<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Paul Miller - The Cloud of Data &#187; Ace Swerling</title>
	<atom:link href="http://cloudofdata.com/tag/ace-swerling/feed/" rel="self" type="application/rss+xml" />
	<link>http://cloudofdata.com</link>
	<description>Linked Data, Cloud Computing, Semantic Web, SaaS, PaaS, more</description>
	<lastBuildDate>Thu, 17 May 2012 15:04:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<copyright>Licensed under the Creative Commons Attribution License, version 3.0 http://creativecommons.org/licenses/by/3.0/</copyright>
	<managingEditor>paul.miller@cloudofdata.com (Paul Miller)</managingEditor>
	<webMaster>paul.miller@cloudofdata.com (Paul Miller)</webMaster>
	<ttl>1440</ttl>
	<image>
		<url>http://cloudofdata.com/logo144x144.jpg</url>
		<title>Paul Miller - The Cloud of Data</title>
		<link>http://cloudofdata.com</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle>conversations with the executives shaping Cloud Computing and the Semantic Web.</itunes:subtitle>
	<itunes:summary>Linked Data, Cloud Computing, Semantic Web, SaaS, PaaS, more</itunes:summary>
	<itunes:keywords>Cloud Computing, Semantic Web, Linked Data, Open Data, SaaS, PaaS</itunes:keywords>
	<itunes:category text="Technology" />
	<itunes:category text="Business" />
	<itunes:author>Paul Miller</itunes:author>
	<itunes:owner>
		<itunes:name>Paul Miller</itunes:name>
		<itunes:email>paul.miller@cloudofdata.com</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://cloudofdata.com/logo300x300.jpg" />
		<item>
		<title>Security and the Cloud; will focus shift to the customer?</title>
		<link>http://cloudofdata.com/2009/08/security-and-the-cloud-will-focus-shift-to-the-customer/</link>
		<comments>http://cloudofdata.com/2009/08/security-and-the-cloud-will-focus-shift-to-the-customer/#comments</comments>
		<pubDate>Fri, 14 Aug 2009 16:52:36 +0000</pubDate>
		<dc:creator>Paul Miller</dc:creator>
				<category><![CDATA[Cloud computing]]></category>
		<category><![CDATA[Enterprise Computing]]></category>
		<category><![CDATA[Ace Swerling]]></category>
		<category><![CDATA[Avanade]]></category>
		<category><![CDATA[Identity management]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cloudofdata.com/?p=765</guid>
		<description><![CDATA[Image via Wikipedia I was talking with Avanade&#8216;s Senior Director for Enterprise Security, Ace Swerling, earlier today. The conversation touched on a wide range of security and identity management issues that I&#8217;ll probably return to, but one of Ace&#8217;s comments brought my attention back to an issue that has been nagging at me for a [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Paris_servers_DSC00190.jpg"><img title="An example of &quot;rack mounted&quot; servers." src="http://upload.wikimedia.org/wikipedia/commons/thumb/0/04/Paris_servers_DSC00190.jpg/300px-Paris_servers_DSC00190.jpg" alt="An example of &quot;rack mounted&quot; servers." width="300" height="225" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Paris_servers_DSC00190.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>I was talking with <a class="zem_slink freebase/guid/9202a8c04000641f80000000009210a6" title="Avanade" rel="homepage" href="http://www.avanade.com">Avanade</a>&#8216;s Senior Director for Enterprise Security, Ace Swerling, earlier today. The conversation touched on a wide range of security and identity management issues that I&#8217;ll probably return to, but one of Ace&#8217;s comments brought my attention back to an issue that has been nagging at me for a while.</p>
<p>As I&#8217;m sure we all know, security concerns often figure highly in discussions about moving Enterprise applications and data to the Cloud. Indeed, <a href="http://cloudofdata.com/2009/02/security-reason-or-excuse/">I spoke with other Avanade executives earlier this year</a> to report on a survey they had commissioned that suggested just how significant these concerns can be for potential customers.</p>
<p>In today&#8217;s conversation, Ace appeared to agree (as do I) with the frequent assertion that Cloud providers&#8217; own systems will tend to be <em>more</em> secure than those that the majority of potential customers have in-house today. These service providers have their entire reputation riding on their security, it&#8217;s absolutely core to their business model, and they can invest in the facilities, procedures and people to get it right. They&#8217;re not claiming to be invincible; nothing is. But the good ones should certainly be capable of being as secure as anything else connected to a network.</p>
<p>Which brings me to the &#8216;problem;&#8217; a data centre like the one in the video below can be physically and virtually secure, equipped with the best hardware, software, procedures and brains that money can buy.</p>
<p style="text-align: center;"><a href="http://channelsun.sun.com/video/tour+the+sun+cloud+datacenter+at+supernap/24586081001" class="broken_link"><img class="size-full wp-image-767 aligncenter" title="supernap" src="http://cloudofdata.com/wp-content/uploads/2009/08/supernap.png" alt="Video of Sun's SuperNAP data centre in Las Vegas" /></a></p>
<p>And then you ruin it by letting the customers in.</p>
<p>The customers who open up all the ports you so carefully closed by default. The customers who use &#8216;password&#8217; as their password. The customers who deploy sloppy code that&#8217;s riddled with holes. The customers who, frankly, are just human&#8230; and who don&#8217;t live and breathe security in the same way that at least <em>someone</em> inside the data centre probably does.</p>
<p>There are plenty of checks, balances and procedures in place to ensure that the idiocy of customer A cannot impact upon the services used by customers B, C, and Z, but what can the data centre do to protect customer A from themselves once they start over-riding default settings and policies?</p>
<p>Maybe, you might say, we should leave customer A to their own devices? If they <em>want</em> to open themselves up to hackers then let them.</p>
<p>The problem, of course, is that Cloud Computing is still pretty new. There are plenty of critics and pundits itching to break the news that &#8220;Sun&#8217;s Cloud,&#8221; &#8220;Amazon&#8217;s Cloud,&#8221; &#8220;Microsoft&#8217;s Cloud,&#8221; or &#8220;Google&#8217;s Cloud&#8221; is clearly not to be trusted because some customer of that Cloud got hacked. It wouldn&#8217;t be news if some small startup no one has ever heard of was hacked. It most certainly <em>would</em> be if they were hosted on EC2, unfair as that might seem.</p>
<p>&#8220;Amazon Cloud insecure,&#8221; the headlines would scream. Werner Vogels could argue <em>forever</em> that the customer ignored safeguards and contravened best practice, but who would be listening? The stock would tank, IBM and VMware would subtly massage their marketing collateral to emphasise their on-premise innovations and downplay the new-fangled Cloud stuff they&#8217;ve been talking about in recent months.</p>
<p>So, I wonder, which will be the first big Cloud provider to turn the tables on the customer? Sure, Cloud providers will still be measured on how secure <em>they</em> are&#8230; but maybe they&#8217;ll start asking questions about how secure their potential <em>customers</em> are, before letting them in the door. Health metaphors might be used, arguing that those without the necessary immunisations and vaccinations put innocent third parties at risk. In talking it through with Ace he suggested a motoring metaphor, pointing out that manufacturer and dealer warranties are void if the customer doesn&#8217;t do their part in ensuring that the car is properly maintained and regularly serviced.</p>
<p>It could actually be quite an easy proposition to sell to many current and potential customers; and maybe you could even provide discounts to those who scored highly in some notional assessment of their securedness.</p>
<p>What would such a relationship between customer and provider look like, would it divert the heat from the service provider when things beyond their control <em>do</em> go wrong, and who is going to make this move first?</p>
<p>Maybe, as the Cloud gets big enough to be <em>serious</em> business, the days of simply letting anyone with a credit card into the data centre are numbered?</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.readwriteweb.com/archives/the_cloud_isnt_safe_or_did_blackhat_just_scare_us.php">The Cloud Isn&#8217;t Safe?! (Or Did Black Hat Just Scare Us?)</a> (readwriteweb.com)</li>
<li class="zemanta-article-ul-li"><a href="http://java.sys-con.com/node/956212">The Three Biggest Tech Barriers to Cloud Computing</a> (java.sys-con.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.businessweek.com/the_thread/techbeat/archives/2009/06/microsofts_ozzi.html">Microsoft&#8217;s Ozzie Says Cloud Services Will Yield Lower Margins</a> (businessweek.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/s/article/9135778/The_tech_jobs_that_the_cloud_will_eliminate?source=rss_careers">The tech jobs that the cloud will eliminate</a> (computerworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.cloudave.com/link/saas-vendors-target-enterprises-using-private-clouds">SaaS Vendors Target Enterprises Using Private Clouds</a> (cloudave.com)</li>
<li class="zemanta-article-ul-li"><a href="http://news.zdnet.com/2100-9595_22-326544.html">Novell aims to tighten cloud security</a> (news.zdnet.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.techcrunchit.com/2009/08/05/unisys-looks-to-safely-move-business-apps-to-the-cloud/">Unisys Looks to Safely Move Business Apps to the Cloud</a> (techcrunchit.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.elasticvapor.com/2009/04/security-guidance-for-critical-areas-of.html">Security Guidance for Critical Areas of Cloud Computing</a> (elasticvapor.com)</li>
<li class="zemanta-article-ul-li"><a href="http://news.zdnet.com/2100-9595_22-328004.html">Shaking that false sense of (IT) security</a> (news.zdnet.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/ab33a2e1-9dc4-457b-8dd9-67e89392e481/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=ab33a2e1-9dc4-457b-8dd9-67e89392e481" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-info pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
<div class="al2fb_like_button"><div id="fb-root"></div><script type="text/javascript">
(function(d, s, id) {
  var js, fjs = d.getElementsByTagName(s)[0];
  if (d.getElementById(id)) return;
  js = d.createElement(s); js.id = id;
  js.src = "//connect.facebook.net/en_US/all.js#xfbml=1&appId=133647763430045";
  fjs.parentNode.insertBefore(js, fjs);
}(document, "script", "facebook-jssdk"));
</script>
<fb:like href="http://cloudofdata.com/2009/08/security-and-the-cloud-will-focus-shift-to-the-customer/" layout="standard" show_faces="true" width="450" action="like" font="arial" colorscheme="light" ref="AL2FB"></fb:like></div>]]></content:encoded>
			<wfw:commentRss>http://cloudofdata.com/2009/08/security-and-the-cloud-will-focus-shift-to-the-customer/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

