Every day brings more headlines about social networking, cloud computing and Software as a Service (SaaS). Each of these fast growth areas shares an important element in common – they rely on a movement of data from private computers into the public cloud. The theory goes that this data is protected by the service provider who is an expert in their field. But in very few cases is that field data security, and there are important implications that should be considered.
Security Researches call for Google and others to use SSL to protect all of the interactions with their services. I agree that’s a basic minimum that everyone should do, but I think it has to go far further! Many cloud providers simply shrug off the responsibility for security in the fine print – see Amazon EC2 license agreement. It’s often the case that providers are unwilling to describe how they protect customer data and simply say “trust us” – Salesforce.com for example uses lots of buzz words in describing their security, but offer no hard facts that a company could rely on for auditing purposes. Network World argues “…it would be difficult to impossible to achieve PCI in a cloud provided by a service provider ….”. In the social networking world the debate over who owns the data uploaded rumbles on.
So let me return to the title – Is “trust us” good enough for private data in the public cloud? Definitely not!
Before private data can really be acceptably safe in the cloud:
At Trend Micro we call it Security FOR the Cloud. Expect to hear that a lot more in the coming months!