The Wayback Machine - https://web.archive.org/web/20121006033224/http://cloudcomputing.sys-con.com:80/node/2388402

Welcome!

Cloud Expo Authors: Elizabeth White, Paul Miller, Liz McMillan, Pat Romanski, Maureen O'Gara

Related Topics: Java, SOA & WOA, .NET, Virtualization, AJAX & REA, Cloud Expo, Apache

Java: Article

A Preposition Makes All the Difference in / of / for / from the Cloud

How a simple preposition alters the scope and meaning from problem to solution

No, this isn't 7th grade English...I promise.

With all the important decisions IT departments make, what’s the big deal whether cloud security means from the cloud, in the cloud, of the cloud or for the cloud. Well, a lot. Among the various media, blogs, professional chatter, webinars, conferences and the like, the concept of cloud security is getting a significant amount of airplay. However, the difference in the application of a simple preposition completely alters the scope and meaning of these conversations to that of a problem or a solution.

Security IN the cloud frames the overarching issue. It is the problems often discussed by IT professionals today. They range from questions about the safety of data held within a virtualized environment to that of cyber hactivism or why do my users keep insisting on using their smartphones to access the network? These issues often point to the cloud as some wide open Wild, Wild West situation. Sorry, but I disagree. I think the cloud as a platform has matured to the point where it is a viable, protective and proactive choice.   These issues would exist on any enterprise’s on-premise set up. Companies like ADP, salesforce.com, Office365, Azure have taken great pains to ensure the data processed or stored on or via their servers have a degree of security equal to or exceeding that of any on premise set-up.

But what about Yahoo? What about LinkedIn? All those passwords breached. But before you set your hair on fire and scream the “cloud is falling,” - for every cloud-centric breach, there are just as many (or more) on-premise breaches. Poor or porous security knows no platform. It favors no deployment scenario and creates no safe haven for users. Security, like any other element of an enterprise is built on smart process, consistent monitoring and effective tools. A substandard, half-hearted approach to any of these three and those unsettling headlines we read about every few months might feature a familiar company name.

In stark contrast, security FROM the cloud is the means to protect IT assets without having the heavy investments in servers, software and a variety of other related costs. But it is much more than cost savings and democratizing access to protection. For some it is the holistic application of best practices, real time visibility and best of breed solutions. “From” the cloud is providing a scalable layer of security that was typically reserved for trillion dollar companies easily deployed for any company of any size.  For others it is the ability to link all the independent silos of information including transactions, proprietary data, applications (legacy and in the cloud) and manage them centrally with a greater degree of focus and accuracy.

Security FROM the cloud answers the questions posed by security IN the cloud. Who has access? Who controls that access? Can we report activity to maintain compliance? What is harmless traffic and what needs to be remediated in real time? Do I have the resources to monitor and react to issues 24/7/365? How do I centralize security analysis so I don’t have to repeat processes system after system? How do I control all those applications the sales team accesses from beyond the so-called network perimeter? What happens when an employee leaves the company or a vendor’s contract expires? Who controls all the passwords? How is data aggregated, stored/destroyed, transited and digested? Is my data safe? So many issues, so little bandwidth…until you apply an answer FROM the cloud.

Now of course, security-as-a-service (aka security FROM the cloud) or cloud-based security is not a panacea. It still depends on workflow process and the expertise to define and apply that process. But the issues surrounding scope, scale, control, capability, centralization, correlation, fast-to-market and cost are answered. The important thing to remember is that FROM the cloud is a holistic (and sometimes automated) set of enterprise controls designed to protect assets. The fact that it is managed and controlled from the cloud is simply a value added advantage. It provides a cost-effective means and accelerated degree of flexibility that can be translated into a redirection of core competency priorities. Simply put…you can worry about one less things and get to work on IT issues that drive your company forward. Of the many hats we often force our IT professionals to wear, here is one they can take off with the confidence that the goals of the enterprise are being met and its assets are properly protected.

So a preposition can make all the difference. Now the next time a blogger or industry pundit explains the wonders or the perils of the cloud…you just have to remember FROM where real solutions come.

More Stories By Kevin Nikkhoo

With more than 32 years of experience in information technology, and an extensive and successful entrepreneurial background, Kevin Nikkhoo is the CEO of the dynamic security-as-a-service startup Cloud Access. CloudAccess is at the forefront of the latest evolution of IT asset protection--the cloud.

Kevin holds a Bachelor of Science in Computer Engineering from McGill University, Master of Computer Engineering at California State University, Los Angeles, and an MBA from the University of Southern California with emphasis in entrepreneurial studies.

Cloud Expo Breaking News
SYS-CON Events announced today that the 20/20 Vision has been named “Bronze Sponsor” of SYS-CON's 11th International Cloud Expo, which will take place on November 5–8, 2012, at the Santa Clara Convention Center in Santa Clara, CA. 20/20 vision Europe provides an easy-to-use, cost-effective cloud-based solution for Budget2Pay automation on Microsoft Azure. Automated PO, contract and invoice approval not just speeds up the process, but increases track and control over spend. 20/20 vision also sup...
SYS-CON Events announced today that the “Holland Pavilion,” eight leading Dutch cloud companies, has been named “Bronze Sponsor” of SYS-CON's 11th International Cloud Expo, which will take place on November 5–8, 2012, at the Santa Clara Convention Center in Santa Clara, CA. Meet the leading Dutch cloud companies at the Holland Pavilion: 20/20 Vision 20/20 vision Europe is a Dutch company that provides successful standard solutions for your entire Budget2Pay process as well as electronic invoi...
Are you aware of the new reality that cloud computing is bringing to bear? Cloud is not as global as you might think. The global acceptance of cloud computing has caused a spike in demand for multi-national cloud capability. As a result, cloud companies are facing an intimidating next step – expanding to new international markets. The Netherlands is the leading cloud hub in Europe that can address this process specific to transatlantic cloud expansion and how to intelligently establish the hig...
SYS-CON Events announced today that Precog, the leading developer of infrastructure for data warehousing and analysis, will exhibit at SYS-CON's 11th International Cloud Expo, which will take place on November 5–8, 2012, at the Santa Clara Convention Center in Santa Clara, CA. Precog is the leading developer of data warehousing and analysis infrastructure designed to help developers build sophisticated Big Data capabilities into their applications. Precog’s family of warehousing, analysis and r...
Jonathan Bryce, the Executive Director of the newly-formed OpenStack Foundation, and who has spent his entire career building the cloud, is to give the opening keynote at 11th Cloud Expo | Cloud Expo Silicon Valley, being held at the Santa Clara Convention Center, Santa Clara, CA, November 5-8, 2012. The OpenStack Foundation promotes the development, distribution and adoption of the OpenStack cloud operating system. As the independent home for OpenStack, the Foundation has already attracted mor...
In her hands-on workshop session at the 11th International Cloud Expo, Diane Mueller, the Cloud Evangelist for ActiveState, will introduce conceptual cloud architectural principles and show how private Platform as a Service enables cloud app development, deployment, and management. She will provide an overview of cloud architectures, present web frameworks and sample applications, then show how to package, create a manifest, and deploy apps to any cloud. By the end of the session, Cloud Expo d...
SYS-CON Events announced today that RightScale Inc, the leader in cloud computing management, will exhibit at SYS-CON's 11th International Cloud Expo, which will take place on November 5–8, 2012, at the Santa Clara Convention Center in Santa Clara, CA. RightScale Inc., cloud management enables organizations to easily deploy and manage business-critical applications across public, private, and hybrid clouds. RightScale provides efficient configuration, monitoring, automation, and governance of c...
No one disputes cloud computing as a viable resource delivery model. Now the challenge? Deliver the best solution in a world where processor power follows Moore’s Law, storage is bound by the physics of spinning media, and cloud providers need to deliver optimized system level performance at a reasonable cost. Solid State Storage combined with dynamic, intelligent caching software to “learn” data “hot spots” and move them transparently onto flash memory fills the gap. In his session at the 11th...
As your datacenter needs more capacity, you're thinking about going to the cloud. What are the key considerations to help plan for the needed capacity over time? And how can the cloud best work with your existing applications? In his session at the 11th International Cloud Expo, Brian Jawalka, Principal Solutions Architect, Cloud Strategy at Rackspace Advisory Services, will show how a hybrid approach can add agility, flexibility and speed-to-market for your organization.
The open B2B transaction cloud integrates social media, business intelligence and open system-to-system connectivity. Social media becomes a common part of day-to-day business transactions. Buyers and suppliers are influenced by each other, learn best practices and save money by being a part of a community. In his session at the 11th International Cloud Expo, Vilayat William, Chief Business Development Officer at TBlox, will show how the key to success of the transaction cloud is the self-conn...