Email Alerts
-
HIPAA cloud computing advice: Ensuring cloud computing compliance
How can an enterprise ensure their cloud service provider is compliant with HIPAA? This HIPAA cloud computing guide offers advice on how to ensure cloud computing compliance. Tutorial
-
CSA launches cloud security certification initiative for service providers
Plan calls for working with certification bodies, government agencies, as well as an independent CSA certification. News | 10 May 2012
-
Panel debates cloud computing governance issues
Problems with data governance in the cloud aren’t much different than traditional outsourcing. News | 27 Jan 2012
-
Calls for cloud security transparency getting louder
Enterprises need cloud security transparency and must understand cloud provider security in order to move forward with engagements. News | 20 Jan 2012
-
Federal officials launch cloud computing security standards initiative
FedRAMP establishes standard approach for federal agencies to assess cloud providers. News | 08 Dec 2011
-
Panel discusses cloud computing security issues
Companies need to educate developers, leverage asset inventories and vet cloud providers, panelists advise. News | 10 Nov 2011
-
Cloud risk management: CSA on its Cloud Controls Matrix
Co-chair of CSA project talks about the CCM and how organizations can leverage it. News | 03 Oct 2011
-
Analysis: Verizon CloudSwitch acquisition fosters cloud application security
Amy Larsen DeCarlo of Current Analysis says the Verizon CloudSwitch acquisition will bolster cloud application security following cloud migrations. Analysis | 31 Aug 2011
-
CSA cloud provider registry aims to boost cloud transparency
Free online registry will provide documentation of cloud provider security controls. News | 04 Aug 2011
-
What about cloud security certifications for cloud providers?
Opinion: CSA Executive Director Jim Reavis assesses the challenges associated with certifying the security capabilities of cloud providers. News | 15 Jul 2011
-
CSA licenses cloud transparency tool from CSC
Free tool gives organizations a standard way to obtain security and compliance information from a cloud provider. News | 14 Jul 2011
- See More: News on Evaluating Cloud Computing Providers
-
Countering cloud computing threats: Malicious insiders
Learn the questions to ask in order to vet your cloud provider’s hiring practices and administrative controls. Tip
-
CSP security: Industry groups work to improve cloud transparency
Organizations need insight into their cloud providers’ security. Industry groups are tackling the cloud transparency challenge. Tip
-
Development of NIST cloud security guidelines a complex process
Several public-private partnerships are working to develop specifications to support the NIST roadmap. Tip
-
Using SSAE 16 standard, SOC reports to assess cloud provider security
The SAS 70 report has been replaced by the SSAE 16, but how does it stack up as a tool to measure a provider’s security? Tip
-
Cloud outages and cloud computing breaches: Lessons learned
Recent incidents illustrate the need for redundancy and provider security reviews Tip
-
Cloud contracts: Cloud computing pricing
The unpredictability of cloud service pricing can make budgeting difficult for CIOs and CISOs. Tip
-
Cloud risk assessment and ISO 27000 standards
How do you measure the trustworthiness of a cloud service provider? The ISO 27000 security series can help. Tip
-
Cloud risk assessment: Data center security and resiliency
How do you determine if a cloud provider’s data center has the level of redundancy and resiliency your company needs? Tip
-
Cloud risk management: Managing the risk of cloud outages
Companies need to prepare for the eventuality of cloud service interruptions. Tip
-
A framework for evaluating cloud computing risk
One approach for building a customized, due-diligence process for evaluating cloud provider risk and presenting the results to management. Tip
- See More: Tips on Evaluating Cloud Computing Providers
-
Minimizing cloud computing threats in the enterprise
In this expert response, Nick Lewis outlines the biggest cloud computing threats, and explains what can be done to mitigate those threats. Ask the Expert
-
Soc 2 (Service Organization Control 2)
A Service Organization Control 2 (Soc 2) reports on various organizational controls related to security, availability, processing integrity, confidentiality or privacy. Definition
-
Security, Trust and Assurance Registry (STAR)
The Security, Trust and Assurance Registry (STAR) is an online registry of cloud provider security controls. Definition
-
Cloud Controls Matrix
The Cloud Controls Matrix is a baseline set of security controls created by the Cloud Security Alliance to help enterprises assess the risk associated with a cloud computing provider. Definition
-
Jim Reavis on cloud transparency, cloud security trends
In this video from RSA Conference 2012, CSA Executive Director Jim Reavis talks about the group’s projects and building cloud security trust. Video
-
Setting the groundwork for IAM in the cloud
This presentation will provide guidance as to some common answers to questions that arise when extending an IAM program to the cloud. Video
-
Countdown: Top five strategies for building a successful cloud IAM architecture
This podcast will count down the top five steps you should take to successfully extend your identity services infrastructure into the cloud. Podcast
-
Cloud computing pros and cons for regulated data
Has your company considered moving regulated data to the cloud? Expert Richard E. Mackey Jr. explains the pros, cons and security challenges of doing so. Video
-
Gartner’s Neil MacDonald on lacking cloud computing security standards
The Gartner VP discusses lacking cloud computing security standards, as well as advice for enterprises seeking to get a handle on cloud computing security. Video
-
Face-off: Assessing cloud computing risks
Security experts Bruce Schneier and Marcus Ranum debate the kinds of risks associated with cloud computing and whether they should be absorbed by the customer. Video
-
CSA launches cloud security certification initiative for service providers
Plan calls for working with certification bodies, government agencies, as well as an independent CSA certification. News
-
Countering cloud computing threats: Malicious insiders
Learn the questions to ask in order to vet your cloud provider’s hiring practices and administrative controls. Tip
-
Soc 2 (Service Organization Control 2)
A Service Organization Control 2 (Soc 2) reports on various organizational controls related to security, availability, processing integrity, confidentiality or privacy. Definition
-
HIPAA cloud computing advice: Ensuring cloud computing compliance
How can an enterprise ensure their cloud service provider is compliant with HIPAA? This HIPAA cloud computing guide offers advice on how to ensure cloud computing compliance. Tutorial
-
CSP security: Industry groups work to improve cloud transparency
Organizations need insight into their cloud providers’ security. Industry groups are tackling the cloud transparency challenge. Tip
-
Jim Reavis on cloud transparency, cloud security trends
In this video from RSA Conference 2012, CSA Executive Director Jim Reavis talks about the group’s projects and building cloud security trust. Video
-
Development of NIST cloud security guidelines a complex process
Several public-private partnerships are working to develop specifications to support the NIST roadmap. Tip
-
Security, Trust and Assurance Registry (STAR)
The Security, Trust and Assurance Registry (STAR) is an online registry of cloud provider security controls. Definition
-
Using SSAE 16 standard, SOC reports to assess cloud provider security
The SAS 70 report has been replaced by the SSAE 16, but how does it stack up as a tool to measure a provider’s security? Tip
-
Panel debates cloud computing governance issues
Problems with data governance in the cloud aren’t much different than traditional outsourcing. News
- See More: All on Evaluating Cloud Computing Providers
About Evaluating Cloud Computing Providers
Just like any vendor relationship, contracting with cloud service providers requires careful evaluation to make sure an organization's information security needs are met. Get tips, case studies and other resources for evaluating the cloud computing providers' security controls.
Cloud Computing Strategies for the CIO