Security Management
Published on Security Management (http://www.securitymanagement.com)
NIST Publishes Cloud Security Guidelines
By John Wagley
Created 02/07/2011 - 13:05



    
Wrap-Up?: 
No
Weight: 
0
Lead Headline?: 
No
Date: 
02/07/2011
By Line: 
By John Wagley
Teaser: 

Organizations should take time to “carefully plan” the security and privacy aspects of cloud computing before implementing any new solution or service, according to a new National Institute of Standards and Technology report.

Organizations should take time to “carefully plan” the security and privacy aspects of cloud computing before implementing any new solution or service, according to a new National Institute of Standards and Technology (NIST) report [1].

That was just one recommendation in the publication, Guidelines on Security and Privacy in Public Cloud Computing, which describes many of cloud computing’s risks as well as numerous steps organizations can take to make cloud computing more secure.

In addition to focusing more on planning, the paper lists three other overarching security-related recommendations. One is for organizations to ensure that any solution meets the organization’s privacy- and security-related requirements. Another is for cloud services customers to ensure that their own “computing environment” meets security and privacy requirements. Cloud computing customers should also work to “maintain accountability” of data and applications involved in cloud services.

The report is mainly intended for federal departments and agencies, but it's also applicable to the private sector, according to the agency.

Along with the guidelines, NIST published a draft definition [2] of cloud computing. Part of the definition states that cloud computing has five “essential characteristics.” These include on-demand service, broad network access, and resource pooling. They also include rapid elasticity, in that “capabilities can be rapidly and elastically provisioned,” as well as measured service.

NIST has asked for comments on the two publications, with a deadline of February 28th.

The agency has also introduced a new Web site [3] that includes information on its cloud computing work and activities. Called the Cloud Computing Collaboration Site, it also allows registered users to participate in certain cloud computing-related discussions.


 ♦ Screenshot of NIST report

Related Resources: 
Thumbnail: 

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 38,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters, 1625 Prince Street, Alexandria, Virginia 22314-2818 U.S.A.
703.519.6200 | fax 703.519.6299 | www.asisonline.org

ASIS

© 2013 Security Management
This site is protected by copyright and trade mark laws under U.S. and International law.
No part of this work may be reproduced without the written permission of Security Management.

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/nist-publishes-cloud-security-guidelines-008198

Links:
[1] http://csrc.nist.gov/publications/drafts/800-144/Draft-SP-800-144_cloud-computing.pdf
[2] http://csrc.nist.gov/publications/drafts/800-145/Draft-SP-800-145_cloud-definition.pdf
[3] http://collaborate.nist.gov/twiki-cloud-computing/bin/view/CloudComputing/