Editor's note: This article is part of a series of short articles by analysts involved in the Cyberspace Solarium Commission, among others, highlighting and commenting upon aspects of the commission's findings and conclusion.
Cloud computing is championed by some as the way to secure smaller and medium-sized enterprises, state and local governments, and individuals. While very little marketing material says outright that cloud computing will solve an organizations security problems, the general implication is that shifting computing workloads into the cloud will address complex security challenges for the user and is a net positive.
The reality is that cloud computing is not a security panacea. The challenge for policymakers is that for all the promise and pitfalls of cloud computing in the abstract, the security capabilities of cloud providers vary wildly in practice.
Cloud services can remove administrative burdens, harness the data of millions of users to provide better security, and offer services to enforce more effective security behavior. However, moving workloads and data to the cloud does not eliminate implicit security problems and it creates some new ones. Much like the internet amplifies the good and bad of our pre-networked selves, organizations bring to the cloud many of the same security problems they had on-premises. Adopting cloud services brings new management challenges and requires security capacity on the part of adopting organizations to make it work (or recover from failure when it doesnt).
Cloud computing can be a lower cost alternative to on-premises information technology at comparable levels of security. The most successful segment of the cloud market, Infrastructure as a Service (IaaS), comes closest to mimicking traditional IT deployments. Cloud providers consolidate the physical security and plant management needed to keep data centers operating. They may offer well-integrated tools to manage credentials and security tokens and help reduce the effort required to manage incident detection and response programs.
Platform as a Service (PaaS) offerings are a more complex kettle, with trends toward containerization and serverless computing handing even more control and administrative responsibility over to cloud providers. This can produce benefits, hyper-cost-efficient services and novel offerings like confidential computing, which allows data to remain encrypted while being handled by a provider. PaaS presents new challenges as well. Serverless in particular offers organizations a new way of organizing their digital resources, creating new headaches in how to secure data, authenticate users and control access to sensitive resources. Users are relinquishing ever more control over security design and operational decisions in exchange for cost efficiencies, less administrative responsibility and potential security benefits.
The U.S. strategy to secure cloud computing is incomplete and, unless there is a shift in regulatory thinking, the push for cloud computing as a solution to security shortfalls in small and medium-sized organizations will only produce more risk. Policies need to reflect the fact that cloud is not a panacea for securityit offers opportunities for large and small enterprises but also serious pitfallsand should address the disparity in different cloud providers security capabilities. Successful efforts will produce certifications and security schemes that are sensitive to the presence of different kinds of infrastructure underneath a cloud service, are quickly adaptable to new features and new threats, and account for the need to manage complexity and not just increase it.
While companies like Microsoft and Google can afford to maintain specialized security and threat intelligence teams and Amazon has engineered its own technical solutions to particular security risks, like the Nitro hypervisor system, size is no guarantee of success. Amazons popular S3 data storage service is regularly plagued by compromised credentials, and a former employee with knowledge of the firms cloud infrastructure was responsible for a massive breach of Capital Ones customer records in 2019. Smaller vendors face the challenge of playing against the same adversaries as hyperscale providers (Microsoft, Amazon, Google and Alibaba) with far fewer resources. Smaller firms also have access to less data derived from their customersa key resource for cloud providers to learn about attacks on their services and stop them more effectively.
The situation is further complicated by overlapping regulatory requirements in the United States, European Union, and globally that require security time and talent be devoted to complying with outdated requirements rather than optimizing to current security challenges. The U.S. governments regulatory approach to cloud computing security is focused largely on risk management of the infrastructure itself, with some consideration for services, and little attention paid to the disparities in security capability between providers. The FedRAMP program provides a framework to authorize cloud services for use by federal agencies and departments. Based on security controls assembled by the boffins at the National Institute of Standards and Technology, FedRAMP is a slow security certification process that has evolved to distinguish different cloud service models but remains hamstrung by outdated federal IT security legislation like the Federal Information Security Management Act. FedRAMP as a whole is improving but is far outstripped by the pace of evolving commercial cloud services market, lags federal cloud adoption, and is ultimately bound to a risk management framework that has been adapted to cloud rather than created for it.
European efforts on cloud security have been limited to national policies, but a working group is underway to build a European Cloud Certification. The content of the certification and its focus are still uncertain. In an ideal world, any new entries to the regulatory landscape would work to fill holes in current standards and policyaddressing gaps in standards for cloud providers supply chain security, inconsistencies in national approaches to sharing security and incident response data, or leveling up the weakest security performers in the cloud industry. Dan Geer and Wade Baker published a short but insightful piece in late 2019, discussing the relative security performance of organizations operating their own computing infrastructure (on-premises) as opposed to those relying on a cloud services vendor. Their conclusion offered support for the thesis that cloud computing is not a panacea for security and gave a narrow but valuable view into the variable security performance of different cloud firms and the cloud as a general model versus on-premises infrastructure.
Cloud computing is an increasingly important domain of technology development and use. Its growth from academic research project to commercial technologies with billions of dollars in sales has commoditized computing capacity, storage, and networking bandwidth and led to a new generation of data-intensive startups. The security of these services as well as the security benefits they might offer organizations are not without cost and bring new challenges. Wherever the renewed debate on cloud computing security in the U.S. goes, it must account for the rapidly changing architecture of cloud services and the flexibility with which new services are created and modified along with the variable security capability of cloud providers. Transparency is an important tool to drive this flexibility with users and regulators and should encourage a more informed marketplace of cloud consumers. Cloud computing isnt a magic wand, but it provides a new set of tools to organizations and policymakers. Building (and rebuilding) policies to complement these tools will be a long but worthwhile effort.
See the original post:
Better to Be Realistic About the Security Opportunities of Cloud Computing - Lawfare
- Open source cloud computing slow to catch on, survey finds [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Oracle CFO: no acquisitions needed to compete in cloud [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- IDC Survey: U.S. Corporations Aim to Tackle IT Challenges with Cloud Computing [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Where does the ICO's new cloud guidance take you? [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- ChinaSoft International Signs Strategic Cooperation Agreement with Alibaba Cloud Computing to Develop PaaS Platform [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- IT Leaders Forum: Shedding light on cloud computing [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Oracle Public Cloud Computing [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Oracle Cloud Computing - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Computing 101 - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Lenovo Gets Into Cloud Computing - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Computing Certification Training | Cloud Computing Training By Simplilearn - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Computing - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Succeeding or Failing with Cloud Computing - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Demystifying the Cloud - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- N: Cloud Computing, Syria PM Defects, US to Clean Agent Orange and MORE! - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Computing - Tv9 - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- AWS 101 Cloud Computing Seminar-Bangalore - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Trust - The Key to Cloud Computing Growth in Europe [Last Updated On: October 6th, 2012] [Originally Added On: October 6th, 2012]
- Cloud Computing Saves Health Care Industry Time And Money [Last Updated On: October 6th, 2012] [Originally Added On: October 6th, 2012]
- Synnex CEO Kevin Murai: Tablets, Mobile, Cloud Computing (p3) - Video [Last Updated On: October 6th, 2012] [Originally Added On: October 6th, 2012]
- Enterprise computing IS the cloud [Last Updated On: October 8th, 2012] [Originally Added On: October 8th, 2012]
- 44 Percent Of US Execs To Tackle IT Challenges Through Cloud [Last Updated On: October 8th, 2012] [Originally Added On: October 8th, 2012]
- ZapThink Announces Expansion of Cloud Computing for Architects Course [Last Updated On: October 9th, 2012] [Originally Added On: October 9th, 2012]
- Euro Zone Eyes Cloud Computing to Kick Start Economy [Last Updated On: October 9th, 2012] [Originally Added On: October 9th, 2012]
- Advantages, challenges of cloud computing discussed Oct. 10 at NJIT [Last Updated On: October 10th, 2012] [Originally Added On: October 10th, 2012]
- Dell Expands Cloud Client Computing Solutions for VMware View®, Desktop as a Service and Channel Offerings to Europe [Last Updated On: October 10th, 2012] [Originally Added On: October 10th, 2012]
- Cloud West to Focus on Entertainment Delivery, Network Infrastructure, and Investment, More at Nov. 8-9th Forum [Last Updated On: October 10th, 2012] [Originally Added On: October 10th, 2012]
- IBM, AT&T Offer Secure Passage to the Cloud [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Cloud computing company hits new fundraising heights [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Cloud computing firm hits new fundraising heights [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Cloud computing: here we go again [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Chinese Want to Put Computer 'Brains' in the Cloud [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- CenturyLink Unveils Cloud Product [Last Updated On: October 12th, 2012] [Originally Added On: October 12th, 2012]
- Cloud Security Evolves in Wellington [Last Updated On: October 14th, 2012] [Originally Added On: October 14th, 2012]
- 2X ApplicationServer XG Joins the Intel AppUp SMB Service Hybrid Cloud [Last Updated On: October 15th, 2012] [Originally Added On: October 15th, 2012]
- Piston Cloud to Exhibit and Present at the 2012 OpenStack Summit in San Diego [Last Updated On: October 15th, 2012] [Originally Added On: October 15th, 2012]
- How to get your first cloud computing job [Last Updated On: October 15th, 2012] [Originally Added On: October 15th, 2012]
- DreamHost Adds Public Cloud Computing Service: DreamCompute [Last Updated On: October 15th, 2012] [Originally Added On: October 15th, 2012]
- Aryaka Receives 2012 Cloud Computing Excellence Award [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Making a Europe fit for the cloud [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Cisco Execs Plumb The Limits Of Cloud Computing [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Cloud firm invests in new network [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- AirWatch Receives 2012 Cloud Computing Excellence Award [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Dell Extends Cloud Client Computing Portfolio with New Solutions Validated by Citrix [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Pano Logic and Alliance InfoSystems Join Forces to Deliver Zero Client Computing [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- 5 Cloud Business Benefits [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Alteva Receives 2012 Cloud Computing Excellence Award [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Open Text profit beats estimates on cloud services [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud computing improves nurse call system [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud computing: Top five tax considerations for your business [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- OKI and ISID to Provide Chemical Information System as Cloud Computing Services [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- As Mobile Grows, So Does Cloud Computing [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- IBM Analytical Decision Management SaaS - IBM Cloud TechTalk October 2012 - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- JAX London 2012: Achieving genuine elastic multitenancy with Waratek Cloud VM for Java - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Microsoft 2020 technology future vision - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Infinity Cloud Point of Sale and Complete Retail Suite.mp4 - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Small Business IT Support, Computer Support, Web Design Atlanta - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud Computing - Simplified - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- How Allied Valve Used the Cloud to Expand in Bakken Oilfield - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud Computing in the Public Sector - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud Computing | Sacramento | Data Protection | IT Consulting | Symmetry Managed Servces - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- The Business Value of Cloud Computing - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- GYMNAZO Owner/Coach Michael Hughes is excited about edufii - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Automation in the age of cloud computing - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud Computing.mp4 - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud computing in 2013: a conversation with Appcore's CEO [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Cloud adoption growing in India: study [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Eastday-Microsoft picks city for cloud computing [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Towards a blue sky: How SMEs can avoid Cloud Computing confusion [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Consultancy Services - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Axxis Solutions Sponsors FIBA Technical Seminar on Cloud Computing - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- RightScale Webinar: 451 Research Webinar: Cloud Dos and Don'ts - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Apple Technology (Vishwa Bandhu Gupta) - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Mind Tree Ltd. - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- BIM Cloud Computing [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Entreda discusses cloud services for small and medium businesses - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Austin IT Company | Computer Networking [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Cloud Computing and Services - After Effects Template - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- FieldStorm App Tour - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- The Hon Brendan O'Connor's speech: AccountRight Live launch event - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]