Governance, Risk & Compliance Advisory Blog
Insights on best practices related to IT Audit & Compliance

Securing the Clouds

August 29, 2011 06:29 by Shashi Shekhar Vyas

Addressing risks in Cloud Computing

IT has the ability to deliver almost anything that you can think of, and here is the latest entrant - The Clouds, which is now a phrase du jour in the IT coliseum already. Clouds are on the rise and so are the organizations looking ahead to capture clouds for their business practices.

Cloud Computing has changed the approach such that a cloud – user now only requires a browser for access to the company’s network. And this raises risks and compliance concerns.

Being a part of GRC, we know what matters to organizations most and here, it is their corporate data which they may put on off-premise servers. So are the clouds safe? What are the risks involved? Will the data (kept off – shore) still sync with their company's internal compliance mandates?  

Being in the GRC domain, I had serious question in front of myself – are clouds secured and safe and what should they do to adhere with IT security norms. How can they be well-equipped to address any IT security concern raised as any organization would want clouds to be safe before putting their enterprise data on-board?

With the current economic scenario, businesses, especially mid-size, may feel the need for cost reduction and look forward to this technology to source some or all of their computing services into the cloud; but what may hold them back are the security concerns. To pass the risk and compliance test, they would need to address the following concern that comes with clouds not only for IT auditors but also for themselves. A lack of robust methodology of identifying risk areas and being compliant may derail the complete concept of clouds. 

First, we discuss the various planks which can be of major concerns to the data owners:

·      SaaS, PaaS and IaaS: Cloud providers use Software as a Service (SaaS) or Platform as a Service (PaaS i.e. providing a platform to build software applications to cloud - users) or Infrastructure as a Service (IaaS like servers) to deliver a single application through the browser serving multiple clients.

·      Use of web services: Use of web services like search engines, web portals, etc.

·      Use of Utility Computing in Clouds: Utility computing i.e. utilization of services and computing resources, such as virtual Data Centers.  

Risks Involved

·      SaaS, PaaS and IaaS: The risk of using Saas, PaaS or IaaS is that all these platforms raise issues of identifying user accounts (duplicate user accounts) and their roles and rights, misalignment of data.  In short, concerns of authorization and authentication. Here, the onus of data security lies not only on the data owners, but also majorly on the cloud providers (Cloud Service Providers), as the data is stored on any third – party software, storage blocks or platform based clouds.

·      Use of web – services: Use of web services in the clouds is crucial to IT security as traditional vulnerabilities like virus, spywares are always of concern. Apart from the traditional villains resting on the web, it is security of the enterprise data to be transmitted to these web services is also under scanner.

·      Use of Utility Computing in Clouds: Utility computing raises a high level of security concern as mission critical data of organizations are under scrutiny. The access to crucial and critical IT environments such Data Centers has always been of high concern to organizations. The fear of clouds growing dark rises, as we are actually looking into the prospects of a ‘virtual Data Center’.  

Compliance practices to tackle the risks

Addressing risk and compliance aspects is fundamental for clouds to grow. This is important as no GRC umbrella over an organization’s cloud cluster would mean a complete degradation of their enterprise data and their business practice. The best practices to tackle the mentioned risks are suggested below:

·      SaaS, PaaS and IaaS: Organizations need to focus on data security which becomes highly important as the clouds reside on storage blocks, software or platforms. User accounts and their roles and rights are absolutely crucial as well as their authorization and validation must be of primary focus to the organizations.Organizations / data owners here would also require robust cloud-based third party policies, rather than just the orthodox enterprise third party-based policies for the service providers who own the clouds (as the data now no more rest in their environment or facility).

·      Use of web services: Filtering (URL filtering) on what is to be viewed on the basis of User roles is an effective measure while using web services on the clouds. This ensures that each cloud users access what is actually necessary for their role. This takes care of access to attractive but distracting information / services, which gives an easy en-route to traditional intruders. In case web security is outsourced to a third - party, SLAs / KPIs and related policies must just not only focus on web-security and filtering concerns, but must also focus on the services to curb and prevent data loss. Here, the responsibility of these measures lies primarily with the organizations, who own the data, because it’s just not their data residing on the clouds, they actually share a room out there! What is notably important here is to realize the guidelines and policies that need to be built around these risks and consistently keep a check on them.

·      Use of Utility Computing in Clouds: To overcome security concerns related to the utilities like virtual Data Centers, it is highly recommended to locate and highlight low, medium and high-level of security concerns and risks in-depth. The policies, authorization and access to Data Centers must not only highlight but also address the risk areas and concerns that have been analyzed. The back-up and restoration methodologies adopted are of high significance too, because the Data Centers in the clouds are just not located off-shore, but are virtual as well. So, if organizations do not want the clouds to grow dark, it is important to primarily focus on the below aspects:

·         Policy management and audit capabilities for themselves and cloud-providers

·         IT security controls and the ability to transport and archive enterprise data

·         Addressing poor visibility into risk exposure properly

·         Avoiding lack of alignment from not having risk and compliance processes embedded within the business

Best practices ensure that the organizations; their corporate and enterprise data remain on cloud nine. Clouds are always pleasant to watch and GRC is all about ensuring they don’t grow dark. We won’t.


Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5
Tags:
Categories:
Actions: E-mail | Permalink | Comments (35) | Comment RSSRSS comment feed

Related posts

Comments

September 13. 2011 11:18

Gravatar

You made some good points there. Good post, really helped.

ben

September 30. 2011 00:27

Gravatar

This is this kind of fantastic handy resource you happen to be furnishing additionally, you supply the idea absent without cost. I really want seeing web pages of which realize on-line associated with furnishing a great useful resource without cost.

blackjack

October 13. 2011 12:10

Gravatar

Well,
That was really interesting blog and i hope your blog wold like by everyone so keep it up these interesting topic.I will wait for the another one.

Management of solid waste in India

November 9. 2011 15:34

Gravatar

I differ with most guys here; I found this blog post I couldn't stop until I was done, even though it wasn't just what I had been searching for, was still a great read though. I will immediately get your blog feed to keep in touch of future updates.

Murray Title Loan

November 12. 2011 19:41

Gravatar

I differ with most guys here; I found this blog post I couldn't stop until I was done, even though it wasn't just what I had been searching for, was still a great read though. I will immediately get your blog feed to keep in touch of future updates.

crew training

November 13. 2011 09:24

Gravatar

I am very impressed with the articles on your site. I get so many ideas to help me. I will be coming back to check if you have more articles in the future.

Game translation

November 13. 2011 22:03

Gravatar

There are certainly a lot of details like that to take into consideration. That is a great point to bring up. I offer the thoughts above as general inspiration.

Kurdish translation services

November 13. 2011 22:35

Gravatar

This post is excellent and so is the manner in which the subject was explained. I like some of the comments as well even though I would rather we all keep it on topic so that to add value to the idea.

public website translation

November 18. 2011 22:06

Gravatar

Benefit of starting a soup diet (http://soupaday.com) regimen is that soup can be made from almost anything, and many soups can be made in minutes. Making soup regulary is also a great way to get rid of leftovers!

Soup diet

November 18. 2011 22:13

Gravatar

Image Group International (http://www.imagegroup.com.au) is recognised as Australasia's leading image consultants and is proud to be the preferred coaching provider to over 500 premier organisations around the globe.

personal brand

November 21. 2011 05:15

Gravatar

The new Zune browser is surprisingly good, but not as good as the iPod's. It works well, but isn't as fast as Safari, and has a clunkier interface. If you occasionally plan on using the web browser that's not an issue, but if you're planning to browse the web alot from your PMP then the iPod's larger screen and better browser may be important.

Her Shampoo

November 22. 2011 03:51

Gravatar

Between me and my husband we've owned more MP3 players over the years than I can count, including Sansas, iRivers, iPods (classic & touch), the Ibiza Rhapsody, etc. But, the last few years I've settled down to one line of players. Why? Because I was happy to discover how well-designed and fun to use the underappreciated (and widely mocked) Zunes are.

Sulfate Free Shampoo

November 26. 2011 11:25

Gravatar

Cloud computing risks outweigh the benefits, according to a survey of 1800 IT professionals who are members of ISACA.

clean up credit report

November 29. 2011 22:19

Gravatar

You wrote something that people could understand and made the subject intriguing for everyone.(http://www.raspberryleaftea.org.uk/)

Raspberry Leaf Tea

December 9. 2011 12:04

Gravatar

The uniqueness that I was looking for is already in this site. Thanks.
(http://www.cars4backpackers.com.au)

Campervans

December 9. 2011 12:07

Gravatar

In my point of view, blog makers should have a unique way in making their site. Thanks.
(http://www.travellers-autobarn.com.au)

campervan australia

December 23. 2011 10:38

Gravatar

There are certainly a lot of details like that to take into consideration. That is a great point to bring up. I offer the thoughts above as general inspiration.

Sharjah hotels

December 23. 2011 21:50

Gravatar

TGC5NFJR6PFEWY
How to Get Genuine UGG Boots at Cheap Prices

oakleys sunglasses

December 24. 2011 00:08

Gravatar

I was searching on google and I stumbled on your site. Good article you have here. I have shared it to my friend who was looking for such info. I am pretty sure this will help him a lot.

hotel apartments Sharjah

December 27. 2011 19:28

Gravatar

Air Source Technology, Inc. provides on-site investigations, audits, management plans, training, as well as indoor air quality investigations, lead risk assessments, industrial hygiene studies, and asbestos inspections for Industrial, Commercial, Medical, Residential, and Public Institution Clients.

Mold

December 28. 2011 00:53

Gravatar

In 1977, Marlowe Granola was born in the bustling kitchen of our fun, food-loving family. Through the years, our mom has perfected her delicious recipe, and though low in both sugar and fat, it never fails to satisfy our taste buds and hunger cravings. More Information About Best Granola Visit marlowegranola.com

Best Granola

December 31. 2011 03:26

Gravatar

Discover the most effective Gout Treatment on the market. Find out why most people choose this Treatment for Gout for their Gout releif.

Gout Treatment

January 1. 2012 14:49

Gravatar

Kentucky Wildcats on Twitter. Twitter feeds from college basketball and football Players and coaches who attend or attended the University of Kentucky.

Kentucky Basketball

January 1. 2012 14:50

Gravatar

Transitions Mobility and Elevator specializes in Residential and Commercial Elevators, Wheelchair Platform Lifts, Auto Lifts, Stair Lifts, Patient Transfer Lifts, Bath Lifts, Pool Lifts, Dumbwaiters, Ramps, and Replacement Parts.

Handicap Lift

January 1. 2012 14:51

Gravatar

Transitions Mobility and Elevator specializes in Residential and Commercial Elevators, Wheelchair Platform Lifts, Auto Lifts, Stair Lifts, Patient Transfer Lifts, Bath Lifts, Pool Lifts, Dumbwaiters, Ramps, and Replacement Parts.

Walk In Bathtub

January 7. 2012 07:21

Gravatar

Whether it’s the multiple trips up and down the stairs with laundry, furniture, kids, seasonal items, or groceries you will be sure to find our residential elevators as a practical addition to your home.

In Home Elevators

January 7. 2012 07:22

Gravatar

Stair lift chairs are suitable for every housing situation with straight or curved stair cases. The home stair lift is equipped with your safety and ease of operating in mind. They are designed with all...

Stair Lift

January 8. 2012 16:56

Gravatar

Chiropractic care is more than just making the pain disappear. It is about taking care of your body to improve your quality of life. At Elswick Chiropractic & Associates, we believe that treatment should combine leading edge technology and traditional, hands-on care. It should be an ongoing partnership between you and your doctor to help you recover from pain and to keep you healthy for life.

Chiropractor Lexington KY

January 28. 2012 15:20

Gravatar

yeah bookmaking this wasn't a speculative determination great post! .

Israel Koplin

February 4. 2012 00:42

Gravatar

Hmm is anyone else having problems with the pictures on this blog loading? I'm trying to find out if its a problem on my end or if it's the blog. Any suggestions would be greatly appreciated.

hot tub

February 8. 2012 05:22

Gravatar

I used to be seeking this kind of information for quite some times. Thank you and best wishes.

buy a house in maryland

February 8. 2012 08:31

Gravatar

UmpHub is the leading provider of online training for baseball umpires. The instructors in our training videos bring hundreds of years of collective experience as baseball umpires working in the most pressure packed situations. The topics of the videos that you will find on Umpair Training include interviews with baseball umpires, advanced baseball umpire mechanics, baseball umpiring rules, baseball umpire questions and much more.

umphub

February 16. 2012 13:27

Gravatar

This is the homepage for Chapelboro.com - the community portal for the Chapel Hill, Carrboro, Hillsborough, and Orange County community.

Chapel Hill News

February 17. 2012 21:39

Gravatar

This is the homepage for Chapelboro.com - the community portal for the Chapel Hill, Carrboro, Hillsborough, and Orange County community.

Chapel Hill News

February 17. 2012 23:37

Gravatar

GKFJAFGZACBZLA I like it very much!

pandora bracelets

Add comment


(Will show your Gravatar icon)  

  Country flag




Live preview

February 23. 2012 07:57

Gravatar