Menu
Standards body sets out cloud guidelines

Standards body sets out cloud guidelines

NIST looks to make recommendations on security and privacy

The US government is setting out to address concerns about security in the cloud. The US National Institute of Standards and Technology has issued a draft document looking at issues such as privacy and security within cloud environments.

The institute has also sought to tackle the uncertainty and confusion that surrounds the technology by introducing a document that sets out a series of definitions of cloud computing.

The Guidelines on Security and Privacy in Public Cloud (registration required) examines some of the security issues facing cloud providers and customers and offers a series of recommendations for organisations to consider when outsourcing data, applications and infrastructure to a public cloud environment.

The report, written by NIST computer scientists Tim Grance and Wayne Jansen, stressed the importance of building in security from the outset. "To maximise effectiveness and minimize costs, security and privacy must be considered from the initial planning stage at the start of the systems development life cycle. Attempting to address security after implementation and deployment is not only much more difficult and expensive, but also more risky."

The report goes on to point out the importance of recognising that the cloud provider has little or no understanding of its customers' individual security requirements. "Organisations should require that any selected public cloud computing solution is configured, deployed, and managed to meet their security, privacy, and other requirements," warns the document.

Other issues for customers include ensuring that client-side computing environment meets the organisation's security and privacy requirements for cloud computing and that the organisation retains accountability for its data and applications deployed in the cloud.

The new cloud definition document,The NIST Definition of Cloud Computing, is NIST's contribution to the debate on cloud services. In its introduction, it points out that l"Cloud computing is still an evolving paradigm. Its definition, use cases, underlying technologies, issues, risks, and benefits will be refined and better understood with a spirited debate by the public and private sectors."

The NIST is looking for public comments on the documents, which must be submitted by 28 February.


Follow Us

Join the newsletter!

Error: Please check your email address.

Tags National Institute of Standards and TechnologyConfiguration / maintenancesecurityhardware systemsData Centre

Featured

Slideshows

Sizing up the NZ security spectrum - Where's the channel sweet spot?

Sizing up the NZ security spectrum - Where's the channel sweet spot?

From new extortion schemes, outside threats and rising cyber attacks, the art of securing the enterprise has seldom been so complex or challenging. With distance no longer a viable defence, Kiwi businesses are fighting to stay ahead of the security curve. In total, 28 per cent of local businesses faced a cyber attack last year, with the number in New Zealand set to rise in 2017. Yet amidst the sensationalism, media headlines and ongoing high profile breaches, confusion floods the channel, as partners seek strategic methods to combat rising sophistication from attackers. In sizing up the security spectrum, this Reseller News roundtable - in association with F5 Networks, Kaspersky Lab, Tech Data, Sophos and SonicWall - assessed where the channel sweet spot is within the New Zealand channel. Photos by Maria Stefina.

Sizing up the NZ security spectrum - Where's the channel sweet spot?
Show Comments