On Aug. 31, the Carnegie Endowment for International Peaces Cyber Policy Initiative released the report Cloud Security: A Primer for Policymakers, written by Tim Maurer and Garrett Hinck, and the Atlantic Councils Cyber Statecraft Initiative launched Four Myths About the Cloud: The Geopolitics of Cloud Computing by Trey Herr. The Carnegie report focuses on (a) the question of what the cloud is, (b) the evolution of the cloud and its market, and (c) cloud security, including a review of past cloud-related incidents and novel frameworks to think through key issues. The Atlantic Councils report offers a brief primer on the concepts that undergird cloud computing and then takes on four myths about the interaction of cloud and geopolitics: (a) that all data is created equal, (b) that cloud computing is not a supply-chain risk, (c) that only authoritarian states distort the public cloud, and (d) that cloud providers do not influence the shape of the internet.
Below is a Q&A with the authors of both reports:
Question #1: How do you think about cybersecurity with respect to the cloud?
When thinking about cloud security from a public policy perspective, the need to address an existing public policy problem must be differentiated from the need to address an emerging public policy problem. The existing public policy problem is the rising cost of cyberattacks and the deteriorating cybersecurity landscape. Most organizationsgovernments and companiesstruggle to protect themselves against efforts to undermine their information systems. Few organizations can rival the security teams of the large cloud service providers, so many opt to entrust these teams with their security. Policymakers must balance these benefits against the emerging risk of concentrationthat increased reliance on a few major cloud service providers could expose societies writ large to systemic risks (see more here).
However, cloud computing security is rooted in shared responsibility. Cloud services provide organizations with a host of capabilities and make things like widespread automation easier, but they dont relieve those organizations of responsibility for understanding and managing their cybersecurity. The same is true in the policy environmentcloud providers can offer answers with technology, but its up to customers to define the questions and up to policymakers to shape which questions and answers are important for the public good.
Question #2: What are the biggest popular misconceptions about cloud computing?
Two are most prominent.
First, theres a misconception that a migration to the cloud will solve all of an organizations cybersecurity problems. While it is generally true that a migration to the cloud will better protect most organizations, the migration itself creates a new, temporary risk, particularly for accidents. It then also requires a different security approach to manage the shared responsibility effectively.
Cloud providers do not operate either as democracies or as monoliths. The reality is somewhere in between; no organization the size of Microsoft or Amazon operates as a cohesive whole. Decision-making is fragmented, business units are competitive, and C-suite leadership is involved in overlapping political coalitionsand theres even the odd coup. Companies make decisions by a mix of consensus and individual leadership, but these deliberations are largely opaque to the public and policy community. Contemporary models of corporate governance are an exemplary way to drive innovation while also keeping the trains running on time, but they get low marks for popular accountability and transparency. As cloud computing increasingly resembles utility infrastructure like power or water, these providers decisions will shape social and political outcomes, and this opacity will steadily become costlier to corporations and citizenry alike.
Oh, and the cloud isnt literally made of clouds, despite the image reinforced by giant advertisements at subway stations, airports, on buses, and the like. The illusion of some fluffy, white ephemera where users store data, which automagically makes computing happen, obscures the realities of the very tangible hardware infrastructure and highly complex software architecture at the clouds foundation. It also obscures the fact that this is a hard-nosed business run primarily by a few giant tech companies.
Question #3: What will cloud governance look like in the future?
It will be messy. The industry is experiencing tremendous competitive pressure as cloud adoption accelerates, especially in Eastern Europe, parts of Africa and Asia. Governments are increasingly asserting the need for sovereignty over data and infrastructure, and this drives cloud providers to repeatedly modify their offerings and technical architecture. Some governments in Europe and, to a greater extent, China are putting pressure on foreign providers to help support domestic cloud competitors, further muddying the good-faith facade of security and privacy regulations. The political schism between the United States and China is slowly rippling into the cloud computing supply chain, forcing companies to reevaluate long-standing vendor relationships and reprice their own exposure to national security risks. As millions of cloud users emerge in Japan, India and Indonesia, the still largely transatlantic debates about data governance in the cloud will become yet more complex.
As other countries attempt to expand their domestic regulatory authority to encompass cloud service providers, either through the extraterritorial reach of domestic laws beyond national borders or by forcing companies to store and process data locally, cloud service providers will likely behave as other firms have in the past. Depending on the market, companies will (a) comply with the regulation for the largest and most important markets such as the U.S., (b) communicate that they comply with other countries regulations de jure, while de facto using only a few jurisdictions as internal benchmarks, or (c) decide not to enter or opt to leave markets that have overly onerous regulatory burdens.
Policymakers could respond with a multilateral regime with common standards akin to the creation of the SWIFT financial transactions network. However, in todays geopolitical environment, such an outcome seems unlikely, especially considering that the largest cloud service providers are located in two countries: the U.S. and China. It is more likely that we will see a fragmented regulatory approach emerge along two dimensions. Along one dimension, fragmentation among jurisdictions will lead to individual countries and small groups of like-minded countries creating regulatory frameworks. Along the other dimension, fragmentation across sectors will lead to individual sectors starting to impose regulations that affect cloud service providers, for example, through third-party provisions.
Cloud governance today is characterized by overlapping security and certification regimes, a thicket of national and supranational data governance rules, and myriad contractual obligations from large enterprise firms and governments. Cloud governance in the future is likely to see these trends accelerate, creating more significant barriers to market entry, legitimate concerns over market concentration, and continuing fragmentation of the public cloud into national and regional community clouds.
Question #4: How can we think about the cloud and resilience today?
It is no secret that tech companies are fiercely competitive, so the willingness of companies to cooperate to tackle shared threats and systemic risks is limited. The U.S. television show Silicon Valley was so popular partly because the satirical show portrayed the rivalries among the leaders of the tech industry apparently rather than accurately. With many tech companies less than three decades old, their maturity as companies and as an industry pales in comparison to other industries such as the finance, automotive or aviation sectors. Even Wall Street firms, usually not known for being cozy with each other, come together to better protect themselves against cyber risks, for example, through sectorwide exercises or joint initiatives such as the Financial Systemic Analysis & Resilience Center.
Improved resilience of cloud computing will come from the diversity of cloud architecture providers and increased capacity for cloud providers to adapt to evolving threats and technology bases. The biggest threat to resilience is fragility and brittlenesssystems that are unable to evolve in response to unexpected changes or that fail gracefully when overwhelmed or compromised. Security certification schemes for the cloud, including some government programs like the U.S. FedRAMP, were adopted from programs and controls built for information technology in the 1990s and 2000s. These programs sought to prescribe best practices as a way to manage risk. The problem is that these programs, and their tendency to prescribe specific tenets of system design, slow a cloud providers ability to adapt their systems or provide novel technical approaches to deliver the same outcome. Security regulations should emphasize outcomes and measurable system performance over architectural prescription. The lack of cloud-native security regulation in the United States provides opportunities for emerging markets like Poland and India, and more flexible security programs like the U.K.s G-Cloud, to become models of resilience.
Question #5: Where are the next great geopolitical flashpoints over the cloud?
As the tensions between the U.S. and China are increasing, the geopolitics between the two powers is starting to affect not only the roll-out of 5G but also other technology policy issuesperhaps even cloud computing. With respect to cloud service providers, countries have limited options. They can choose among the main cloud service providers today that are located in either the U.S. or China. While some states are trying to build their own cloud infrastructure, such as the E.U. with its GAIA-X project, it is uncertain if these efforts will succeed. This will likely lead to a landscape where companies in countries that are allies and partners close to Washington will choose a U.S.-based cloud service provider over a Chinese-based one, whereas companies in countries close to Beijing will choose a Chinese one. The most interesting area to watch will be those countries aligned with neither Washington nor Beijing. In those countries caught in the middle, will companies decide to spread the risk among cloud providers from each of the two rivals or find the value proposition of one more appealing than the other?
Another next great flashpoint could well be hacker-for-hire firms operating out of Russia, India and parts of the Middle East. These groups build, and in some cases deploy, offensive cybersecurity capabilities on behalf of paying customers targeting users and organizations all over the world. As cloud adoption has accelerated, an increasing number of these targets are hosted on one providers cloud infrastructure. The challenge is that at large scale, these hacker-for-hire groups operate with some degree of benign neglect, if not complicity, from their host governments. As cloud providers increasingly sell to companies in these countries, even to these same governments, they will be forced to choose between, on the one hand, hampering the operation of these hacker-for-hire groups and protecting their users or, on the other, cozying up to new markets and regimes. The result is likely to ensnare the United States and other allied states as well.
Go here to see the original:
A Few Questions on Cybersecurity and the Cloud - Lawfare
- Open source cloud computing slow to catch on, survey finds [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Oracle CFO: no acquisitions needed to compete in cloud [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- IDC Survey: U.S. Corporations Aim to Tackle IT Challenges with Cloud Computing [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Where does the ICO's new cloud guidance take you? [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- ChinaSoft International Signs Strategic Cooperation Agreement with Alibaba Cloud Computing to Develop PaaS Platform [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- IT Leaders Forum: Shedding light on cloud computing [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Oracle Public Cloud Computing [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Oracle Cloud Computing - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Computing 101 - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Lenovo Gets Into Cloud Computing - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Computing Certification Training | Cloud Computing Training By Simplilearn - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Computing - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Succeeding or Failing with Cloud Computing - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Demystifying the Cloud - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- N: Cloud Computing, Syria PM Defects, US to Clean Agent Orange and MORE! - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Computing - Tv9 - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- AWS 101 Cloud Computing Seminar-Bangalore - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Trust - The Key to Cloud Computing Growth in Europe [Last Updated On: October 6th, 2012] [Originally Added On: October 6th, 2012]
- Cloud Computing Saves Health Care Industry Time And Money [Last Updated On: October 6th, 2012] [Originally Added On: October 6th, 2012]
- Synnex CEO Kevin Murai: Tablets, Mobile, Cloud Computing (p3) - Video [Last Updated On: October 6th, 2012] [Originally Added On: October 6th, 2012]
- Enterprise computing IS the cloud [Last Updated On: October 8th, 2012] [Originally Added On: October 8th, 2012]
- 44 Percent Of US Execs To Tackle IT Challenges Through Cloud [Last Updated On: October 8th, 2012] [Originally Added On: October 8th, 2012]
- ZapThink Announces Expansion of Cloud Computing for Architects Course [Last Updated On: October 9th, 2012] [Originally Added On: October 9th, 2012]
- Euro Zone Eyes Cloud Computing to Kick Start Economy [Last Updated On: October 9th, 2012] [Originally Added On: October 9th, 2012]
- Advantages, challenges of cloud computing discussed Oct. 10 at NJIT [Last Updated On: October 10th, 2012] [Originally Added On: October 10th, 2012]
- Dell Expands Cloud Client Computing Solutions for VMware View®, Desktop as a Service and Channel Offerings to Europe [Last Updated On: October 10th, 2012] [Originally Added On: October 10th, 2012]
- Cloud West to Focus on Entertainment Delivery, Network Infrastructure, and Investment, More at Nov. 8-9th Forum [Last Updated On: October 10th, 2012] [Originally Added On: October 10th, 2012]
- IBM, AT&T Offer Secure Passage to the Cloud [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Cloud computing company hits new fundraising heights [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Cloud computing firm hits new fundraising heights [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Cloud computing: here we go again [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Chinese Want to Put Computer 'Brains' in the Cloud [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- CenturyLink Unveils Cloud Product [Last Updated On: October 12th, 2012] [Originally Added On: October 12th, 2012]
- Cloud Security Evolves in Wellington [Last Updated On: October 14th, 2012] [Originally Added On: October 14th, 2012]
- 2X ApplicationServer XG Joins the Intel AppUp SMB Service Hybrid Cloud [Last Updated On: October 15th, 2012] [Originally Added On: October 15th, 2012]
- Piston Cloud to Exhibit and Present at the 2012 OpenStack Summit in San Diego [Last Updated On: October 15th, 2012] [Originally Added On: October 15th, 2012]
- How to get your first cloud computing job [Last Updated On: October 15th, 2012] [Originally Added On: October 15th, 2012]
- DreamHost Adds Public Cloud Computing Service: DreamCompute [Last Updated On: October 15th, 2012] [Originally Added On: October 15th, 2012]
- Aryaka Receives 2012 Cloud Computing Excellence Award [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Making a Europe fit for the cloud [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Cisco Execs Plumb The Limits Of Cloud Computing [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Cloud firm invests in new network [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- AirWatch Receives 2012 Cloud Computing Excellence Award [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Dell Extends Cloud Client Computing Portfolio with New Solutions Validated by Citrix [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Pano Logic and Alliance InfoSystems Join Forces to Deliver Zero Client Computing [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- 5 Cloud Business Benefits [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Alteva Receives 2012 Cloud Computing Excellence Award [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Open Text profit beats estimates on cloud services [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud computing improves nurse call system [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud computing: Top five tax considerations for your business [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- OKI and ISID to Provide Chemical Information System as Cloud Computing Services [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- As Mobile Grows, So Does Cloud Computing [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- IBM Analytical Decision Management SaaS - IBM Cloud TechTalk October 2012 - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- JAX London 2012: Achieving genuine elastic multitenancy with Waratek Cloud VM for Java - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Microsoft 2020 technology future vision - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Infinity Cloud Point of Sale and Complete Retail Suite.mp4 - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Small Business IT Support, Computer Support, Web Design Atlanta - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud Computing - Simplified - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- How Allied Valve Used the Cloud to Expand in Bakken Oilfield - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud Computing in the Public Sector - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud Computing | Sacramento | Data Protection | IT Consulting | Symmetry Managed Servces - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- The Business Value of Cloud Computing - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- GYMNAZO Owner/Coach Michael Hughes is excited about edufii - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Automation in the age of cloud computing - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud Computing.mp4 - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud computing in 2013: a conversation with Appcore's CEO [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Cloud adoption growing in India: study [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Eastday-Microsoft picks city for cloud computing [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Towards a blue sky: How SMEs can avoid Cloud Computing confusion [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Consultancy Services - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Axxis Solutions Sponsors FIBA Technical Seminar on Cloud Computing - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- RightScale Webinar: 451 Research Webinar: Cloud Dos and Don'ts - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Apple Technology (Vishwa Bandhu Gupta) - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Mind Tree Ltd. - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- BIM Cloud Computing [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Entreda discusses cloud services for small and medium businesses - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Austin IT Company | Computer Networking [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Cloud Computing and Services - After Effects Template - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- FieldStorm App Tour - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- The Hon Brendan O'Connor's speech: AccountRight Live launch event - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]