SaaS working group up and running

04.03.2011
The Cloud Security Alliance (CSA) launched a Security as a Service working group at the RSA conference in February, to help organizations evaluate and implement security solutions provided via the SaaS model.

So far much of the effort has focused on organizing the group, while the real work still lies ahead, says Michael Sutton, vice president of security research at Zscaler and head of the working group.

More on cloud computing and security

CSA's stated mission is to promote the use of best practices for providing security assurance within cloud computing, and to provide education on the uses of cloud computing to help secure all other forms of computing.

The first part of the mission focuses on security technologies developed in the cloud, Sutton says, while the second focuses on leveraging the cloud to deliver security to other organizations -- security that was traditionally delivered via software and appliances.

"To date, CSA has primarily focused on the first part of the mission statement," Sutton says. The working group will focus on the second part. He says there's no shortage of companies claiming to deliver security via a SaaS model, "however, there has been very little done to define [security as a service] and establish best practices. We aim to change that."