27 Sep 2010
The use of public and private cloud technologies raises several security challenges, but none that are impossible to meet. In order to effectively and efficiently secure cloud computing, organisations need to match threats and business demands with the right security approach.
The term "cloud" is overhyped, so let's first get some terminology defined: Gartner defines "cloud computing" as "a style of computing where scalable and elastic IT-enabled capabilities are delivered as a service to customers using internet technologies."
“Private cloud” is similar but where the customers are internal to the business.
Just as there is no one-size-fits-all approach to business success, there are different approaches to using IT for business gain. Gartner has long defined organisations as Type A, Type B or Type C, essentially based on how aggressively an organisation uses technology. Similarly, even organisations in identical industries often have very different levels of risk tolerance and very different approaches to security. Because of this, for Type C organisations, the cost advantages of cloud computing will often cause them to use cloud computing earlier than Type B organisations.
Gartner identifies three broad styles of security that will be applied to public and private cloud computing services.
1: Depend on security built into the cloud infrastructure
Just as operating system vendors, such as IBM, Microsoft and Sun, built some security functions right into their operating systems, and switch vendors such as Cisco did the same in network infrastructure, the vendors of virtualisation technologies for private cloud (such as Citrix and VMware) and the external cloud service providers (like Amazon and Google) will build security technologies into their cloud "operating systems". VMware and Google have already acquired and integrated security. For many smaller organisations and those where security concerns are not a high priority, relying on the built-in security capabilities of the public or private cloud infrastructure will be good enough - as long as there has been some third-party validation of the effectiveness of those security controls. Typical use cases will be:
• Applications that only store or process public data
• Small businesses that are not subject to compliance demands
• Private cloud applications that are well-shielded from external access.
For this scenario, organisations need to focus on the transparency of the security services built into the cloud platform and the quality (and freshness) of the third-party security audit.
Hi John, great article.
Like so many of the concepts associated with cloud, such as compliance and performance, security itself can be broken into a number of sub-components. These include elements such as data at rest, data in transit, ID management, role based access, and log management.
Within an organisation, each of these sub-components is likely to be treated with differing levels of severity. Everyone seems fixated with public and private clouds but it's time we stopped trying to fit everything into a 'box' and accept that the hybrid model is already being used by many enterprises today. I agree also that in time security vendors will develop products and APIs that further enable organisations to push more of their services into the external cloud.
For me, user access is going to become a key component or issue depending on how you look at it. I can see a new 'Security as a Service' model appearing, where a federated approach to user access is provided allowing users to gain access to private and multiple public cloud services and applications from a single repository.
Posted by: Tom Brand 29 Sep 2010
Have your say on this article
Newsletters
Latest stories from Services and Outsourcing
Latest videos
You may also like
Services and Outsourcing jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?