Feeds

Easier to secure the cloud than your data center - IBMer

Really?

Securing Web Applications Made Simple and Scalable

To summarise, a rant

Risk and responsibility are the big issues here. A corporation hosting its important data retains control over security and the risks it is willing to take. If it screws up, it pays the price for it. In a cloud scenario, this isn’t the case. With most cloud providers, a security breach or provider screw-up will yield a heartfelt apology and a refund of the current month’s fee – and no more.

When we’re talking about important applications and data, the risk imbalance between the customer and cloud provider is massive. If there is a security failure or loss of data, you, the customer, could conceivably be put out of business. The cloud provider? They risk some reputation points and lost revenue – but they probably have plenty of other customers, or at least can get some more.

And you? You’ll be on the street living in a cardboard box and eating out of dumpsters until you finally die of exposure. Or, after being found guilty of criminal mismanagement of data, you’ll be thrown in prison and get shanked during a mess hall riot. Okay, maybe it won’t result in death … but having your business go down the tubes due to a cloud problem would be plenty uncomfortable.

Cloud providers have to put real skin in the game and provide explicit and specific guarantees on security and availability to convince enterprises that this is a valid choice for critical processing. SLAs will have to be negotiated and agreed upon, with penalties and remedies stipulated up-front.

To make this worthwhile, the cloud provider must have at least a minimum usage commitment from the customer that covers the provider’s costs. The cloudy ‘pay only for what you use, as you use it’ model is a non-starter in this context.

To conclude, a truly secure cloud offering isn’t really a cloud at all, in my opinion. It’s really a traditional hosting or outsource agreement. And those have been around for a long, long time. They aren’t trendy, hip, or cool, and in a lot of cases they end up costing more than providing the same functions in-house.

IBM, of course, is a leading provider of outsourcing and is also a cloud provider, so they have more than a little interest in getting enterprise customers to embrace clouds. [end rant]

The last line in the IBM blog asks, “Is Moss right? Or is this a bunch of self-serving IBM marketing spin?”

I weigh in on the side of “Self-serving IBM marketing spin.” But what do you think? Use the comments section below to share your own thoughts or rants. ®

The Essential Guide to IT Transformation

More from The Register

next story
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
EU's top data cops to meet Google, Microsoft et al over 'right to be forgotten'
Plan to hammer out 'coherent' guidelines. Good luck chaps!
US judge: YES, cops or feds so can slurp an ENTIRE Gmail account
Crooks don't have folders labelled 'drug records', opines NY beak
FLAPE – the next BIG THING in storage
Find cold data with flash, transmit it from tape
Seagate chances ARM with NAS boxes for the SOHO crowd
There's an Atom-powered offering, too
Gartner: To the right, to the right – biz sync firms who've won in a box to the right...
Magic quadrant: Top marks for, er, completeness of vision, EMC
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Mobile application security vulnerability report
The alarming realities regarding the sheer number of applications vulnerable to attack, and the most common and easily addressable vulnerability errors.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.