CIO
Gartner on cloud security: 'Our nightmare scenario is here now'
Analyst firm's view on security in the cloud
Ellen Messmer (Network World)  22 October, 2009 05:28:00

At the Gartner Symposium IT/Expo this week, thousands of IT managers packed into sessions on the topic of virtualization of enterprise computers, along with the prospect of adopting public cloud-based services or building private ones. Some say the revolution is underway, and security managers are caught in the middle, losing their earlier controls.

Gartner analysts, including David Cearley and Gene Phifer, trotted out user case studies involving FedEx, Presidio Health, Johnson Diversey and others extolling the public or private cloud, while in a separate session Michael Lock, head of enterprise sales at Google, found himself looking like a budding rock star in front of an huge audience of high-tech execs eager to hear about Google Apps. With new ways of conducting enterprise computing and application development shaking up established IT practices, the darker mood about it all was mainly heard from Gartner's security analysts, recognizing the revolution underway is ripping away the security controls of today.

"Our nightmare scenario is here now," said Gartner analyst John Pescatore. Botnet-driven cybercrime is clearly accelerating as online predators involved in "cybercrime as a service" plunder corporate and consumer data for financial gain. In addition, corporate employees are now using handheld smartphones the company didn’t even issue and spending substantial time on networks not owned by the enterprise.

Now comes cloud computing as service offerings and "obviously attacks will come after this," Pescatore said. In many instances, the fact is the "IT organization is being driven to have less control over software and hardware."

The implication of this, Pescatore said, is they can sit and dream of something pleasant, like the return of the mainframe, or they will have to make a shift to using or developing "security as a service" to adapt to new threat scenarios in both public cloud computing and virtualization of their IT infrastructure.

With the cloud taking shape nebulously as many types of public, private and hybrid services, an important technology to turn to will likely be encryption services. "In the next few years, you'll see encryption services out there," Pescatore said.

Gartner analyst Neil MacDonald also minced no words in describing the implications for security in the virtualization and cloud-computing revolution.

"We're at a critical point," MacDonald said. Adoption of consumer technologies and the transformation of the technical infrastructure in the enterprise means that there's "frustration of the business units with us," MacDonald said.

With virtualization, the key concept of "locking down a physical device" is disappearing in favor of virtual machine-oriented security, such as virtual security appliances as software instead of physical appliances, he said. In addition, the enabling of quick deployment of virtualized applications and databases to facilitate business partnerships will need to be done, though "security becomes very difficult in this environment."

Cloud computing and virtualization "break one of the foundational principles of security architecture: Us and them," MacDonald said.

Known technologies such as signature-based antivirus are now insufficient, increasingly useless and he added, way overpriced. Antivirus must be buttressed with whitelisting to control application use, and the newer software-based virtual appliances for security have to be examined for use in a virtual-machine environment.

About the physical security appliances out on the market today, MacDonald said "these boxes are expensive," and he disparaged Cisco, Juniper and TippingPoint as "not having much going on now because they like to sell boxes."

When it comes to cloud computing services, the security professional is being pressured to "get out of the way" and figure out something that's "secure enough," said MacDonald, though the impulse will be to say no to the cloud.

Though the public cloud "makes sense for less-sensitive data," there are limits, such as "PCI stuff, no way," MacDonald said, referring to the data falling under the Payment Card Industry security requirements.

But there are going to be "trade-offs" as new cloud service offerings, and the stance the security professional should take is to clearly explain the risks to the business owners of the data and make sure they accept it, not push it back onto the security and IT department.

"They get all the accolades and you take all the risk, who wants that job?" he pointed out.

Speaking on a panel at the Gartner conference, a number of CIOs acknowledged their prime concerns are about security in cloud computing.

June Hartley, CIO at the National Business Center of the U.S. Department of the Interior, said security requirements known as FISMA that the U.S. government uses for security compliance will likely be changed to meet the new world of private and public cloud computing. 

Casey Coleman, CIO at the General Services Administration and co-chair of what's known as the Federal Cloud Council, agreed, but both indicated there was no apparent barrier to that.

Sometimes there are some unexpected risks.

Sal Allavarpu, senior director, product marketing at Citrix Systems, a player in the virtualization market which has created virtual appliance versions of its Access Gateway, Branch Repeater and NetScaler security, network and application control appliances, says there are new security issues that arise in virtualization and cloud computing.

For one thing, it's not advised to run applications with different levels of trust controls on virtual machines located on the same physical server, he says. "It's best to keep them separate, virtual machines with the same trust controls on the same physical server," he said, noting auditors prefer this.

Without sharing detail, he said he knows of a recent occurrence in a cloud-computing arrangement where law enforcement going after someone seized the data for the entire physical server even though the suspect had data on just one virtual machine on that server. This caused a lot of consternation among other companies whose data happened to be on that same physical server in separate virtual machines. He noted that virtualization and cloud computing is new to law enforcement in some instances and this kind of issue is still being hammered out.

Mark Hurd, chairman and CEO at HP, who gave the keynote at Gartner yesterday, evoked a knowing chuckle from the audience when he said he has visited with many CEOs and frankly, they didn't like the term "cloud" because they would prefer to think they're operating in "clear skies."

But without tipping his hand, he hinted that HP could be active in this arena itself with cloud-oriented services over time, probably the more private cloud varieties.

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Enter the fully qualified URL, eg. http://www.example.com/
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Zones
Newsletters
Sign up for our CIO newsletters!
Syndicate content Syndicate content Syndicate content Syndicate content

URL
www.kyoceramita.com.au

Call us on
Australia: 1800 339 003
New Zealand: 0508 596 2732

Email us
marketing@kyoceramita.com.au

Did you realise that the cost or running a laser printer over its lifetime is likely to exceed the original purchase price by several times? To compare your current printer's running costwith a Kyocera printer, select the TCO Calculator

Total Cost of Ownership (TCO)
Kyocera Saves... Try our Saving Estimator now
Calculate Now

Testimonials

 

Wondering how to improve your business with UC on an IP Network?

Join Computerworld's Live Webinar where we will address the move many companies are making towards IP based voice services (SIP trunking, VoIP) and look at how they are using a single connection for data and voice rather than separate lines. Learn about the latest in IP networks and how it can help your organisation.

Wednesday 25th November 2009, Time 10.30 am EST (Sydney, Australia) Screening at your desk

Register now

  • +

    CA brings SOA security to open source JBoss 09 February, 2010 10:08:00

    More commercial options for widely-used app server
    CA has announced its SiteMinder and SOA Security Manager products are now available for the open source JBoss middleware platform.
  • +

    Indian pleads guilty in overseas stock hacking scheme 08 February, 2010 07:50:00

    The group of hackers compromised brokerage accounts, then pumped up the prices of stocks
    An Indian national pleaded guilty Friday to conspiracy and aggravated identity-theft charges related to an international fraud scheme to hack into online brokerage accounts in the U.S. and use them to manipulate stock prices, the U.S. Department of Justice said.
  • +

    E-mail scam steals €3 million in carbon credits 05 February, 2010 06:47:00

    The phishing scheme resulted in losses of up to €3 million from companies
    A clever phishing scheme launched last week may have stolen more than €3 million (US$4.1 million) worth of carbon emission permits from companies.
  • +

    Windows 7 Tips: Best Security Features 04 February, 2010 04:52:00

    IT can specify which applications can run on employees' desktops
    For both enterprises and consumers, one of the big draws of Windows 7 has been its tighter security features.
  • +

    Twitter forces password reset to protect some accounts 04 February, 2010 05:48:00

    The company has discovered that log-in information has been stolen in compromised torrent file-sharing sites
    Twitter required some users to reset their passwords on Tuesday after discovering that their log-in information may have been harvested via security-compromised torrent Web sites, the company said.

Upcoming Industry Events
  • No upcoming events available
Whitepaper

Connect and Empower Mobile Salespeople

New technologies can help salespeople on the road be more effective, better manage customer relationships, and close more deals. Want to know more? Download this free white paper now.

CIO Industry Insight Podcast #6: Brenton Smith, Managing Director, CA (ANZ)
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper
Securing People and Information: How to Protect Against Today’s Web-based Threats

This white paper explores the benefits of an Application Delivery Network, highlighting the ability to protect your users and applications and still deliver outstanding application performance with confidence, consistency and cost-effectiveness across your distributed network.

Read Whitepaper

Brought to you by