Cloud security: The basics
- 16 June, 2010 02:04
- Comments 1
Cloud computing is one of the most-discussed topics among IT professionals today. And not too long into any conversation about the most highly touted cloud models--software as a service (SaaS), infrastructure as a service (IaaS) or platform as a service (PaaS)--the talk often turns to cloud security.
According to Milind Govekar, an analyst at Gartner, cloud has rocketed up the list from number 16 to number two in Gartner's annual CIO survey of key technology investments. "Like with anything new, the primary concern is security," he says. In fact, the vast majority of clients who inquire about cloud, he says, would rather create a virtualized data center on their own premises--what some call a private cloud--because they're uncomfortable with the security issues raised by cloud computing and the industry's ability to address them.
Read the companion article "Cloud security in the real world: 4 examples"
"We are in the early stages of a fascinating journey into a new computing model that, for all its purported advantages, from a security and risk point of view, is a difficult thing to deal with," agrees Jay Heiser, an analyst at Gartner. "The things that make it easy and appealing--like the immediate plug-and-play productivity--also make it impossible to conclusively assess your relative risks." Current certifications, such as SAS 70 and ISO 27001 and 27002, are not sufficient, he says, leading to frustration for both buyers and sellers.
For this reason, securing cloud computing environments will be a major focus of vendor efforts over the next year, says Jonathan Penn, an analyst at Forrester Research. In the short term, he sees users having to do a lot of the legwork, but over time, "cloud providers themselves will see the opportunity to differentiate themselves by integrating security," he says. Security vendors accustomed to selling directly to the enterprise will find that they need these cloud providers as a way to reach the market, Penn says, and as the market matures, customers will want this stuff baked into the services they're buying. "That will be quite a radical change and a disruption," he adds.
In the meantime, organizations such as the Cloud Security Alliance (CSA) are working to put some shape around the security issues and the ways to address them. The CSA recently released a summary of the strategic and tactical security pain points within a cloud environment, along with recommendations on how to address them. The organization divided the domains into two broad areas: governance and operations.
Domains grouped under governance include:
* governance and ERM
* legal and electronic discovery
* compliance and audit
* information lifecycle management
* portability and interoperability
Domains grouped under operations include:
* traditional security, business continuity and disaster recovery
* data center operations
* incident response, notification and remediation
* application security
* encryption and key management
* identity and access management
* virtualization
The CSA also summarized the top threats of cloud computing, along with the cloud models each threat most pertains to and guidance for remediation.
The categories of tools that can help address these threats include XML, SOA and application security; encryption tools for data in transit and at rest; smart key management; log management; identity and access management; virtual firewalls and other virtualization-management tools; data-loss prevention; and more. "You're translating the existing security architecture into the cloud, so there are a lot of different tools you'll need, some of which already exist and other cases where you need new technology," Reiser says.
For instance, malware scanning tools will need to look specifically for emerging malware that targets virtual platforms; identity management systems will need to authenticate not just users but also devices and applications; and security information management (SIM) systems will need to log billions of events and analytics.
Forrester also released a list of questions that enterprises should ask to secure their cloud implementation, covering the areas of security and privacy, compliance, and other legal and contractual issues.
Cloud layers
Experts also emphasize that the level of exposure and risk for the three cloud models are very different, and the way of addressing security also differs, depending on which layer you're engaging with. "The security requirements are really the same, but as you go from SaaS to PaaS and IaaS, the level of control you have over security changes," says Mike Kavis, founder of Kavis Technology Consulting and CTO at a startup company. "From a logical view, nothing has really changed, but how you physically do it changes dramatically."
SaaS.
As the CSA explains, with SaaS, the provider's applications run on a cloud infrastructure and are accessible through a Web browser. The consumer does not manage or control the network, servers, operating systems, storage or even individual application capabilities.
For this reason, the SaaS model integrates the most functionality directly into the offering, with the least consumer extensibility, and "security responsibilities are almost entirely up to the vendor," Reiser says. "If the vendor doesn't encrypt data, it's not encrypted. If there isn't activity monitoring, you won't get any."
PaaS.
With PaaS, consumers create applications using programming languages and tools supported by the vendor and then deploy these onto the cloud infrastructure, the CSA explains. As with SaaS, the consumer does not manage or control the infrastructure--the network, servers, operating systems or storage--but does have control over the deployed applications and possibly the application-hosting environment configurations.
There are fewer customer-ready or built-in security features with PaaS than with SaaS, the CSA says, and those that do exist are less complete, but there is more flexibility to layer on additional security. This means users need to pay attention to application security, as well as security issues surrounding the management APIs, such as authentication, authorization and auditing.
IaaS.
Here, consumers can provision processing, storage, networks and other fundamental computing resources, as well as deploy and run operating systems and applications, according to the CSA. While they don't manage or control the underlying cloud infrastructure, they do have control over operating systems, storage and deployed applications, and possibly limited control of select networking components, such as host firewalls, the CSA says.
With IaaS, there are few integrated security capabilities beyond protecting the infrastructure itself, but there's enormous extensibility, according to the CSA. This means users need to manage and secure operating systems, applications and content, typically through an API.
Also see "How to avoid the stormier implications of the cloud"
"A lot of the perimeter security is handled by the vendor, but they're giving you access to virtual machines, so you still have to build the application and provide the infrastructure control," Kavis says.
With IaaS, virtualization management is a big concern, says Heiser, particularly when it comes to intrusion detection and the integrity of partitioning virtual machines. "You need to mediate separation and make sure they don't interact with each other," he says.
Chris Barber, CIO at Wescorp, says he is concerned about multitenancy and hypervisor vulnerabilities. "Since you have multiple users on a single physical box, there may be a security vulnerability that one user could somehow access another user's virtual machine," he says.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- HP ePrint Enterprise mobile printing solution
- IDC MarketScape: Worldwide Business Process Platforms 2011 Vendor Analysis
- Risk management: ensuring the security of your hosted information
- A buyer’s guide to application lifecycle management (ALM) solutions
- Justifying Business Intelligence Applications
-
Australia's first 4G smartphone is the HTC Velocity 4G
-
Swedish e-commerce startup's execs linked to NYC sex crime
-
Face Time - Interview with John Brennan and Robert DiStefano
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
Oracle Exadata Database Machine Warehouse Architectural Comparisons
Exadata is Oracle’s fastest growing new product. Much of the growth of Exadata has come at the expense of specialized data warehouse appliance vendors. These vendors have published competitive comparisons to Exadata, claiming: Architecture is what really matters for performance, Purpose-built data warehousing architectures perform best, They see architecture as an end in itself rather than as a means to an end. Read on. -
Information Security Policies, Standards and Procedure
As a result of the adjustments in the way business is conducted, ownership of information does not carry the same clear accountability it once did. Physical and behavioural boundaries used to exist around information management but these can be missing in the modern workplace. Clearly thought-out information security policies, standards and procedures addressing internationally supported standards, will go a long way to addressing the risk exposure these changes have created. In this third paper, “Policies, Standards and Procedures,” we discuss guidelines for effective information security management. -
Pathways Advanced ICT Leadership Development Program Brochure and Course Outline 2012
Developed by the CIO executive Council in conjunction with Rob Livingstone Advisory, Pathways Advanced is a 12-month CIO delivered, small group, mentor based professional leadership development program. Pathways Advanced brings together best practice, thought leadership and business insights for today’s most promising ICT professionals
-
Quicken All-In-One Desk Reference for Dummies
-
Professional Wikis
-
Lotus Notes 6 for Dummies
-
Microsoft Sharepoint 2010 All-In-One for Dummies®
-
The Game Artist's Guide to Maya (Includes CD-ROM)
-
Web Applications
-
John Walkenbach's Favorite Excel 2007 Tips & Tricks
-
Big C++ 2E WileyPlus Standalone Registration Card
-
Introduction to Information Systems








Comments
CloudNinja
Great article outlining critical issues in security in the Cloud. While security needs critical examination - I think that John Mullinax hit it on the head when he commented :"Companies trust their data to external environments all the time. They generally do not trust ALL their data to these environments, for good reasons. But they generally do trust SOME of their data. It's a good dialogue to have - what data is ok in the cloud? -- but as cloud computing is maturing, we also need to have a more nuanced conversation about trust and the cloud. The question of when will everything move to the cloud has largely been answered... it's not likely going to happen.
The Cloud represents a new generation of computing paradigm, but like the platform paradigms that have come before (mainframe, mini computer, PC, client-server, web - all of which are still around) we should not expect the cloud to replace everything that came before it.
The question to ask is what data *would* make sense in the cloud? Or even better, what parts of my technology and data portfolio should live in the cloud?
It's a good discussion topic, and there's no one right answer for everyone. Since Windows Azure has been purposefully designed interoperate/span across on-premise boundaries, there are many options on the continuum between cloud and on-premise.
BTW, with highly automated service provisioning and data center operations, ISO 27001 certification, SAS70 certification, etc... the Microsoft data centers that run Windows Azure are probably "safer" and more reliable than many other environments. More than safety and reliability, what you give up to some degree is loss of direct control. "
IMHO, when considering security, 2 items need to be addressed:
1) Physical security of the hardware 2) Security of the Data - here are some resources I've found that discuss this and act as guidelines when considering security and the cloud:
Physical security:
http://www.globalfoundationservices.com/security/index.html
http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf
Data Security:
http://www.research.microsoft.com/en-us/projects/cryptocloud/
http://www.research.microsoft.com/en-us/projects/secpal/
thoughts?
hope that helps
-cn
Post new comment