IT Today Catalog Auerbach Publications ITKnowledgebase IT Today Archives Book Proposal Guidelines IT Today Catalog Auerbach Publications ITKnowledgebase IT Today Archives Book Proposal Guidelines

Auerbach Publications

IT Performance Improvement



Networking and Telecommunications

Software Engineering

Project Management


Share This Article

Free Subscription to IT Today

Powered by VerticalResponse

Cloud Enterprise Architecture by Pethuru Raj; ISBN 9781466502321
Bring Your Own Devices (BYOD) Survival Guide by Jessica Keyes; ISBN 978-1-4665-6503-6
The Internet of Things in the Cloud: A Middleware Perspective by Honbo Zhou; ISBN 9781439892992
Securing Cloud and Mobility: A Practitioner's Guide by Ian Lim, E. Coleen Coolidge, and Paul Hourani; ISBN 978-1-4398-5055-8
Cloud and Virtual Data Storage Networking by Greg Schulz; ISBN 9781439851739
Implementing and Developing Cloud Computing Applications by David E. Y. Sarna; ISBN 9781439830826
Cloud Computing: Technologies and Strategies of the Ubiquitous Data Center by Brian J.S. Chee and Curtis Franklin, Jr.; ISBN 9781439806128

The Top 5 Brilliant Things the Cloud Can Deliver (If You Get Your Security Right)

by Dave Anderson, Director of Strategy, Voltage Security

Everyone has an opinion about the 'Cloud' and its effect on business - some believe it is dark and scary and fraught with unnecessary risk, while others would argue its silver lined and the path to greater business performance and cost savings. The truth is that the Cloud undeniably has the potential to open up a whole new dimension of opportunities to businesses, but only if data security is properly addressed.

First, let's dispel any misperceptions you might have about the Cloud. It's nothing mystical, nothing whimsical, and nothing to be afraid of. Or is it? The reason many fear the Cloud is its reputation as a dangerous, or 'risky,' place. And that is true. Anything beyond the physical perimeter of the organization is also, theoretically, beyond the physical protection of the organization. And let's face it, although there are dangers and risks out there, it doesn't mean you have to stay behind a locked door. Instead, by arming yourself with the right security you can stay clear of danger and fully tap into the Cloud's potential.

The Cloud and security are intrinsically intertwined, and only when both work in symbiosis can a business truly grow. There are five main areas where security can team up with the Cloud to offer companies the greatest potential to thrive, and it isn't hard to get it right:

  1. Data Protection
    Data is key and possibly the most important asset for organisations - a single breach or leak of sensitive data can cripple the entire business, so a data protection strategy must protect the data itself. The ability to move sensitive information into and throughout the Cloud is essential for businesses to function and collaborate efficiently, quickly and freely - but this ability must be supported by a comprehensive data protection strategy. The trick is to protect data at the moment of creation, before it moves out of the enterprise or even enters the Cloud. Only by doing that can you ensure that any data source is comprehensively protected, and the risk to potential exposure is minimised.
  2. Regulatory Compliance and Data Residency Requirements
    Sensitive data that is moved into and across Cloud infrastructures can easily introduce additional complexity and cost to regulatory compliance - potentially costing thousands in fines and damaging reputations. Companies that ensure sensitive data is comprehensively protected can greatly reduce cost, complexity and overall risk in meeting and maintaining regulatory compliance.
  3. Scalability and Flexibility
    The Cloud has opened up previously unseen opportunities for organisations to grow and expand quickly, smoothly and with ease. With information immediately and easily available anywhere, anytime, regardless their own infrastructure the Cloud offers the flexibility and scalability that in the past was an insurmountable obstacle for businesses restricted by their on-site resources. The key to successfully harnessing this opportunity is a flexible data security architecture that is extensible and adaptable across multiple applications and systems, while not adversely impacting the user experience. Failure to put a comprehensive, data-centric protection program can cause Cloud initiatives to be delayed or fraught with hidden security issues.
  4. Cost Efficiencies
    This element is two-fold. Reap the powerful cost savings, by only paying for what you use, so there's the capital, and operating, expenditure benefits. The second element is that most cloud computing platforms provide the means to capture, monitor, and control usage information for accurate billing. A single, comprehensive data protection platform can eliminate the threat of risky fines from compliance breaches or data loss while also reducing the need to invest into multiple security tools.
  5. Access to Data Anytime, Anywhere
    When harnessed correctly, cloud-computing capabilities offer numerous opportunities to drive business innovation. Rather than having to provide remote access to your infrastructure, it is available 24/7 for the workforce to access. No longer will you arrive for a meeting only to find the materials on your USB stick are a previous version. Instead you access the original file wherever you happen to be. Sales teams can check stock levels in real time. An employee stuck at home waiting for a delivery, or in an airport waiting for an 'ash cloud' to disperse, can still work as effectively as in the office. By employing a security strategy that protects and travels with all data, anywhere, anytime businesses can confidently tap into this invaluable resource.

With so many key business benefits of the Cloud directly affected by and depending on security one would easily be mislead into thinking that a plethora of security measures has to be adhered to in order to address potential issues. Truth is, it all comes back to the data. A single framework that comprehensively protects all enterprise data from point of creation and throughout its lifecycle can eliminate practically all potential security hazards that could threaten the Cloud.

Below are five tips for a security framework that will allow you to fully harness the Cloud's business benefits:

  1. Leverage Data-Centric Encryption
    By encrypting data, regardless of type or source, at capture and protecting it throughout the entire lifecycle, wherever it resides and wherever it moves, data can be protected, used and moved across the enterprise and into the cloud without the need to encrypt and decrypt the data as it enters or leaves different IT environments.
  2. Maintain Referential Integrity
    Format-preserving encryption (FPE) retains the initial structure and format of the data set, encrypting the data while ensuring the structure fits into existing schemas without requiring changes in IT infrastructure or underlying systems in order to store and manage the data. FPE also preserves 'referential integrity' of the data, which allows the data to be analysed in a protected state, without having to de-crypt it first.
  3. Ensure High Performance Processing
    High performance encryption results from eliminating manual and constant encryption and decryption processes as data moves through the enterprise, which removes database performance bottlenecks and enables linear scalability. A data protection strategy that includes encryption and tokenisation which can be performed locally at the application, database, or webserver level allows an organisation to dynamically protect terabytes of data on demand, without having to introduce complex procedures, additional technology or interrupt current business process.
  4. Policy Controls
    By giving users or applications permission to decrypt or de-tokenize directly, linking directly to enterprise data access rules and policies, the extension of enterprise controls into the Cloud can be enabled and user management is simplified.
  5. "Stateless" Tokenization
    Tokenization is a way of substituting sensitive data with non-sensitive values, and is one of the prescribed data protection methods recommended under industry regulations, including PCI DSS. Stateless tokenization eliminates the token database and any need to store sensitive data as well as the keys that map the tokens to the initial sensitive data. This allows organisations to efficiently address national and international data residency and privacy requirements, as sensitive data can be maintained in a valid jurisdiction with only a representation of the data being moved. In-scope data can be securely moved and stored across Cloud environments, and only decrypted and used within jurisdictions where it is specifically permitted.

When harnessed correctly, cloud-computing capabilities offer numerous opportunities to drive business innovation. Recent technology and social connectivity trends have created a perfect storm of opportunity for companies to embrace the power of cloud to optimise, innovate and disrupt their existing business models. Could you join them?

© Copyright 2008-2013 Auerbach Publications