5 cloud security trends experts see for 2011
CSO - What do CSOs and other IT security experts expect to be top-of-mind cloud security issues in 2011? Here are five things to watch for in the coming year:
Smartphone data slinging
More users will be accessing large amounts of data on the devices of their choice, says Randy Barr, CSO at Qualys Inc. and member of the Cloud Security Alliance (CSA).
"This comes with a lot of unaddressed security issues," Barr says. "We can expect new solutions to address mobile devices, but could see a large data breach to expose the issue of mobile security before we see a solution." Among the possible scenarios, Barr says, are insecure cloud-based backup and highly confidential data on mobile devices.
"There are some interesting inter-dependencies when using multiple cloud services on mobile devices, with possibly different security models and assumptions," he says. A hacked cloud provider could provide mass access to confidential mobile device data when mobile users are using cloud-based mobile device support, he says. In addition, loss or theft of mobile device could provide root-level access to cloud services and data. Mobile apps are often providing direct and automated access to cloud services and data, he says. If an admin-level person's mobile device is stolen, this could be a major threat to highly confidential data or even cloud services administered by such a person from an insecure mobile device.
MORE ABOUT CLOUD SECURITY
- 2010: Security for large-company cloud providers
- 2010: In security outsourcers we trust
- 2010: Akamai releases 'game changing' cloud-based payment service
- 2008: Cloud security strategies: Where does IDS fit in?
2. Need for better access control and identity management
"The cloud by nature is highly virtualized and highly federated, and you need an approach to establish control and manage identities across your cloud and other peoples' clouds," says Alan Boehme, senior vice president of IT strategy and architecture at financial services firm ING.
"There are some third parties that have delivered products and services that will address these issues, but they might not be adequate for large enterprises that have a mix of legacy and cloud components."
3. Ongoing compliance concerns
"I think that compliance, especially PCI, is likely to continue to be a security issue," says Andy Ellis, CSO at Akamai.
"Organizations still often need to come to grips with completely different processes that they have for managing data and apps in the cloud. And I think we will hear more rumblings about health-care data in the cloud."
4. Risk of multiple cloud tenants
Given that most cloud services make heavy use of virtualization technology, the risks associated with multiple organizations' data housed on a single physical hypervisor platform exist, and will continue to unless specific segmentation measures are enacted, says Dave Shackleford, director of security assessments and risk & compliance at Sword & Shield Enterprise Security, and a member of the faculty of research firm IANS.
- The 20 Best iPhone/iPad Games of 2013 So Far
- 9 Steps to Build Your Personal Brand (and Your Career)
- 7 Consumer Technologies Coming to an Enterprise Near You
- 11 Signs Your IT Project is Doomed
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
-
Your Data under Siege: Protection in the Age of BYODs
Download Kaspersky Lab's new whitepaper, Your Data under Siege: Protection in the Age of BYODs, to learn about:
- How a mobile workforce stretches... - Protection for Every Enterprise: How BlackBerry 10 Security Works Get an IT-level review of BlackBerry® 10 Security, addressing data leakage protection, certified encryption, containerization and much more.
- A Comprehensive Strategy to Leverage Mobile A successful mobile strategy begins with a common platform for integrating and managing mobile devices and the corporate assets that are stored on...
- IDC - SAP Enterprise Mobility: Bringing a Cohesive Approach to a Complex Market This IDC white paper discusses key mobility trends and examines how SAP's mobile enterprise solutions map to meet organization's mobile requirements.
- Boost Performance & Profitability with Better Planning & Mobile Reporting This session will discuss how Ashurst, a top-tier legal service provider for private and public sector clients worldwide, was able to effectively manage...
- Apps and BlackBerry 10 - Tips for IT Learn how to easily create, deploy and manage both off-the-shelf and custom apps, improving productivity and efficiency for employees by mobilizing apps, processes... All Mobile/Wireless White Papers | Webcasts
Our weekly newsletter will cover a wide range of topics and trends related to consumerization. Stay up to date with news, reviews and in-depth coverage of BYOD, smartphones, tablets, MDM, cloud, social and how consumerization affects IT. Subscribe now!