Posts

Showing posts with the label Cloud Security Alliance

Work on the CSA CCM 3.01 Azure entry

Hello everyone. Today my team released an update to the response Cloud Security Alliance's (CSA) Cloud Control Matrix (CCM) version 3.01 framework. It's quite phenomenal  level of work in getting such a massive document lifted revised, and posted.  Interested in the work, read the paper which is over 36 pages long and covers 130 controls. Here's what we announcement -  Microsoft Azure is proud to release our response to the Cloud Security Alliance's (CSA) Cloud Control Matrix (CCM) version 3.01 framework. The response document provides customers a straightforward process for evaluating Azure’s security, privacy and compliance capabilities and its commitments to trust and transparency using industry-accepted standards and practices. In addition, the CCM—and its entry into the CSA Security, Trust, and Assurance Registry (STAR)—provides a “one stop shop” offering a comprehensive guide addressing standard requests for information that cloud adopters need in orde...

8 ways cloud providers save you money

After completing my blog on how you would move to the cloud I started thinking about some compelling reasons to adopt cloud computing. Here are 8 immediate cost benefits moving to the cloud for a start-ups or small or mid-sized company.  1. Established ISMS Information Security Management System:   Many companies talk about setting up an ISO27002 based ISMS but struggle. That’s because it take lots of people resources, and money. The major cloud providers have this already built out, and tested.  2. Gates, fortified walls, guards, fences Facility Security:   Cloud providers help restrict access by role, and by granting access to small sets of trusted staff members. Most cloud providers have well established facility security including gates, fences, guards, lighting, and many other security measures. 3. Tested backup and recovery solutions Data Retention Policy:   Cloud providers should have a plan for data retention and storage that...

Deperimiterized with Security in mind - Part 3

In part 3 of my moving to the cloud recommendation, I address a new taxonomy of securing your cloud based network or - service oriented architecture (SOA). As companies embraces the cloud and BYOD they are also embarking on a journey where traditional IT security, and compliance measure will not work as effectively. Security and compliance require enabling effective people, process and technology solutions. Cloud based architecture requires new set of security processes and technologies. The new strategy starts by addressing your network design architecture that outline how you Identify your hosts, and perimeter points. Network and port scanners are not enough to outline your network devices anymore. Traditional network diagrams, do not provide enough detail to outline the boundaries of your network. More complex data flow diagrams (DFD) that focus on application layer design are needed in a cloud only service model.  The design can be complex but worth the effort.  I...

Cloud (Cost + Trust)

Cloud providers benefit statement boils down to only two variables that matters to you - COST + TRUST You may look at this and agree, say this seems obvious. Then again you might consider this model too simple and wonder what about flexibility, elasticity, feature/function and other cloud benefits that influence moving to the cloud. These are all important, but in my humble opinion, cost and trust are the most important two lynch pins for selecting a cloud provider, and you need to expect service providers to provide both effectively, be willing to provide both with equal fervor, and honestly disclose their position.  COST Moving to the cloud proposes the single best opportunity to reduce overall IT and operational costs. Today all organizations, from your gardener, hair stylist, and even big organizations like Nordstrom, Exxon, Starbucks, and even all the three letter government agencies are faced with the stark reality that cloud computing will reduce cost of t...