Research reveals gap in cloud security and compliance protocols
A new research report from the Ponemon Institute has exposed a growing rift between IT security professionals and compliance officers managing cloud environments.
The Ponemon survey polled the opinions of 1,000 IT security practitioners and enterprise compliance officers to gather insight on potential cloud security challenges. The findings seem to suggest that both organizational and technological shortcomings are contributing to heightened data security risks.
According to the study, less than half of all respondents believed their companies had the requisite technology in place to effectively secure cloud environments. However, there were clear differences between the two groups when it came to gauging potential threats and responding with possible solutions.
Only one in three IT security professionals expressed belief that Infrastructure-as-a-Service paradigms were as secure as in-house data centers. Conversely, half of the responding compliance officers trusted the security of cloud platforms.
In response, there was a serious diffusion of responsibility across departments. One in five compliance officers felt that cloud security responsibilities were under their jurisdiction while the same margin of IT security administrators felt that power resided with individual department heads.
"While we were surprised by the different attitudes towards cloud security among IT practitioners and compliance officers, the findings did reveal that security in the cloud is a concern for both groups, especially in IaaS environments," said Ponemon Institute chairman and founder Larry Ponemon. "What is most troubling is the fact that while respondents feel they lack adequate technologies to secure their IaaS environments, ownership for security in the cloud is dispersed throughout the organization."
Whichever department ultimately assumes responsibility for cloud security issues, companies need to act fast to evolve their defense strategies.
According to the survey, less than one third of responding organizations bother encrypting data and files stored and accessed in the cloud. Also, more than half of respondents revealed that their organization's data audit review process has not be amended to address cloud security issues.
In addition to implementing these pillars of data security, Network World contributor Christine Burns recently highlighted new competencies enterprises will need to establish for cloud-specific security.
To begin, Burns suggests identifying and securing all endpoints. Most notably, this will mean a comprehensive mobile device management solution in many cases. Also, companies are encouraged to use their cloud providers as allies and advocate for the inclusion of security features in service level agreements.
Cloud Security News from SimplySecurity.com by Trend Micro
Spotlight
- Trend Micro researchers delve deeper into Luckycat APT campaign
- Researchers track consequences of lost mobile devices
Cloud Computing
- Where to store cloud encryption keys? Adhere to compliance guidance.
- Report lends advice to government organizations adopting cloud computing
- Cloud security researchers shift focus to identity management
- Security teams worried about evolving cloud complexities
Virtualization
- Virtualization promises benefits for small companies too
- Solving security through desktop virtualization
- Leveraging virtualization for tighter security
- Virtual IT environments requiring tougher data security measures
Internet Safety
- Virtualization promises benefits for small companies too
- Solving security through desktop virtualization
- Leveraging virtualization for tighter security
- Virtual IT environments requiring tougher data security measures
Vulnerabilities & Exploits
CTO Insights
First Line of Defense
Newsletter
Stay up to date with the latest news and information on online threats.
Recent News
- Security is essential to virtualization deployments
- Op-ed: Understanding FTC’s new consumer privacy protection guidelines
- Report to Congress details FISMA compliance progress
- Cybercrime sending shockwaves through financial sector
Tag Cloud
cloud cloud computing cloud computing security Cloud Security Compliance & Regulations Current News cybercrime data security Encryption Internet Safety Internet Safety - DO NOT USE Internet Security Malware Mobile Security Mobility Policy Policy - DO NOT USE Privacy Spotlight threat intelligence threat research Trend Labs virtualization Vulnerabilities Vulnerabilities - DO NOT USE web security web threats




Comments
[...] the recent Ponemon Institute Reserach Report ignites new heat over old cloud security fears, we here at CloudLock have been turning our [...]
Pingback by CloudLock Joins the Cloud Security Alliance — CloudLock on November 10, 2011 at 10:47 am
There are some article dealing on it. and it’s got been uncovered by health-related researchers at Cedars-Sinai Clinic right here recently. It can be well worth mentioning that Ayurveda, a standard Indian health care science, proceeds to get utilizing turmeric considering that hundreds of years like a medication. Hope its Help…
Comment by Wm Washington on January 2, 2012 at 1:52 am