<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Open IT Forum: What are your cloud security concerns for 2011?</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/open-it-forum-what-are-your-cloud-security-concerns-for-2011/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/open-it-forum-what-are-your-cloud-security-concerns-for-2011/</link>
	<description></description>
	<lastBuildDate>Thu, 20 Jun 2013 11:12:44 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: cloudresearcher</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/open-it-forum-what-are-your-cloud-security-concerns-for-2011/#comment-100406</link>
		<dc:creator>cloudresearcher</dc:creator>
		<pubDate>Fri, 16 Dec 2011 18:53:08 +0000</pubDate>
		<guid isPermaLink="false">#comment-100406</guid>
		<description><![CDATA[Data and Network Security will be in Focus atleast for next 2-3 years]]></description>
		<content:encoded><![CDATA[<p>Data and Network Security will be in Focus atleast for next 2-3 years</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pakella</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/open-it-forum-what-are-your-cloud-security-concerns-for-2011/#comment-93713</link>
		<dc:creator>pakella</dc:creator>
		<pubDate>Tue, 28 Jun 2011 15:40:42 +0000</pubDate>
		<guid isPermaLink="false">#comment-93713</guid>
		<description><![CDATA[Melanie, colleagues:

According to IDC, your concerns about data security are echoed by 48% of organizations that they surveyed!

As a prospect, looking to acquire and use a cloud-based SaaS solution, I might consider a framework that looks something like:
&lt;b&gt;1.	Access/authentication security&lt;/b&gt;
a.	Are there sufficient mechanisms and controls – including multiple firewalls, data encryption, and password protection – to help ensure critical information is highly secure yet still usable and shareable?
b.	Are the latest security standards used?

&lt;b&gt;2.	System (user, application, network) security&lt;/b&gt;
a.	Are secure standards used across the stack? Within the application and across the entire business scenario? From SSL at the transport layer to APIs at the application integration layer through the integrity of the app data within the app (multi-tenancy, multi-roles) to the integrity at the end point where the user accesses the app. 

&lt;b&gt;3.	Data security&lt;/b&gt;&lt;pre&gt;&lt;/pre&gt;
a.	Is the center running to the appropriate standards – ISO 9001, ISO 20000, and ISO 27001?
b.	Are there strict policies that meet SAS 70 Type II audit standards?
c.	Is personal data adequately secured – EU’s Data Protection Directive 95/46/EC?
d.	Does it meet federal compliance standards (e.g., HIPPA)?
e.     Is the data being backed and protected adequately?

&lt;b&gt;4.	Financial security&lt;/b&gt;
a.	Is the hosting provider financially viable? Will they be around tomorrow, when you need them?

&lt;b&gt;5.	Physical security&lt;/b&gt;
a.	Is the physical data center adequately protected? From miscreants, tsunamis, and other acts of man and God.
b.	Are people working in the facility adequately monitored? (e.g., 24x7x365 surveillance, including motion-sensing, closed-circuit monitoring and recording; licensed onsite security staff; and secure card reader plus 4-digit PIN access to raised floor areas)

Best
-prasad]]></description>
		<content:encoded><![CDATA[<p>Melanie, colleagues:</p>
<p>According to IDC, your concerns about data security are echoed by 48% of organizations that they surveyed!</p>
<p>As a prospect, looking to acquire and use a cloud-based SaaS solution, I might consider a framework that looks something like:<br />
<b>1.	Access/authentication security</b><br />
a.	Are there sufficient mechanisms and controls – including multiple firewalls, data encryption, and password protection – to help ensure critical information is highly secure yet still usable and shareable?<br />
b.	Are the latest security standards used?</p>
<p><b>2.	System (user, application, network) security</b><br />
a.	Are secure standards used across the stack? Within the application and across the entire business scenario? From SSL at the transport layer to APIs at the application integration layer through the integrity of the app data within the app (multi-tenancy, multi-roles) to the integrity at the end point where the user accesses the app. </p>
<p><b>3.	Data security</b>
<pre></pre>
<p>a.	Is the center running to the appropriate standards – ISO 9001, ISO 20000, and ISO 27001?<br />
b.	Are there strict policies that meet SAS 70 Type II audit standards?<br />
c.	Is personal data adequately secured – EU’s Data Protection Directive 95/46/EC?<br />
d.	Does it meet federal compliance standards (e.g., HIPPA)?<br />
e.     Is the data being backed and protected adequately?</p>
<p><b>4.	Financial security</b><br />
a.	Is the hosting provider financially viable? Will they be around tomorrow, when you need them?</p>
<p><b>5.	Physical security</b><br />
a.	Is the physical data center adequately protected? From miscreants, tsunamis, and other acts of man and God.<br />
b.	Are people working in the facility adequately monitored? (e.g., 24x7x365 surveillance, including motion-sensing, closed-circuit monitoring and recording; licensed onsite security staff; and secure card reader plus 4-digit PIN access to raised floor areas)</p>
<p>Best<br />
-prasad</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Selltest4pass</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/open-it-forum-what-are-your-cloud-security-concerns-for-2011/#comment-93564</link>
		<dc:creator>Selltest4pass</dc:creator>
		<pubDate>Thu, 23 Jun 2011 06:05:56 +0000</pubDate>
		<guid isPermaLink="false">#comment-93564</guid>
		<description><![CDATA[Test4pass: Leading the way in studying IT certifications. Best Practice, Guaranteed Certify!   It can help you pass you exams .you can search &quot;test4pass 000-152 &quot;by Google. http://www.test4pass.com/000-152-exam.html]]></description>
		<content:encoded><![CDATA[<p>Test4pass: Leading the way in studying IT certifications. Best Practice, Guaranteed Certify!   It can help you pass you exams .you can search &#8220;test4pass 000-152 &#8220;by Google. <a href="http://www.test4pass.com/000-152-exam.html" rel="nofollow">http://www.test4pass.com/000-152-exam.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cloud Security Wrap-Up - Enterprise IT Watch Blog</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/open-it-forum-what-are-your-cloud-security-concerns-for-2011/#comment-88788</link>
		<dc:creator>Cloud Security Wrap-Up - Enterprise IT Watch Blog</dc:creator>
		<pubDate>Mon, 28 Feb 2011 17:55:45 +0000</pubDate>
		<guid isPermaLink="false">#comment-88788</guid>
		<description><![CDATA[[...] What are your cloud security concerns for 2011?: Batye, MicroAcres, and Rechil expressed concern about understanding normal processes such as backups and security in relation to the new technology. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] What are your cloud security concerns for 2011?: Batye, MicroAcres, and Rechil expressed concern about understanding normal processes such as backups and security in relation to the new technology. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rechil</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/open-it-forum-what-are-your-cloud-security-concerns-for-2011/#comment-87416</link>
		<dc:creator>rechil</dc:creator>
		<pubDate>Wed, 02 Feb 2011 06:08:19 +0000</pubDate>
		<guid isPermaLink="false">#comment-87416</guid>
		<description><![CDATA[Of course this is a great topic that about concerns of the present cloud security scenario....

1. &lt;b&gt;Concern About Need for Better Access Control and Identity Management&lt;/b&gt;, there are some third parties exist that deliver some products and services that may address these issues
2. &lt;b&gt;Concern About Smart Phone Data Slinging&lt;/b&gt;, there might be chance for hacking of the cloud provider could provide mass access to confidential mobile device data when mobile users are using cloud-based mobile device support
3. &lt;b&gt;Concern About Ongoing Compliance Issues&lt;/b&gt; and always keep in mind it
4. &lt;b&gt;Concern About Risk of Multiple Cloud Tenants&lt;/b&gt;, which is the most cloud services make heavy use of virtualization technology, the risks associated with multiple organizations data housed on a single physical hypervisor platform exist
And the most I think, Concerns over Email Security in the Cloud !

Thanks--]]></description>
		<content:encoded><![CDATA[<p>Of course this is a great topic that about concerns of the present cloud security scenario&#8230;.</p>
<p>1. <b>Concern About Need for Better Access Control and Identity Management</b>, there are some third parties exist that deliver some products and services that may address these issues<br />
2. <b>Concern About Smart Phone Data Slinging</b>, there might be chance for hacking of the cloud provider could provide mass access to confidential mobile device data when mobile users are using cloud-based mobile device support<br />
3. <b>Concern About Ongoing Compliance Issues</b> and always keep in mind it<br />
4. <b>Concern About Risk of Multiple Cloud Tenants</b>, which is the most cloud services make heavy use of virtualization technology, the risks associated with multiple organizations data housed on a single physical hypervisor platform exist<br />
And the most I think, Concerns over Email Security in the Cloud !</p>
<p>Thanks&#8211;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: batye</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/open-it-forum-what-are-your-cloud-security-concerns-for-2011/#comment-87413</link>
		<dc:creator>batye</dc:creator>
		<pubDate>Wed, 02 Feb 2011 04:52:31 +0000</pubDate>
		<guid isPermaLink="false">#comment-87413</guid>
		<description><![CDATA[at the present time - I could be wrong but in higher educational institution this days - student never encourage by teachers to ask Why? and What?
if Co. could ask What is our security concerns and before looking for the security solution in the cloud  get clear scope of the problem and solution/resolution]]></description>
		<content:encoded><![CDATA[<p>at the present time &#8211; I could be wrong but in higher educational institution this days &#8211; student never encourage by teachers to ask Why? and What?<br />
if Co. could ask What is our security concerns and before looking for the security solution in the cloud  get clear scope of the problem and solution/resolution</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: microacres</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/open-it-forum-what-are-your-cloud-security-concerns-for-2011/#comment-87385</link>
		<dc:creator>microacres</dc:creator>
		<pubDate>Tue, 01 Feb 2011 20:08:22 +0000</pubDate>
		<guid isPermaLink="false">#comment-87385</guid>
		<description><![CDATA[I had a serious meltdown at small legal office client who was not able to monitor their tape backup processes sufficiently and got caught with no proper backup after a thorough and complete SBS 2003 server hard drive crash. (Mirror crashed, too) 
After a harrowing and expensive drive data recovery process, they decided to go with a Cloud solution for both Exchange and some applications (Timeslips, Wordperfect, MS Office) .

I have expressed my concern that they do not have a complete and recent backup copy of all of their business data on site at their offices, and that if the Internet goes down for any prolonged period, their business day is toast.

1. What good solution is there to having almost current copy of the applications data at their office? My suggestion to them was something like an NAS with Egnyte, which appears to solve the issue with a mirror in the cloud , while their working data is also local.

2. What are people doing for having a local copy of the Hosted Exchange data on hand locally? Just relying on the caced Exchange OST loca files for each user? Seems a bit didgy, at best.

Thanks]]></description>
		<content:encoded><![CDATA[<p>I had a serious meltdown at small legal office client who was not able to monitor their tape backup processes sufficiently and got caught with no proper backup after a thorough and complete SBS 2003 server hard drive crash. (Mirror crashed, too)<br />
After a harrowing and expensive drive data recovery process, they decided to go with a Cloud solution for both Exchange and some applications (Timeslips, Wordperfect, MS Office) .</p>
<p>I have expressed my concern that they do not have a complete and recent backup copy of all of their business data on site at their offices, and that if the Internet goes down for any prolonged period, their business day is toast.</p>
<p>1. What good solution is there to having almost current copy of the applications data at their office? My suggestion to them was something like an NAS with Egnyte, which appears to solve the issue with a mirror in the cloud , while their working data is also local.</p>
<p>2. What are people doing for having a local copy of the Hosted Exchange data on hand locally? Just relying on the caced Exchange OST loca files for each user? Seems a bit didgy, at best.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 6/8 queries in 0.012 seconds using memcached
Object Caching 353/354 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-06-20 12:43:30 -->