Saturday, December 5, 2009

Cloud Computing - What we really should discuss

I have put many links in recently concerning products, strategies and directional links. I am taking a few minutes to post a few words on information cloud computing. Cloud services are active today whether they are Google, Amazon, or others and carry both business and financial transactional data for consumers. One of the concerns I have remains, the ability to audit and know controls are in place for information protection. Some cloud technologies are putting some interesting architectural decisions in front of security professionals. These decisions are often being posed as "faster", "less cost" and "more efficient" and even " you won't need your firewalls anymore". The basic premise by security practitioners is that we need layered defenses for data, application, network segmentation. The "blur" of these points and traditional security design occured when mobility came forward and third parties were requiring trust within the organizations backend systems. Today, we are rapidly moving towards a mixed architecture where some applications will truly be cloud enabled, yet others will remain traditional security architecture and controlled. I remain somewhat skeptical at cloud based security models and how processes such as vulnerability analysis will occur in the "cloud".

No comments:

Post a Comment

Followers