Welcome!

Government Cloud Authors: Pat Romanski, Elizabeth White, Liz McMillan, Dana Gardner, Gopala Krishna Behara

Related Topics: @CloudExpo, Cloud Security, Government Cloud

@CloudExpo: Blog Feed Post

Industry Leaders Set Cloud Security Benchmarks By @Kevin_Jackson | @CloudExpo #Cloud

(ISC)2, CSA set cloud computing security benchmarks

Security has long been the No. 1 cloud computing business concern. Although the apprehension is absolutely valid, cloud computing business decision and strategies are all too often driven by the many broadly shared misconceptions and misunderstandings. They include:

  • Public cloud is more easily breached that a private cloud
  • Any infrastructure that you manage or own is more secure than any cloud computing infrastructure
  • Cloud-hosted applications are technically no different than enterprise-hosted applications
  • The cloud service provider infrastructure and personnel will address and remediate all security issues
  • The end user has very little control over cloud security
  • A corporate network provides protection even when using cloud apps
  • Cloud platforms lack security features and cloud providers offer no visibility into their platform
  • Strong authentication mechanisms are sufficient for ensuring security

Although every one of these statements have been proven false, they continue to be socially propagated. While this is sometimes done for self-serving commercial reasons, perpetrators are often well-meaning individuals holding critical corporate responsibilities. This latter scenario has been driven by the lack of industry consensus on security and a dearth of nonvendor specific cloud security training and certifications. Because cloud computing is a young industry so this is understandable, but maintaining this view exacerbates the harm.

These troubling facts are why I was thrilled last month when cloud computing security industry leaders Cloud Security Alliance (CSA) and the International Information System Security Certification Consortium ((ISC)²) addressed this issue head-on by collaborating on the development and release of the Certified Cloud Security Professional (CCSP) Certification Program. Both nonprofits, their individual missions and goals are synergistic:

CSA: To promote best practices for providing security assurance within cloud computing and provide education on the uses of cloud computing to help secure all other forms of computing.

(ISC)²: To support and provide members and constituents with credentials, resources, and leadership to secure information and deliver value to society.

By stepping up to the challenge of cloud security certification, these organizations are explicitly addressing their missions.

Vendors are also stepping up. According to a recent CRN article, commercial cloud security platforms are helping enterprises mitigate the risks of using cloud-based applications and services. These offering are providing strong data protection capabilities by incorporating data loss prevention, data encryption and tokenization. Some cloud security companies provide identity and access management capabilities while others monitor cloud-based systems for suspicious activity and provide policy enforcement, reporting and alerting capabilities. Cloud-based sandbox environments for controlling employee laptops, smartphones and tablets, regardless of their location, are in the marketplace as well.

A specific example of strong industry cloud security capabilities is Dell SecureWorks. It is positioned in the Leader's Quadrant of Gartner's Magic Quadrant for Global Managed Security Service Providers. In April 2015, the Info Security Products Guide recognized the company by announcing Dell as the Grand Trophy Winner as well as the winner of 12 additional awards, including one in cloud security for the Dell Cloud Access Manager.

The CCSP credential was designed to reflect the holder's deep knowledge of cloud computing security. In order to gain this certification, a candidate must demonstrate hands-on information security and cloud computing experience. Certification requires a minimum of five years of cumulative, paid, full-time information technology experience, of which three years must be in information security and one year in one of six domains of the CCSP examination. It also requires:

  • Passing an exam;
  • A legal commitment to the code of ethics;
  • Endorsement from an appropriate certified professional; and a
  • Commitment to continuing professional education.

In providing the CCSP certification, CSA and (ISC)² have set a new benchmark for cloud security knowledge and competence. They have also established a reliable indicator for overall proficiency in cloud security and have gone a long way toward eliminating cloud computing security misconceptions and misunderstandings.

This post was written as part of the Dell Insight Partners program, which provides news and analysis about the evolving world of tech. Dell sponsored this article, but the opinions are my own and don't necessarily represent Dell's positions or strategies.

Bookmark and Share

Cloud Musings

- © Copyright Kevin L. Jackson 2015)

Follow me at http://Twitter.com/Kevin_Jackson

Read the original blog entry...

More Stories By Kevin Jackson

Kevin Jackson, founder of the GovCloud Network, is an independent technology and business consultant specializing in mission critical solutions. He has served in various senior management positions including VP & GM Cloud Services NJVC, Worldwide Sales Executive for IBM and VP Program Management Office at JP Morgan Chase. His formal education includes MSEE (Computer Engineering), MA National Security & Strategic Studies and a BS Aerospace Engineering. Jackson graduated from the United States Naval Academy in 1979 and retired from the US Navy earning specialties in Space Systems Engineering, Airborne Logistics and Airborne Command and Control. He also served with the National Reconnaissance Office, Operational Support Office, providing tactical support to Navy and Marine Corps forces worldwide. Kevin is the founder and author of “Cloud Musings”, a widely followed blog that focuses on the use of cloud computing by the Federal government. He is also the editor and founder of “Government Cloud Computing” electronic magazine, published at Ulitzer.com. To set up an appointment CLICK HERE

IoT & Smart Cities Stories
The platform combines the strengths of Singtel's extensive, intelligent network capabilities with Microsoft's cloud expertise to create a unique solution that sets new standards for IoT applications," said Mr Diomedes Kastanis, Head of IoT at Singtel. "Our solution provides speed, transparency and flexibility, paving the way for a more pervasive use of IoT to accelerate enterprises' digitalisation efforts. AI-powered intelligent connectivity over Microsoft Azure will be the fastest connected pat...
There are many examples of disruption in consumer space – Uber disrupting the cab industry, Airbnb disrupting the hospitality industry and so on; but have you wondered who is disrupting support and operations? AISERA helps make businesses and customers successful by offering consumer-like user experience for support and operations. We have built the world’s first AI-driven IT / HR / Cloud / Customer Support and Operations solution.
Codete accelerates their clients growth through technological expertise and experience. Codite team works with organizations to meet the challenges that digitalization presents. Their clients include digital start-ups as well as established enterprises in the IT industry. To stay competitive in a highly innovative IT industry, strong R&D departments and bold spin-off initiatives is a must. Codete Data Science and Software Architects teams help corporate clients to stay up to date with the mod...
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throug...
Druva is the global leader in Cloud Data Protection and Management, delivering the industry's first data management-as-a-service solution that aggregates data from endpoints, servers and cloud applications and leverages the public cloud to offer a single pane of glass to enable data protection, governance and intelligence-dramatically increasing the availability and visibility of business critical information, while reducing the risk, cost and complexity of managing and protecting it. Druva's...
BMC has unmatched experience in IT management, supporting 92 of the Forbes Global 100, and earning recognition as an ITSM Gartner Magic Quadrant Leader for five years running. Our solutions offer speed, agility, and efficiency to tackle business challenges in the areas of service management, automation, operations, and the mainframe.
The Jevons Paradox suggests that when technological advances increase efficiency of a resource, it results in an overall increase in consumption. Writing on the increased use of coal as a result of technological improvements, 19th-century economist William Stanley Jevons found that these improvements led to the development of new ways to utilize coal. In his session at 19th Cloud Expo, Mark Thiele, Chief Strategy Officer for Apcera, compared the Jevons Paradox to modern-day enterprise IT, examin...
With 10 simultaneous tracks, keynotes, general sessions and targeted breakout classes, @CloudEXPO and DXWorldEXPO are two of the most important technology events of the year. Since its launch over eight years ago, @CloudEXPO and DXWorldEXPO have presented a rock star faculty as well as showcased hundreds of sponsors and exhibitors! In this blog post, we provide 7 tips on how, as part of our world-class faculty, you can deliver one of the most popular sessions at our events. But before reading...
DSR is a supplier of project management, consultancy services and IT solutions that increase effectiveness of a company's operations in the production sector. The company combines in-depth knowledge of international companies with expert knowledge utilising IT tools that support manufacturing and distribution processes. DSR ensures optimization and integration of internal processes which is necessary for companies to grow rapidly. The rapid growth is possible thanks, to specialized services an...
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throug...