|By Dan Morrill||
|October 28, 2008 03:45 AM EDT||
The Cloud Ave Blog
When headlines like “RMS hates cloud computing; says you should too”, “Cloud Computing a Trap” or “Cloud computing puts your health data at risk” show up on the Internet, it looks like the same old FUD (Fear Uncertainty and Doubt) that have been the inevitable response from the security community or from people who do not accommodate change well.
It is time to start embracing where business is going, and trying to make sure that they are doing it in the safest way possible.
It is one thing to create FUD, it is quite another to offer no solutions or pointers to the solutions for the problems we are seeing. To remain credible security professionals have to provide solutions to go along with what we are talking about.
The problem is also that we are not providing answers back to the security community that needs support and guidance. There are very few information security experts in cloud computing. It is hard to have your average IDS watcher, or network security engineer understand that cloud computing offers benefits and risks, just as much as virtualization, or even the iPhone.
What security professionals need to be doing rather than creating their own FUD is work out ways to make it safer. It is time to stop fearing change and learn about cloud computing technology and what it can and cannot do for the business. Work through a risk matrix, work through measures and counter measures, do all those good things that security engineers should be doing.
What I am seeing in the community, on blogs, and in private communications is the same earnest viewpoint of proposing a six million dollar security solution for a 15-minute wireless test by insisting that a Faraday cage had to be built around the two buildings we wanted to use in the test. That the Faraday cage would have invalidated the test because we never would have been able to go point-to-point wireless as the test protocol asked for.
While we might struggle with new technology, it is time for information security folks to step up to the plate and get smart on how the technology works, what the risks are, and how those risks can be reasonably addressed by good security solutions.
There are tricks to cloud computing that will remind you of a SAN, there are things that will annoy you like logging, there are things that will make you happy like automatically having an MD5 has on every object on the system if you use Amazon AWS or S3. Or using the power of the cloud to acquire and digest computer images for forensics. Let alone the power that the cloud represents in actually meeting C2 logging levels for databases, or the raw log crunching power of the system. Or the ability to test patching routines for systems by building instances against images and regression testing there instead of on a thrown together test bed. There is a lot of love when it comes to cloud computing.
There are things to worry about, privacy, control of objects, legal discovery, who has access to what questions that arise anyways in a corporate environment, e-mail security, database security, what about the provider going out of business, or a host of other legitimate concerns about the security, privacy, access, and availability of the data or the objects.
There is also very little usable information from the security viewpoint on these issues, some of this is addressable, some of it will mean that information security professionals learn as they go using the best practices. They will also have to fall back on what they know, what they are legally responsible for, and what the real issues are to help management make the best decision that they can. They will not make a decision that security folks will like, because many data points are going to move off the local networks, and go to reside somewhere else in the world.
There are some great resources for good information, Cloud Ave is one of them, but Trend Micro, IBM, Google, Amazon, Microsoft, Oracle and others who have all figured out that this can be a very neat technology and help companies expand and contract according to business need and market conditions.
While it is not ‘inevitable’, it is probable that companies are going to move some operations off the local network and into the cloud. The best bet right now for the security engineer is to work through the process, and get smart now so that management can benefit from what you have learned.
[This post appeared originally here and is republished in full by kind permission of the editor-in-chief of CloudAve.com.]
Attribution to http://www.cloudave.com
SYS-CON Events announced today that DatacenterDynamics has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY. DatacenterDynamics is a brand of DCD Group, a global B2B media and publishing company that develops products to help senior professionals in the world's most ICT dependent organizations make risk-based infrastructure and capacity decisions.
Apr. 29, 2016 05:45 AM EDT Reads: 2,387
SYS-CON Events announced today TMCnet has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Technology Marketing Corporation (TMC) is the world's leading business-to-business and integrated marketing media company, servicing niche markets within the com...
Apr. 29, 2016 04:45 AM EDT Reads: 2,338
The IoT has the potential to create a renaissance of manufacturing in the US and elsewhere. In his session at 18th Cloud Expo, Florent Solt, CTO and chief architect of Netvibes, will discuss how the expected exponential increase in the amount of data that will be processed, transported, stored, and accessed means there will be a huge demand for smart technologies to deliver it. Florent Solt is the CTO and chief architect of Netvibes. Prior to joining Netvibes in 2007, he co-founded Rift Technol...
Apr. 28, 2016 07:00 PM EDT Reads: 1,465
Join IBM June 8 at 18th Cloud Expo at the Javits Center in New York City, NY, and learn how to innovate like a startup and scale for the enterprise. You need to deliver quality applications faster and cheaper, attract and retain customers with an engaging experience across devices, and seamlessly integrate your enterprise systems. And you can't take 12 months to do it.
Apr. 28, 2016 04:45 PM EDT Reads: 1,724
This is not a small hotel event. It is also not a big vendor party where politicians and entertainers are more important than real content. This is Cloud Expo, the world's longest-running conference and exhibition focused on Cloud Computing and all that it entails. If you want serious presentations and valuable insight about Cloud Computing for three straight days, then register now for Cloud Expo.
Apr. 28, 2016 04:30 PM EDT Reads: 1,617
IoT device adoption is growing at staggering rates, and with it comes opportunity for developers to meet consumer demand for an ever more connected world. Wireless communication is the key part of the encompassing components of any IoT device. Wireless connectivity enhances the device utility at the expense of ease of use and deployment challenges. Since connectivity is fundamental for IoT device development, engineers must understand how to overcome the hurdles inherent in incorporating multipl...
Apr. 28, 2016 02:45 PM EDT Reads: 1,360
Machine Learning helps make complex systems more efficient. By applying advanced Machine Learning techniques such as Cognitive Fingerprinting, wind project operators can utilize these tools to learn from collected data, detect regular patterns, and optimize their own operations. In his session at 18th Cloud Expo, Stuart Gillen, Director of Business Development at SparkCognition, will discuss how research has demonstrated the value of Machine Learning in delivering next generation analytics to im...
Apr. 28, 2016 02:30 PM EDT Reads: 1,550
Manufacturers are embracing the Industrial Internet the same way consumers are leveraging Fitbits – to improve overall health and wellness. Both can provide consistent measurement, visibility, and suggest performance improvements customized to help reach goals. Fitbit users can view real-time data and make adjustments to increase their activity. In his session at @ThingsExpo, Mark Bernardo Professional Services Leader, Americas, at GE Digital, will discuss how leveraging the Industrial Interne...
Apr. 28, 2016 01:15 PM EDT Reads: 1,085
The paradigm has shifted. A Gartner survey shows that 43% of organizations are using or plan to implement the Internet of Things in 2016. However, not just a handful of companies are still using the old-style ad-hoc trial-and-error ways, unaware of the critical barriers, paint points, traps, and hidden roadblocks. How can you become a winner? In his session at @ThingsExpo, Tony Shan will present a methodical approach to guide the holistic adoption and enablement of IoT implementations. This ov...
Apr. 28, 2016 01:00 PM EDT Reads: 1,500
SYS-CON Events announced today that Stratoscale, the software company developing the next generation data center operating system, will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. Stratoscale is revolutionizing the data center with a zero-to-cloud-in-minutes solution. With Stratoscale’s hardware-agnostic, Software Defined Data Center (SDDC) solution to store everything, run anything and scale everywhere...
Apr. 28, 2016 12:45 PM EDT Reads: 1,450
Angular 2 is a complete re-write of the popular framework AngularJS. Programming in Angular 2 is greatly simplified – now it's a component-based well-performing framework. This immersive one-day workshop at 18th Cloud Expo, led by Yakov Fain, a Java Champion and a co-founder of the IT consultancy Farata Systems and the product company SuranceBay, will provide you with everything you wanted to know about Angular 2.
Apr. 28, 2016 12:15 PM EDT Reads: 1,602
Digital payments using wearable devices such as smart watches, fitness trackers, and payment wristbands are an increasing area of focus for industry participants, and consumer acceptance from early trials and deployments has encouraged some of the biggest names in technology and banking to continue their push to drive growth in this nascent market. Wearable payment systems may utilize near field communication (NFC), radio frequency identification (RFID), or quick response (QR) codes and barcodes...
Apr. 28, 2016 12:00 PM EDT Reads: 532
SYS-CON Events announced today that Men & Mice, the leading global provider of DNS, DHCP and IP address management overlay solutions, will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. The Men & Mice Suite overlay solution is already known for its powerful application in heterogeneous operating environments, enabling enterprises to scale without fuss. Building on a solid range of diverse platform support,...
Apr. 28, 2016 11:30 AM EDT Reads: 2,175
You deployed your app with the Bluemix PaaS and it's gaining some serious traction, so it's time to make some tweaks. Did you design your application in a way that it can scale in the cloud? Were you even thinking about the cloud when you built the app? If not, chances are your app is going to break. Check out this webcast to learn various techniques for designing applications that will scale successfully in Bluemix, for the confidence you need to take your apps to the next level and beyond.
Apr. 28, 2016 11:00 AM EDT Reads: 1,394
The increasing popularity of the Internet of Things necessitates that our physical and cognitive relationship with wearable technology will change rapidly in the near future. This advent means logging has become a thing of the past. Before, it was on us to track our own data, but now that data is automatically available. What does this mean for mHealth and the "connected" body? In her session at @ThingsExpo, Lisa Calkins, CEO and co-founder of Amadeus Consulting, will discuss the impact of wea...
Apr. 28, 2016 10:30 AM EDT Reads: 526
Whether your IoT service is connecting cars, homes, appliances, wearable, cameras or other devices, one question hangs in the balance – how do you actually make money from this service? The ability to turn your IoT service into profit requires the ability to create a monetization strategy that is flexible, scalable and working for you in real-time. It must be a transparent, smoothly implemented strategy that all stakeholders – from customers to the board – will be able to understand and comprehe...
Apr. 28, 2016 10:15 AM EDT Reads: 938
So, you bought into the current machine learning craze and went on to collect millions/billions of records from this promising new data source. Now, what do you do with them? Too often, the abundance of data quickly turns into an abundance of problems. How do you extract that "magic essence" from your data without falling into the common pitfalls? In her session at @ThingsExpo, Natalia Ponomareva, Software Engineer at Google, will provide tips on how to be successful in large scale machine lear...
Apr. 28, 2016 10:00 AM EDT Reads: 717
SYS-CON Events announced today that Ericsson has been named “Gold Sponsor” of SYS-CON's @ThingsExpo, which will take place on June 7-9, 2016, at the Javits Center in New York, New York. Ericsson is a world leader in the rapidly changing environment of communications technology – providing equipment, software and services to enable transformation through mobility. Some 40 percent of global mobile traffic runs through networks we have supplied. More than 1 billion subscribers around the world re...
Apr. 28, 2016 10:00 AM EDT Reads: 676
SYS-CON Events announced today that Fusion, a leading provider of cloud services, will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. Fusion, a leading provider of integrated cloud solutions to small, medium and large businesses, is the industry's single source for the cloud. Fusion's advanced, proprietary cloud service platform enables the integration of leading edge solutions in the cloud, including cloud...
Apr. 28, 2016 09:30 AM EDT Reads: 2,498
The IETF draft standard for M2M certificates is a security solution specifically designed for the demanding needs of IoT/M2M applications. In his session at @ThingsExpo, Brian Romansky, VP of Strategic Technology at TrustPoint Innovation, will explain how M2M certificates can efficiently enable confidentiality, integrity, and authenticity on highly constrained devices.
Apr. 28, 2016 09:00 AM EDT Reads: 943