Cloud
Could Computing is a growing market
R E L A T E D   C O N T E N T
ADVERTISEMENT

Security still an issue for cloud computing, says report

Tom Young, Computing 19 Nov 2009

But Enisa argues that when done properly, security can be better in the cloud

ADVERTISEMENT

The hosting of IT services online, known as Cloud Computing, is both a friend and a foe for chief security officers, according to a new report from EU IT security body Enisa.

While significant resources and data present a more attractive target to attackers, cloud-based defences can be more robust, scalable and cost-effective.

Giles Hogben, an ENISA expert and editor of the report said the business case for cloud computing is clear but boards want reassurance on security.

"The number one issue holding many people back is security," he said. "How can I know if it’s safe to trust the cloud provider with my data and in some cases my entire business infrastructure?"

The report provides a detailed check-list of criteria allowing potential customers to identify whether a cloud provider is security conscious.

Businesses should check contracts for legal responsibility in the case of data loss.

They should pay particular attention to their rights and obligations related to notifications of breaches in security, data transfers, creation of derivative works, change of control, and access to data by law enforcement entities.

And checking that cloud deployed applications are able to combat threats from the internet.

They should check that models are designed with standard security countermeasures in mind to guard against common web vulnerabilities and ensure an effective patch strategy is in place.

In addition, they should not be tempted to use custom implementations of authentication, authorisation and accounting (AAA) as these can become weak if not properly implemented.

But if all these criteria are fulfilled, cloud computing can be a security enabler, according to Udo Helmbrecht, executive director of ENISA.

“The scale and flexibility of cloud computing gives the providers a security edge," he said.

"For example, providers can instantly call on extra defensive resources like filtering and re-routing. They can also roll out new security patches more efficiently and keep more comprehensive evidence for diagnostics.”

IDC forecasts a growth of European cloud services from €971m in 2008 to €6,005m in 2013.

But this potential will only be fulfilled if security concerns can be satisfied, the report says.

M A R K E T P L A C E
V-SOL: Supply Premium Vehicle Tracking Systems to MOD, TRansport for LONDON and EDF-CHANNEL RELEASE!
Expert Buyers is the UKs Leading No Savings No Fee IT Procurement Service. Claim your Free Audit Now
WAN based, automated, daily vulnerability assessments. Click here to try and request our whitepapers.
As recognised by the Accountancy Age Awards 2004, 2005 and 2006.
Online Time & Attendance Tracking 30 Day Free Trial ( $49 a year )
Have your product or service listed here >   
| A f I D (Accounting for International Development)
A f I D works in conjunction with UK charities offering their partners a completely free and impartial coaching and mentoring programme designed to strengthen their financial management and planning capabilities of small grass root ... more >
| Vitality Partnership
•Establish and maintain sound financial systems across the organisation and all locations •Perform all daily bookkeeping duties •Process amp;L account • Make appropriate recommendations to the exec board on an ad hoc ... more >
| Holden Jones Ltd
We are seeking an experienced individual to join this highly successful international organisation, taking responsibility for most aspects of its EMEA credit function. The majority of your role will be to support the Credit and ... more >
| WH Marks Sattin
Audit Partner - £90,000 ... more >
More Jobs in Finance

Job zone
Job of the week
Related jobs
Search for a job
 
Try our Advanced search