SlideShare a Scribd company logo
Security	
  &	
  Privacy	
  Issues	
  
                 in	
  
The	
  Hype	
  
“The interesting thing about cloud
  computing is that we’ve redefined cloud
  computing to include everything that we
  already do. I can’t think of anything that
  isn’t cloud computing with all of these
  announcements. The computer industry
  is the only industry that is more fashion-
  driven than women’s fashion. Maybe I’m
  an idiot, but I have no idea what anyone
  is talking about. What is it? It’s complete
  gibberish. It’s insane. When is this
  idiocy going to stop?”

Larry Ellison, CEO, Oracle      (WSJ 9/25/08)
Video	
  
Closer	
  to	
  Earth	
  
•  Let’s	
  presume	
  that	
  Cloud	
  Compu>ng	
  
   is	
  real.	
  	
  
•  What	
  is	
  it?	
  
•  Let’s	
  try	
  to	
  cut	
  through	
  the	
  
   hyperbole	
  and	
  define	
  Cloud	
  
   Compu>ng	
  and	
  see	
  what	
  it	
  has	
  to	
  
   offer	
  consumers	
  and	
  organiza>ons.	
  	
  
Security & Privacy in Cloud Computing
Example:	
  MicrosoK	
  
Sor>ng	
  things	
  out…	
  




                     U>lity	
  or	
  
                     Infrastructure	
  



                                          PlaMorm	
  
             SoKware	
  
Infrastructure	
  as	
  a	
  Service	
  
•  Amazon	
  sells	
  compu>ng	
  power	
  in	
  a	
  
   way	
  similar	
  to	
  how	
  we	
  get	
  electricity	
  
   from	
  the	
  power	
  company.	
  
•  Uses	
  a	
  pay-­‐as-­‐you-­‐go	
  model	
  for	
  
   offering	
  VM	
  instances,	
  compu>ng	
  
   power	
  and	
  storage	
  on	
  demand.	
  
PlaMorm	
  as	
  a	
  Service	
  
•  One	
  step	
  above	
  the	
  u>lity,	
  you	
  find	
  
   the	
  PaaS	
  providers,	
  like	
  Google	
  App	
  
   Engine,	
  Salesforce’	
  force.com,	
  and	
  
   the	
  recently	
  announced	
  MicrosoK	
  
   Azure	
  plaMorm.	
  	
  
•  Here	
  you	
  develop	
  apps	
  and	
  leverage	
  
   a	
  common	
  development	
  framework	
  
   and	
  plaMorm	
  for	
  delivery.	
  
SoKware	
  as	
  a	
  Service	
  
•  SoKware	
  as	
  a	
  Service	
  (SaaS)	
  is	
  what	
  
   most	
  people	
  are	
  familiar	
  with.	
  This	
  is	
  
   where	
  many	
  of	
  the	
  common	
  Web	
  2.0	
  
   applica>ons	
  are,	
  like:	
  Flickr,	
  Gmail,	
  
   Google	
  Apps,	
  Facebook,	
  TwiZer....	
  
•  There	
  are	
  also	
  enterprise	
  
   applica>ons,	
  such	
  as	
  SAP,	
  Oracle,	
  
   MicrosoK	
  and	
  others	
  aZemp>ng	
  to	
  
   gain	
  market	
  share	
  here.	
  
Terminology	
  
•  Let’s	
  face	
  it,	
  the	
  use	
  of	
  all	
  these	
  
   acronyms	
  can	
  get	
  confusing!	
  
•  SOA	
  and	
  SaaS	
  oKen	
  get	
  confused.	
  
•  The	
  u>lity	
  and	
  plaMorm	
  services	
  are	
  
   oKen	
  called	
  nothing	
  more	
  than	
  the	
  
   evolu>on	
  of	
  third-­‐party	
  hos>ng	
  
   services	
  that	
  companies	
  have	
  used	
  for	
  
   years.	
  	
  
•  There	
  are	
  good	
  reasons	
  these	
  
   assump>ons	
  are	
  incorrect.	
  
SOA	
  is	
  dead…?	
  
“SOA met its demise on January 1, 2009, when it was
  wiped out by the catastrophic impact of the economic
  recession. SOA is survived by its offspring: mashups,
  BPM, SaaS, Cloud Computing, and all other
  architectural approaches that depend on “services.”
  Manes’ real point, to quote her is that “we should not be
  talking about an architectural concept that has no
  universally accepted definition and an indefensible
  value proposition. Instead we should be talking about
  concrete things (like services) and concrete
  architectural practices (like application portfolio
  management) that deliver real value to the business.”


Anne Thomas Manes, Burton Group
Consumers	
  
•  Cloud	
  Compu>ng	
  is	
  a	
  new	
  name	
  for	
  things	
  
   consumers	
  are	
  already	
  doing.	
  
•  Consumers	
  are	
  >red	
  of	
  being	
  IT	
  techs.	
  
•  Consumers	
  want	
  to	
  DO	
  things	
  online,	
  and	
  	
  
   have	
  the	
  	
  Internet	
  cloud	
   I	
  don’t	
  care	
  
   be	
  as	
                                 what’s	
  up	
  
                                            there,	
  as	
  long	
  
   simple	
  as	
                           as	
  it	
  WORKS!	
  
   Cable	
  TV.	
  
The	
  Business	
  Case	
  
•    Cost	
  Savings	
  from	
  economies	
  of	
  scale	
  
•    Scalability	
  
•    Elas>city	
  
•    Reliability	
  
•    (and	
  in	
  some	
  cases,	
  they	
  enjoy	
  a	
  
     transfer	
  of	
  liability	
  by	
  outsourcing	
  
     services)	
  
2007




       Source: www.cio.com/article/print/
       109706
Source: www.cio.com/article/print/
109706
Where	
  does	
  it	
  make	
  sense?	
  
•  Start-­‐ups	
  
•  Apps	
  that	
  are	
  not	
  processing	
  key	
  
   data	
  
•  Apps	
  that	
  benefit	
  greatly	
  from	
  
   economies	
  of	
  scale,	
  and	
  that	
  require	
  
   high	
  availability	
  and	
  DRP	
  
•  Apps	
  that	
  need	
  periodic,	
  huge	
  
   capacity	
  or	
  CPU	
  processing	
  
Security & Privacy in Cloud Computing
Where	
  does	
  it	
  not	
  make	
  sense?	
  
•  Key	
  apps	
  that	
  are	
  earning	
  your	
  bread	
  
   and	
  buZer	
  
•  Apps	
  that	
  touch	
  personal	
  data	
  or	
  
   process	
  high-­‐value/consumer	
  
   transac>ons	
  should	
  be	
  considered	
  
   carefully	
  
•  Most	
  cloud	
  compu>ng	
  works	
  well	
  for	
  
   highly	
  paralell,	
  but	
  not	
  serial	
  apps	
  
On-­‐site	
  vs.	
  Off-­‐site	
  
•  PaaS	
  can	
  be	
  hosted	
  at	
  your	
  data	
  center,	
  
   outsourced,	
  or	
  hosted	
  in	
  a	
  hybrid	
  environment	
  
   like	
  this	
  example.	
             Source: cohesiveft.com/vpncubed
Concern	
  in	
  the	
  Cloud	
  
•    Security	
  
•    Control	
  
•    Performance	
  
•    Support	
  
•    Vendor	
  Lock-­‐In	
  
•    Speed	
  of	
  Scaling	
  
•    Configurability	
  
Security	
  Concerns	
  
•  CIA	
  +	
  Privacy	
  
•  Can	
  you	
  extend	
  your	
  policies	
  to	
  the	
  
   cloud?	
  
•  Regulatory	
  compliance	
  
•  Managing	
  data	
  on	
  shared	
  systems	
  
•  Forensics	
  
•  Audi>ng	
  
•  Segrega>on	
  of	
  data	
  
•  Portability	
  &	
  Interoperability	
  
•  Reliability	
  &	
  Manageability	
  
In	
  The	
  News	
  
•  Monster.com Breach May Preface
   Targeted Attacks
•  Salesforce.com Admits

   Data Loss
•  Millions of Gmail

   Users Left in the

   Lurch
•  Gmail is down,

   down, down
More…	
  
•  United	
  Airlines	
  Flight	
  Opera>ons	
  
   Computer	
  System	
  Failure	
  
•  San	
  Francisco	
  Power	
  Grid	
  Failure	
  
•  PayPal	
  Subscrip>on	
  Processing	
  Fails	
  
•  Skype	
  Down	
  for	
  Days	
  
•  LAX	
  TSA	
  Screening	
  System	
  Failure	
  
   	
  
•  What	
  if	
  Google	
  were	
  to	
  disappear	
  for	
  a	
  
   few	
  days?	
  Or,	
  Facebook?	
  Yahoo?	
  
Compliance	
  in	
  the	
  Cloud	
  
•  Let	
  me	
  just	
  list	
  some	
  common	
  U.S.	
  
   regula>ons	
  and	
  speak	
  to	
  them:	
  
            •  PCI	
  
            •  SOX	
  
            •  HIPAA	
  
            •  GLB	
  
            •  California	
  Breach	
  Law	
  (SB1386)	
  
Future	
  Trends	
  
•  The	
  Web	
  as	
  a	
  Par>cipatory	
  Worldwide	
  
   Communica>ons	
  Media	
  (Wikipedia,	
  
   Facebook,	
  YouTube…)	
  
•  The	
  Need	
  to	
  Use	
  Less	
  Energy	
  
•  Innova>on	
  Impera>ve	
  
•  Quest	
  for	
  Simplicity	
  	
  
•  Structure	
  Out	
  of	
  Chaos	
  



          Source: www.cio.com/article/438371/
          Cloud_Computing_Hype_Versus_Reality
Grinch	
  in	
  the	
  Cloud	
  
•  The	
  Grinch:	
  It	
  came	
  without	
  segrega>on.	
  It	
  came	
  without	
  
   recovery	
  goals.	
  It	
  came	
  without	
  adequate	
  physical,	
  logical,	
  or	
  
   personnel	
  access	
  controls.	
  It	
  could	
  have	
  been	
  high,	
  it	
  could	
  
   have	
  been	
  low,	
  I	
  just	
  have	
  no	
  clue	
  where	
  the	
  data	
  may	
  flow!	
  
•  Narrator:	
  Then	
  the	
  Grinch	
  thought	
  of	
  something	
  he	
  hadn't	
  
   before.	
  	
  
•  The	
  Grinch:	
  Maybe	
  the	
  perfect	
  solu>on	
  doesn't	
  	
  
   come	
  from	
  a	
  store.	
  Maybe	
  solving	
  business	
  
   problems	
  securely...	
  	
  
•  Narrator:	
  He	
  thought	
  	
  
•  The	
  Grinch:	
  ...means	
  a	
  liZle	
  bit	
  more.	
  	
  
   	
  
Useful	
  Resources	
  
•  World	
  Privacy	
  Forum,	
  
   www.worldprivacyforum.org	
  
•  Security	
  Monks	
  Blog,	
  
   hZp://blog.securitymonks.com/2009/01/25/
   recent-­‐cloud-­‐pos>ngs/	
  
•  Ra>onal	
  Survivability	
  Blog,	
  
   hZp://ra>onalsecurity.typepad.com/	
  

More Related Content

PPTX
Privacy in cloud computing
PPTX
Cloud computing
PDF
Palo Alto Networks CASB
PDF
Unit 1: Introduction to DBMS Unit 1 Complete
PPT
Cloud deployment models
PPTX
ORDBMS.pptx
PDF
Cloud computing risk & challenges
PPTX
Cloud Application Development – The Future is now
Privacy in cloud computing
Cloud computing
Palo Alto Networks CASB
Unit 1: Introduction to DBMS Unit 1 Complete
Cloud deployment models
ORDBMS.pptx
Cloud computing risk & challenges
Cloud Application Development – The Future is now

What's hot (20)

PPTX
PPTX
Migrating on premises workload to azure sql database
PPT
INTRODUCTION TO CLOUD COMPUTING
PPTX
Azure Security Fundamentals
PDF
Collaborating Using Cloud Services
PPTX
Windows Azure Virtual Machines
PPT
3. mining frequent patterns
PPT
WSN IN IOT
PPTX
Public vs private vs hybrid cloud what is best for your business-
PPT
Lecture 6: IoT Data Processing
PDF
Introduction to Azure
PPTX
Secure your Access to Cloud Apps using Microsoft Defender for Cloud Apps
PPTX
Networking in cloud computing
PPSX
Cloud computing
PDF
Chapter 5 IoT Design methodologies
PPTX
Fog Computing
PPTX
Market oriented Cloud Computing
PPTX
Fog computing technology
PDF
Overview of computing paradigm
Migrating on premises workload to azure sql database
INTRODUCTION TO CLOUD COMPUTING
Azure Security Fundamentals
Collaborating Using Cloud Services
Windows Azure Virtual Machines
3. mining frequent patterns
WSN IN IOT
Public vs private vs hybrid cloud what is best for your business-
Lecture 6: IoT Data Processing
Introduction to Azure
Secure your Access to Cloud Apps using Microsoft Defender for Cloud Apps
Networking in cloud computing
Cloud computing
Chapter 5 IoT Design methodologies
Fog Computing
Market oriented Cloud Computing
Fog computing technology
Overview of computing paradigm
Ad

Viewers also liked (20)

PDF
Privacy and security in the cloud Challenges and solutions for our future inf...
PPT
Security & Privacy In Cloud Computing
PPTX
Lecture01: Introduction to Security and Privacy in Cloud Computing
PDF
The Security and Privacy Threats to Cloud Computing
PPTX
Cloud security ppt
PDF
Cloud Security And Privacy
PDF
Lessons Learned from an early Multi-Cloud journey
PPTX
Journey to the cloud
PPTX
Data Centre Evolution: Securing Your Journey to the Cloud
PDF
soCloud: distributed multi-cloud platform for deploying, executing and managi...
PPTX
Cloud Computing : Top to Bottom
PPTX
Security and Privacy in Cloud Computing - a High-level view
PDF
C-SEC|2016 Session 3 How to pass and get certify on the new cyber/cloud secur...
PPT
Standing on the clouds
PDF
Philip Hung Cao - Cloud security, the journey has begun
PDF
Cloud Security & Privacy Standard Slide
PDF
How Privacy in the Cloud Affects End-Users
PDF
Journey to the Cloud, Hype or Opportunity
PDF
Dimension Data – Enabling the Journey to the Cloud: Real Examples
PDF
الحوسبة السحابية في بيئة المكتبات / إعداد محمد عبدالحميد معوض
Privacy and security in the cloud Challenges and solutions for our future inf...
Security & Privacy In Cloud Computing
Lecture01: Introduction to Security and Privacy in Cloud Computing
The Security and Privacy Threats to Cloud Computing
Cloud security ppt
Cloud Security And Privacy
Lessons Learned from an early Multi-Cloud journey
Journey to the cloud
Data Centre Evolution: Securing Your Journey to the Cloud
soCloud: distributed multi-cloud platform for deploying, executing and managi...
Cloud Computing : Top to Bottom
Security and Privacy in Cloud Computing - a High-level view
C-SEC|2016 Session 3 How to pass and get certify on the new cyber/cloud secur...
Standing on the clouds
Philip Hung Cao - Cloud security, the journey has begun
Cloud Security & Privacy Standard Slide
How Privacy in the Cloud Affects End-Users
Journey to the Cloud, Hype or Opportunity
Dimension Data – Enabling the Journey to the Cloud: Real Examples
الحوسبة السحابية في بيئة المكتبات / إعداد محمد عبدالحميد معوض
Ad

Similar to Security & Privacy in Cloud Computing (20)

PPTX
UNIT I - UNDERSTANDING CLOUD COMPUTING.pptx
PPT
Cloud computing and zuora
PPTX
Getting Started in the Nonprofit Cloud
PDF
Lecture 6 cloud
PPT
Enabling Cloud Computing
PPTX
Trends in recent technology
PDF
Cloud Computing Contracts and Services: What's Really Happening Out There? T...
PPTX
Navigating through the Cloud - 7 feb 2012 at Institute for Information Manage...
PPTX
Cloud Computing Overview
PDF
The cyber security hype cycle is upon us
PPT
Agora2013 Yugo Neumorni
PDF
Cloud computing: identifying and managing legal risks
PPT
cloud computing Architecture in Details.ppt
PDF
Tech essentials for Product managers
PPTX
Cloud Security - Cloud Arena - Tim Willoughby
PDF
Cloud computing.pptx
PPTX
Cloud storage & cloud computing
PDF
Cloud Computing 101
PDF
The Cloud Imperative – What, Why, When and How
PDF
cloud session uklug
UNIT I - UNDERSTANDING CLOUD COMPUTING.pptx
Cloud computing and zuora
Getting Started in the Nonprofit Cloud
Lecture 6 cloud
Enabling Cloud Computing
Trends in recent technology
Cloud Computing Contracts and Services: What's Really Happening Out There? T...
Navigating through the Cloud - 7 feb 2012 at Institute for Information Manage...
Cloud Computing Overview
The cyber security hype cycle is upon us
Agora2013 Yugo Neumorni
Cloud computing: identifying and managing legal risks
cloud computing Architecture in Details.ppt
Tech essentials for Product managers
Cloud Security - Cloud Arena - Tim Willoughby
Cloud computing.pptx
Cloud storage & cloud computing
Cloud Computing 101
The Cloud Imperative – What, Why, When and How
cloud session uklug

More from John D. Johnson (14)

PDF
Security & Privacy Considerations for Advancing Technology
PPTX
IoT and the industrial Internet of Things - june 20 2019
PPTX
All The Things: Security, Privacy & Safety in a World of Connected Devices
PPSX
Fundamentals of Light and Matter
PDF
CERIAS Symposium: John Johnson, Future of Cybersecurity 2050
PPTX
Managing Enterprise Risk: Why U No Haz Metrics?
PPTX
Presenting Metrics to the Executive Team
PPTX
Big Data: Big Deal or Big Brother?
PPTX
The Journey to Cyber Resilience in a World of Fear, Uncertainty and Doubt
PPTX
Cyber Education ISACA 25 April 2017
PDF
Discovering a Universe Beyond the Cosmic Shore
PDF
AITP Presentation on Mobile Security
PDF
Mars Talk for IEEE
PDF
2011 SC Magazine Insider Threat Keynote
Security & Privacy Considerations for Advancing Technology
IoT and the industrial Internet of Things - june 20 2019
All The Things: Security, Privacy & Safety in a World of Connected Devices
Fundamentals of Light and Matter
CERIAS Symposium: John Johnson, Future of Cybersecurity 2050
Managing Enterprise Risk: Why U No Haz Metrics?
Presenting Metrics to the Executive Team
Big Data: Big Deal or Big Brother?
The Journey to Cyber Resilience in a World of Fear, Uncertainty and Doubt
Cyber Education ISACA 25 April 2017
Discovering a Universe Beyond the Cosmic Shore
AITP Presentation on Mobile Security
Mars Talk for IEEE
2011 SC Magazine Insider Threat Keynote

Security & Privacy in Cloud Computing

  • 1. Security  &  Privacy  Issues   in  
  • 2. The  Hype   “The interesting thing about cloud computing is that we’ve redefined cloud computing to include everything that we already do. I can’t think of anything that isn’t cloud computing with all of these announcements. The computer industry is the only industry that is more fashion- driven than women’s fashion. Maybe I’m an idiot, but I have no idea what anyone is talking about. What is it? It’s complete gibberish. It’s insane. When is this idiocy going to stop?” Larry Ellison, CEO, Oracle (WSJ 9/25/08)
  • 4. Closer  to  Earth   •  Let’s  presume  that  Cloud  Compu>ng   is  real.     •  What  is  it?   •  Let’s  try  to  cut  through  the   hyperbole  and  define  Cloud   Compu>ng  and  see  what  it  has  to   offer  consumers  and  organiza>ons.    
  • 7. Sor>ng  things  out…   U>lity  or   Infrastructure   PlaMorm   SoKware  
  • 8. Infrastructure  as  a  Service   •  Amazon  sells  compu>ng  power  in  a   way  similar  to  how  we  get  electricity   from  the  power  company.   •  Uses  a  pay-­‐as-­‐you-­‐go  model  for   offering  VM  instances,  compu>ng   power  and  storage  on  demand.  
  • 9. PlaMorm  as  a  Service   •  One  step  above  the  u>lity,  you  find   the  PaaS  providers,  like  Google  App   Engine,  Salesforce’  force.com,  and   the  recently  announced  MicrosoK   Azure  plaMorm.     •  Here  you  develop  apps  and  leverage   a  common  development  framework   and  plaMorm  for  delivery.  
  • 10. SoKware  as  a  Service   •  SoKware  as  a  Service  (SaaS)  is  what   most  people  are  familiar  with.  This  is   where  many  of  the  common  Web  2.0   applica>ons  are,  like:  Flickr,  Gmail,   Google  Apps,  Facebook,  TwiZer....   •  There  are  also  enterprise   applica>ons,  such  as  SAP,  Oracle,   MicrosoK  and  others  aZemp>ng  to   gain  market  share  here.  
  • 11. Terminology   •  Let’s  face  it,  the  use  of  all  these   acronyms  can  get  confusing!   •  SOA  and  SaaS  oKen  get  confused.   •  The  u>lity  and  plaMorm  services  are   oKen  called  nothing  more  than  the   evolu>on  of  third-­‐party  hos>ng   services  that  companies  have  used  for   years.     •  There  are  good  reasons  these   assump>ons  are  incorrect.  
  • 12. SOA  is  dead…?   “SOA met its demise on January 1, 2009, when it was wiped out by the catastrophic impact of the economic recession. SOA is survived by its offspring: mashups, BPM, SaaS, Cloud Computing, and all other architectural approaches that depend on “services.” Manes’ real point, to quote her is that “we should not be talking about an architectural concept that has no universally accepted definition and an indefensible value proposition. Instead we should be talking about concrete things (like services) and concrete architectural practices (like application portfolio management) that deliver real value to the business.” Anne Thomas Manes, Burton Group
  • 13. Consumers   •  Cloud  Compu>ng  is  a  new  name  for  things   consumers  are  already  doing.   •  Consumers  are  >red  of  being  IT  techs.   •  Consumers  want  to  DO  things  online,  and     have  the    Internet  cloud   I  don’t  care   be  as   what’s  up   there,  as  long   simple  as   as  it  WORKS!   Cable  TV.  
  • 14. The  Business  Case   •  Cost  Savings  from  economies  of  scale   •  Scalability   •  Elas>city   •  Reliability   •  (and  in  some  cases,  they  enjoy  a   transfer  of  liability  by  outsourcing   services)  
  • 15. 2007 Source: www.cio.com/article/print/ 109706
  • 17. Where  does  it  make  sense?   •  Start-­‐ups   •  Apps  that  are  not  processing  key   data   •  Apps  that  benefit  greatly  from   economies  of  scale,  and  that  require   high  availability  and  DRP   •  Apps  that  need  periodic,  huge   capacity  or  CPU  processing  
  • 19. Where  does  it  not  make  sense?   •  Key  apps  that  are  earning  your  bread   and  buZer   •  Apps  that  touch  personal  data  or   process  high-­‐value/consumer   transac>ons  should  be  considered   carefully   •  Most  cloud  compu>ng  works  well  for   highly  paralell,  but  not  serial  apps  
  • 20. On-­‐site  vs.  Off-­‐site   •  PaaS  can  be  hosted  at  your  data  center,   outsourced,  or  hosted  in  a  hybrid  environment   like  this  example.   Source: cohesiveft.com/vpncubed
  • 21. Concern  in  the  Cloud   •  Security   •  Control   •  Performance   •  Support   •  Vendor  Lock-­‐In   •  Speed  of  Scaling   •  Configurability  
  • 22. Security  Concerns   •  CIA  +  Privacy   •  Can  you  extend  your  policies  to  the   cloud?   •  Regulatory  compliance   •  Managing  data  on  shared  systems   •  Forensics   •  Audi>ng   •  Segrega>on  of  data   •  Portability  &  Interoperability   •  Reliability  &  Manageability  
  • 23. In  The  News   •  Monster.com Breach May Preface Targeted Attacks •  Salesforce.com Admits
 Data Loss •  Millions of Gmail
 Users Left in the
 Lurch •  Gmail is down,
 down, down
  • 24. More…   •  United  Airlines  Flight  Opera>ons   Computer  System  Failure   •  San  Francisco  Power  Grid  Failure   •  PayPal  Subscrip>on  Processing  Fails   •  Skype  Down  for  Days   •  LAX  TSA  Screening  System  Failure     •  What  if  Google  were  to  disappear  for  a   few  days?  Or,  Facebook?  Yahoo?  
  • 25. Compliance  in  the  Cloud   •  Let  me  just  list  some  common  U.S.   regula>ons  and  speak  to  them:   •  PCI   •  SOX   •  HIPAA   •  GLB   •  California  Breach  Law  (SB1386)  
  • 26. Future  Trends   •  The  Web  as  a  Par>cipatory  Worldwide   Communica>ons  Media  (Wikipedia,   Facebook,  YouTube…)   •  The  Need  to  Use  Less  Energy   •  Innova>on  Impera>ve   •  Quest  for  Simplicity     •  Structure  Out  of  Chaos   Source: www.cio.com/article/438371/ Cloud_Computing_Hype_Versus_Reality
  • 27. Grinch  in  the  Cloud   •  The  Grinch:  It  came  without  segrega>on.  It  came  without   recovery  goals.  It  came  without  adequate  physical,  logical,  or   personnel  access  controls.  It  could  have  been  high,  it  could   have  been  low,  I  just  have  no  clue  where  the  data  may  flow!   •  Narrator:  Then  the  Grinch  thought  of  something  he  hadn't   before.     •  The  Grinch:  Maybe  the  perfect  solu>on  doesn't     come  from  a  store.  Maybe  solving  business   problems  securely...     •  Narrator:  He  thought     •  The  Grinch:  ...means  a  liZle  bit  more.      
  • 28. Useful  Resources   •  World  Privacy  Forum,   www.worldprivacyforum.org   •  Security  Monks  Blog,   hZp://blog.securitymonks.com/2009/01/25/ recent-­‐cloud-­‐pos>ngs/   •  Ra>onal  Survivability  Blog,   hZp://ra>onalsecurity.typepad.com/