Email this article   Print article 


Study: Cloud Security Improving But Far From Fixed

By Ken Presti
March 08, 2013    5:30 PM ET

Page 1 of 2

According to a recent study, organizations have improved their cloud security practices over the past three years, but security continues to be a major concern around cloud adoption.

The research was conducted by the Ponemon Institute, which surveyed 748 professionals in information technology and IT security. All of the respondents resided in the U.S., and most were rated at supervisory level or higher. The research was commissioned by CA Technologies as a follow-up to a similar study conducted in 2010.

The findings suggest that security practices have been improved over the past three years, but there continues to be widespread concern about the effectiveness of those practices. The study also revealed that security is a key criterion in the public cloud provider selection process in only approximately half of the responding organizations.

[Related: Gartner: Cloud, CRM To Drive SoftwareSpend Through 2014]

"In general we conclude that there is evidence of improvement from a security point of view, both in terms of Software-as-a-Service and in terms of Infrastructure-as-a-Service," said Dr. Larry Ponemon, founder of the Ponemon Institute. "When we did a comparable study two years ago, security was a somewhat bigger issue and the people in the organization that were doing cloud were actually doing insecure cloud. The main issue to drive cloud is cost-efficiency, which continues to reign supreme, but we see that a lot of organizations are starting to think about and implement better security measures. It's a small improvement overall, but an improvement nonetheless."

Ponemon added that one of the changes most urgently needed would be a move toward a higher role for security personnel in the cloud provider selection process.

"One of the issues that hasn't changed very much since 2010 is the lack of a role for security professionals in selecting the cloud provider," he said. "They're just not being asked very often, which is a mistake because these people should be the first line of defense. It should not be decided by end users who don't really understand security."

Meanwhile, the report cites a lack of agreement regarding who has ultimate responsibility for cloud security, most notably whether it is solely the responsibility of the cloud provider, or if the end user carries the primary burden.

But whether or not a company is more secure operating in the cloud, as opposed to operating on-premise, largely depends on the relative effectiveness of how on-premise security is handled, according to Ponemon.

"Smaller organizations often benefit greatly from cloud security because what they're currently doing in terms of in-house security is really not that great," Ponemon told CRN. Bigger companies have the resources to buy the latest and greatest technologies. Smaller companies also often improve their security profile by moving from on premises to the cloud."

NEXT: Effective Access Control



1 | 2 | Next >>

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Cloud

Recent Articles

10 Intriguing Product Updates From Google I/O 2013

CRN takes a look at some of the key ways Google intends to influence the way we do business and enjoy our free time. A number of product rollouts and updates were made at I/O 2013. Here are the most intriguing.

8 Tips For Successful Cloud Migrations

Successful cloud migrations don't merely focus on changes in technology; they are also focused on the comfort levels of both people who are familiar with the new technology as well as those who might be slightly apprehensive about the forthcoming changes.

9 Key Concerns That Block Cloud Sales

The benefits of the cloud are heavily touted by cloud providers and the various types of channel partners with which they work. But a number of stumbling blocks still remain. Channel partners outlined for CRN some of the objectives they hear most often.

  More Slide Shows




Related Videos
Loading...