phpbb and sql errors asp sqlserver odbc sql errors

Today´s Diary

If you have more information or corrections regarding our diary, click here to contact us.

Published: 2009-11-29,
Last Updated: 2009-11-29 18:07:55 UTC
by Patrick Nolan (Version: 1)
0 comment(s) Facebookacebook witter

There are times, like over a long US Holiday weekend leading up to your Handler duty shift, you get the "opportunity" to catch up with information security issues of the day and run into some great work that warrants mention for any number of reasons. And over this weekend I had the "opportunity" to look a bit deeper into Cloud Computing information security. Some exceptional work I ran into while perusing the cloudscape included the two following efforts, and both provide extensive citations and links.

  • The "Security Guidance for Critical Areas of Focus in Cloud Computing", prepared by the Cloud Security Alliance (CSA), a group certainly fulfilling their mission statement. In their guidance executive summary they mention that every "attempt has been made to focus on areas of concern that are either unique to cloud computing, or are greatly exacerbated by the model". They certainly achieved the focus they wanted. An example of that focus, in the executive summary section on compliance and audit, is when they reference the "scope" of various attestations of security, when they note that "It is critical to examine the scope of SAS 70 Type II audits and ISO 27001 certifications" and later in the guidance state "Provider site certifications such as SAS 70, WebTrust® and SysTrust®, Service Capability & Performance (SCP) or ISO27001 can be directed as desired by the provider and are a point in time certification if there is any such certification". The CSA guidance is also quite focused elsewhere .

You can read about participating (or collaborating) here - Cloud Security Alliance Membership

  • The European Network and Information Security Agency (ENISA), an EU agency, "risks assessment on cloud computing business model and technologies". This is an "in-depth and independent analysis that outlines some of the information security benefits and key security risks of cloud computing". The report also provides "a set of practical recommendations". In-Depth indeed, see  - "Cloud Computing Benefits, risks and recommendations for information security".

Between now and my next Handler shift/Diary at the end of December, I'm sure there will be other weekend "opportunities" to pursue related work. I hope to present some information from Josh Corman of the451group on a developing cloud computing information security "reference" architecture extension that has utility for working through cloud information security issues in your environment.

0 comment(s) Facebookacebook witter

If you have more information or corrections regarding our diary, click here to contact us.

Diary Archive

DateAuthorTitle
2009-11-29Patrick Nolan A Cloudy Weekend
2009-11-26Tony Carothers What Are You Thankful For?
2009-11-26Tony Carothers Microsoft Security Advisory (977981)
2009-11-25Jim Clausing Tool updates
2009-11-25Jim Clausing Microsoft Updates requiring reboot
2009-11-25Jim Clausing Updates to my GREM Gold scripts and a new script
2009-11-24Rick Wanner Microsoft Security Advisory 977981 - IE 6 and IE 7
2009-11-24John Bambenek BIND Security Advisory (DNSSEC only)
2009-11-23John Bambenek Government Approaches to Cybersecurity - What are your tips?
2009-11-23Scott Fendley New Nmap Beta Released
Complete Archive
Search Diaries:

StormCast


last update 10 hrs 25 min ago.

Featured Event

Latest Reading Room Papers

Gathering Security Metrics and Reaping the Rewards
Hey Dude! I Can Do a Great Humphrey Bogart!
A Multi-Perspective View of PHP Remote File Include Attacks
Check Point Firewall Log Analysis In-Depth
Efficiently Deducing IDS False Positives Using System Profiling

Poll

I back up data on my home PCs...
daily, or whenever files change or get added
once a week
once a month
every now and then
other (please leave comment)

Trends

trends more details

World Map

Worldmap