How to make sure your cloud provider can protect your data as promised

FREE

Become An Insider

Sign up now and get free access to hundreds of Insider articles, guides, reviews, interviews, blogs, and other premium content from the best tech brands on the Internet: CIO, CITEworld, CSO, Computerworld, InfoWorld, ITworld and Network World. Learn more.

Certifications and inspections should be included in your contract

At the end of my Cloud Expo West presentation last week, I was asked, "How can we verify that a cloud provider actually has all of these infrastructure and security mechanisms in place?" It's a great question, one that deserves a fuller answer than I was able to give in the time available. So here's a more detailed version of my response.

The primary options -- certifications and inspections -- could be added as a requirement in your contract with the cloud provider. Currently, there isn't one formal standard for cloud computing certification, but the following are increasingly being used:

FIPS 200/SP 800-53

As a result of the Federal Information Security Management Act (FISMA), the National Institute of Standards and Technology (NIST) developed the Federal Information Processing Standards 200 (FIPS 200), Minimum Security Requirements for Federal Information and Information Systems, and the Special Publication (SP) 800-53, Recommended Security Controls for Federal Information Systems and Organizations. (You can see why the acronyms are preferred.)

To continue reading, register here to become an Insider. You'll get free access to premium content from CIO, Computerworld, CSO, InfoWorld, and Network World. See more Insider content or sign in.

To continue reading, please begin the free registration process or sign in to your Insider account by entering your email address:
Mobile Security Insider: iOS vs. Android vs. BlackBerry vs. Windows Phone
Join the discussion
Be the first to comment on this article. Our Commenting Policies