JAN 25, 2012 3:03pm ET

Related Links

Retention Practices Lost in Shuffle of Handling Sensitive Enterprise Data
June 14, 2013
Trend Micro Introduces Web App Security Service
June 13, 2013
Mocana Releases New Version of Mobile App Protection
June 11, 2013

Web Seminars

How to Run a Successful Bring Your Own Device (BYOD) Scheme
Available On Demand
IBM MobileFirst Management: Empower Your Mobile Workforce
June 25, 2013
Open Software-defined Storage for the Modern Hybrid Datacenter
June 26, 2013
news

Cloud Accountability Starts from the Inside

Print
Reprints
Email

January 25, 2012 – Internal accountability and governance are paramount for the security and privacy of information in the cloud, according to new guidelines finalized by the National Institute of Standards and Technology.

The report, geared at informing IT leaders, executives and security network administrators involved in cloud computing initiatives, delves into threats, risks and safeguards to public cloud environments. NIST noted that, while cloud adoption has grown immensely in the last few years, in terms of maturity it “remains a work in progress.”

Among the key elements in the report for shifting data, applications and infrastructure to the cloud, NIST expressly pointed to internal accountability of information, even when accessed off-premise, as a painstaking yet vital initiative. In addition, NIST warned that deployments require increased attention to data governance  and compliance due to a perceived lack of information control.

“Public cloud computing and the other deployment models are a viable choice for many applications and services. However, accountability for security and privacy in public cloud deployments cannot be delegated to a cloud provider and remains an obligation for the organization to fulfill,” said report co-author Tim Grance in a news release.

The guidelines also emphasize careful planning prior to engagement, an understanding of the cloud environment being offered, and satisfaction that cloud offerings meet internal and client-side requirements. Ultimately, NIST likened preparing for cloud security and privacy as an “exercise in risk management.”
Overall for security and privacy, NIST touted such upsides to public deployments as staff specialization, increased technological acumen for smaller enterprises, platform strength, and access and concentration of data for mobile users.

NIST standards provide the baseline for federal and many governmental IT and technological plans.

Click here
to download the 80-page PDF of the guidelines, entitled “Guidelines on Security and Privacy in Public Cloud Computing.”

Justin Kern is senior editor at Information Management and can be reached at justin.kern@sourcemedia.com. Follow him on Twitter at @IMJustinKern.

Advertisement

Where do young IT professionals (30 and under) obtain information to aid with daily role responsibilities and career development?

Trade publication websites 14%
Social media 23%
Vendor websites 4%
Vendor/community forums 7%
Newsletters 1%
Trade conferences/meetups 2%
RSS feeds 6%
Web search 44%

 

Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.