Welcome!

Ruby-On-Rails Authors: Liz McMillan, Pat Romanski, Elizabeth White, Hovhannes Avoyan, Yeshim Deniz

Related Topics: @CloudExpo, Release Management , Ruby-On-Rails, Apache, Cloud Security

@CloudExpo: Blog Post

Cloud Computing Security Issues and Challenges By @GiladPN | @CloudExpo [#Cloud]

Digital data theft is more prevalent than physical theft

The US Federal Communications Commission has recently reported that "theft of digital information has become the most commonly reported fraud, surpassing physical theft." Businesses can do a lot to protect themselves. The FCC issued a Tip Sheet for small businesses to promote employee security training, firewalls, securing of WiFis, and more. But for business operating in (or migrating to) cloud environments; data security, cloud computing security issues, and challenges take on  new meanings and require new strategies.

Security in the Cloud: Unique Challenges
In the cloud, data security poses new risks and challenges. We are no longer concerned just with burglars breaking into our offices to steal computers, but rather with the data belonging to complete systems deployed to the cloud.

Security in the cloud cloud security issues Cloud Security Cloud Encryption cloud computing security issues and challenges  cloud computing security issues and challenges Cloud Computing Security Issues and Challenges:  Digital data theft is more prevalent than physical theft

When using public cloud infrastructure like that of AWS, VMware, Microsoft Azure, or HP Helion, we also have little fear of "bad guys" breaking into their datacenters. These large providers take access controls and infrastructure security very seriously.

Instead, security in the cloud becomes not about protecting our hardware, but rather protecting the sensitive information regardless of its physical location. For this, burglar alarms are irrelevant and firewalls are only one part of the approach for security in the cloud.

A way to visualize the unique challenges of data security in the cloud is that where before we had brick walls and steel locks to keep us safe; we now must construct mathematical walls as barriers to our data.

An important aspect in cloud security is cloud encryption. By properly encrypting the data we store in the cloud, we ensure that even if our security perimeter is breached, our data is rendered unreadable, unusable, and unsellable.

But, as it turns out, cloud encryption in and of itself is also not enough. Companies have encrypted well, using best-in-class algorithms to protect their business data, and still been compromised. The important piece is the encryption key. When businesses store the key to decrypt their data in the cloud, alongside the encrypted data itself, they make it easy for a hacker to use the same access point used to get the data to then get the key to decrypt it. In other examples, companies have entrusted their encryption keys to their cloud provider: the cloud provider essentially owns the sensitive data in this situation. The best practice must be different.

Security in the Cloud: Unique Solutions
The cloud has posed interesting obstacles to data security. And, as it turns out, the cloud has also brought forth even more interesting solutions.

In our new software-defined existence, the solution to cloud challenges resides in software built for the cloud.

For example, a pair of new technologies known as split key encryption and homomorphic key management have reinvented the way cloud encryption keys are handled; thus solving the issue of cloud key management.

By splitting encryption keys into two (or more) parts, this software-defined approach mimics the successful security of Swiss banks, where the account owner holds one key, the banker holds one key, and both keys are required to access the contents. Split key encryption is the first of two important cloud advancements toward total security in the cloud.

The next advancement is homomorphic key management, which is also a software-defined, cloud approach. With it, the encryption keys themselves are encrypted. This way, even while the key is being used in the cloud, it is never in unencrypted form, never to be seen "bare" by hackers, and renders the data it protects totally inaccessible to anyone but the data owner.

Security in the Cloud to Protect Privacy and Achieve Compliance
It is not just businesses themselves that have been concerned with data security in the cloud. Regulatory bodies in many industries view cloud security has a major concern and have amended their regulations to match. The approaches of split key encryption and homomorphic key management help businesses protect the privacy of their customers while also enable them to achieve compliance with HIPAA, PCI, and other regulations.

The post Cloud Computing Security Issues and Challenges: Digital data theft is more prevalent than physical theft appeared first on Porticor Cloud Security.

Read the original blog entry...

More Stories By Gilad Parann-Nissany

Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.

IoT & Smart Cities Stories
Tapping into blockchain revolution early enough translates into a substantial business competitiveness advantage. Codete comprehensively develops custom, blockchain-based business solutions, founded on the most advanced cryptographic innovations, and striking a balance point between complexity of the technologies used in quickly-changing stack building, business impact, and cost-effectiveness. Codete researches and provides business consultancy in the field of single most thrilling innovative te...
Atmosera delivers modern cloud services that maximize the advantages of cloud-based infrastructures. Offering private, hybrid, and public cloud solutions, Atmosera works closely with customers to engineer, deploy, and operate cloud architectures with advanced services that deliver strategic business outcomes. Atmosera's expertise simplifies the process of cloud transformation and our 20+ years of experience managing complex IT environments provides our customers with the confidence and trust tha...
With the introduction of IoT and Smart Living in every aspect of our lives, one question has become relevant: What are the security implications? To answer this, first we have to look and explore the security models of the technologies that IoT is founded upon. In his session at @ThingsExpo, Nevi Kaja, a Research Engineer at Ford Motor Company, discussed some of the security challenges of the IoT infrastructure and related how these aspects impact Smart Living. The material was delivered interac...
Intel is an American multinational corporation and technology company headquartered in Santa Clara, California, in the Silicon Valley. It is the world's second largest and second highest valued semiconductor chip maker based on revenue after being overtaken by Samsung, and is the inventor of the x86 series of microprocessors, the processors found in most personal computers (PCs). Intel supplies processors for computer system manufacturers such as Apple, Lenovo, HP, and Dell. Intel also manufactu...
Darktrace is the world's leading AI company for cyber security. Created by mathematicians from the University of Cambridge, Darktrace's Enterprise Immune System is the first non-consumer application of machine learning to work at scale, across all network types, from physical, virtualized, and cloud, through to IoT and industrial control systems. Installed as a self-configuring cyber defense platform, Darktrace continuously learns what is ‘normal' for all devices and users, updating its understa...
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throug...
Apptio fuels digital business transformation. Technology leaders use Apptio's machine learning to analyze and plan their technology spend so they can invest in products that increase the speed of business and deliver innovation. With Apptio, they translate raw costs, utilization, and billing data into business-centric views that help their organization optimize spending, plan strategically, and drive digital strategy that funds growth of the business. Technology leaders can gather instant recomm...
OpsRamp is an enterprise IT operation platform provided by US-based OpsRamp, Inc. It provides SaaS services through support for increasingly complex cloud and hybrid computing environments from system operation to service management. The OpsRamp platform is a SaaS-based, multi-tenant solution that enables enterprise IT organizations and cloud service providers like JBS the flexibility and control they need to manage and monitor today's hybrid, multi-cloud infrastructure, applications, and wor...
The Master of Science in Artificial Intelligence (MSAI) provides a comprehensive framework of theory and practice in the emerging field of AI. The program delivers the foundational knowledge needed to explore both key contextual areas and complex technical applications of AI systems. Curriculum incorporates elements of data science, robotics, and machine learning-enabling you to pursue a holistic and interdisciplinary course of study while preparing for a position in AI research, operations, ...
CloudEXPO has been the M&A capital for Cloud companies for more than a decade with memorable acquisition news stories which came out of CloudEXPO expo floor. DevOpsSUMMIT New York faculty member Greg Bledsoe shared his views on IBM's Red Hat acquisition live from NASDAQ floor. Acquisition news was announced during CloudEXPO New York which took place November 12-13, 2019 in New York City.