stored on a server, leaving more room for other files that the user may need. There are no downloads required for cloud computing. Simply log into the network and store the desired files.

Since work is stored on a server and not on an individual's computer, project team members can access files on the cloud and work from any computer, phone, or tablet that has Internet access. This allows files to be edited regardless of their location, so if a user remembers they need to make a change to a document but they've already left their computer, it's possible to use another computer or a smartphone to open and edit that document.

Cloud computing can make life easier for business owners and employees. Although there have been skeptics of cloud computing who claim there's a number of security risks associated with the practice, these risks must be very minor or non-existent if companies as big as Amazon, Yahoo, Google, and Microsoft are cloud advocates. Proper safety measures can be taken by strictly limiting who has access to sensitive information, and this will all but eliminate any chance for security issues and allow users to improve work quality.




For more information about cloud computing development, visit Magenic Technologies who have been providing innovative custom software development to meet unique business challenges for some of the most recognized companies and organizations in the nation.




Cloud Computing - The Legal Issues Are Somewhat Cloudy in the Cloud


"Cloud computing" has become a very hot topic. For the uninitiated, "cloud computing" generally refers to providing access to computer software through an Internet browser, with the software and data stored at a remote location at a "data center" or "server farm," instead of on the computer's hard drive or on a server located on the user's premises. This is also referred to "software as a service."

Proponents of this approach claim many benefits, including lower costs, less need for on-site support and "scalability." "Scalability" means that the number of licenses and available resources can easily be adjusted as the need increases. Access can typically be provided to any computer with a browser and an Internet connection, but can be controlled through password protection and other measures. Proponents also argue that the cloud makes it easier to manage and push down software upgrades. Software as a service is usually provided on a fee for service approach that may result in cost savings compared to the traditional local area network. Think of it as somewhat like renting as opposed to owning.

Cloud computing is not a technology of the future, but is here today. Google, for example, uses this approach to provide its suite of business applications intended to compete with Microsoft Office. Google applications are provided free or at very little cost. Salesforce.com is one of the best known providers, providing customer relationship management ("CRM") software to a growing list of companies. IBM and Microsoft are also entering the playing field.

There appears to be little doubt that cloud computing is here to stay, and that it may indeed represent the future of information technology. There are many advantages and potential advantages to the cloud computing model.

That said, from a legal perspective, cloud computing raises a host of issues. Having spoken recently to several cloud computing vendors, there are some rather obvious questions. Perhaps the most obvious question is, "What happens if you lose my data?" The answers I was provided focused on technical and not legal issues, such as the back-up procedures provided.

Technical issues are important, and there are certainly technical issues that a potential customer may want to consider, such as maintaining a back-up on site, or a back-up through a separate vendor. These approaches might provide some real practical protection in the event of a catastrophic failure or bankruptcy at the primary provider. Other technical issues might focus on what happens when the relationship ends, whether happily or not. Is there another vendor that can provide the software and host the data? Will data have to be converted to a different format? If the customer decides to switch back to a local area network, will the terminals that have been used for cloud computing (which, I am told, can be very basic "low powered" machines) be of any use, or will a completely new network need to be installed?

Although technical solutions are a good thing, over twenty-five years of litigation experience have taught me that disasters do happen, even with fail-safe plans in place, and even with parties acting in complete good faith. And, I suppose, it is natural for a lawyer to focus on legal rights and remedies rather than technical solutions.

From a legal standpoint, cloud computing appears to raise a host of essentially contractual issues to be addressed by the parties' contract or licensing arrangements. There are also potential regulatory issues (ranging from privacy to export control issues), potential e-discovery issues, and certainly other issues that have not yet crossed my mind.

As businesses and their lawyers become more experienced with cloud computing issues, it is likely that a consensus will emerge as to how cloud computing issues will be addressed. Hopefully, purveyors of cloud computing services will be flexible and reasonable in addressing legitimate business concerns. However, given the prevalence of "standard" licensing in the software field (often on a shrinkwrap or clickwrap basis) and efforts to limit liability under any circumstances, there is some cause for pessimism.

All that said, here is a list of issues that one might wish to consider asking a vendor or otherwise considering in entering into a possible cloud computing arrangement:


What contractual obligation will you assume to protect my data? This could include reference to particular steps and procedures, including back-up obligations. The contract or license may specify a standard of care that the provider must meet.
What contractual obligation will you assume regarding uptime, if any? Will you provide any type of uptime warranty? Even if such a warranty is subject to a limited remedy, it probably would provide considerable incentive for the provider to limit downtime.
Most providers seem savvy enough to disclaim any interest in your data and will freely say -- in a sales setting anyway -- that "your data is your data." Well, that's good, but how do I physically get my data back at the end of the contract or if you go bankrupt?
What remedy limitations, if any, are in your terms? Are consequential damages excluded? Are total damages capped (such as to a return of fees paid)? Even if contractual obligations are assumed, if remedies are severely limited, the provider may be shielded from liability.
Where is my data going to be stored? Are you willing to agree that all my data will be kept in this location under specified conditions and at agreed security levels? This could be important for regulatory reasons, but also for reasons associated with meeting general customer confidentiality obligations or complying with privacy policies.
Have you inserted a forum selection clause into the terms? Many providers want to insist on litigating on their home turf (which often, it seems, is California), but that is rarely a happy instance for a customer.
How do I get out of this arrangement if you do not perform and what is my exit strategy? What rights do I have upon termination? What obligations do you have to assist in transitioning to a new vendor or back to a self-managed platform?

If you are considering going to the cloud, you should consider involving your business and technology lawyer early in the process. As stated, there are probably many other legal issues that have not even occurred to me. It is clear, however, that lawyers need to begin considering these issues, because cloud computing is clearly not going away.




John L. Watkins is a Shareholder of Chorey, Taylor & Feil, a Professional Corporation, a business litigation and business law firm in Atlanta. John has been a commercial litigator for over 25 years, and has handled a wide variety of cases. Currently, John's litigation practices concentrates on trade secret (including computer data misappropration), insurance coverage, corporate, shareholder, and commercial contract matters. Joh also negotiates and drafts sales contracts, non-disclosure agreements, and other business documents. John represents domestic and international companies or their U.S. subsidiaries. He has spoken frequently at public and private domestic and international seminars on various legal topics.

John graduated first in his class at the University of Georgia law school in 1982. He was named to the list of Georgia Super Lawyers in Business Litigation by Atlanta Magazine and the Journal of Law and Politicis. John is rated AV by the Martindale-Hubbell Law Directory, its highest rating, and 10.0 by the AVVO website, its highest rating. More information can be found at the firm's website, http://ctflegal.com, or its podcast page, http://ctflegal.blip.tv




A Beginners Guide to the World of Cloud Computing


Cloud computing has taken off and is now accepted in the business world as an viable and safe alternative to the traditional network server and hardware based IT Infrastructure. For some though the terminology can still be overwhelming to the beginner. In simple terms, Cloud Computing means your IT (information technology), your files and applications are stored in the 'cloud', another term for the internet, instead of being on your own network server hardware.

It can be a cheaper option for some businesses as you now no longer need to purchase applications, hard drives or back up disks or software every again. All of your data and files are stored on the 'Cloud' and rented through a cloud hosting provider.

IT as a Service on the Cloud

Moving IT infrastructure to cloud computing sees delivery of IT resources as services incorporating infrastructure as a service (IaaS), platform as a service (PaaS) and software as a service (SaaS) over the internet. The advantages, beside the cost benefits of not need to constantly upgrade hardware, are that business operations tend to be faster, more flexible and highly efficient.

To access the 'Cloud' and all your data and applications, all you need is a cloud computer called a Notebook or Netbook and an internet connection with a cloud hosting service provider. You do not need expert technology knowledge or cumbersome computer hardware. If you can operate a lap top and a browser you can easily become a user of cloud computing.

A Cloud computing service provider allows for common business applications online, as mentioned above, accessed from a web browser. Business software and data are stored on the servers of your cloud host.

The Benefits of Moving to the Cloud

* Reduction in capital expenditure over the long haul (no need to constantly invest in new infrastructure)

* Increases business operations efficiency

While security and monitoring have been issues in the past with moving to the cloud, much of this is sorted out now with the military and Governments moving off hardware. This move has seen a dramatic maturation of cloud security. Security is becoming less of a problem as more larger companies move their entire IT infrastructure to cloud computing. It is still always a good idea to check with your cloud host or provider, what their back up and security protocols are and be satisfied you data and files will be in safe hands.




For more information visit the Cloud Computing Guide.




The Debate Over Public Vs Private Cloud Computing


Whenever discussing cloud computing systems, you will often hear mentions made to private and public clouds, along with debates over the comparative advantages of each. To the cloud technology novice, this entire private cloud vs. public cloud dispute can sometimes sound like it is being debated in a foreign language. The following article identifies the differences between public and private cloud computing, and explains their important differences in common terminology.

Defining Private Cloud Technology

To put it simply, private cloud technology is a type of architecture that is set up for a lone client (generally a large business). With this kind of arrangement, the provider controls the framework but enables the client to control data storage, as well as the manner in which it's transferred. It's this higher degree of customer control that makes private cloud technology popular with clients who happen to be particularly concerned about security.

Benefits of Private Cloud Solutions

By providing the customer additional control, the private cloud is able to eliminate many prospective security concerns. By shifting its existing IT system to the cloud, the client will be able to enjoy the conveniences of scalability, flexibility and better productivity, but has the ability to do so without having to sacrifice the accountability for data security that may be related to public cloud computing systems.

The Disadvantages to Private Cloud Technology

Possibly the biggest problem with private cloud services is that often the end user must purchase computer hardware, configure it, and be able to continue to maintain it. While the public cloud consumer can essentially buy a cheap, ready-from-the-box system that can be employed immediately, the private user has to commit substantial capital up front to get a system that will be hosted internally, and then continue to deal with its management going forward. So as to benefit from the increased security that comes with a private solution, this is the required trade-off.

Understanding Public Cloud Computing

Instead of the closed design in the private cloud, public cloud computing solutions are almost always available to the public. Consequently all users using the service manage their files, and utilize software and platforms from a shared network server. The cloud computing vendor handles all online security and control over data files and software.

Advantages of Public Cloud Solutions

In terms of flexibility, scalability, hassle-free operation, and cost-effectiveness, public cloud technology surpasses private cloud alternatives each day of the week. The ability to make use of all services, especially infrastructure, on a pay-per-use framework, and become rid of the problems connected to their routine management delivers what many business users point to as the greatest advantage of cloud technology.

The Drawbacks to Public Cloud Systems

As alluded to in the previous paragraph, weaker security is the main relative disadvantage in public cloud technology. That isn't to suggest that public services do not possess security - quite a few have fantastic procedures in place - however, for clients who deal in large amounts of very-delicate personal data (e.g. financial businesses), the very idea of entrusting this information to a third party can often be intolerable.

You Choose Which is Better! Public Cloud or Private Cloud Computing?

The answer to this specific question clearly will depend on the client's kind of business. While public cloud services would seem to have public options beat on most fronts, the point that they put the responsibility for guarding client's confidentiality in the hands of another party is not just unnerving, but can even cause legal problems in some areas.

To lay this particular round of the debate to sleep, if your business does not require an elevated amount of data security, then the public cloud option will be better to fill your needs. Should your company deal in privileged customer data, though, private cloud computing options will still supply you with much improved scalability, flexibility and ease of use, however you will wind up paying more to have greater security.




If you would like to find out more about how cloud technology can benefit you personally and professionally, visit Roy Valance's review of the top cloud computing companies!




What Is Private Cloud Computing (Dedicated Cloud Computing)?


One of the hottest phrases in technology today is private cloud computing and you might be scratching your head wondering what this is all about. This type of computing (also known as dedicated cloud computing), is not your standard type of Internet hosting. This type of hosting is so much more.

Private cloud computing is a type of Internet hosting in which a client leases an entire server that is not shared with anyone else. This type of service offers the client more flexibility because organizations now have full control over their servers. This level of control means the company has their choice of operating system, hardware and more. Private clouds are made up of a proprietary computing architecture that provides hosted services to a limited number of people behind a firewall.

With this private type of computing, corporate network and data center administrators become service providers that meet the needs of the individual or company. A company generally chooses dedicated computing because it allows them to operate their IT applications in a cloud, but they still have full control over data and resources.

Private cloud computing also offers a number of other benefits.

If there is an increase in demand on IT systems, private cloud can scale to meet these demands, which offers companies a level of elasticity that they would otherwise not have.
Organizations control their data, which ensures that all the information within the cloud is secure.
Computing capacity is reduced by giving higher-priority tasks more power during peak hours.
Companies enjoy reduced overhead because in a virtual data center, x86 servers and other related resources can be managed as a unit rather than separately.
Most IT professionals today realize that this type of computing is the future. By investing in this technology, they're helping their company prepare for the future.

No matter what you call it, private or dedicated cloud computing services are the future. Investing in this type of Internet hosting today can save your company money while ensuring that computing resources are used efficiently and that all information is secure.




Bryan Smith is the VP of Sales & Marketing at Expedient, a company specializing in cloud computing services. With Smith's years of experience in cloud computing, he has ensured that each dedicated cloud with Expedient operates at maximum efficiency. Smith's expertise has ensured that each client's data is secure at all times.




Home Computing in "The Cloud"


The trends lead me to believe the computing we do at home will soon predominately reside "in The Cloud." This means the applications we use and rely on everyday are not on our computer at home but in an application out on the Internet and accessed by your browser.

Move Yourself To "The Cloud"

Many folks have already made the move. Here are some of the typical things others have done and what you can do to make the switch yourself:



Use Google Docs as your basic productivity tools. Not only are they very effective and free tools, but they are on-line and available wherever you go (docs.google.com). You don't need to buy Microsoft Office or even download the free Open Office at OpenOffice.org. I find that on my six year old PC, Google Docs will launch an application (e.g., Documents, Spreadsheet, GMail, etc.) in The Cloud faster than I can launch a Microsoft Office product (e.g., Word, Excel, Outlook, etc.) on my PC. Also, there is freedom in not being tied to that one PC sitting someplace where you can't always get to it. A notebook works pretty well in this regard, but what happens when that notebook breaks or it goes missing? It kind of feels the same as when you lose your wallet or your keys. It does not feel good at all. With home computing in The Cloud, it is a problem to lose your equipment, but little of what you had been working on is lost.

Use Mint.com, Quickenonline.com or other online financial tracking programs. First, they are currently free. That is one big advantage. They are not as good, in my opinion, as an installed program such as Quicken, at least not yet. However, if you are doing nothing other than wanting to track your current balances to ensure your cash flow is positive (i.e., not overspending), then these look like great tools.

Use Facebook, LinkedIn or other social networking sites. These sites provide a powerful place to manage your social and professional life. This includes keeping in touch with family and friends and showing your photos, to staying networked with business associates and looking for that next big opportunity.

Get your news from CNN.com, USAToday.com or get more focused news of interest from more specialized sites. For example, I pour through consumerist.com and pcmag.com for practical information I can use every day.

Access "The Cloud" From Anywhere

Because I've moved much of my mainstream computing to The Cloud, I find I can access it from just about any PC and from my mobile phone. Having my Cloud in my phone, which can browse the Internet, is a phenomenal tool. If the Palm Pre or the iPhone were to work with my wireless service provider, I would upgrade and give up my trusty Motorola A1200.

Use "The Cloud" But Backup Your Critical Data

Do keep backups of your data, especially data you need to access your sites on the web.

For passwords I use Password Safe which is free from sourceforge.net. This way I have all my passwords in one place. Consequently, I also have all those key sites I access in this same place. (This, I discovered, was very handy when I changed my e-mail account recently.) I backup the password file everyday to The Cloud using IDrive.com. I also do a monthly backup of the password file to a USB drive which I keep stored in a fire safe.

Be Secure In "The Cloud"

The scariest part of moving to the Cloud deals with the protection of your privacy and with security of your information. I admit this still worries me a bit. Can I really trust Google? Or how about trusting QuickenOnline.com with my financial data? We hear about data breaches every day. Some hacker broke in and stole personal information from thousands of customers. I have been notified more than once that this has happened at a company with which I do business. I have free credit monitoring right now due to a recent incident at an investment company.

I have also been called by my bank asking about charges made to my credit card. They turned out to be fraudulent and the bank removed the charges from my account. What was interesting is that I had just downloaded my most recent bank transactions into Quicken. I did not see these fraudulent charges. I immediately did another download of my bank transactions. There they were, along with transactions reversing the charges. My bank had detected and responded very quickly to these illegitimate activities.

My confidence in reasonable security in The Cloud is based upon my doing business over the Internet since the early 1990s when the Internet opened to commercial sites. The examples with my bank and with my investment company have helped reassure me that they are proactively trying to minimize the risk of loss. There is no guarantee of security. However, it is not obvious that your risk of loss is any greater in The Cloud than it is anywhere else.

"The Cloud" Is Here And Advertising Will Pay For It

I do believe that what we know as personal computing is moving into The Cloud. In the near future we will have much less reliance on a single piece of equipment loaded down with lots of pricey software, much of which we will never use.

Of course, like the broadcast media for decades, this Cloud is driven by advertising. So just as we once watched TV for free, before cable, and still listen to radio for free, it looks like we are going to a personal computing Cloud paid for by advertising. The personal computer will be needed to access The Cloud, but your software applications and information will be in The Cloud and not on your personal computer.





Bruce Benson is a Software Development and Information Technology Consultant. He writes about: You Are Your Most Important Project Management Tool! at Project Management Tools That Work!

(c) Copyright - Bruce W. Benson. All Rights Reserved Worldwide.




The Pros & Cons of Cloud Computing, and is it Secure?


Remember, our simplified definition of cloud computing consists of shared computing resources that are virtualized and accessed as a service through an APL.

The Pros

1- Costs/capital expenditures

If cloud computing is right for your company, then major cost savings can be seen in buying and maintaining the needed infrastructure, support equipment, and communication costs. The vendors and/or service provider, who charge the users a utility or user type fee, own these costs.

2- Scalability

One of IT's biggest problem is the constant need to add more equipment to keep up with the growing demand of accessing, storing and analyzing information by both internal and external users. One example is in the data center where adding servers is a major cost issue (actually power for the data center is the number one issue, but it is related to the growing need for items like servers). Since cloud computing is virtual, one can expand or contract equipment/infrastructure as demands change.

3- Start - up

Since the cloud (theoretically) contains the infrastructure and applications, all one just needs to do is "dial" in to the cloud. One can start using applications immediately versus a customary installation, testing and then providing access to the appropriate user community. (Training is assumed to a constant.)

4- Business Applications

Again, the cloud (actually the vendors and/or service providers) through contracts (Service Level Agreements -SLAs) provides numerous business applications for any user who is their client. Again like scale, enterprises only need to know which applications they need to run their business and understand what is actually provided to have access to various business applications. (Training is assumed to be a constant.)

5- Flexibility

Since cloud computing is a virtual offering, a user has the flexibility to choose, on a regular basis, the applications, amount of bandwidth or the number of users by basically modifying his user contract and increasing or decreasing costs at a known rate or factor.

The Cons

1-SLA Agreements

This is the tricky and most important one. SLAs can be very involved and it really leaves the onus on the user to understand and define all requirements in specific detail, and more importantly understand what one is getting in the terms of support, performance, security, etc. A good example is quality of service; one should understand what is offered and what the recourses are if the specified quality is not maintained.

2-Performance

Performance guarantees are usually part of the SLA document, but I have singled this one out because it is critical to maintain the performance (uptime) one needs both for internal AND external users. Understand if the performance guarantee is defined as an average or just during peak times versus a "uniform" performance. If performance is compromised, it can impact many things including revenue and your company's goodwill.

3-Vendors

Not all vendors are created equally! Many vendors are claiming to provide cloud computing, but in reality, they are just providing a specific service, or a specific application or worst they are a middleman and provide no value-add at all. As I sated in my previous posting, one needs to understand the difference between cloud computing and hosted services or managed services or seemingly some form of virtualization. My best advice is to definitely get with reference customers and see if they model what you would like from the cloud.

4-Security

We all know that the internet has some security issues and since the cloud utilizes the internet coupled with applications infrastructure and support, users should be aware of the potential for new threats and increased risk exposure. It is important to include your firm's risk tolerance in any decision to move to cloud computing, as not all the security issues are understood, and new ones will arise.

5-IT Staffing

If one does utilize the cloud, then make sure one understands the vendor staffing that is available to support your needs and hundreds of others using their cloud. A number of vendors out-source staffing and some of the personnel may not be as good as your own internal organization. Ask the potential service provider if they have trained personnel to support the applications you request.

As I have always stated, know your strategy for your IT organization and your lines of business and weigh whether the "pros" out weigh the "cons" for going with cloud computing. Note that there are a number of advantages and disadvantages; do not be swayed by looking at cloud computing from only a cost-saving point of view.

In all probability the answer will be some thing in the "middle", i.e. some hybrid form of cloud computing.

As for security and cloud computing

In Forrester's article titled " A Close Look At Cloud Computing Security" by Chenxi Wang, Ph.D. Wang states "While cloud computing is able to deliver many benefits, organizations should not jump on the "cloud" wagon without a compelling business driver and a clear understanding of the security, privacy, compliance, and legal consequences. An effective assessment strategy covering these items will help you reach the ultimate goal: Make the cloud service work like your own IT security department and find ways to secure and optimize your investments in the cloud."

Forrester includes data protection, disaster recovery, and identity management as some of the areas under security and suggest that an audit of the potential cloud provider to see what level of security is actually provided.

As for compliance, the user should analyze how the cloud may or may not impact one's compliance requirements.

For legal and contractual issues, Forrester advises that one understands who owns/is responsible for what, between the user and the provider (the data, the infrastructure, etc.)

Another article by Network World's Jon Brodkin titled "Gartner: Seven Cloud - Computing Security Risks" he talks about seven security risk areas.

1. Privileged user access, sensitive data processed outside the enterprise.

2. Regulatory compliance, how does the cloud provider match your guidelines?

3. Data location, where exactly is your data housed?

4. Data segregation, understand that your data is "sitting" next to other's data

5. Disaster Recovery, what happens when there is an outage?

6. Investigating inappropriate or illegal activity may be impossible in cloud computing,

7. Long-term viability, what happens if your provider "goes away"?

Another article in Network World that reported on the RSA conference, and stated that the former technical director of NSA, Brian Snow is very concerned about vendors offering cloud computing from a security point of view. He is concerned about vendors not addressing current security issues and about new issues that cloud computing will create. Ironically another panelist was concerned about "Big Brother" listening in on cloud computing and how this might impact enterprises' privacy and compliance issues.

So to wrap up, the internet has security issues, and since cloud computing is in the internet, cloud computing will have those security issues, ones listed above, and ones yet to be discovered. It comes down to the risk profile for your corporation; what level of risk is right for your company relative to investing in cloud computing? Obviously part of the risk assessment depends on your type of company. If you are a financial advisor or in stock management where your intellectual property is basically the company then cloud computing as we currently know it is not right for you at any cost savings. If you resell ping -pong balls (no offense to ping- pong ball resellers) than the risk is relatively low and the savings from cloud computing outweigh the security and other considerations.

Have you conducted an adequate risk assessment before deciding to move to cloud computing?




Dick Lush http://www.firealarmmarketing.com or dick.lush@firealarmmarketing.com or phone 508-643-0411

Fire Alarm Marketing is a marketing and business development consulting team that focuses on product introductions, revenue generations, building partnerships and creating new opportunities and markets. We are a New England based company with more then 40 years of collective experience.




Security Challenges for Cloud Computing - How Prepared Are You?


Cloud computing is here, and has been embraced by many an organization. Cloud computing as defined by the US National Institute of Standards and Technology (NIST) is "a model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction." [1]. Cloud computing is basically about outsourcing IT resources just like you would outsource utilities like Electricity or water off a shared public grid. The cloud services options include:

Software as a Service (SaaS): Whereby the consumer uses the cloud provider's applications running on a cloud infrastructure and the applications are accessible from various client devices through a thin client interface such as a web browser (e.g., web-based email).

Platform as a Service (PaaS):Here the consumer deploys their own applications on the provider's infrastructure. This option allows the customer to build business applications and bring them online quickly they include services like, Email Campaign management, Sales Force Automation, Employee management, Vendor management etc...

Infrastructure as a Service (IaaS): The consumer has access to processing, storage, networks, and other fundamental computing resources where the consumer is able to deploy and run arbitrary software, which can include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure but has control over operating systems; storage, deployed applications, and possibly limited control of selected networking components (e.g., host firewalls).

Cloud computing has become popular because, Enterprises are constantly looking to cut costs by outsourcing storage, software (as a service) from third parties, allowing them to concentrate on their core business activities. With cloud computing, enterprises save on setting up their own IT infrastructure which would otherwise be costly in terms of initial investment on hardware and software, as well as continued maintenance and human resource costs.

According to the Gartner report on cloud security [2], Enterprises require new skill set and to handle the challenges of cloud security. Enterprises need to see to it that their cloud service provider has most of "the boxes ticked" and that they have their security concerns addressed. Cloud computing being a somewhat a new field of IT with no specific standards for security or data privacy, cloud security continues to present managers with several challenges. There is need for your provider to be able to address some of the issues that come up including the following:

Access control / user authentication: How is the access control managed by your cloud service provider? To be more specific, Do you have options for role based access to resources in the cloud,? How is the process of password management handled? How does that compare to your organization's Information security policy on access control?

Regulatory compliance: How do you reconcile the regulatory compliance issues regarding data in a totally different country or location? How about data logs, events and monitoring options for your data; does the provider allow for audit trails which could be a regulatory requirement for your organization?

Legal issues: Who is liable in case of a data breach? How is the legal framework in the country where your cloud provider is based, visa vi your own country? What contracts have you signed and what issues have you covered/discussed with the provider in case of legal disputes. How about local laws and jurisdiction where data is held? Do you know exactly where you data is stored? Are you aware of the conflicting regulations on data and privacy? Have you asked your provider all the right questions?

Data safety: Is your data safe in the cloud? How about the problems of Man-in-the-middle attacks and Trojans, for data moving to and from the cloud. What are the encryption options offered by the provider? Another important question to ask is; who is responsible for the encryption /decryption keys? [3]. Also you will find that cloud providers work with several other third parties, who might have access to your data. Have you had all these concerns addressed by your provider?

Data separation / segregation: Your provider could be hosting your data along with several other clients' (multi-tenancy).. Have you been given verifiable assurance that this data is segregated and separated from the data of the provider's other clients? According to the Gartner report, its a good practice to find out "what is done to segregate data at rest," [2]

Business continuity: What is the acceptable cloud service down time that you have agreed with your provider? Do these down times compare well with your organization acceptable down time policy? Are there are any penalties/ compensations for downtime, which could lead to business loss? What measures are in place by your provider to ensure business continuity and availability of your data / services that are hosted on their cloud infrastructure in case of disaster? Does your provider have options for data replication across multiple sites? How easy is restoring data in case a need arises?

Cloud services providers have increased their efforts in addressing some of the most pressing issues with cloud security. In response to cloud security challenges, an umbrella non-profit organization called the Cloud Security Alliance was formed, some of its members include: Microsoft, Google, Verizon, Intel, McAfee, Amazon, Dell, HP, among others, its mission is "To promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing" [4]

As more and more organizations move to the cloud for web-based applications, storage, and communications services for mission-critical processes, there is need to ensure that cloud security issues are addressed.

References

1. National Institute of Standards and Technology, N., Cloud Computing definition, I.T. Laboratory, Editor. 2009.

2. Gartner (2008) Assessing the Security Risks of Cloud Computing

3. Rittinghouse, J.W. and J.F. Ransome, Cloud Computing: Implementation, Management, and Security. 2009., New York: Auerbach Publications.

4. Alliance, C.S. Cloud Security Alliance. 2011; Available from: https://cloudsecurityalliance.org/.




About the Author

Mr. Thomas Bbosa, CISSP, is an Information Systems security Consultant and Managing Partner with BitWork Consult Ltd - ( http://www.bitworkconsult.com ) a leading East African IT security consulting firm, based in Kampala, Uganda. He is a certified Information Systems Security Professional (CISSP), with over 12 years Experience in the IT industry. He has been involved in various roles of IT infrastructure management and support, Information systems Security management & solutions deployment.




Get Your Head Into the Cloud: What Is Cloud Computing?


Everyone from the government, to large corporations, to small businesses and university programs are talking about Cloud Computing (the Cloud) these days, but just what is cloud computing anyway?

The National Institute of Standards and Technology, Information Technology Laboratory, an agency of the U.S. Department of Commerce, founded in 1901 as the nation's first federal physical science research laboratory, also known as NIST, is the government's authority on all matters pertaining to securing our nations information systems. According to NIST, cloud computing "is a model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This computing model promotes availability and is composed of five essential characteristics, three service models, and four deployment models."

Basically, cloud computing is a developing word that defines the expansion of many current technologies and computing methodologies into something new and different. The cloud divides application and information resources from the basic infrastructure, and the tools used to distribute them.

For organizations adopting this methodology, using the cloud improves cooperation, agility, scaling, and availability, and by improved and efficient computing practices, provide the possibility of cost reduction for the organization.

More precisely, cloud computing defines the use of a collection of services, applications, information, and infrastructure containing pools of compute, network, information, and storage resources. These mechanisms can be swiftly arranged, provisioned, implemented and decommissioned, and scaled up or down. This in turn provides for an on-demand utility-like model of allocation and consumption that is very beneficial to organizations.

From an information architecture viewpoint; there is much misunderstanding about how cloud computing is both like and different from existing models of computing; and how these likenesses and differences impact the organizational, operational, and technological methods to network and information security practices.

The solution to appreciating how this computing architecture influences security architecture are a common and concise lexicon, joined with a static arrangement of selections that can analyze cloud services and architecture, plotting them to a model of compensating security and operational controls, risk assessment and management frameworks, and ultimately to compliance standards that can be adopted by organizations choosing to utilize all the cloud has to offer.




Derek A. Smith is IT Security Manager, Consultant and Associate at a large Fortune 500 company. He is an expert at Information, Cyber, and Physical security with 30 years' experience in the security and law enforcement industry. To learn more visit Derek's website at http://www.Cybersecuritysamurai.com




Security and Cloud Computing


Cloud computing and its potential to offer powerful computing and data storage options to even bootstrapped small businesses at highly competitive prices have generated plenty of excitement in the industry. So much so, however, that critical questions regarding the security of the data stored "in the cloud" are often overlooked by its most enthusiastic adopters. It's understandable, given the heavyweight names behind some of the biggest cloud computing projects in the world. (Google Apps, anyone?) If companies like Cisco and Oracle are betting their futures and fortunes on cloud computing, surely that must mean that all the kinks have been worked out already, right? Or at the very least, security must be a top priority for them as well, given their zealous approach to network security in general, and we can all enjoy the trickle-down effect of their tireless efforts to firewall our data from any and all security breaches.

Right?

Well, yes and no. Cisco CEO John Chambers admitted as much in a speech he delivered in 2009 that, while cloud computing presents innumerable opportunities, it's also a "security nightmare." And with good reason. Some of the security issues that cloud computing providers must address in order to allay customer fears include:


Multi-tenancy issues. Cloud computing, by definition, involves shared data storage among a number of users spread across multiple companies and locations. Providers must be able to reassure corporate clients that users from another company will not be able to gain access to - accidentally or otherwise - their account and information.
Data loss and recovery. What happens in the event of a catastrophe that results in data loss? Does the provider have a rigorously and regularly tested backup solution to ensure data recovery? If a problem occurs in one client's account that results in data loss, does the provider have fail-safe systems in place to ensure that a devastating cascading effect doesn't occur that will lead to data loss among their other clients? What if the cloud computing provider goes out of business, is bought or taken over by another company, or declares bankruptcy? How will its clients be assured that their sensitive corporate data won't be lost in the transition or closure?
Storage and hosting information. Where is the data itself physically stored? Are the servers somewhere in Silicon Valley, Chicago, or Bangalore, India? Who provides the actual hosting services? If the host provider is a third-party, has the cloud computing provider properly vetted its credentials to ensure that they adhere to industry standards for data security?
Security tests and updates. How often is the software or platform updated? How often is it tested? During and after testing, does the provider have systems in place to ensure that any updates or tweaks not result in security breaches? You'll want to make sure that unauthorized users - from your company, your provider or a third-party - don't inadvertently gain access to your information.
Compatibility of different security policies. If your company has an established security policy regarding sensitive client and corporate information, does it differ from the policy offered by the provider? Is the provider willing to meet your internal standards of security? What about third-party companies with whom the provider does business and who may be involved in some way with the service? Will they adhere to your corporate standards as well?
Collaboration issues. One of the most appealing benefits of cloud computing is its ability to promote collaboration among its users, either with internal staff or external parties. Does the software or platform provider have systems in place to ensure that collaboration doesn't compromise security?
Human resource issues. Who within the provider will have access to your company information? Who is in charge of data security? Are they made available to you to discuss any concerns you may have? Can they adequately address your questions to your full satisfaction? What is their experience and background in corporate data and network security?
Downtime reports and frequency. How often does the company's servers experience downtime? Will they make their downtime reports available to you so that you can investigate the reliability of their network? Do they have systems in place to ensure that your data is secure and that no unauthorized users will have access to your account both during and after the downtime periods?
Cyberattack defense. It's inevitable that cloud computing is the next great frontier for cyberattackers salivating over the vast amounts of sensitive information concentrated in a relative handful of services, all available on the web. How does the provider plan to address potential cyberattacks, because it's only a matter of when, not if, they'll experience a hacking attempt on their network?

This list is just the beginning. The best cloud computing providers spend the majority of their waking hours - and I'd be willing to bet some of their dreaming hours, too - thinking about security issues and how they can be proactive in the face of increasing threats that can potentially compromise their clients' business and destroy the trust and faith that they've built with their audience. It's an ongoing conversation that we at Mothernode are excited to be a part of, and one that will be consuming our industry for the foreseeable future.




Ken Pearson
President
Mothernode, LLC
(800) 928-6055 x300
ken.pearson@mothernode.com
http://www.mothernode.com

Mothernode is a Software-as-a-Service (SaaS) business system that offers Small and Medium Business (SMB) a suite of powerful on-demand applications, components and expansion packs designed to streamline all aspects of operations. The software suite includes Salesforce Automation, Customer Relationship Management (CRM), Enterprise Resource Planning (ERP), Order Fulfillment, Quoting and Proposals, Inventory Control Systems (ICS), Vendor Access, Invoicing, Performance Indicators and so much more.




Will Cloud Computing Crush Viruses from Catastrophic Calamity on Your Computer?


Will Americans be any safer from the coming cyber storm as Internet Technology evaporates into the clouds? Will users be safe from hackers with cloud computing? Will their data, identity, money, etc, be safe in the clouds? I wonder, I am very skeptical, but let's talk.

There was an interesting article recently in Homeland Security news which discussed the inherent safety of cloud computing running devices with no executable files, or ways for computer viruses to get in and load themselves onto the computer. The article was titled "Is Google's Chromebook impervious to viruses?" which was published 16 May 2011. Have you heard about the new laptops Google is planning, they will run on completely on the cloud, and without the need for Anti-Virus software - what about the computer anti-virus software industry the article asks? Good point indeed.

Now then, I have a question about all this; what about an internal challenge at the data center, or elimination of the data center due to a terrorist attack? What if a disgruntled employee puts a virus into that data center? The article also states I am not alone in my worries, "but, not all analysts are convinced that Google's Chromebook is as secure as they claim; this move to a cloud based computer could signal a broader shift that could hamper the antivirus industry's future prospects."

They Promise to Save Us from Cyber Pearl Harbor Attacks - But Can We Trust Them?

The US Government is also working on Cyber Security too. Yes there was a very interesting article in Physorg [dot] com recently titled; "White House unveils global cyberspace strategy" by Chris Lefkow posted on May 16, 2011, which states in the first sentence that they administration "unveiled a set of policy proposals Monday for international cooperation in ensuring an open and secure Internet," and in the article it stated that; "To date, the international community has lacked the collective willingness to engage in a meaningful conversation on the need for a global approach," he said. "US leadership is critical to reaching a consensus solution."

Can we really trust this Administration to protect the American People from Cyber Attack? No, absolutely not, say I, but let me explain my points of contention why. First, if the government attempts to move to all devices being on the cloud, and it can control everything (for reasons of security) then in essence they will create another "Great Wall of China" type scenario, basically eliminating any and all privacy - forever. As an American, well, you can understand I have a problem with all of this.




Lance Winslow is the Founder of the Online Think Tank, a diverse group of achievers, experts, innovators, entrepreneurs, thinkers, futurists, academics, dreamers, leaders, and general all around brilliant minds. Lance Winslow hopes you've enjoyed today's discussion and topic. http://www.WorldThinkTank.net - Have an important subject to discuss, contact Lance Winslow.




Will Cloud Computing Crush Viruses from Catastrophic Calamity on Your Computer?


Will Americans be any safer from the coming cyber storm as Internet Technology evaporates into the clouds? Will users be safe from hackers with cloud computing? Will their data, identity, money, etc, be safe in the clouds? I wonder, I am very skeptical, but let's talk.

There was an interesting article recently in Homeland Security news which discussed the inherent safety of cloud computing running devices with no executable files, or ways for computer viruses to get in and load themselves onto the computer. The article was titled "Is Google's Chromebook impervious to viruses?" which was published 16 May 2011. Have you heard about the new laptops Google is planning, they will run on completely on the cloud, and without the need for Anti-Virus software - what about the computer anti-virus software industry the article asks? Good point indeed.

Now then, I have a question about all this; what about an internal challenge at the data center, or elimination of the data center due to a terrorist attack? What if a disgruntled employee puts a virus into that data center? The article also states I am not alone in my worries, "but, not all analysts are convinced that Google's Chromebook is as secure as they claim; this move to a cloud based computer could signal a broader shift that could hamper the antivirus industry's future prospects."

They Promise to Save Us from Cyber Pearl Harbor Attacks - But Can We Trust Them?

The US Government is also working on Cyber Security too. Yes there was a very interesting article in Physorg [dot] com recently titled; "White House unveils global cyberspace strategy" by Chris Lefkow posted on May 16, 2011, which states in the first sentence that they administration "unveiled a set of policy proposals Monday for international cooperation in ensuring an open and secure Internet," and in the article it stated that; "To date, the international community has lacked the collective willingness to engage in a meaningful conversation on the need for a global approach," he said. "US leadership is critical to reaching a consensus solution."

Can we really trust this Administration to protect the American People from Cyber Attack? No, absolutely not, say I, but let me explain my points of contention why. First, if the government attempts to move to all devices being on the cloud, and it can control everything (for reasons of security) then in essence they will create another "Great Wall of China" type scenario, basically eliminating any and all privacy - forever. As an American, well, you can understand I have a problem with all of this.




Lance Winslow is the Founder of the Online Think Tank, a diverse group of achievers, experts, innovators, entrepreneurs, thinkers, futurists, academics, dreamers, leaders, and general all around brilliant minds. Lance Winslow hopes you've enjoyed today's discussion and topic. http://www.WorldThinkTank.net - Have an important subject to discuss, contact Lance Winslow.