NIST report aims to help U.S. agencies deploy cloud apps
Cloud computing can provide value only if security, management is properly planned, NIST says
Computerworld - Organizations that are deploying public cloud computing applications need to pay close attention to security and management risks, the National Institute of Standards and Technology said in a report released Wednesday.
"With the wide availability of cloud computing services, lack of organizational controls over employees engaging such services arbitrarily can be a source of problems," NIST noted in a document prescribing a set of security and privacy guidelines for cloud computing. "Without proper governance, the organizational computing infrastructure could be transformed into a sprawling, unmanageable mix of insecure services."
The issue is somewhat similar to the problems created when individual employees and small groups set up rogue wireless access points in an enterprise network, the report noted.
NIST prepared the Guidelines on Security and Privacy in Public Cloud Computing in response to a directive from federal CIO Vivek Kundra.
As part of his effort to accelerate the government adoption of cloud computing Kundra asked NIST to develop a set of security standards and guidelines agencies can use when moving applications and data to the cloud.
The goal of the document is not to create fear among federal agencies, said Tim Grance, a computer scientist at NIST and an author of the report. Rather, the guidelines aim to prepare federal IT managers for cloud projects.
"Public cloud computing is a very viable choice" for government agencies, Grance said. "We are not by any means saying 'don't do it.' But you have to be careful. You got to make sure that [cloud computing] is part of a coherent overall strategic process."
NIST's 60-page document, currently open for public comment, provides a detailed analysis of many familiar cloud security and privacy issues.
For instance, the report highlights multiple compliance issues, such as those related to data location, facing cloud adopters.
Often, detailed information about the location of an organization's data is unavailable or not disclosed by the cloud provider, the report noted, making it hard for organizations to determine whether security controls are in place and if legal and regulatory requirements for protecting data are being met.
Similarly, U.S. federal agencies are required to comply with several security and privacy related mandates, the report notes. However, the degree to which cloud providers are willing to accept liability for data under their control remains largely untested, NIST said.
Organizations using public cloud computing systems relinquish direct control over many security aspects, and confer an unprecedented amount of trust in the provider. Moving to the cloud can sometimes exacerbate insider threat issues, raise questions about data ownership and control, and make risk assessment and management harder, NIST said.
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Securing Internet File Transfers This solution brief describes the four essential elements of secure Internet transfers.
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts