|
How secure is the data on cloud and what are the associated security risks to it? How is cloud tested?
asked
by Shreyas Lad
11 months ago
Hi,I am a student of MS Information Systems Business IT at Manchester Business School – UK, doing my research project on Application of Cloud computing technologies in distance learning education delivery. As a part of my research, I will require inputs to my questions (listed below) from the people who are into cloud computing industry or the ones who have substantial knowledge on it. The questions are mainly based on the security issues associated with cloud. Your views and inputs will be very beneficial for me to build up further analysis on my research. You can either reply on this forum with your answers or email me on shreyas.lad@postgrad.mbs.ac.uk as soon as you can. The questions are
with your answers or email me on shreyas.lad@postgrad.mbs.ac.uk as soon as you can. The questions are
|
Three security risks should not b overlooked:
a) Privileged User Access– Sensitive data processed outside the enterprise brings with it an inherent level of risk, because outsourced services bypass the physical, logical and personnel controls IT departments exert over in-house programs. Put simply, outsiders are now insiders.
b) Server Elasticity – One of the major benefits of cloud computing is flexibility, so aside from the fact that you may not know (or could have little control over) exactly where your data is hosted, the servers hosting this data may also be provisioned and de-provisio
isioned frequently to reflect current capacity requirements. This changing topology can be an obstacle to some technologies you rely on today, or a management nightmare if configurations must be updated with every change.
c) Regulatory Compliance: Organizations are ultimately responsible for the security and integrity of their own data, even when it is held by a service provider. The ability to demonstrate to auditors that their data is secure despite a lack of physical control over systems, hinges in part on educating them, and in part on providing them with the necessary visibility into all activity.
(more)



