"Cloud" security is not a myth five source strict control

Source: Internet
Author: User
Keywords Security Microsoft data Center
While Google, Amazon and Salesforce have attracted a lot of "eyeballs" as cloud service providers, Microsoft now has more than 300 products and services for data centers, which can be said to have autonomous large "cloud banks."

This May, Microsoft also issued a document stating that it would provide cloud services and planned how to secure cloud services. The document, issued by Microsoft's global infrastructure for software services infrastructure, describes the dangers of current online services, including the growing interdependence between service providers and customers, and more sophisticated Internet attacks.

Microsoft believes its security solution, which started in 2002 on "Trustworthy Computing", is still valid for online services but needs to be modified to address the current situation.

"If I adopt a traditional security specification, it doesn't change in rules and methods," he said. "It's just that we've expanded the scope of security controls," said Charliemcnerney, senior manager of Microsoft's business risk management. ”

In a recent interview, McNerney and other cloud service providers shared Microsoft's ideas about cloud services and the power supply of data centers.

1. We should discuss the risks of cloud services with customers to dispel the concerns of many customers, McNerney said. The key point of communication is to clarify the customer data security aspects of their respective responsibilities and what responsibilities to perform.

"Where is the flaw when business is interrupted in a cloud service environment?" What responsibilities should be assumed by all parties? Such problems are now being talked about most in large enterprises. "McNerney said.

Microsoft also found that the biggest worry for customers is not just security. Websites and emails are important components of any company's brand and need to be protected as well. "I find that no enterprise can ignore it. "Those small businesses that operate through the Internet have the same security needs as big businesses," McNerney said. ”

2, attention to try to reduce customer concerns. Microsoft has invested a lot of time in organizing the necessary controls to meet the requirements of various standards.

Microsoft has cut 26 different types of audits in 200 of the necessary control lists, and has developed a comprehensive data center environment and services control. Standardization means that Microsoft does not have to open the company's data center entrance to every customer or auditor.

"Large business users want to understand their control, but how many companies can I get into the data center?" "McNerney said. "If you think about what you can do, I can't actually get all the customers into our equipment," he said. ”

As an alternative, Microsoft has developed a regulatory framework that customers need to comply with, allowing auditors to enter test menus and return results. "Every company will want to know the test process and the results. "This is our opportunity and challenge," McNerney said. ”

3, to develop better standards, better customer service, large cloud suppliers need to work together to make their platform standardized, McNerney said.

"Amazon has a standard, Yahoo has a standard, Google also has a standard." "But our standards are different," McNerney said. Next, we have to come up with a framework for cooperation and then build a cross-platform product on the Internet based on this framework. ”

For example, an enterprise needs to achieve a unified approach to global identity identification. At present, the problem of multiple identities on the internet has not been developed from a standard point of view, McNerney said. "Customers want cloud computing to be their interoperability environment." ”

4. Privacy and security are not as significant as Microsoft's cloud computing application model and its services and data centers. Microsoft sees little difference in the security and privacy of cloud computing. McNerney said.

The results are a bit surprising, McNerney says, because Microsoft has developed tools for managing security and privacy, and there is no particularly striking distinction between them. "Most people's approach is one way to protect privacy, another way to protect security." "But in the field of cloud computing, it's more rational and scientific in a hybrid way," McNerney said. ”

5. Please do not link cloud security with the Windowsazure platform that is about to be launched this fall, Microsoft will have a series of new considerations. Jaychaudhry, chief executive of Zscaler, the Internet Security Service provider, said.

Chaudhry that the security considerations for each cloud service are different. Better controls are available for Office applications, e-mail services, and access to databases, but other services, such as Exchange servers, require a lot of setup and security is more difficult to guarantee.

The

Enterprise needs specific areas for specific consideration and proper resolution. "There is no way to solve all the security problems in the cloud computing world," Chaudhry said. "Database services, storage services, and risk assessment services have different security considerations, and the upcoming Windowsazure platform service may do better in terms of security," Chaudhry said.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.