The most popular and comprehensive Open Source ECM platform
Cloud Computing: Vendors Focus on Improving Security Weaknesses
Secure Cloud Computing. To some, at least with the current state of technology, that might sound like an oxymoron. When asked about cloud computing, security is the main issue that concerns most organizations. That sentiment isn’t being ignored by cloud vendors. In fact, many cloud vendors realize that the long-term success of their businesses depends on the need for them to convince customers that their data will be secure.
Forrester Research has picked up on this. Jonathan Penn, analyst at Forrester, recently wrote that “heightened pressure by cloud customers and prospects is fueling the rapid evolution of solutions. How rapid and radical an evolution? By 2015, security will shift from being the No. 1 inhibitor of cloud to one of the top enablers and drivers of cloud services adoption.” Penn is predicting that by 2015 the cloud security market will be a $1.5 billion force with 5 percent of all security spending going towards the cloud.
Many organizations already have security budgets for their in-house IT projects. Forrester sees the allocation of those funds changing, and moving towards being applied to cloud application computing. He sees a new category of products being created that can specifically enhance the security of cloud applications. A Forrester report observes that “end user organizations are beginning to seek security as an inherent feature of cloud services, where it is more effective, more easily managed, and less expensive.”
Partnerships between cloud vendors and security vendors is beginning to happen. Amazon has teamed with Symantec’s Symantec Endpoint Protection product for Windows. Verizon Business and McAfee are also teaming up. We can expect more such partnerships and products in the future.
Penn argues for the cloud security market to take shape and for there to be more acceptance that cloud security standards are needed. Many of the existing standards around hosted applications aren’t sufficient for guaranteeing security of data. Penn wrote that “Certifications and other operational standards such as SAS 70 Type II (or even the new SSAE 16 designed to replace it), SEI CMMi and ISO 27001 are ill-fitted assurances for the security of cloud environments. Nor can SLAs sufficiently cover everything: Adopting organisations need more detail and concrete assurances of operational practices – such as specifying both the control technologies and policies in place, access to system logs, and regular communication of results from security scans – rather than relying on general contract language.”
eWeek quotes Allen Allison, chief security officer at naviSite as saying that “it must be understood that not all clouds are the same, not all security requirements are equal and not all customers have the same level of expectations; thus, costs of compliance should be considered as standards as cloud security is developed.”













