toute l'actualité "International"
neswletterenvoyercontactimprimerrss


CIO en VO : la boîte de Pandore sécuritaire de la mise du SI dans les nuages


Edition du 20/04/2009 - par ComputerWorld UK

L'emploi du cloud-computing ouvre la voie à de nombreux cauchemars quant à la sécurité du SI, malgré les discours rassurants des fournisseurs. Le Jericho Forum vient de publier un document explosif.

Businesses installing cloud computing environments risk opening a "Pandora's Box of security nightmares", according to independent security group the Jericho Forum.

The Forum has Friday launched a document aimed at educating businesses about the security risks associated with moving to a cloud computing model. It described the paper as a "work in progress" and has called on key stakeholders, including end users and vendors, to work with them to establish best practices for securing collaboration in the cloud.

The paper details a Cloud Cube Model that describes various types of cloud computing environments, and the associated security issues.

According to Jericho, security, identity and access management are currently immature in the cloud computing setting, especially when it comes to collaboration between enterprises.

"The cloud approach to organising business can be both more secure and more efficient than the old-style silo structure," said Adrian Seccombe, chief information security officer at pharmaceuticals firm Eli Lilly and Jericho Forum board member.

"On the one hand cloud computing offers a compelling opportunity to achieve a more effective solution, do more with less, and deliver cost savings coupled with extreme flexibility and scalability. Viewed from a different perspective it opens a potential Pandora's Box of security nightmares, not least of which is loss of data confidentiality and integrity."

But the Forum said cloud computing could become more secure than traditional environments if the right controls are put in place.

"In fact, a pure cloud model really can make the user king, providing him with ultimate flexibility. But reaching that pure level is not easy. It's essential to get the foundations right and for each business to develop a cloud model that enables consumerisation, drives down cost and reduces risk," said Seccombe.

The model defines four criteria by which to measure types of clouds: whether it is internal or external; proprietary or open; insourced or outsourced; and whether it has a security perimeter or not.

Companies are advised to first classify their data according to sensitivity and regulatory or compliance restrictions, before deciding which data and processes to move to the cloud and which cloud models to adopt.

In addition to the video produced for Computerworld UK, Jericho Forum has provided a video on YouTube that explains key parameters for secure collaboration.

Siobhan Chapman - (c) ComputerWorld / IDG 2009

ACTUALITES
A LA UNE
Chiffres-clés

Etude PAC : le logiciel libre croit avec l'hybridation

11/03/2010 18:51:34 - La crise ? Quelle crise ? Le Logiciel Libre n'en connait aucune selon la dernière étude de Pierre Audoin Consultants (PA (...)

Evènements

Ecoresponsabilité des entreprises et IT

22/02/2010 11:40:38 - Réduire les coûts tout en étant éco-responsable n'est pas contradictoire. C'est même au contraire concordant. Et respect (...)

>> Toute l'actualité
CONFERENCES
CLOUD COMPUTING
23/03/2010
De 8h30 - 14h00 à l'Automobile Club de France - Paris 8e
Programme   Inscrivez-vous

AGENDA
Journée Française des Tests Logiciels (2ème édition)
Du mardi 30 mars 2010 au mardi 30 mars 2010
Cap 15, quai de Grenelle, Paris 15

CONTRIBUTIONS

Web au cube : la révolution du Web à venir !

David Fayon

David Fayon - Parole d'expert

Directeur de projets SI
Le Web au carré est venu compléter la définition restrictive que certains faisaient du Web 2.0. Et alors (...)

La virtualisation impose de nouvelles compétences

Nicolas CHABRIER

Nicolas CHABRIER - Parole d'expert

Président et fondateur de la SSII Evaluant
Virtualiser, c'est bien. Mais encore faut-il disposer des compétences nécessaires. (...)


CONNEXION AU CIO PDF
E-MAIL :
MOT DE 
PASSE : 
   Mot de passe oublié ?




SONDAGE
Comment percevez-vous le DSI de transition comme Philippe Tassin interviewé dans CIO.PDF 15 ?

HUMOUR - LE DESSIN DE FIX