A recent article in Government Computer News raised the topic of FISMA
reporting, specifically describing the "pessimism" of many USG agencies over
meeting the September 2012 deadline for "using continuous monitoring to meet
Federal Information Security Management Act reporting requirements." The
article cites a survey of over 200 government IT professionals, conducted by
RedSeal Networks, in which 55% of respondents felt they won't be ready, or
don't know if they will be ready, by the deadline. One can certainly debate
the significance of the number of agencies expressing concern over meeting
the deadline, and the reasons given would likely drag the conversation to
arguing over the validity of a deadline set by government for something that
is far more complex than "flipping a switch." But set that aside for the
moment.
More interesting is the fact that, when you... (more)
Cloud Security Track at Cloud Expo
For companies considering a transition to cloud computing (CC), one of the
major concerns is (or should be) security. If addressed properly while
selecting a cloud computing provider or cloud provider (CP), security can
actually improve for many companies. For many firms, a cloud computing
provider can provide better security than their in-house facilities. This is
because the CPs are devoting huge resources to making security a non-issue
for customers and, in fact, a selling point versus other CPs. With billions
of dollars of potential busines... (more)
Security Pavillion at Cloud Expo
With its ability to provide users dynamically scalable, shared resources over
the Internet and avoid large upfront fixed costs, cloud computing promises to
change the future of computing. However, storing a lot of data creates a
situation similar to storing a lot of money, attracting more frequent
assaults by increasingly skilled and highly motivated attackers. As a result,
security is one - if not the - top issue that users have when considering
cloud computing.
Cloud Security Concerns
Storing critical data on a cloud computing provider's servers... (more)