The most popular and comprehensive Open Source ECM platform
Cloud Computing: How and When — A Recipe for Success
What does it take to move to the cloud? That’s what many organizations are asking now, and unfortunately, there isn’t a cookbook answer for how organizations can [painlessly move there. Answering this question is a task that National Institute of Standards and Technology (NIST) has taken on. There is strong interest in being able to securely use the cloud to gain better efficiency and reduce costs. The interest is universal and is being driven by by federal, state and local governments as well as from commercial and non-profit organizations.
Many organizations worry that they don’t fully understand what’s involved with selecting the cloud. They’re worried without a complete understanding of the technology that there are risks that they aren’t aware of. The risks need to be understood first before they can be minimized or eliminated.
The NIST report is currently in a draft state and is up for comment. The report in its current form recommends that organizations take the following actions when moving to the cloud:
Secure your clients. Before even considering the cloud environment, make sure that web browser clients that will be used to access cloud services are secure. The report suggests auditing client configurations and enacting security best practices.
Use SSL. HTTPS/SSL secure communications should be used when any data accessed from the cloud is sensitive or confidential. Any communications or transfer of this data between any other applications or services supporting the transaction should also be securely encrypted.
Host in a Secure Facility. The cloud hosting facility where the servers reside should be secure. Cloud vendors need to have written plans in place for how they will recover from physical attacks or natural disasters. Cloud vendors that can provide redundancy and hosting facilities in multiple widely-separated geographic locations are preferred.
Authentication Tokens. The use of authentication tokens can further secure accounts and minimize the potential for “account hijacking”.
Access Controls. The cloud vendor should be able to support granular access controls and provide tools that can be used to assign access controls to users.
Performance Benchmarking. The cloud vendor should be able to provide performance benchmarking that includes the results in key performance areas, such as, for example, the responsiveness of applications with user interactivity and performance benchmarks related to bulk data transfers.
Transparency. The cloud vendor should provide visibility of their operations and processes.













