Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, June 10, 2012

Best Practices in Cloud Computing Implementation



We will love to have IT Managers' and CIOs comments to enrich this recompilation of the best practices on Cloud Computing implementation! To start here there are 2 important factors to consider when implementing Cloud Computing:


  • Security: As we have seen in previous posts this is the main topic debated when talking about Cloud Computing implementation. The Best Practice here is to be sure that the provider you chose have specialist in charge of the security 24/7 besides the normal setup and maintenance processes. Is worth to read about the Cloud Security Alliance a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders.
  • Choosing the Cloud Provider: The best practice here is to choose a renowned vendor in the industry. The more growth to the provider the more negotiation space you will have. Make sure you have SLAs (Service Level Agreements). Investigating the reliability and viability of a cloud provider is one of the most complex areas faced when managing the cloud. How to choose the right Cloud Computing Service Provider for Dummies
Here there are some more recompilations of Best Practices in Cloud Computing but we will like to enrich this recompilation with yours!!

Save Money on IT Infrastructures

Reduce IT Infrastructure Costs


Infrastructure as a Service (IaaS) is less known to the general public since it is usually addresses large companies' needs, rather than individuals'. However, IaaS services have a lot to offer to even small companies and could reduce IT costs significantly. In this post, I'll try to elaborate about this topic to help you save money on unnecessary in-house IT infrastructures.



As I've mentioned in the Cloud-up your business post, IaaS is related to IT infrastructure services that can be bought, or rented, over the Internet. For those who needs it most, this definition means nothing. In order to simplify it, here are some examples of infrastructures that are in use in businesses: storage, network services, security appliances and databases.

But how could you use export your organization storage, or network services, to the cloud?

Imagine that your business required 1TB of storage in 2008 to archive all invoices, customers' data, internal documents, accounting reports and so on. If you want a reliable way to store all this important data, and to allow access to it from every where, you would have to do the following:
(1) Buy at least 2 hard-drives (for redundancy) of 3 TB each (to allow future growth)
(2) Install it in a secure and appropriate place (so nobody would be able to steal it, or just accidentally trip over it)
(3) Connect it to the business network (using another computer or a router)
(4) Configure everything
(5) Define security policy and how to enforce it
(6) Routinely maintain the disks so it won't get fragmented (which affects speed and performance)
(7) Install UPS to the storage and network devices to allow availability in case of a power failure

Having done all this, and you still left with a major problem - if there are more than one physical locations for your office, or you wish to work from home, in every problem that may happen from those HDs to the remote location, you will loose your ability to work. If the UPS is down, if the cleaning lady/guy broke something by mistake, if the router has malfunctioned, if there are too many people accessing the HD at once, if...    All would damage your work in the short run, and make you loose customers and business opportunities in the long run.

Using the alternative cloud-based storage is done as follows:
(1) Select your preferable service provider (such as Dropbox, Google Drive, Amazone Web Services, etc.)
(2) Sign-up for the service
(3) Configure all devices to work with the selected service
(4) Go to a happy-hour-beer-serving bar and watch a Euro 2012 football match

In this way, you would never have to worry about maintenance, or possible failures. As long as you have an Internet connection, you will always be able to access your business data. The IaaS service provider companies will take care of the rest - matinating the health of their storage device, the security policy, backups, replacing malfunctioned hardware, iron your shirts, and so one. And all for just a few dollars per month. Amazing, isn't it?!

This is also applied for network services, which allows you to set a secured network for your organization, without installing your own modems and routers from point-to-point. ISP are using advanced network technologies such as MPLS (Multiprotocol Label Switching) to set-up Virtual Private Networks (VPNs) according to their customers' needs and specifications. These VPNs acts as private networks for organizations and businesses allowing them to control traffic, ensure quality-of-service to end-users, enforce security policy and more. Before that, companies needed to install their own network appliance to benefit from these services. Nowadays, it is all one phone call  away from being "installed" in your company and starting to save you money and increase your efficiency.

You can use Cloudorado, or alternative comparison websites, to compare between some of the IaaS providers.

The main takeaway is that almost everything can be bought/rented as a cloud service. All that needs to be done is to define the specifications of your needs and find the appropriate provider.


NinjaCloud

Monday, May 28, 2012

Acknowledging Security Issues in Cloud Computing


Seven cloud-computing security risks
Here is an interesting article about some of the risks cloud computing carries, and things you should watch out.

Gartner: Seven cloud-computing security risks

Cloud computing is picking up traction with businesses, but before you jump into the cloud, you should know the unique security risks it entails

By Jon Brodkin | Network World

Cloud computing is fraught with security risks, according to analyst firm Gartner. Smart customers will ask tough questions and consider getting a security assessment from a neutral third party before committing to a cloud vendor, Gartner says in a June report titled "Assessing the Security Risks of Cloud Computing."
Cloud computing has "unique attributes that require risk assessment in areas such as data integrity, recovery, and privacy, and an evaluation of legal issues in areas such as e-discovery, regulatory compliance, and auditing," Gartner says. (Compare security products.)
Amazon's EC2 service and Google's Google App Engine are examples of cloud computing, which Gartner defines as a type of computing in which "massively scalable IT-enabled capabilities are delivered 'as a service' to external customers using Internet technologies."
[ Learn more about what cloud computing really means and the new breed of utility computing and platform-as-a-service offerings. ]
Customers must demand transparency, avoiding vendors that refuse to provide detailed information on security programs. Ask questions related to the qualifications of policy makers, architects, coders and operators; risk-control processes and technical mechanisms; and the level of testing that's been done to verify that service and control processes are functioning as intended, and that vendors can identify unanticipated vulnerabilities.
Here are seven of the specific security issues Gartner says customers should raise with vendors before selecting a cloud vendor.
1. Privileged user access. Sensitive data processed outside the enterprise brings with it an inherent level of risk, because outsourced services bypass the "physical, logical and personnel controls" IT shops exert over in-house programs. Get as much information as you can about the people who manage your data. "Ask providers to supply specific information on the hiring and oversight of privileged administrators, and the controls over their access," Gartner says.
2. Regulatory compliance. Customers are ultimately responsible for the security and integrity of their own data, even when it is held by a service provider. Traditional service providers are subjected to external audits and security certifications. Cloud computing providers who refuse to undergo this scrutiny are "signaling that customers can only use them for the most trivial functions," according to Gartner.
3. Data location. When you use the cloud, you probably won't know exactly where your data is hosted. In fact, you might not even know what country it will be stored in. Ask providers if they will commit to storing and processing data in specific jurisdictions, and whether they will make a contractual commitment to obey local privacy requirements on behalf of their customers, Gartner advises.
4. Data segregation. Data in the cloud is typically in a shared environment alongside data from other customers. Encryption is effective but isn't a cure-all. "Find out what is done to segregate data at rest," Gartner advises. The cloud provider should provide evidence that encryption schemes were designed and tested by experienced specialists. "Encryption accidents can make data totally unusable, and even normal encryption can complicate availability," Gartner says.
5. Recovery. Even if you don't know where your data is, a cloud provider should tell you what will happen to your data and service in case of a disaster. "Any offering that does not replicate the data and application infrastructure across multiple sites is vulnerable to a total failure," Gartner says. Ask your provider if it has "the ability to do a complete restoration, and how long it will take."
6. Investigative support. Investigating inappropriate or illegal activity may be impossible in cloud computing, Gartner warns. "Cloud services are especially difficult to investigate, because logging and data for multiple customers may be co-located and may also be spread across an ever-changing set of hosts and data centers. If you cannot get a contractual commitment to support specific forms of investigation, along with evidence that the vendor has already successfully supported such activities, then your only safe assumption is that investigation and discovery requests will be impossible."
7. Long-term viability. Ideally, your cloud computing provider will never go broke or get acquired and swallowed up by a larger company. But you must be sure your data will remain available even after such an event. "Ask potential providers how you would get your data back and if it would be in a format that you could import into a replacement application," Gartner says.

http://www.infoworld.com/d/security-central/gartner-seven-cloud-computing-security-risks-853?page=0,0