Gartner: Don't Trust Cloud Provider to Protect Your Corporate | News | ChannelWorld.in

PARTNER HOTLINES

Gartner: Don't Trust Cloud Provider to Protect Your Corporate

Added on May 28, 2012 by Brandon Butler

When a family with a baby buys a new car, they don't buy a car seat from the vehicle manufacturer: There is specialized equipment to handle the family's most sensitive asset. John Pescatore, a Gartner vice president and security analyst, says cloud security can be thought of in a similar way: Users shouldn't rely on their cloud service provider's security features to protect their most critical data.  

Sensitive information that needs to be protected -- customer data, mission critical applications, production-grade information -- in many cases needs its own security controls to be fully protected. "As you move out to cloud-based models, there are some things you can trust your cloud provider with, but for critical business data and regulation-controlled information, very rarely is the infrastructure going to be enough," Pescatore said during a webinar sponsored by Gartner this week.

Security remains a top concern for companies looking to deploy a cloud strategy, but Pescatore says there are ways to alleviate the fears. One key, he says, is to have security provisions that are designed to specifically protect cloud applications, data or workloads. A prime example is credit card information. Payment Card Industry (PCI) certification requires that any customer credit card data that is stored electronically be encrypted. Some cloud service providers will offer encryption services within their cloud-based storage offering. But, there are a range of third-party applications that customers can buy to provide encryption services, distributed denial-of-service (DDoS) protection, and access control measures that are tailored specifically for cloud deployments. Many of these are delivered in a cloud format.

There are a variety of cloud security products on the market for numerous functions. Providers such as Zscaler, Websense or ScanSafe from Cisco are "gateway" products that sit between the user and the cloud provider to monitor what data is being put into the cloud and to make sure malicious data or applications don't penetrate into the user's system. If the cloud is being used to host a website, there are website protection services, such as Imperva, CloudFlare and even some from Akamai in this area, for example.

Overall though, Pescatore says cloud security starts at a basic level. Most enterprises begin their journey to the cloud with a private, internal cloud, and that's a good place to start with security controls, too. "Get security right in the private cloud first, then extent it into the hybrid and public," he suggested. Having processes in place to protecting virtualized environments from outside attacks is important, he says. "Get visibility into the system, the change controls and the vulnerabilities," he says. This includes securing the orchestration of the architecture and the provisioning of new accounts, domains and virtual machines.

The migration beyond a private cloud is usually then toward incorporating some public cloud services. Many times companies expand to public cloud services for non-mission critical applications though, such as test, development or bursting capacity. So, not everything may have to be secured to a maximum security level. "Protect the sensitive information and only put the less sensitive data into the cloud in the native form," he says, referring to the process of tokenization.

Pescatore says the focus for cloud security should be on the processes of protecting the cloud. Create policies for cloud security, then make sure they are implemented throughout the cloud deployment and stick with them. The vulnerabilities are created when there are inconsistent policies or unenforced security controls, he says. "We really have not yet seen major new attacks that are trying to compromise the cloud infrastructure or the virtualization layer," he says. "The reality today is that the easy pickings (for the hackers) are attacking the companies using the cloud services." 

The good news is customers have a wide variety of options. For low-level security requirements, the cloud service provider, either on the infrastructure or software as a service side, usually each have their own security features. Amazon Web Services is FISMA compliant; FireHost, another cloud service provider, is PCI compliant. At the least, Pescatore says users should look for their providers to be ISO 27001, SOC 2 or SOC 3 certified. Beyond that, and especially for sensitive information, there are third-party security offerings for a range of uses.

Latest Videos

How We Deal With the Government Sector: Jaimin Patel, E-Connect Solutions

Perseverance, patience and endurance are key to succeed in the government sector, says Jaimin Patel, Director, E-Connect Solutions, who derives 70 percent of his revenue from the government sector.

Converged Security is the Next Big Thing for Channels: Ranjit Nambiar, HID Global

The blurring lines between physical and IT security in today's organizations will increase the business potential for channel partners, says Ranjit Nambiar, Director, IAM, India & SAARC, HID Global.

Our End-to-End Security Story Will Benefit Channels: Sunil Sharma, Cyberoam

A stronger R&D team, an enhanced portfolio and robust channel ecosystem will accelerate our continued growth in the security space, says Sunil Sharma, Vice President, Sales & Operations, India & SAARC, Cyberoam (a Sophos Company).

Cloud, Analytics Accelerating Storage Demand: Gurpreet Singh Bhatia, Arrow PC Network

New-age solutions like flash storage will be key drivers of growth, says Gurpreet Singh Bhatia, MD, Arrow PC Network.

EDITOR'S PICK

19 free cloud storage options

The cloud is full of free storage, if you know where to look.

4 tips to help CEOs find their CIO soulmate

The role of a CIO involves more than overseeing the technological infrastructure of a company. A good CIO will demonstrate strong communication skills, flexibility and an ability to adapt and change. It can never be stated enough, but working in IT means you will be expected to keep up to date on changing and emerging trends in the industry.

Security Innovation: Where Will it Come From Next?

For years, security innovation rarely came from large established companies. Are startups the best and only place to bring true security innovation to the market?

SLIDESHOWS

CIO Survey: What’s Inside Your Customer’s Mind (Cloud Computing)

A look at the findings of the State of the CIO 2014 survey and the challenges, benefits, and strategies of cloud computing that are keeping your customers on their toes. As their channel partners, here's what you need to know.

CEO Comebacks: For Better or for Worse?

We bring to you six global CEOs who made the idea work, or not.

Datacenters in the Weirdest Places

A peek into some of the most unusual datacenter locations in the world. Here are 13 datacenters that are built in unusual locations like mines, ships, trucks and even a nuclear collidor. Taking about common wisdom, eh?

6 Leaders Who Headed for an Abrupt Exit

The abrupt exit of top leaders of Indian and global tech companies this year, with many of them citing ambiguous reasons, surprised the technology world.

India's Leading VADs

Why Channels Want to Partner With Inflow Technologies

Inflow Technologies’ tie up with 39 vendor companies, an extensive tech portfolio, and a services play, are great value propositions for enterprise channels, says its President and CEO, Byju Pillai.

iValue Creates Real Value for Channels in India

Focused on niche vendor alliances around data, network and app management backed by a robust channel ecosystem marked iValue's success in 2014. What clicked for the seven-year-old VAD?

RAH Infotech Shows Channels the Way Ahead

Mutual trust and long lasting bond with vendor companies and channel partners helps VADs to evolve and succeed in today’s aggressively competitive market. Leveraging competent channel partners and forge niche vendor alliances marks RAH Infotech’s success in 2014.

How Satcom Infotech is Adapting to New Security Landscape

As a leading value added distributor, Satcom Infotech is emerging as an end-to-end security player, helping both customers and partners grow.

How ComGuard Shields Channel Partners

As emerging technologies introduce new threats to the enterprise landscape, they are making channel partners anxious. But VADs like ComGuard are putting their worries to rest. Here's how.

Tech Chat

Collaborating To Outcome Based World: Priyadarshi Mohapatra, Avaya

Priyadarshi Mohapatra, Managing Director, India and SAARC, Avaya, on how IT is transitioning from a keep-the-lights-on role to one that enables customers to deliver results.

The Dawn of the Digital Age: Akhilesh Tuteja, KPMG

The development of digital infrastructure will be a key growth driver for technology and solution providers. 

Paradigm Shift from End-Users to User-First : Parag Arora,Citrix

Parag Arora, Area Vice President and India Head, India Sub-continent, Citrix, says new technologies will force organizations to take a user-first approach in 2015.

Mobile and Cloud Are Gamechangers of the Future: Karan Bajwa, Microsoft

Karan Bajwa, Managing Director, Microsoft India, says, in  2015, organizations will adopt a mobile-first and cloud-first strategy to get ahead of competition.

A Network for the Internet of Everything : Dinesh Malkani,Cisco

Dinesh Malkani, President, India and SAARC, Cisco, talks about IoT and the significant technology transitions in the networking world.

Moving to the Third Platform: Jaideep Mehta, IDC

Cloud and mobility are the two technologies that will fuel the rapid adoption of the third platform in India.

Envisaging a Holistic Security Strategy For 2015: Sanjay Rohatgi,Symantec

Sanjay Rohatgi, President–Sales, Symantec India, says the company has a set of holistic solutions in place to secure organizations from security threats. 

Beating the Bad Guys: Sivarama Krishnan, PwC

Organizations will need to turn inwards to establish robust information security strategies.

Building Capabilities for a Digital Tomorrow: Alok Ohrie,Dell

Alok Ohrie, President and Managing Director, Dell India, on the company’s investments to build end-to-end solutions and delivery capabilities for a digital world.

FAST TRACK

Kamtron Systems

Transitioning towards a service-oriented company will boost our growth, believes Kavita Singhal, director, Kamtron Systems.

TIM Infratech

Delivering ‘best of breed’ technologies to enterprises is key to success, says Monish Chhabria, MD, TIM Infratech

Mudra Electronics

A vendor-agnostic strategy helped us sustain business, says Bharat Shetty, CMD, Mudra Electronics.

Systematix Technologies

Our USP is a customer-friendly approach backed by services, says Akhilesh Khandelwal, Director, Systematix Technologies.

CorporateServe Solutions

Our ability to turnaround complex ERP projects in record time is what gets us customer referral, says Vinay Vohra, Founder & CEO, CorporateServe Solutions.

KernelSphere Technologies

We are emerging as an end-to-end systems integrator, says Vinod Kumar, MD, KernelSphere Technologies.

Uniware Systems

We constantly validate emerging technologies for first-mover advantage, says Vergis K.R., CEO, Uniware Systems.

Astek Networking & Solutions

An innovative approach helps us stay successful, says Ashish Agarwal, CEO, Astek Networking & Solutions.

CSM Technologies

Our approach is backed by innovation and simplicity, says Priyadarshi Nanu Pany, CEO, CSM Technologies.

SOCIAL MEDIA @ CW India
SIGNUP FOR OUR NEWSLETTER

Signup for our newsletter and get regular updates.