Access and Feeds

Cloud Computing: How Safe? How Much Trust?

By Dick Weisinger

The reason repeated over and again for why many organizations are reluctant to use cloud computing is the risk.  There is the risk that sensitive data will be remote to the organization, that cloud data can be easily compromised or that the organization will lose control of the data once moved to an off-site server.  Enter Neil McDonald, vice president and fellow at Gartner.

McDonald is adamant that this line of thinking is misguided. He notes that many people say the cloud can handle CRM data, but really sensitive data should not be moved to the cloud.  But really, CRM data may be one of a company’s most sensitive set of information — it’s a live database of all interactions with the company’s customers.  Salesforce.com has 80,000 customers with two million users that seem comfortable with keeping that data in the cloud.  Another example that he points to is the fact that no one seems much concerned that 70 percent of companies are already outsourcing their payroll and benefits programs.  Most of these services are not (yet) in the cloud, but these programs require very sensitive employee information to be transferred to outsiders.  McDonald points out that people seem comfortable with that.

McDonald says that the move to the cloud is inevitable and is being accelerated by a number of factors.  One of which is mobility.  People want to be able to get at data anywhere.  Mobility was the driver for the success of CRM and now it is pushing other categories of applications to change too.   People need to be able to access information from any kind of device.  The delivery mechanism of the cloud facilitates these requirements.

McDonald said that “… if the workload can move from this data center to that data center, heck we might as well just move it to Amazon. All of these are taking place simultaneously. Increasingly, we do not control elements of our IT infrastructure.  The Cloud is just one element of that, and yet we’re fighting it.”

“Security and control are different issues and need to be treated as such.   In the past we had the idea that control is a proxy for trust. If I have control, I trust. If I don’t have control, I don’t trust. But that assumption is flawed. I have devices that I can control that can be infected. Cloud challenges these assumptions.”    McDonald recommends organizations “to focus on outcomes, not control. The transformation is going to take place and you don’t have your control anyway. Baseline your security profile where the business needs to be and hold cloud providers to this.”

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*