Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Not Enough Attention to Application Security | Main | Rethinking Cybersecurity Strategies »

Unfair and Deceptive Practices in the Cloud

The world of cloud computing is running with few generally accepted rules. It's a one-cloud-provider-one-privacy-policy business right now. One researcher thinks "swamp" is a better term than cloud. I've argued the cloud makes sense in some cases and not others, it's a matter of balancing benefits and risks. To do that though we need to be informed about the risks and that's the hard part. Bruce Schneier gives a good example.

In a recent post he sees cloud providers taking too little responsibility for the data entrusted to them:

Take Google, for example. Last month, the Electronic Privacy Information Center (I'm on its board of directors) filed a complaint with the Federal Trade Commission concerning Google's cloud computing services. On its website, Google repeatedly assures customers that their data is secure and private, while published vulnerabilities demonstrate that it is not. Google's not foolish, though; its Terms of Service explicitly disavow any warranty or any liability for harm that might result from Google's negligence, recklessness, malevolent intent, or even purposeful disregard of existing legal obligations to protect the privacy and security of user data. EPIC claims that's deceptive.

Good governance policy advocates often argue for transparency in business so investors can make informed, rational decisions. We need the same in the software as a service business. Cloud providers are undermining their own business model with irresponsible practices. Some cloud provider will realize that, offer reasonable protections and put the sloppy ones out of business, or at least relegate them to the level of $2 a month Web host segment of the market.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/1033

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net