Page 1 of 1

Data Motility and the Cloud

Posted: Sat Nov 13, 2010 1:07 am
by stoupeace
[...]

The great convenience of availability and motility gives rise to important concerns. Simply protecting against “who” can see or steal your data isn’t enough, companies must now also protect against where resources are located. Several regions (Canada and the European Union to name two) have enacted very strict data privacy and processing laws that forbid the collection or processing of personal information beyond their boundaries.

So how can you protect yourself from the headaches that come from unruly and nomadic information?

1)First, take a thoughtful and methodical approach to the information you store in the cloud. This should include a data lifecycle program that classifies the criticality, sensitivity and timelines of processes and information residing in the cloud. This can help companies avoid losing control of those truly important bits.

2)Next, conduct a deduplication program. Doing so will give you comfort about the number of sensitive documents in the cloud, help you destroy all necessary data when the time comes, and ultimately cut down on storage costs.

3)Most importantly, gain a thorough understanding from your cloud service provider of the level of influence you have over how your data is handled. Your SLA should clearly define the controls your CSP places around your assets. Seriously consider if you want to rely on an IaaS vendor that won’t attest to its processes, controls and procedures.

4)Lastly, when in doubt – encrypt! Standard 256-bit encryption of your storage volumes should deter the curious administrator or seasoned hacker from prying, thieving or simply poking around where they don’t belong. Encryption will also reduce the risk that repurposed storage devices could contain important information when volumes are vacated or when the associated drives are reclaimed for replacement.
πηγή

Ενδιαφέρον και βασικά μία απο τις πιο κατανοητές αναλύσεις για το cloud privacy που'χω διαβασει. Γενικα δεν έπιανα χριστό απ'όσα διάβαζα.

Το 3 να μου εξηγήσετε!

Re: Data Motility and the Cloud

Posted: Sat Nov 13, 2010 1:29 am
by cypher
Αν δεν απατωμαι τo 3) σου λεει ουσιαστικα να μαθεις ποση επιδραση εχεις εσυ στα δεδομενα σου και ποση εχει και ο cloud service provider(csp) με βαση το service agreement license (sla) του. Οποτε και δεν εμπιστευεσαι Location as a Service (LaaS) vendors που δεν αποδεικνυουν καπως τους τροπους χειρισμου/επεξεργασιας των δεδομενων σου.

Re: Data Motility and the Cloud

Posted: Sat Nov 13, 2010 10:43 am
by proskopos
Υπάρχει μια εξαιρετική δουλειά, που κυκλοφορεί σε ψαγμένα λιμέρια επιστημόνων και σχετίζεται με το θέμα...
Integrity and Confidentiality at cloud computing networks... :-D
λύνει κάθε απορία και προτίνει λύσεις...
Spoiler: εμφάνιση/απόκρυψη
Θα έλεγα ότι ειναι υποψήφιο και για turing βραβείο, αλλά μέχρι να βραβευθεί δεν "κάνει" :smt005
Για την ερώτησή σου πάντως ο γκλυκός :smt016 , καλά τα λέει...
Πάντως το 256bit encryption, είναι αρκετά αυθαίρετο... Εξαρτάται από τα δεδομένα και την ασφάλεια που θες να παρέχεις... Πιθανών, η κρυπτογράφιση να μην αποτελεί καν λύση....

Re: Data Motility and the Cloud

Posted: Mon Nov 15, 2010 8:21 pm
by rose