Access and Feeds

Cloud Computing: How Complete is Your Cloud Vendor's Security Checklist?

By Dick Weisinger

Run a query on “SAS-70 certification” and you’ll get a page full of SaaS/Cloud Computing/On-Demand services that have achieved certification for their services.  Many of these articles and press releases contain language like this one:  “This SAS 70 Type II showcases to other stakeholders that their internal controls are above market standards.”

Well, it certainly sounds good, but should a SAS-70 certification be sufficient to ease your worries of any problems that might crop up with your Cloud computing vendor?  Unfortunately, the answer is no. Not all SAS-70 certification reports are equal.  In fact, it’s not really possible to compare vendors based on their SAS-70 results.  Not unless, of course, there is actually something bad that is contained in the report. But that’s not usually the case because vendors have a lot of control over determining which aspects of their cloud business will be reviewed for the report.  And things they feel less comfortable about can simply be omitted.

Grep Shipley wrote in an InformationWeek article: There is certainly value to a SAS 70 Type II audit, but the relevance of that value heavily depends on the controls being investigated–the what. As any IT professional who has undergone a SAS 70 will attest, you can simply remove controls that you don’t want audited. Don’t have desktop patching? Strike it. No security integrated into the software development life cycle? Don’t have your auditor look at that. Don’t run vulnerability scanners? Keep it off the objectives list… Aggravating the situation, we’ve seen cloud providers that will provide a letter of attestation but refuse to list the SAS 70 control objectives. This is akin to saying, “Yes, we were audited, but no, we won’t tell you what the auditors looked at.”

And then there is also the question of who made the audit?  That’s something that you need to dig a bit deeper to find out.  What is their reputation and their credentials?  Their methodology?  There are a lot of questions and very little uniformity currently in how the information is reported.

This is clearly one area that needs to be addressed before more companies will be able to feel comfortable about cloud computing.

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*