The State of Cloud Computing Security

Share  
1  |  2  |  3  |  4  |  5  |  6  |  7  |  8  |  9  |  10  |  11  |  12  |  13  |  14
Previous Next

Click through to see key finding from a survey from the Ponemon Institute, sponsored by CA Technologies.

Topics : Unisys, Stimulus Package, Security Breaches, Symantec, Electronic Surveillance


One of the most heated debates in all of enterprise computing these days centers on the security of cloud computing. One IT camp argues that cloud computing is inherently more secure because of the ability to invest in all the policies and expertise required to make the overall IT environment secure.

The other camp argues just as vociferously that the centralization of IT into a few cloud computing platforms makes it easier for the bad guys to focus their efforts and that, once breached, hundreds of thousands of records will be as risk because of all the shared infrastructure inherent to the cloud computing model.

Into the midst of this debate comes a new study from the Ponemon Institute that was funded by CA Technologies. The study of 642 IT executives in the U.S and another 283 from Europe, the Middle East and Africa finds that about half of worldwide IT organizations said that no one in their organization evaluates cloud computing providers for security. Worse yet, half said they were pretty sure that no one in their organizations knew about every cloud computing service that end users in their company were storing data on.

Larry Ponemon, chairman of the Ponemon Institute, says the study clearly shows that at the moment the risk factors with cloud computing are high because not all cloud computing providers have the same level of security. In addition, there is no security rating system in place for cloud computing, so business users can’t even rely on third-party security validations.

Lina Liberti, vice president of marketing for security management at CA Technologies, said the real issue is the total lack of transparency between cloud computing providers and internal IT organizations. The end result is that IT organizations don’t want to take responsibility for things like external cloud computing providers that they can’t manage. Of course, business users have lots of good reasons for wanting to use cloud computing services, but with those decisions they also need to be fully cognizant of the associated risks that they are taking responsibility for.

Longer term, Ponemon notes, there is a potential for cloud computing to actually result in more secure enterprise computing environments because as both public and private cloud computing platforms evolve, IT organizations will get a second chance to rethink their entire approach to security, especially as awareness of cloud computing security issues heighten and the work being done by the Cloud Security Alliance continues to evolve.

In the meantime, Ponemon advises both IT organizations and the end users they serve to proceed with caution.

 

More Slideshows

Security45-290x195 Cyber Crime: Law Enforcement Fights Back

While cyber crime continued to dominate headlines and wreak havoc on organizations of all sizes across nearly every industry in the first half of 2014, it's refreshing to note law enforcement also stepped it up. ...  More >>

Security44-290x195 August Patch Tuesday: IE Vulnerabilities and Enforcement of 8.1 Update

The patches released by Microsoft for the August Patch Tuesday include nine bulletins (two critical and seven important) and cover 38 CVEs. ...  More >>

Security43-290x195 Five Steps to Protect Your Passwords Before It's Too Late

Here are five steps organizations and individual users should take now to protect their most sensitive password-protected information. ...  More >>

Subscribe to our Newsletters

Sign up now and get the best business technology insights direct to your inbox.