Cloud Computing Search

Cloud Security Alliance


The Cloud Security Alliance (CSA) is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. It's Mission is " To promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing" .

History

The issues and opportunities of cloud computing gained considerable notice in 2008 within the information security community. At the ISSA CISO Forum in Las Vegas, in November of 2008, the concept of the Cloud Security Alliance was born. Following a presentation of emerging trends by Jim Reavis that included a call for action for securing cloud computing, Reavis and Nils Puhlmann outlined the initial mission and strategy of the CSA. A series of organizational meetings with industry leaders in early December 2008 formalized the founding of the CSA. Our outreach to the information security community to create our initial work product for the 2009 RSA Conference resulted in dozens of volunteers to research, author, edit and review our first whitepaper. For more details and regular update see here.

Building a Private Cloud



PCI DSS Cloud Computing Guidelines


The PCI Security Standardscouncil is an open global firm that is responsible for the development, management, education, and an awareness of the PCI Data Security Standard (PCI DS) and other standards that increase payment data security. It has issued PCI DSS Cloud Computing Guidelines that govern payment transactions in cloud environments.

Cloud computing is a form of distributed computing that is yet to be standardized. There are number of factors to be considered when migrating to cloud services, and organizations need to clearly understand their needs before they can determine if and how they will be met by a particular solution or provider. As cloud computing is still an evolving technology, evaluations of risks and benefits may change as the technology becomes more established and its implications become better understood.



Cloud security is a shared responsibility between the cloud service provider (CSP) and its clients. If payment card data stored, processed or transmitted in a cloud environment, PCI DSS will apply to that environment, and will typically involve validation of both the CSP’s infrastructure and the client’s usage of that environment. The allocation of responsibility between client and the provider for managing security controls does not exempt a client from the responsibility of ensuring that their cardholder data is properly secured according to applicable PCD DSS requirements.

PCI DSS Cloud Computing Guidelines provides guidance on the use of cloud technologies and considerations for maintaining PCI DSS controls in cloud environment. This guidance builds on that provided in the PCI DSS Virtualization Guidelines and is intended for organizations using , or thinking of using, providing , or assessing cloud technologies as part of a cardholder data environment ( CDE)  

Ferris from Cloud Sherpas to help Google App Engine Developers

Cloud Sherpas, a company that helps businesses implement cloud computing services, released Thursday an open source Python framework to simplify custom app development on Google App Engine. But in 2011, the company was losing custom app development opportunities presented by its enterprise clients because there were too few tools available to accelerate Google App Engine projects. The absence of a mature tool ecosystem for App Engine meant that custom apps tended to take longer and cost more than clients would accept. 

The result was Ferris, a Python framework for accelerating Google App Engine development. Named in honor of the work-avoiding protagonist of the 1986 film Ferris Bueller's Day Off, Ferris aspires to make life easier for App Engine developers.
"What Ferris does is it provides an application framework that prevents the developer from having to do a lot of the redundant work to wire [application components] together," said Lockyear.
Lockyear said that while Google Apps provides users with collaboration and content creation tools, it doesn't include workflow or business process applications, which tend to be different for every organization. And according to Lockyear, one of the first things Google Apps customers want to do is extend the environment to meet specific workflow and business process needs. As an example, he pointed to an HR issue-tracking system created for one client. For complete details see here

Cloud Computing makes World Brain Vision Practical


Power and potential of connected world and cloud computing is immense. Today cloud computing has made the World Brain concept practically possible and functional. World Brain is a collection of essays and addresses the English science fiction pioneer, social reformer, evolutionary biologist and historian H. G. Wells written during the period 1936-38. Throughout the book, Wells describes his vision of the world brain: a new, free, synthetic, authoritative, permanent "World Encyclopaedia" that could help world citizens make the best use of universal information resources and make the best contribution to world peace.



In practical terms what cloud computing has made possible is that active brains around world with their thinking and knowledge are available and accessible to rest of the world. They are just a click way, always ready to share and willing to co-operate and collaborate. 
Today the cloud computing resources are so abundant in scope and size that, it is impossible to think of a "need" or "requirement" that is not already thought. Not only that someone one has already thought it out, but also already shared with rest of the world. Thus cloud computing has become a resource superior. 

An illustration
Sometime back, I thought of publishing my post in two or more languages. A simple search lead me to a source  that has not only found a way to publish a blog in two languages and but also ready to share it. Later refined searches led to another programmable resource and which can help you translate into many languages.  Here is the result where you can read my blogs in a number of languages.  That's I call cloud computing a "world brain" waiting for extending help to anyone seeking for it .  


Top Ten Industries Hiring Cloud Computing Professionals in positions paying $100K or more

Cloud Computing And Banking Security

Financial institutions need to approach cloud computing the same way they approach most ventures; with an eye on security. When planning due diligence for a cloud computing vendor, banks need to consider the following:
  • Information Security
  • Audits
  • Legal & Regulatory compliance
  • Business Continuity



Large banks may have the ability to build their own virtual cloud while smaller institutions may either avoid the cloud altogether or outsource smaller parts of their business. Big or small, the lack of standards is a challenge for financial institutions trying to decide how to approach entering the cloud in a safe and prudent manner. Bank Systems Technology recently published a document, "Is the Cloud Safe" which you can download here.  The National Institute of Standards and Technology has also issued a set of cloud computing guidelines. Here are more details 

One more related resource on cloud computing and banking security is here



 

blogger templates 3 columns | Make Money Online