The most popular and comprehensive Open Source ECM platform
Cloud Computing Security: IT Leaders Too 'Hands Off' When it Comes to Cloud Security
About half of organizations have policies in place that for vetting cloud computing applications for possible security risks before deploying them, according to a report from the Ponemon Institute on the state of Cloud User Security in 2013. The group also summarized the findings of their study in an infographic available here. That is an improvement, although a relatively small one. The number of organizations saying that risks need to be assessed prior to cloud adoption has jumped about 10 percent this year compared to the results of a similar survey taken in 2010.
But CA Technologies, sponsor of the report, says that cloud risk assessment isn’t really yet at a level that is ‘good enough’. The results of the Ponemon report found that improvements in cloud security over the past two years have really only been incremental. Mike Denning, general manager of the Security group at CA Technologies, said that “Cloud security struggles to get past a grade of 50 percent when it comes to best practices, including the percentage of organizations that say they engage their security teams in determining the use of cloud services.”
The report notes that many IT leaders are ‘alarmingly hands off’ when it comes to both SaaS and IaaS security:
- 49 percent of organizations evaluate IaaS for security risks prior to deployment
- 22 percent say that the responsibility for security of IaaS is with the cloud provider
- 22 percent say that IaaS security is in the domain of IT itself
- 21 percent say that IaaS security is ultimately the responsibility of the end users
But the report does not that there has been some improvement in the ability to prevent or curtail data loss from theft from the cloud. Businesses are ranked nine percentage points higher in that area than they were back in 2010. Ponemon attributes that to improvements in technology. Larry Ponemon, founder of the Ponemon Institute, said that “In the last two years, there have been a ton of products building encryption technology in the cloud.”













