You are here: silicon.com > Software > Security Strategy

Security Strategy

Can business trust "immature" cloud computing?

Not yet, warn security experts

Tags: security, cloud

By Tom Espiner

Published: 10 December 2008 08:52 GMT

Cloud-computing services are on the rise but the security around them is not yet mature enough to trust, security experts have cautioned.

Identity-and-access control is one of the biggest factors in ensuring online services are secure, Adrian Seccombe, chief security officer with pharmaceutical company Eli Lilly, told silicon.com sister site ZDNet UK last week. However, he was not convinced software as a service (SaaS)-related online ID and access offerings had been in existence long enough for large customers to be able to trust them.

"You could use SaaS to enhance how you manage identity and authentication," Seccombe said, but added "this is immature in most of the SaaS market".

Security from A to Z

Click on the links below to find out more...

A is for Antivirus
B is for Botnets
C is for CMA
D is for DDoS
E is for Extradition
F is for Federated identity
G is for Google
H is for Hackers
I is for IM
J is for Jaschan (Sven)
K is for Kids
L is for Love Bug
M is for Microsoft
N is for Neologisms
O is for Orange
P is for Passwords
Q is for Questions
R is for Rootkits
S is for Spyware
T is for Two-factor authentication
U is for USB sticks/devices
V is for Virus variants
W is for Wi-fi
X is for OS X
Y is for You
Z is for Zero-day

In addition, Seccombe said the majority of cloud-based ERP (enterprise resource planning) services had insufficiently developed security models for him to recommend the use of those services.

Seccombe is a board member of the Jericho Forum, a group of corporate chief security officers who espouse 'deperimeterisation', or the putting in place of security regimes that allow the free flow of information. ZDNet UK spoke to Seccombe and other security experts at the CSO Interchange Forum in London last week.

Cloud computing in general and SaaS in particular present a challenge for companies, as they necessitate a complete change in security thinking, said analyst Jon Collins of Freeform Dynamics.

"The trouble is that SaaS rides roughshod over basic principles of security," Collins said. "Traditionally, if you want to keep data safe you lock it away or keep it underground. Suddenly, you say I have to give it to a third party."

Companies planning to implement SaaS need to think about confidentiality, the integrity of the data and its availability, Collins added.

Confidentiality could be a potential problem for data-at-rest, or stored data, as IT professionals need to trust the security of the third-party storage. Interception of data-in-motion is a risk companies would also need to take into account.

"Is the information sufficiently encrypted as it passes over other people's servers? You, as a customer, have no idea where your data goes between the plug in the wall and the SaaS provider," he said.

The integrity of the data as it passes over other people's systems also raises questions. "The fact that the information could be changed in some way is a risk," said Collins, who added that "the scary thing is the organisations that don't think about this stuff".

However, some of these security risks could also be mitigated by the use of SaaS. "It could be easier to lock down information if it's administered by a third party rather than in-house, if companies are worried about insider threats", Collins said.

In addition, it may be easier to enforce security via contracts with online services providers than via internal controls. "With a third-party company, you can architect it to say 'Encrypt here, decrypt here, only these people have access rights', as part of the contract," Collins said.

Philippe Courtot, chief executive of security SaaS company Qualys, agreed that contracts with third-party companies could help augment security.

"Technical issues become contractual issues," Courtot said. "You can secure data at the data level itself, so the data knows who can copy it and who can share it."

Courtot said there was a "clear trend" where companies in the EU and the US were turning to SaaS to cut costs in a time of economic gloom. "Essentially it's because of cost, with secondary drivers being ease of use, deployment and maintenance," said Courtot.

Original article: Security experts advise caution in the cloud from ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Security Consultant

Leading security and verification organisation are looking for a Senior Consultant to be responsible for integrating services and applications with ...

Sourcing Manager - IT & Telco

Role Purpose - Over all responsibility for driving commercial value, in collaboration with business, from key third party facing sourcing ...

Head of Third Party Operations - Geneva

Head of Third Party Operations ? One of their key business units, contributing approximately $3.5 billion, has recently experienced major ...

Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: