{"id":22457,"date":"2016-05-12T14:48:46","date_gmt":"2016-05-12T14:48:46","guid":{"rendered":"http:\/\/www.businesscloudnews.com\/?p=252842"},"modified":"2016-05-12T14:48:46","modified_gmt":"2016-05-12T14:48:46","slug":"the-top-three-cloud-security-myths-busted","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/the-top-three-cloud-security-myths-busted\/","title":{"rendered":"The top three cloud security myths: BUSTED"},"content":{"rendered":"<p><a href=\"http:\/\/www.businesscloudnews.com\/files\/2016\/05\/Security-Protected.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-252852 alignright\" src=\"http:\/\/www.businesscloudnews.com\/files\/2016\/05\/Security-Protected-300x269.jpg\" alt=\"a safe place to work\" width=\"300\" height=\"269\" \/><\/a>The rise in global cyber-attacks and the <a href=\"https:\/\/protect-us.mimecast.com\/s\/wXWmB3Un1k46cd\">subsequent high-profile press coverage<\/a>, understandably makes businesses question the security of cloud. After all, the dangers of hosting anything in an environment where data loss or system failure events are attributed to an outside source are magnified. As a result, many CIOs are also still struggling to identify and implement the cloud services most suitable for their business. In fact, <a href=\"https:\/\/protect-us.mimecast.com\/s\/arG6BRuzR0X8FK\">research finds<\/a> over three quarters (79%) of CIOs find it a challenge to balance the productivity needs of employees against potential security threats. Moreover, 84% of CIOs worry cloud causes them to lose control over IT.<\/p>\n<p>But is cloud really more vulnerable than any other infrastructure? And how can organisations mitigate any risk they encounter? The reality is that all systems have vulnerabilities that can be exploited, whether on-premise, in the cloud or a hybrid of the two. It\u2019s safe to say that people fear what they don\u2019t understand \u2013 and with cloud becoming increasingly complex, it\u2019s not surprising that there are so many myths attached to it. It\u2019s time to clear up some of these myths.<\/p>\n<p><strong>Myth 1: Cloud technology is still in its infancy and therefore inherently insecure<\/strong><\/p>\n<p>Cloud has been around for much longer than we often think and can be traced as far back as the 1970\u2019s. The rapid pace of cloud development, coupled with an awakening realisation of what cloud can do for businesses, has thrust it into the limelight in recent years.<\/p>\n<p>The biggest issue CIOs have with cloud is their increasing distance from the physical technology involved. Indeed, many CIO\u2019s feel that if they cannot walk into a data centre and see comforting lights flashing on the hardware, then it is beyond their reach. As a result, many organisations overlook instrumentation in the cloud, so don\u2019t look at the data or systems they put there in the same way they would if it were on a physical machine. Organisations then forget to apply their own security standards, as they would in their own environment, and it is this complacency that gives rise to risk and exposure.<\/p>\n<p><strong><a href=\"http:\/\/www.businesscloudnews.com\/files\/2016\/04\/Justice.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-249542 alignright\" src=\"http:\/\/www.businesscloudnews.com\/files\/2016\/04\/Justice-300x199.jpg\" alt=\"Lady Justice On The Old Bailey, London\" width=\"300\" height=\"199\" \/><\/a>Myth 2: Physical security keeps data safe<\/strong><\/p>\n<p>It is a common misconception that having data stored on premise and on your own servers is the best form of protection. However, the location of data is not the only factor to consider. The greatest form of defence you can deploy with cloud is a combination of strict access rights, diligent data stewardship and strong governance.<\/p>\n<p>Common security mistakes include not performing full due diligence on the cloud provider and assuming that the provider will be taking care of all security issues. In addition, it is still common for organisations to not take into account the physical location of a cloud environment and the legal ramifications of storing data in a different country. Indeed, a <a href=\"https:\/\/protect-us.mimecast.com\/s\/27lnBgUp2lemcq\">recent European Court of Justice ruling<\/a> found the Safe Harbour accord was invalid as it failed to adequately protect EU data from US government surveillance. Cloud providers rushed to assure customers they were dealing with the situation, but the main takeaway from this is to not believe that a cloud provider will write security policy for you \u2013 organisations need to take ownership.<\/p>\n<p><strong>Myth 3: Cloud security is the provider\u2019s responsibility <\/strong><\/p>\n<p>All of the major public clouds have multiple certifications (ISO27001, ISO27018, ENISA IAF, FIPS140-2, HIPAA, PCI-DSS) attained by proving they have controls to ensure data integrity.<\/p>\n<p><a href=\"http:\/\/www.businesscloudnews.com\/files\/2016\/05\/Security-Camera.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-252862 alignright\" src=\"http:\/\/www.businesscloudnews.com\/files\/2016\/05\/Security-Camera-300x199.jpg\" alt=\"Security CCTV camera in office building\" width=\"300\" height=\"199\" \/><\/a>The real risk comes when organisations blindly park data, thinking that security is just implicit. Unless the data is protected with encryption, firewalls, access lists etc., organisations remain vulnerable. The majority of cloud exposures can in fact be traced back to a failure in policy or controls not being applied correctly \u2013 look at the TalkTalk hack for example, and consider the alternate outcome had the database been encrypted.<\/p>\n<p><strong>Education and ownership is the future<\/strong><\/p>\n<p>The speed at which cloud is evolving can understandably cause a few teething problems. But it is the responsibility of providers and clients alike to take ownership of their own elements and apply security policies which are right for their business, their risk profile and the data which they hold. As with any technological change, many interested parties quickly jumped on the cloud bandwagon. But the allure of a technology can inhibit a lack of critical thinking, and the broader view of choosing the right application at the right cost, with appropriate security to mitigate risk, is lost. Remember, the cloud is not inherently secure and given the fact it stands to underpin enterprise operations for years to come, it\u2019s worth approaching it not as a bandwagon but as an important part of enterprise infrastructure.<\/p>\n<p><em>Written by Mark Ebden, Strategic Consultant, Trustmarque<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&rsquo;s safe to say that people fear what they don&rsquo;t understand &ndash; and with cloud becoming increasingly complex, it&rsquo;s not surprising that there are so many myths attached to it. It&rsquo;s time to clear up some of these myths.<\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2125,1976,2254],"tags":[118],"class_list":["post-22457","post","type-post","status-publish","format-standard","hentry","category-data-protection","category-news-analysis","category-trustmarque","tag-security"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/22457","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=22457"}],"version-history":[{"count":1,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/22457\/revisions"}],"predecessor-version":[{"id":22458,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/22457\/revisions\/22458"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=22457"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=22457"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=22457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}