Skip to main content

Posts

Showing posts with the label CSA

Virtualization is not Cloud Computing

Recently Forrester stated that 70% of "private clouds" aren't really clouds at all http://www.networkworld.com/news/2013/022613-forrester-private-clouds-267108.html Therein lies a tale of deceit, misinformation and false gratification of many organizations believing they have a cloud in place.  To get the facts right we need to revisit the definition of cloud computing as defined by NIST which in may opinion is the final authority on cloud computing standards and is followed by the industry and professionals.  http://csrc.nist.gov/publications/nistpubs/800-145/SP800-145.pdf Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared  pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that  can be rapidly provisioned and released with minimal management effort or service provider interaction.  This cloud model is composed of five essential characte...

CISO will be the future CEO in a Cloud Enabled World

Last week I had an opportunity to address some of the finest CISO's in India about the Cloud Security Alliance and Securing Cloud Computing . Interacting with these CISO's convinced me that they have the potential to be future CEO's as Business is adopts Cloud Computing for agility and economics. As business moves to the cloud for  computing  IT GRC will be a key driver for acceptance of Cloud Computing. The CISO will be like a large tree protecting the organization from vulnerabilities and ensuring  business continuity in the Cloud. CISO is like a large tree providing protection . The Wikipedia defines the Influence of the CISO. Typically, the CISO's influence reaches the whole organization. Responsibilities include: Information security  and  information assurance Information  regulatory compliance  (e.g., US  PCI DSS ,  FISMA ,  GLBA ,  HIPAA ; UK  Data Protection Act 1998 ; Canada  PIPEDA ) In...