Sun CTO to form cloud security forum

By Tom Espiner, ZDNet UK
Wednesday, May 27, 2009 12:07 PM

Sun's U.K. chief technology officer is working with major British public and private organizations to set up a cross-sector forum to resolve cloud-computing security issues.

Cloud-computing systems could become as important as the U.K. critical national infrastructure, and they need to be secured in an appropriate manner, Wayne Horkan told ZDNet Asia's sister site ZDNet UK last week. The Sun executive said he is working on setting up the forum alongside organizations such as the CBI, Microsoft and Accenture; government departments such as Berr, Dius and the Treasury; and the government's chief scientific advisor, Professor John Beddington.

"I'm concerned about the security of the supply," Horkan said at the Cloud Expo Europe conference in London. "If cloud computing becomes a utility, it's important to me that the United Kingdom as a nation state has good security of supply. It's important that the United Kingdom has the appropriate capability in cloud computing."

Horkan is also concerned about cloud-computing compliance issues facing the public and private sectors. Most of the major cloud-computing suppliers, which include Amazon and Google, are US-based. Horkan said that European organizations using cloud services based outside Europe face the possibility of not being in compliance with European data-protection law, as sensitive customer data could be inappropriately shared, or exposed through legal discovery.

"In Europe, you could put your data on the Google cloud, where it would be stored on its Lithuanian or Zurich data centers," said Horkan. "Overnight, the data gets uploaded onto an American server. The implication is, if you have sensitive data you are legally obliged not to share, you will inadvertently have shared it."

Horkan said U.K. legislation such as the Data Protection Act, and regulations such as PCI-DSS, need to be examined by companies considering cloud computing. However, he said he plans to push the U.K. government to re-examine data legislation.

Amazon Web Services (AWS) told ZDNet UK that businesses using its services it could be compliant with data law.

"We provide certification for data centers to comply with regulatory rules, and we offer Amazon in the EU. If you need to host in the EU we have data centers in Ireland," said Simone Brunozzi, AWS evangelist. "Large organizations are solving this [problem] by encrypting data, or [contractually] through terms and conditions."

Brunozzi added that Amazon had an interest in maintaining the security and availability of its services. "If we are down for one second, we lose a lot of money," said Brunozzi. "We have a lot of focus on security because we have details of millions of [payment] cards."

However, AWS is not a "silver bullet" for solving cloud-computing compliance and security issues, Brunozzi admitted.

"For some situations, it doesn't make sense to move to the cloud yet," said Brunnozzi. "We give security and availability, yet some specific use cases are not movable to the cloud yet [in terms of PCI-DSS compliance]."

Simon Wardley, the software services manager at Ubuntu Linux backer Canonical, said companies might become less competitive if they failed to utilize cloud computing. "There's the risk of being left behind," said Wardley. "There's no point in turning up to the cat fight with a snazzy rifle if everyone else has brought a tank. You need to evolve even to stand still relative to an ecosystem."

The next version of Ubuntu, Karmic Koala, will have extensive built-in cloud-computing functionality.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

A look at the Terminal Services Manager in Windows Server 2008

Windows Server

Terminal Services Manager has been around for a while, but Microsoft made some changes to the utility in Windows Server 2008. Here's what you'll find.


Read more »



Open source blog reloaded!

Blog thumbnail

This is with great pleasure that this "little corner of the Web" is resuming activities through another member of the (now famous ;-)) Beijing Linux User Group (BLUG) doing the..... by Fred Muller

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. google inc.
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web