<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Roger Halbheer on Security &#187; Cloud</title>
	<atom:link href="http://www.halbheer.ch/security/tag/cloud/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.halbheer.ch/security</link>
	<description>Information Security Discussion by Microsoft&#039;s Worldwide Chief Security Advisor.</description>
	<lastBuildDate>Wed, 16 May 2012 18:03:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Office 365 Single Sign-On with AD FS 2.0 whitepaper</title>
		<link>http://www.halbheer.ch/security/2012/03/05/office-365-single-sign-on-with-ad-fs-2-0-whitepaper/</link>
		<comments>http://www.halbheer.ch/security/2012/03/05/office-365-single-sign-on-with-ad-fs-2-0-whitepaper/#comments</comments>
		<pubDate>Mon, 05 Mar 2012 10:39:28 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Federation]]></category>
		<category><![CDATA[Identity]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/?p=2612</guid>
		<description><![CDATA[<p>Sorry, I did not blog for quite a while. </p> <p>When looking at the Cloud, one of the key challenges to address &#8211; in my opinion &#8211; is how to manage the identity of the different users. If you have to add an additional identity to all the logons you already have, the Cloud will <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2012/03/05/office-365-single-sign-on-with-ad-fs-2-0-whitepaper/">Office 365 Single Sign-On with AD FS 2.0 whitepaper</a></span>]]></description>
			<content:encoded><![CDATA[<p>Sorry, I did not blog for quite a while. </p>
<p>When looking at the Cloud, one of the key challenges to address &#8211; in my opinion &#8211; is how to manage the identity of the different users. If you have to add an additional identity to all the logons you already have, the Cloud will just add to the burden. Therefore, I am a firm believer that you need to have federation between your on-premise identity and your cloud identities.</p>
<p>We just released a paper <a href="http://www.microsoft.com/download/en/details.aspx?id=28971" target="_blank">Office 365 Single Sign-On with AD FS 2.0 whitepaper</a> on how to address this with Office 365 and ADFS 2.0:</p>
<blockquote><p>Through its support for the WS-Federation (WS-Fed) and WS-Trust protocols, Microsoft Active Directory Federation Services (AD FS) 2.0 provides claims-based (Web) single sign-on (also known as identity federation) with the Microsoft Office 365 offering and its Web application and rich client applications. </p>
<p>Building on existing documentation, this document is intended to provide a better understanding of the different single sign-on deployment options for the services in services in Office 365, how to enable single sign-on using corporate Active Directory credentials and AD FS 2.0 to the service in Office, and the different configuration elements to be aware of for such deployment.</p>
<p>This document is intended for system architects and IT professionals who are interested in understanding the basics of the single sign-on feature of Office 365 with AD FS 2.0 along with planning and deploying such a deployment in their environment.</p>
</blockquote>
<p>You should have an in-depth look at this</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2012/03/05/office-365-single-sign-on-with-ad-fs-2-0-whitepaper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Office 365 Becomes First and Only Major Cloud Productivity Service to Comply With Leading EU and U.S. Standards for Data Protection and Security</title>
		<link>http://www.halbheer.ch/security/2011/12/16/office-365-becomes-first-and-only-major-cloud-productivity-service-to-comply-with-leading-eu-and-u-s-standards-for-data-protection-and-security/</link>
		<comments>http://www.halbheer.ch/security/2011/12/16/office-365-becomes-first-and-only-major-cloud-productivity-service-to-comply-with-leading-eu-and-u-s-standards-for-data-protection-and-security/#comments</comments>
		<pubDate>Fri, 16 Dec 2011 13:09:09 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Office365]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/?p=2585</guid>
		<description><![CDATA[<p>A long title but this was the title of the official press statement yesterday. Compliance is always a key question in the public cloud space. Therefore it is very important for us that we now achieved three things:</p> Office 365 is compliant with EU Model Clauses, Data Processing Agreements and ISO 27001 among other standards. <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/12/16/office-365-becomes-first-and-only-major-cloud-productivity-service-to-comply-with-leading-eu-and-u-s-standards-for-data-protection-and-security/">Office 365 Becomes First and Only Major Cloud Productivity Service to Comply With Leading EU and U.S. Standards for Data Protection and Security</a></span>]]></description>
			<content:encoded><![CDATA[<p>A long title but this was the title of the official press statement yesterday. Compliance is always a key question in the public cloud space. Therefore it is very important for us that we now achieved three things:</p>
<ul>
<li>Office 365 is compliant with EU Model Clauses, Data Processing Agreements and ISO 27001 among other standards.</li>
<li>Office 365 is the first and only major cloud productivity service that enables HIPAA compliance.</li>
<li>The Office 365 Trust Center provides in-depth information about the privacy and security practices for Office 365 and was recently redesigned to be more accessible and easy to understand.&#160; The new site can be accessed at <a href="http://trust.office365.com">http://trust.office365.com</a>.</li>
</ul>
<p>If you are interested in the official press statement: <a title="http://www.microsoft.com/Presspass/press/2011/dec11/12-14O365CloudPR.mspx" href="http://www.microsoft.com/Presspass/press/2011/dec11/12-14O365CloudPR.mspx">http://www.microsoft.com/Presspass/press/2011/dec11/12-14O365CloudPR.mspx</a></p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/12/16/office-365-becomes-first-and-only-major-cloud-productivity-service-to-comply-with-leading-eu-and-u-s-standards-for-data-protection-and-security/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Definition of Cloud Computing</title>
		<link>http://www.halbheer.ch/security/2011/09/16/definition-of-cloud-computing/</link>
		<comments>http://www.halbheer.ch/security/2011/09/16/definition-of-cloud-computing/#comments</comments>
		<pubDate>Fri, 16 Sep 2011 04:41:03 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Fun]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Cloud]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/09/16/definition-of-cloud-computing/</guid>
		<description><![CDATA[<p>Just found this on http://news.yahoo.com/photos/new-adventures-of-queen-victoria-slideshow/20110914-naqv110914-gif-photo-050626492.html</p> <p></p> <p>Love that </p> <p>Roger</p> ]]></description>
			<content:encoded><![CDATA[<p>Just found this on <a title="http://news.yahoo.com/photos/new-adventures-of-queen-victoria-slideshow/20110914-naqv110914-gif-photo-050626492.html" href="http://news.yahoo.com/photos/new-adventures-of-queen-victoria-slideshow/20110914-naqv110914-gif-photo-050626492.html">http://news.yahoo.com/photos/new-adventures-of-queen-victoria-slideshow/20110914-naqv110914-gif-photo-050626492.html</a></p>
<p><img src="http://media.zenfs.com/en_us/News/ucomics.com/naqv110914.gif" /></p>
<p>Love that <img style="border-bottom-style: none; border-left-style: none; border-top-style: none; border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://www.halbheer.ch/security/wp-content/uploads/2011/09/wlEmoticon-smile.png" /></p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/09/16/definition-of-cloud-computing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Searchable Encryption for the Cloud&#8211;soon?</title>
		<link>http://www.halbheer.ch/security/2011/08/10/searchable-encryption-for-the-cloudsoon/</link>
		<comments>http://www.halbheer.ch/security/2011/08/10/searchable-encryption-for-the-cloudsoon/#comments</comments>
		<pubDate>Wed, 10 Aug 2011 11:41:04 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/08/10/searchable-encryption-for-the-cloudsoon/</guid>
		<description><![CDATA[<p>This is a very interesting development. Encryption generally would solve a lot of problems around data sovereignty. So, encrypting the data, keeping the key and moving the data to the public cloud could basically address a lot of the risks. Today, it comes with a high price as the data which resides encrypted in the <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/08/10/searchable-encryption-for-the-cloudsoon/">Searchable Encryption for the Cloud&#8211;soon?</a></span>]]></description>
			<content:encoded><![CDATA[<p>This is a very interesting development. Encryption generally would solve a lot of problems around data sovereignty. So, encrypting the data, keeping the key and moving the data to the public cloud could basically address a lot of the risks. Today, it comes with a high price as the data which resides encrypted in the Cloud cannot be index (therefore is not searchable) nor can any operation be conducted.</p>
<p>The solution is homomorphic encryption, where a lot of research is done but it is still too slow. People at Microsoft Research now took a new angle on it: They took, what is already here and looked at the scenarios, which are already possible today.</p>
<p>The following article gives an interesting overview, what would be possible based on today’s research: <a href="http://www.technologyreview.com/computing/38239/" target="_blank">A Cloud that Can&#8217;t Leak</a></p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/08/10/searchable-encryption-for-the-cloudsoon/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Video on Microsoft&#8217;s Datacenter</title>
		<link>http://www.halbheer.ch/security/2011/07/29/video-on-microsofts-datacenter/</link>
		<comments>http://www.halbheer.ch/security/2011/07/29/video-on-microsofts-datacenter/#comments</comments>
		<pubDate>Fri, 29 Jul 2011 10:13:43 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Processes]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/07/29/video-on-microsofts-datacenter/</guid>
		<description><![CDATA[<p>A very good overview over the way we run Microsoft’s Cloud. The interesting thing is – if you look at the video – that most customers are still running their datacenters on generation 1-2, which means that the efficiency (labor as well as energy) we can deliver is significantly higher – not talking of our <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/07/29/video-on-microsofts-datacenter/">Video on Microsoft&#8217;s Datacenter</a></span>]]></description>
			<content:encoded><![CDATA[<p>A very good overview over the way we run Microsoft’s Cloud. The interesting thing is – if you look at the video – that most customers are still running their datacenters on generation 1-2, which means that the efficiency (labor as well as energy) we can deliver is significantly higher – not talking of our security.</p>
<p>Enjoy this tour:</p>
<p><iframe src="http://www.youtube.com/embed/hOxA1l1pQIw" frameborder="0" width="560" height="349"></iframe></p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/07/29/video-on-microsofts-datacenter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Security in Office365</title>
		<link>http://www.halbheer.ch/security/2011/07/15/cloud-security-in-office365/</link>
		<comments>http://www.halbheer.ch/security/2011/07/15/cloud-security-in-office365/#comments</comments>
		<pubDate>Fri, 15 Jul 2011 08:12:29 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[People]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/07/15/cloud-security-in-office365/</guid>
		<description><![CDATA[<p>You heard about the launch of Office365 recently and I hope you read the blog post on the application of the Cloud Computing Security Considerations to the private. cloud. If not, here it is: Security Considerations in a Private Cloud</p> <p>To complete the series now, we released an additional paper on how these considerations can <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/07/15/cloud-security-in-office365/">Cloud Security in Office365</a></span>]]></description>
			<content:encoded><![CDATA[<p>You heard about the launch of Office365 recently and I hope you read the blog post on the application of the <a href="http://go.microsoft.com/?linkid=9708479" target="_blank">Cloud Computing Security Considerations</a> to the private. cloud. If not, here it is: <a href="http://www.halbheer.ch/security/2011/06/24/security-considerations-in-a-private-cloud/" target="_blank">Security Considerations in a Private Cloud</a></p>
<p>To complete the series now, we released an additional paper on how these considerations can be applied to Office 365. It is not about the security features of Office 365. It is about how a the responsibilities between the customer and us can and shall be split. This is a really interesting paper in my opinion: <a href="http://download.microsoft.com/download/2/2/0/220AE513-4A01-4D95-9275-11E71215A0C2/CloudSecurityConsiderations_MicrosoftOffice365.pdf" target="_blank">Addressing Cloud Computing Security Considerations with Microsoft Office 365</a>.</p>
<p>Additionally, we took a deeper look at the Cloud Security Alliance’ Cloud Control Matrix (CCM) at provided an answer for each question/control raised in this document: <a href="http://www.microsoft.com/download/en/details.aspx?id=26647" target="_blank">Standard Response to Request for Information &#8211; Security and Privacy</a>.</p>
<p>These are all steps to provide you with the necessary transparency to get into the public cloud and on Office 365!</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/07/15/cloud-security-in-office365/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Considerations in a Private Cloud</title>
		<link>http://www.halbheer.ch/security/2011/06/24/security-considerations-in-a-private-cloud/</link>
		<comments>http://www.halbheer.ch/security/2011/06/24/security-considerations-in-a-private-cloud/#comments</comments>
		<pubDate>Fri, 24 Jun 2011 14:31:38 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[People]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Private]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/06/24/security-considerations-in-a-private-cloud/</guid>
		<description><![CDATA[<p>I am talking a lot about Cloud Security. There are a few observations I made:</p> Even though a lot of people are talking about the Cloud, there is still not too much knowledge about it. What is a private Cloud versus a public Cloud? What is Infrastructure as a Service, Platform as a Service, Application <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/06/24/security-considerations-in-a-private-cloud/">Security Considerations in a Private Cloud</a></span>]]></description>
			<content:encoded><![CDATA[<p>I am talking a lot about Cloud Security. There are a few observations I made:</p>
<ul>
<li>Even though a lot of people are talking about the Cloud, there is still not too much knowledge about it. What is a private Cloud versus a public Cloud? What is Infrastructure as a Service, Platform as a Service, Application as a Service? And where are the key differences when it comes to risks?</li>
<li>A lot of businesses look at it as an all or nothing. This is simply a massive mistake. There are workloads (like your identity management) you will wait a really long time until you move it to the Cloud and keep on premise. There are others, you might want to move immediately to the public Cloud and some of it will stay in a private Cloud.</li>
<li>There is a lot of fear out there and not a lot of frameworks, which can help with to bring the whole discussion to rational level. Actually, there is a lot of material out there but not a lot, which is simple to read and consume.</li>
</ul>
<p>That’s the reason, why Doug Cavit and me wrote the <a href="http://go.microsoft.com/?linkid=9708479" target="_blank">Cloud Computing Security Considerations</a> about an year ago. We came up with 5 points to be considered, when looking at the Cloud from a security perspective:</p>
<blockquote><ul>
<li><i>Compliance and Risk Management</i>: Organisations shifting part of their business to the cloud are still responsible for compliance, risk, and security management.</li>
<li><i>Identity and Access Management</i>: Identities may come from different providers, and providers must be able to federate from on-premise to the cloud, as well as to enable collaboration across organisation and country borders.</li>
<li><i>Service Integrity</i>: Cloud-based services should be engineered and operated with security in mind, and the operational processes should be integrated into the organisation’s security management.</li>
<li><i>Endpoint Integrity</i>: As cloud-based services originate&#8211;and are then consumed&#8211;on-premise, the security, compliance, and integrity of the endpoint have to be part of any security consideration.</li>
<li><i>Information Protection</i>: Cloud services require reliable processes for protecting information before, during, and after the transaction.</li>
</ul>
</blockquote>
<p>These five considerations are very well received and seem to work well for the customers to address part of the points above. The number 1 question I got, however, was: How can apply this to the different scenarios?</p>
<p align="center"><strong>Therefore I am happy to announce, that we just released a paper to the web called: </strong><a href="http://download.microsoft.com/download/2/2/0/220AE513-4A01-4D95-9275-11E71215A0C2/CloudSecurityConsiderations_PartnerPrivateCloud.pdf" target="_blank">Addressing Cloud Computing Security Considerations with a Partner Private Cloud</a><strong>.</strong></p>
<p>We show you how to split responsibilities between the partner and the customer and what the considerations mean for both sides – as always, your feedback is more than welcome!</p>
<p>Finally, stay tuned: In a few days, we will do the same with the public Cloud. This time, however focused on Office365. As soon as we go live with Office365, we will publish it.</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/06/24/security-considerations-in-a-private-cloud/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Does the business really hate IT?</title>
		<link>http://www.halbheer.ch/security/2011/06/23/does-the-business-really-hate-it/</link>
		<comments>http://www.halbheer.ch/security/2011/06/23/does-the-business-really-hate-it/#comments</comments>
		<pubDate>Thu, 23 Jun 2011 12:55:27 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Outsourcing]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/06/23/does-the-business-really-hate-it/</guid>
		<description><![CDATA[<p>Back at the times of outsourcing, there was real tension between IT and the business. Internal IT had the “comfortable” position of having a monopoly: The business used the internal IT and basically just had to pay the bill. Then times came, where the business was not satisfied anymore. That basically started with the time <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/06/23/does-the-business-really-hate-it/">Does the business really hate IT?</a></span>]]></description>
			<content:encoded><![CDATA[<p>Back at the times of outsourcing, there was real tension between IT and the business. Internal IT had the “comfortable” position of having a monopoly: The business used the internal IT and basically just had to pay the bill. Then times came, where the business was not satisfied anymore. That basically started with the time of the PC. IT was in kind of a losing position: If the decentralized IT worked, it was just what users expected, if it did not, users complained. Additionally, as IT was treated as an art rather than an engineering discipline (that’s the way it is still run in a lot of occasions), cost just grew, without a real need of rationalizing. IT is critical for all the businesses but the value is hard to measure (until you lose your mail server once for a day).</p>
<p>Then outsourcing came and everything was getting better – not really. A lot of companies outsourced a problem – they used the same people with the same attitude and outsourced everything to the outsourcing provider. But now they had a contract – and so did the outsourcer. There were (and still are) numerous meetings I have been in, where the customer and the outsourcer were fighting, whether applying a patch is part of the contract or not and whether patch management should be done more than every six months. Finally, the customer had to learn to become a customer as well and specify their needs.</p>
<p>Why do I write this? Because I see similar discussions today with the Cloud. Business is not satisfied with how internal IT delivers. They are too slow, too expensive and too unreliable – therefore the business is looking at the promises of the Cloud: Fast, reliable, inexpensive. What does it really mean for the business? For IT?</p>
<ul>
<li>To me the business has to understand that if they move to the public cloud, there is a good chance that they have to adapt their business processes. Remember the huge ERP projects? It is not that different. This might be good as it forces the organization to clean up – but it shall be a conscious decision. Even for the part you are moving to the cloud, you still have to keep part of your responsibilities: You are still ultimately responsible for your compliance. You should keep your identity management in house and risk management for your business cannot be outsourced. You have to have a data classification, which is applied and lived – this is, how we described it in our <a href="http://go.microsoft.com/?linkid=9708479">Cloud Computing Security Considerations</a>. Last but not least: You are the customer of a standardized service. Make sure you understand this as this will be a long-term partnership you are going for, with very, very limited flexibility of the final solution.</li>
<li>If you move to the private cloud, the situation is slightly different as you might have more influence on how your solution looks like but even the private cloud is not an outsourcing as you knew it – e.g. most probably you will not be able to tell the cloud provider how they will run their datacenters. You will run on your own OS-instances (does not necessarily mean your own hardware as the solution will most probably be virtualized) but even the question of the data location might have to be negotiated. And: It definitely costs more.</li>
<li>If you are an IT organization: Become a Cloud provider. Become the partner for your business in the Cloud. You business will want to have part of it in a private cloud – offer this in a way you can compete with third-parties as you will not be able to compete in the public cloud.</li>
</ul>
<p>This decision has to be a strategic decision and not a decision taken because business does not like their own IT. For the internal IT it might be a threat (if you decide to sit and wait) or an opportunity if you take the strategic decision and opportunity.</p>
<p>Now, the reason for this post was actually in an article, which was sent to me: <a href="http://www.itworld.com/cloud-computing/174967/business-users-abandoning-it-quicker-self-serve-cloud-apps" target="_blank">Why businesses move to the cloud: They hate IT</a></p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/06/23/does-the-business-really-hate-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Who cares where your data is?</title>
		<link>http://www.halbheer.ch/security/2011/06/10/who-cares-where-your-data-is/</link>
		<comments>http://www.halbheer.ch/security/2011/06/10/who-cares-where-your-data-is/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 11:51:04 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Policies]]></category>
		<category><![CDATA[Regulation]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/06/10/who-cares-where-your-data-is/</guid>
		<description><![CDATA[<p>Wow, I guess the reason for you clicking on the link is this statement – right? Well, “unfortunately” I cannot claim ownership of it. It was made by a Google representative during an interview in Australia: Google: Who cares where your data is?</p> <p>To me, the whole Cloud discussion sometimes drives into interesting directions. I <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/06/10/who-cares-where-your-data-is/">Who cares where your data is?</a></span>]]></description>
			<content:encoded><![CDATA[<p>Wow, I guess the reason for you clicking on the link is this statement – right? Well, “unfortunately” I cannot claim ownership of it. It was made by a Google representative during an interview in Australia: <a href="http://www.scmagazine.com.au/News/260041,google-who-cares-where-your-data-is.aspx" target="_blank">Google: Who cares where your data is?</a></p>
<p>To me, the whole Cloud discussion sometimes drives into interesting directions. I often feel that Cloud providers develop a solution and tell the world that the policy decisions were on purpose to protect the customers. Like some providers told the world in the past that you should not care how your data is protected. They take care of your security and you should just trust them – like banks. Nonsense! If you have to prove compliance, you will definitely want to understand how your data is protected and what controls are enforced in the Cloud environment. But as the industry – including the regulators – is still trying to understand the impact of the Cloud, it is a good time to drive such messages and sell the setup as “best practice”. </p>
<p>Things will change and outdated policies will be adopted to today’s reality but making a statement that you should not care where your data is, simply neglects some “minor” obligations you carry like protection of the privacy of the people you have data from… or the fact that you probably not want your state secrets in another country (even though I do not expect a country putting Top Secret material to the public cloud – yet).</p>
<p>Just because the Cloud provider does not know, where your data is does not mean that you shouldn&#8217;t care…</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/06/10/who-cares-where-your-data-is/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud computing providers: Clueless about security?</title>
		<link>http://www.halbheer.ch/security/2011/05/04/cloud-computing-providers-clueless-about-security/</link>
		<comments>http://www.halbheer.ch/security/2011/05/04/cloud-computing-providers-clueless-about-security/#comments</comments>
		<pubDate>Wed, 04 May 2011 17:04:53 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Incident Sharing]]></category>
		<category><![CDATA[Incidents]]></category>
		<category><![CDATA[Processes]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/05/04/cloud-computing-providers-clueless-about-security/</guid>
		<description><![CDATA[<p>To me, one of the benefits of moving to the Cloud is security – obviously besides availability and costs.</p> <p>Recent incidents made me doubt:</p> Amazon not only having significant downtime but in the same time losing customer data. Sony’s game network being significantly compromised. <p>This is definitely not to blame them but I was heavily <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/05/04/cloud-computing-providers-clueless-about-security/">Cloud computing providers: Clueless about security?</a></span>]]></description>
			<content:encoded><![CDATA[<p>To me, one of the benefits of moving to the Cloud is security – obviously besides availability and costs.</p>
<p>Recent incidents made me doubt:</p>
<ul>
<li>Amazon not only having significant downtime but in the same time losing customer data.</li>
<li>Sony’s game network being significantly compromised.</li>
</ul>
<p>This is definitely not to blame them but I was heavily surprised. And then, I found this study by the Ponemon Institute: <a href="http://www.ca.com/~/media/Files/IndustryResearch/security-of-cloud-computing-providers-final-april-2011.pdf" target="_blank">Cloud computing providers: Clueless about security?</a></p>
<p>If we look at this, it gives us a really scary picture of the industry – especially if I know how much effort we (and other Cloud provider) out into securing our customer’s data. If you look at the management summary, they say:</p>
<blockquote>
<ul>
<li>The majority of cloud computing providers surveyed do not believe their organization views the security of their cloud services as a competitive advantage. Further, they do not consider cloud computing security as one of their most important responsibilities and do not believe their products or services substantially protect and secure the confidential or sensitive information of their customers.</li>
<li>The majority of cloud providers believe it is their customer’s responsibility to secure the cloud and not their responsibility. They also say their systems and applications are not always evaluated for security threats prior to deployment to customers.</li>
<li>Buyer beware – on average providers of cloud computing technologies allocate10 percent or less of their operational resources to security and most do not have confidence that customers’ security requirements are being met.</li>
<li>Cloud providers in our study say the primary reasons why customers purchase cloud resources are lower cost and faster deployment of applications. In contrast, improved security or compliance with regulations is viewed as an unlikely reason for choosing cloud services.</li>
<li>The majority of cloud providers in our study admit they do not have dedicated security personnel to oversee the security of cloud applications, infrastructure or platforms.</li>
<li>Providers of private cloud resources appear to attach more importance and have a higher level of confidence in their organization’s ability to meet security objectives than providers of public and hybrid cloud solutions.</li>
<li>While security as a “true” service from the cloud is rarely offered to customers today, about one-third of the cloud providers in our study are considering such solutions as a new source of revenue sometime in the next two years.</li>
</ul>
</blockquote>
<p>What we should not think is, that the customer can just throw their data “over the wall” to the Cloud provider and then all the problems are solved. The customer still has obligations and as we state in our <a href="http://go.microsoft.com/?linkid=9708479" target="_blank">Cloud Computing Security Considerations</a> paper:</p>
<blockquote><p><em>Compliance and Risk Management</em>: Organizations shifting part of their business to the cloud are still responsible for compliance, risk, and security management.</p></blockquote>
<p>We are currently working on a series of papers for Private Clouds, Office 365 as well as Azure to show what still is the customer’s responsibility and what can be transferred to the Cloud Provider.</p>
<p>If you consider the points in the study above, it means that you have to do the due diligence and looking into what the provider does to secure your data. Process transparency is key in this respect!</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/05/04/cloud-computing-providers-clueless-about-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

