Search This Blog

Wednesday, June 09, 2010

Cloud computing is shifting the way we view IdM

Mobile phone security dos and don'ts | Microsoft patches IE8's Pwn2Own bug in massive update

Network World Security: Identity Management

Forward this to a Friend >>>


Cloud computing is shifting the way we view IdM
This should be the last newsletter to cover events at last month's European Identity Conference. I say "should be" because I think I've finally learned not to ever say "final" again. Read More


RESOURCE COMPLIMENTS OF: SailPoint

Live Webinar featuring Burton Group: Rethinking Provisioning
IS YOUR PROVISIONING SOLUTION STRETCHED TO THE LIMIT? Join SailPoint and Burton Group on June 10 to discuss the new compliance and business demands affecting the identity management landscape. You'll get a roadmap that leads to provisioning success. And, you'll learn about new technology that gets you from here to there quickly. REGISTER NOW!

WHITE PAPER: IBM

IBM Analytics Solutions
Business leaders today are making decisions with major blind spots. But with advanced analytics, you can become a smarter, more fact-based enterprise. Read this white paper to see how IBM Analytics Solutions can help you gain a competitive advantage by enabling real-time or near-real-time decisions. Read More

Mobile phone security dos and don'ts
Is your enterprise security team struggling to keep up with the rapid proliferation of mobile and smart phones? Five experts offer advice to help you protect everything from the BlackBerry to the iPhone and Droid. Read More

Microsoft patches IE8's Pwn2Own bug in massive update
Microsoft today patched 34 vulnerabilities in Windows, Office and Internet Explorer (IE), including an IE8 bug used by a Dutch security researcher in March to win $10,000 at the Pwn2Own contest. Read More


E-GUIDE: Compuware

Perfecting Application Performance
The enterprise application scene has become increasingly complicated over the years. Things have changed with the rise of Web services, SOA, Virtualization and cloud computing. In this Executive Guide explore how to get the best performance out of today's application environments. Read Now.

What kind of software costs $920 million?
Some big defense contractors got even bigger this week as the Air Force awarded a $919,640,000 deal for the development of its critical mission planning software. Read More

Here's a better idea for securing the nation's electric grid
Last week Ellen Messmer wrote an article recapping NERC's report on many potential paths to destruction of our North American Electrical Grid (www.ere-security.ca and http://www.networkworld.com/news/2010/060210-nerc-cyberattack-power-grid.html?page=1.) In my opinion, while NERC (North American Electric Reliability Corporation, www.nerc.org ) has managed to accurately identify real security... Read More


WHITE PAPER: Riverbed

Strategies for Unleashing Cloud Performance
Whether a business builds out its own cloud or buys cloud services from someone else, they need to be sure the end results are optimized for the speed users require. This paper identifies where the limitations of cloud computing exist and provides actionable strategies to unleash cloud performance. Click here!

New security/management software targets enterprise smartphones
A new client-server product uses a smartphone-based agent and server-based application to create and enforce security and management policies for four leading mobile operating systems. Read More

Hacker justifies turning in Wikileaks informer
Former hacker Adrian Lamo has claimed to be the source who informed on a US soldier accused of sending the Wikileaks whistleblowing site video footage of a helicopter shooting unarmed Iraqi civilians. Read More

Group lists top five social media risks for businesses
As businesses increasingly trying to figure out how to use social networking tools in the enterprise, an IT governance group has released a ranking of the top five risks that social media poses to companies. Read More

Zombie PCs to be quarantined under new ISP code
The Internet Industry Association (IIA) has urged ISPs to better secure their networks by adopting recommendations in a new voluntary code of practice on cyber security. Read More



Join us on LinkedIn

Discuss the networking issues of the day with your colleagues, via Network World's LinkedIn group. Join today!
- Jeff Caruso, Executive Online Editor

Computerworld and Network World: Best of Green IT

Computerworld and Network World: Best of Green IT Computerworld and Network World are teaming up to identify the top organizations leading the way with green-IT efforts and the coolest green-IT products. Computerworld will feature two ranked lists in its Oct. 25 issue: Top green-IT end-user organizations and a Top green-IT data center suppliers/vendors. Network World will feature the most effective green-IT products, as cited by survey respondents, in its Oct. 25 issue and online. Please fill out our short survey or forward this link to the person in your company best able to answer questions about IT energy issues. Surveys should be submitted by Thursday, July 1 at 12 noon EST.

SLIDESHOWS

10 useful Firefox-based apps
Here are 10 useful desktop programs that run on the open-source Web browser's native technology. All of these applications are free for you to download and use -- and only one is a Web browser.

5 things we love/hate about cloud automation tools
Here are some things we love and some things we hate about cloud automation tools.

MOST-READ STORIES

  1. Six misconceptions about cloud apps
  2. Scientist 'infected by computer virus' catches publicity fever
  3. Some iPhone 4 features will be marred by poor networks
  4. No 4G for Apple's iPhone 4
  5. What would your ultimate network security look like?
  6. AT&T details early iPhone 4 eligibility, pricing
  7. Networking's 20 greatest arguments
  8. Apple announces iPhone 4
  9. Ubuntu Linux wins over Windows power user
  10. An open letter to Dan Hesse, Sprint CEO

Do You Tweet?
Follow everything from NetworkWorld.com on Twitter @NetworkWorld.

You are currently subscribed to networkworld_security_identity_management_alert as security.world@gmail.com.

Unsubscribe from this newsletter | Manage your subscriptions | Privacy Policy

If you are interested in advertising in this newsletter, please contact: bglynn@cxo.com

To contact Network World, please send an e-mail to customer_service@nww.com.

Copyright (C) 2010 Network World, 492 Old Connecticut Path, Framingham MA 01701

** Please do not reply to this message. If you want to contact someone directly, send an e-mail to customer_service@nww.com. **


1 comment:

AMDE said...

As John Mullinax said:
"Companies trust their data to external environments all the time. They generally do not trust ALL their data to these environments, for good reasons. But they generally do trust SOME of their data. It's a good dialogue to have - what data is ok in the cloud? -- but as cloud computing is maturing, we also need to have a more nuanced conversation about trust and the cloud. The question of when will everything move to the cloud has largely been answered... it's not likely going to happen.

The Cloud represents a new generation of computing paradigm, but like the platform paradigms that have come before (mainframe, mini computer, PC, client-server, web - all of which are still around) we should not expect the cloud to replace everything that came before it.

The question to ask is what data *would* make sense in the cloud? Or even better, what parts of my technology and data portfolio should live in the cloud?

It's a good discussion topic, and there's no one right answer for everyone. Since Windows Azure has been purposefully designed interoperate/span across on-premise boundaries, there are many options on the continuum between cloud and on-premise.

BTW, with highly automated service provisioning and data center operations, ISO 27001 certification, SAS70 certification, etc... the Microsoft data centers that run Windows Azure are probably "safer" and more reliable than many other environments. More than safety and reliability, what you give up to some degree is loss of direct control. "
IMHO, when considering security, 2 items need to be addressed:
1) Physical security of the hardware 2) Security of the Data - here are some resources I've found that discuss this and act as guidelines when considering security and the cloud:

Physical security:
http://www.globalfoundationservices.com/security/index.html
http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf


Data Security:
http://www.research.microsoft.com/en-us/projects/cryptocloud/
http://www.research.microsoft.com/en-us/projects/secpal/

thoughts?

hope that helps
-cn