Advertisement
Promo

Security threats Toolkit

Cloud Watch

Beware business cloud dangers, says EU agency

Tom Espiner ZDNet UK

Published: 20 Nov 2009 16:46 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Businesses should exercise caution when procuring cloud services, according to the European agency charged with promoting IT security good practice.

The European Network and Information Security Agency (Enisa) on Friday published advice and a checklist for organisations thinking of jumping into the cloud, outlining the benefits and risks of using online service provision.

Primarily, organisations should beware of lock-in to cloud services, Enisa told ZDNet UK on Friday. "There is very little in the way of tools and standards for exporting data from one provider to another," said Enisa network security expert Giles Hogben. "That's one of the biggest risks."

Enisa risk management expert Daniele Catteddu told ZDNet UK that governance issues were also a major risk. "There are client code issues like patching, security testing, and policy enforcement," he said.

The Enisa experts also pointed to the dangers of  'isolation failure' where access control or bandwidth provision are inadequate.

Cattedu said legal and contractual issues are another risk, including data-protection compliance. "Under data-protection law, the cloud customer is the data controller," said Catteddu. "One of the [cloud customer's] duties is to ensure that data is managed in a proper way."

Both experts recommended businesses closely study liability limitations in a contract, and negotiate contracts to reduce the chance of vendor lock-in. "It may be a market differentiator that a provider is offering to share the cost of a migration [to another vendor]," said Catteddu.

The Enisa experts also highlighted several benefits of cloud computing. For smaller businesses, cloud services run by larger organisations may offer more security, as smaller businesses may not have the resources or expertise to adequately defend their networks.

In addition, cloud services can scale to mitigate the effects of denial-of-service attacks, said Hogben.

The checklist published on Friday will evolve into an assurance framework for cloud providers within a year, said the experts. Providers will be able to use this framework to be certified in a similar way to a kitemark, or guarantee of quality, said Hogben.

Cloud services are becoming increasingly sophisticated. For example, on Thursday Google said its Chrome operating system will run applications only in its browser, and store all data in the cloud.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
6 out of 6 people found this useful


Full Talkback thread

2 comments

  1. Yup but.. CA
  2. Small Business? Tezzer

More in this Special Report

Roundup: Cloud Watch special report

Roundup: Cloud Watch special report

Untangle the hype and the promise, the good and the bad, the risks and the benefits of cloud computing more

Cloud clout: Who are the real powers in the cloud?

Cloud clout: Who are the real powers in the cloud?

Cloud computing looks like it will reshape the IT landscape, but which vendors are the real powerhouses behind that change. We pick out the Big Five — plus one to watch more

Five cloud computing myths exploded

Five cloud computing myths exploded

The cloud is providing a fertile habitat for the marketeers and their exaggerated claims. We examine the hokum and debunk the five most frequently peddled misconceptions about the cloud more

Must all apps be virtualisation-aware for the cloud?

Must all apps be virtualisation-aware for the cloud?

On the face of it, reluctance to virtualise certain applications could conflict with a shift to cloud computing, says Lori MacVittie more

Amazon gives users more cloud control

Amazon gives users more cloud control

Amazon Web Services unveils new features that let users monitor, adjust and balance its cloud services more

Cloud won't become standard, says Kaspersky

Cloud won't become standard, says Kaspersky

At Infosecurity 2009, Eugene Kaspersky told ZDNet UK that businesses will use both traditional networks and cloud computing in the future more

Cloud savings fail to make up for loss of control

Cloud savings fail to make up for loss of control

The price of a cloud service is not necessarily the most important factor. That's because cost is always trumped by control, says Rafe Needleman more

Q&A: HP plans reign of ink from the cloud

Q&A: HP plans reign of ink from the cloud

The company wants to move consumer printing away from PCs and onto the web, shedding drivers along the way more

Inside IBM's only European Cloud Centre

Inside IBM's only European Cloud Centre

IBM has set up its first cloud centre in Europe, and it is in Ireland, just outside Dublin more

What is the cloud's killer app?

What is the cloud's killer app?

SAP chief technology officer Vishal Sikka discusses the next big thing in cloud apps at the Interop conference in Las Vegas more

Video: Who is really moving to the cloud?

Video: Who is really moving to the cloud?

A panel of experts offer their take on what types of organisation are taking up cloud-computing services more

Four reasons why business will take to the cloud

Four reasons why business will take to the cloud

Over the next five years, there will be a huge financial incentive to make the switch to cloud computing — and it will be hard to resist, says Jason Hiner more

Video icon

Video

Sentry Posts Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Bletchley Park calls for operators for...

The home of World War II codebreaking has called for engineers to operate an electro-mechanical machine developed by mathematician Alan Turing. The Turing Bombe was a brute-force... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters