Forrester: Need for scrutiny heightened in cloud security

11.05.2009
The demand greater scrutiny than traditional IT outsourcing models, a new Forrester report says.

With traditional outsourcing models, a customer places its own servers in someone else's data center, or a service provider manages devices dedicated to that customer. But multi-tenancy rules the day in cloud computing, and customers may not know where their data is stored or how it's replicated, Forrester analyst Chenxi Wang writes in a " 

"Cloud computing decouples data from infrastructure and obscures low-level operational details, such as where your data is and how it's replicated," Wang writes. "Multi-tenancy, while it is rarely used in traditional IT outsourcing, is almost a given in cloud computing services. These differences give rise to a unique set of security and privacy issues that not only impact your risk management practices, but have also stimulated a fresh evaluation of legal issues in areas such as compliance, auditing, and eDiscovery."

The rise of software-as-a-service, http://www.networkworld.com/topics/saas.html along with Web-based platforms for building applications and hosting server or storage capacity have many industry watchers examining the benefits and pitfalls of cloud computing.

Wang notes that the recently against Google with the U.S. Federal Trade Commission, alleging that its security and privacy controls are inadequate.

Wang quotes Boeing chief security architect Steve Whitlock as saying: "Like many others, we see huge potential and benefits for moving into 'the cloud,' but we see risks, security issues, and interoperability issues. The community has much work to do to make the cloud a safe place to collaborate." Whitlock is also on the board of the , an industry group that examines the erosion of the network perimeter. While securing applications and data in the cloud is difficult because of the lack of visibility and control, customers must make the effort to evaluate vendors' security and privacy practices, Wang says.