Technical Exchange

Walking in the Cloud: Who Pays for Your Security?




  In 2015, cloud security will take center stage. As enterprises increasingly experience the benefits of cloud technology such as cost reduction and better resource utilization, more will move their operations to the cloud. However, with frequent cloud security incidents over the past two years, cloud security has become the top obstacle for enterprises implementing cloud solutions. When a security incident occurs while using a cloud provider's services, the resulting losses can be immeasurable. Who will be accountable to the enterprise for such losses?

  Therefore, before choosing a cloud service provider, enterprises must think carefully and ensure the provider has viable security measures that can fully protect enterprise data and be accountable for security incidents.

  Two Major Categories of Cloud Security

  In 2014, just as Microsoft was gradually gaining user recognition and beginning to compete on equal footing with major rivals including Amazon Web Services, its credibility took a major hit. Shortly after midnight GMT on November 19, a large-scale outage occurred lasting several hours. Recently, according to CloudHarmony data, Microsoft topped the outage charts in 2014, with 214 outages totaling approximately 54 hours for the entire year. Although Amazon's public cloud performed best, it still experienced 34 outages totaling 5 hours of downtime.

  Gartner analyst Jonah Kowall noted that these issues were essentially caused by human error rather than hardware infrastructure failures, suggesting that insufficient capabilities among cloud management personnel led to security problems. Downtime is just one aspect of cloud security, representing internal risks from the cloud provider. Another example is the hacking of Apple's iCloud that led to the leak of celebrity photos, an attack primarily targeting iCloud accounts that exposed inadequate cloud security measures. This represents the second category of cloud security issues: external malicious attacks, requiring cloud providers to have strong technical expertise.

  In a narrow sense, Cloud Computing refers to the delivery and usage model of IT infrastructure, where required resources (hardware, platforms, software) are obtained on-demand and in a readily scalable manner over the network. The network that provides resources is called the "cloud." Resources in the "cloud" appear virtually unlimited to users, are available at any time, used on demand, scaled at will and charged by usage. This characteristic is often described as using IT infrastructure like water and electricity.

  How to Evaluate a Cloud Service Provider's Security?

  As Cloud Computing prices continue to decline, more large enterprises will adopt cloud technology. How can enterprises overcome or bypass the obstacle of cloud security? When choosing a suitable cloud service provider, how should enterprises evaluate the provider's security, and what aspects of the vendor's security measures should they consider?

  According to standards organizations such as NIST, the PCI Security Standards Council and ISO, cloud service provider security can be guaranteed at four levels:

  Platinum:Equivalent to military-grade security, featuring stronger encryption and the removal of cloud provider administrator access.

  Gold:Equivalent to financial-institution security, including penetration testing, multi-factor authentication, storage encryption and physical server isolation.

  Silver:Equivalent to general enterprise security, including network intrusion prevention, event logging, continuity planning and more robust security documentation.

  Bronze:Basic security, such as antivirus, firewalls, vulnerability management, security event monitoring and physical access restrictions.

  All enterprises wishing to use cloud technology hope their cloud vendors can provide Platinum-level security services. Correspondingly, all cloud service providers are striving toward the Platinum security level to earn the trust of enterprise customers.

Source: 51CTO.com

 

Screenshots on this page show the Chinese user interface. English materials are available on request.
E-mail: market@windica.cn  ·  We reply within 2 business days.
This English version is a translation for reference; the Chinese version shall prevail.