Thursday, March 04, 2010

Cloud Computing - Top 10 Threats

With 24x7 availability and accessible by almost any device with a browser, cloud computing allows organizations to scale their IT infrastructure and software applications as needed. However, like any technology, cloud computing has its risks.

#1) Changes the business model. Cloud computing changes the way IT services are delivered. No longer delivered from an on-site location, servers, storage, and applications are provided by external service providers. Organizations need to evaluate the risks associated with the loss of control of the infrastructure.

#2) Abuse. Initial registration with a cloud computing service is a pretty simple process. In many cases, the service provider even offers a free trial period. Organizations should consider their risks due to anonymous signup, lack of validation, service fraud, and ad-hoc services.

#3 Insecure interfaces. Application programming interfaces (API) are used to establish, manage, and monitor services. These interfaces may be subject to security vulnerabilities that put your users at risk.

#4 Malicious insiders. One of the benefits of cloud computing is that your organization doesn't need to know the technical details of how the services are delivered. The provider's procedures, physical access to systems, monitoring of employees, and compliance related issues are transparent to the customer. Without full knowledge and control, your organization may be at risk.

#5 Shared technology. Cloud computing allows multiple organizations to share and store data on the servers. However, the original server hardware and operating systems were most likely designed for use by a single tenant (one organziation). Organizations should ensure the appropriate controls are in place to keep your data secure.

#6 Data loss and leakage. With shared infrastructure resources, organizations should be concerned about the service provider's authentication systems that grant access to data. Organizations should also ask about encryption, data disposal procedures, and business continuity.

#7 Account hijacking. Organizations should be aware that account hijacking can occur. Simple Internet registration systems, phishing and fraud schemes can allow a hacker to take over control of your account.

#8 Risk profile. For many service providers, the focus is on functionality and benefits, not security. Without appropriate software updates, intrusion preventation, and firewalls, your organization may be at risk.

#9 Users. When using cloud services, your users' activities such as clicking links in e-mail messages, Instant Messaging, visiting fake web sites, etc. can download malware to a local workstation. Once installed, the malware can launch attacks against your internal network.

10# Browsers. Several years ago, hackers used to attack software operating systems. More recently, hackers have shifted their attacks to target user browsers. By exploiting browser vulnerabilities, hackers have access to the same applications and data that your users access.

Internet cloud computing services provide both business and technical benefits. Risk assessments help organizations identify, manage, and reduce their cloud computing risks so that they may achieve the greatest benefits at the lowest level of risk.

Labels: , , ,

Tuesday, August 04, 2009

Protecting Intangible Assets

As recently as 1982, tangible equipment such as buildings, facilities, furniture, computer hardware, etc. comprised 62% of an organization's business value. Unfortunately, large buildings and facilities were expensive to acquire and maintain. Over time, organizations adopted a new business model, relying on technology to deliver products and services at a lower cost.

By reworking their business model, firms automated many of their manual processes and migrated from manufacturing plants and equipment to the electronic delivery of products and services. This transition shifted organization value from tangible to intangible assets. By 2002, tangible assets were only 12% of an average company's market value. 88% of the value of the organization was attributed to intangible assets such as intellectual property and "information assets".

With the change in business model from tangible equipment to "information assets", organizations experienced a new type of business risk, electronic threats. Electronic threats included viruses, hackers, data theft, and many others. Without proper protection, organizations found that their market value was at risk. Over time, organizations implemented security in a reactive manner, first installing anti-virus software and later implementing firewalls as Internet risks increased. Unfortunately, this ad-hoc approach wasn't sufficient and many firms experienced downtime, lost employee efficiency, and reduced market value.

Leading organizations took a different approach, realizing that security needed to be implemented according to the value of their intangible assets. Since many threats were hidden, a proactive approach of using risk assessments helped these organizations identify hidden threats, implement steps to manage these risks, and eliminate or reduce threats to acceptable levels.

Not all risks are created equal and risk assessments help firms reduce their costs while increasing protection of their “information assets”.

Labels: , , , ,