x



Loading... Please wait...

Blog Author

The Information Security Awareness Forum Blog's blog 13-11-2009 14:56

Clouds over Jericho

As I travelled into London earlier this week for a meeting, I pondered on cloud computing and whether any of the people extolling the concept had any knowledge of the Jericho Forum and the security model it offers.  While I know there is an alliance between Jericho and the Cloud Security Alliance, are the people selling cloud computing products aware of this alliance and if they are, do they support its principle?

It seems to me that cost is the main driver behind the sale of cloud computing (e.g. free or very low cost file storage, office products etc etc) and I don’t see too much about security and what there is tends to talk about virus protection and spam filtering, use of SSL for browser sessions and, if you are lucky, some form of password strength indication.  

So, not a lot hope for a secure world there then – discuss

This Blog has been written by ISAF Blog team member Peter Wenham, CISSP

 



Permalink:
http://www.infosecurityadviser.com/view_message?id=155

Comments:

The Information Security Awareness Forum Blog  15:35 pm, Thu 26th Nov 2009

Nice to know that there is someone out there reading the blog.  Great feedback.
I was at the BCS Thought Leadership dinner/debat the other eveing where we discussed Cloud computing. Without wishing to take away from the BCS and its editorial, one of the outputs was that we don't have the appropriate tools currently to properly asses risk as it applies to the 'cloud'. Another output was that whilst 'cloud' computing will prove adventageous for many organisations/individuals, the actual needs will vary i.e. the needs of an SME will be different to a large enterprise and a large enterprise will have different needs to Government......
Clerkendweller  14:11 pm, Thu 26th Nov 2009

Hello Peter
Did you see ENISA's risk assessment for cloud computing at:
http://www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing-risk-assessment/
I haven't had a chance to read it fully, but it looks useful. ENISA are also an affiliate member of the Cloud Security Alliance.  Dennis Hurst (HP) spoke about the forthcoming update to the CSA's security guidance at OWASP AppSec Washington DC 2009.

© 2009 Reed Exhibitions | Contact Us | Privacy Policy

Infosecurity Adviser is produced by Reed Exhibitions with thanks to Tangent Labs