Security - CIOInsight
Home arrow Security arrow Page 2 - Black Hat 2010: 10 Security Hotspots for CIOs
RECENT NEWS



CIO STRATEGY
The Perfect IT Book for the Business?

Parkinson needs a book that explains IT to the business. Got any suggestions?    

  Security


Black Hat 2010: 10 Security Hotspots for CIOs



By Sean Martin


  Table of Contents:
  1. Black Hat 2010: 10 Security Hotspots for CIOs
  2. Cloud Security Challenges
  3. Virtualization Pitfalls
  4. Risk Management: Depth or Breadth?
  5. Collaboration Carries Exploit Potential
  6. Enterprise Mobility Has Inherent Risks
  7. Open-Source Tools Carry Dangers
  8. System Hardening: Its Time Has Come
  9. SSL and HTTPS: Not So Strong?
  10. Web-Based Attacks Gain Power
  11. Social Networking Hides Hazards

The annual Black Hat Technical Security Conference is known for its colorful audience, many of which are self-described hackers. Here are the 10 hottest security topics from the event, plus actions every CIO can take to minimize enterprise risks.

Rate This Article:
Add This Article To:

Black Hat 2010: 10 Security Hotspots for CIOs - Cloud Security Challenges


( Page 2 of 11 )

As you probably know, the Cloud is the mass-market, low-cost, commodity abstraction of hyper-scalable computer, network and storage capabilities. These are delivered as a managed service, replacing and/or augmenting what was once an in-house collection of physical IT infrastructure, platforms, and software. This dramatic change in how information is stored, accessed, and transferred certainly opens up cloud computing to many security concerns. Primary among these is that, with cloud solutions, the traditional boundaries of an information system – for example, a firewall that surrounds the perimeter of an organization's physical IT infrastructure -- either disappear and/or continuously move based on the business needs for the system. Additionally, trust and security for the service is typically transferred to the cloud provider's physical and virtual infrastructure, while the legal liability remains with the enterprise using the cloud service.As you consider the cloud for any off-site hosted infrastructure, platform, or software services, your organization should only look to outsource routine processes and systems. Once the decision has been made to outsource, it is critical that you have a clear view into the steps the cloud provider has taken to continuously protect your data, the operating systems and the applications accessing and storing that data, including the virtual and physical systems tasked with hosting your environments. These are the top three things to look for:

  1. Data Confidentiality: Who has access to the system and its data, from which locations/systems/applications, and for which activities. Are there other Cloud instances residing physically next to yours, such as that of your biggest competitor?
  2. Data Integrity: How are the providers controlling and monitoring how the data has been accessed or manipulated; are they employing any identity management and/or timestamping technologies to authorize access and prove data integrity?
  3. Data Availability: How are they ensuring operational continuity of the systems and consumption of the data – what are the redundancy, failover, archiving, and recovery technologies and processes?

     
     
    >>> More Security Articles          >>> More By Sean Martin
     


FEATURED SPONSORED VIDEOS

FEATURED SPONSORED ARTICLES

Erasable E-Paper Saves Trees, Cuts Costs

Why Smart Companies Should Adopt the Lessons of Gaming

Interest in Mobile WiFi Hotspots Fuels New Solutions

A Closer Look at Public Cloud Security

View More Articles

  Brought to You By
Click Here




EDITORS' PICKS

LATEST STORIES


Advertisement
FEEDBACK
Ziff Davis Enterprise RSS Feeds

Sponsored Links
  • Try Windows Azure free for 90 days

  • Introducing the world's first family of systems with integrated expertise

  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 77% of the Fortune 500 Manage Content Securely with Box.
  • Leverage your virtual computing environment with Dell.
  • Build an IT Infrastructure That Delivers the Future
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • eWEEK Quick LInks

     
    Close this advertisement