[ insider_reports_insider ] Companies Lag On Cloud Security
Mike Sachoff Staff Writer
2010-04-07
Insider Reports RSS Feed
Most organizations lack the procedures, policies and tools to ensure sensitive information they put in the cloud remains secure, according to a new survey by Symantec and the Ponemon Institute.
 | | Companies Lag On Cloud Security |  |
Despite security concerns and the expected growth in cloud computing, only 27 percent of respondents said their organizations have steps in place for approving cloud applications that use sensitive or confidential information.
In most organizations, large gaps exist between those currently evaluating cloud computing vendors and the IT and security business leaders that should ideally be responsible. Of the organizations surveyed, 68 percent indicated that ownership for evaluating cloud-computing vendors resides with end users and business managers. Only 20 percent of the organizations surveyed reported that their information security teams are regularly involved in the decision making process and approximately a quarter said they never participated at all.
However, 69 percent of the respondents indicated they would prefer to see the information security or corporate IT teams lead the cloud decision-making process.
"Despite widespread interest in adopting cloud computing technologies, many organizations are 'flying blind' with respect to making them secure, potentially putting their business operations, company data and customer information at risk," said Justin Somaini, chief information security officer, Symantec.
"Today, organizations need stronger information governance for managing corporate information and enabling confidence in the cloud. The success of cloud computing hinges on the trust and confidence that can only occur when the information security teams have better visibility into the security posture and operations of cloud initiatives."
Additional highlights from the survey:
*Only 23 percent of organizations require proof of security compliance such as SAS 70, 18 percent rely on in-house security assessments and just six percent rely on third-party assessments by security experts.
*More than 75 percent indicated the move to cloud computing was occurring in a less-than ideal manner due to a lack of control over end users.
*Only 19 percent reported that their company provides general data security training that discusses cloud applications.
About the Author:
Mike is a staff writer for WebProNews. Visit WebProNews for the latest ebusiness news.
More insider_reports_insider Articles
Insider Reports RSS Feed
|
|