Information Security in the Real World. Confidentiality, Availability, Integrity, Practicality.

Showing posts with label cloud. Show all posts
Showing posts with label cloud. Show all posts

Monday, 21 November 2011

The Cloud Security Standard is out, and the ISO27001 author is unhappy.

What tangled webs we weave -David Lacey. Quotes from David Lacey's latest criticism of the "standards industry" include: "The standard [which became ISO27002] aimed to remove 90% of the effort in risk assessment by documenting commonly applied controls. Unfortunately it was hijacked by a consultancy community who subsequently reintroduced the need for mandatory risk assessment. It was also intended to be sufficiently broad and deep to minimise the need for any further standards. Yet two decades on, it has inspired a family of dozens of near identical standards and guidelines.". What has sparked Lacey's ire is the Cloud Security Standard. At 176 pages: "The real challenge however will be to turn this impressive body of knowledge into something of practical use to busy security managers. "


There is a reason I called this column "Practically Secure". Because I know how Mr. Lacey feels. Pragmatism is way down the list of objectives for the authors of today's security standards.


[NB I have finally edited this post to add my commentary, sorry for the delay!]

Thursday, 28 January 2010

Cloud Nine... er seven

Infoworld have summarised Gartner's assessment of cloud computing security, listing the seven deadly risks of cloud computing. Key among them is number two on the list, Regulatory Compliance. Why indeed would you insist that your traditional service providers comply with regulations and undergo compliance audits, without subjecting cloud service providers to the same level of scrutiny? Indeed you might find you are bound to do so by the regulations in your industry.

Also one of the many perceived benefits of the cloud is availability and resilience of service, but are your cloud service provider's DR capabilities good enough? Are your data, transaction logs and applications all co-located, or are they stored and hosted in multiple, geographically diverse locations? Do they do DR at least as good as you could with traditional architecture?

Practically speaking, does your cloud provider introduce unacceptable security risks?