| By Reuven Cohen | Article Rating: |
|
| February 16, 2010 02:00 PM EST | Reads: |
3,700 |
Cloud Security Journal on Ulitzer
In the midst of the 1990's economic bubble, Alan Greenspan once famously referred to all the excitement in the market as Irrational exuberance. Similarly in today's cloud computing market a lot of the discussions seem to be driven by a new set of irrational expectations. The expectation by some that cloud computing will solve all man's problems and by others the expectation that cloud computing is inherently flawed. Flawed by an ended less list of problems most notably that of security. Like most things in life, the reality is probably somewhere in the middle. So I thought I'd take a closer look at the unrestrained pessimism and sometimes irrationality found in the cloud security discussions.
To understand security, you must first understand the psychology of how [cloud] security itself is marketed and bought. It's marketing based on fear, uncertainty and most certainly doubt (FUD). Fear that your data will be unwittingly exposed, uncertainty of who you can trust and doubt that there is any truly secure remote environments. At first glance these are all logical, rational concerns, hosting your data in someone else's environment means that you are giving away partial control and oversight to some third party. This is a fact. So in the most basic sense if you want to micro-manage your data, you'll never have a more secure environment than your own data center. Complete with bio-metric entry, gun toting guards and trust worthy employees. But I think we all know that "your own" data center also suffers from it's own issues. Is that guard with the gun actually trust worthy? (Among others)
Recently it occurred to me that the problem with cloud security is a cogitative one. In a typical enterprise development environment security is mostly an after thought, if a thought at all. The general consensus is it's behind our firewall, or our security team will look at it later, or it's just not my job. For all practical purposes most programmers just don't think about security. What's interesting about cloud computing is all the FUD that's been spread has had an interesting consequence, programmers are actually now thinking about security before they start to develop & deploy their cloud applications and cloud providers are going out of their way to provide increased security (Amazon's VPC for example). This is a major shift, pro-active security planning is something that as far I can tell has never really happened before. Security is typically viewed as a sunk cost (sunk costs are retrospective past costs which have already been incurred and cannot be recovered). But the new reality is that cloud computing is in a lot of ways more secure simply because people are actually spending time looking at the potential problems beforehand. Some call it foresight, I call it completely and totally rational.
Read the original blog entry...
Published February 16, 2010 Reads 3,700
Copyright © 2010 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Reuven Cohen
Reuven Cohen is Founder & CTO for Toronto based Enomaly Inc. - leading developer of Cloud Computing products and solutions focused on enterprise businesses. Enomaly's products include the Enomaly elastic computing platform, an open source cloud platform that enables a scalable enterprise IT and local cloud infrastructure platform. Cohen is a thought leader in the emerging cloud computing industry and maintains a blog at www.elasticvapor.com.
Reuven is also founder of several technology organizations;
Enomaly.com - Elastic Computing Platform (Cloud Computing),
Cloud Camp - Local Cloud Computing events,
the Unified Cloud Interface Project - Semantic Cloud Abstraction API
Cloud Interoperability Forum - Cloud Standards Group.
(twitter @ruv : Linkedin : RSS Feed)
- Microsoft’s Second UI Innovation
- What Motivates Open Standards in the Cloud?
- StorSimple Supports OpenStack
- What to Expect in 2012: Cloud Computing and Open Source Software
- Ten Hot Trends in Cloud Data for 2012
- HP Expands Its HANA Alliance with SAP
- Write Once Run Anywhere or Cross Platform Mobile Development Tools
- End-User Participation to Provide Unique Forum for Peer Collaboration at 2012 Technology Convergence Conference
- Three Buzzwords That Every CIO Hears but One They Should Listen To
- Microsoft’s New Cloudware Could Cast a Shadow over VMware
- Cloud Expo New York: Cloud Architectures Require Scale-out Storage
- AT&T Joins OpenStack, Floats Cloud Architect
- The Future of Cloud Computing: Industry Predictions for 2012
- HP Puts Activist Shareholder on Board
- Gartner Hype Cycle for Emerging Technologies 2011
- Microsoft’s Second UI Innovation
- Cloud Computing: A Comparison of Computing Models
- What Motivates Open Standards in the Cloud?
- Big Data Bug Bites GE
- StorSimple Supports OpenStack
- What to Expect in 2012: Cloud Computing and Open Source Software
- Apprenda Upgrades Its .NET Private PaaS
- Ten Hot Trends in Cloud Data for 2012
- Cloud Expo Takeaways: Cloud Confusion Still Exists
- The Top 150 Players in Cloud Computing
- Where Are RIA Technologies Headed in 2008?
- FullArmor GPAnywhere Secures Microsoft Application Virtualization Applications Through Group Policy
- SYS-CON's Virtualization Conference & Expo: Themes & Topics
- SYS-CON's Virtualization Journal Opens Its "Readers' Choice Awards" Nominations
- Application Virtualization: Instant Migration to Vista, Fast Delivery, Secure Access, Side-by-Side Deployments
- "Virtualization Is Now a Key Strategic Theme," Says Citrix CTO
- Application Virtualization
- Integration with Windows Vista, Microsoft Excel, and Microsoft Application Virtualization
- Will Microsoft Buy Citrix?
- mValent Extends Automated Application Configuration Management to Virtualization Environments
- Has the Technology Bounceback Begun?





















