Showing posts with label NIST. Show all posts
Showing posts with label NIST. Show all posts

21 February 2012

UNDERSTANDING CLOUD SECURITY: PART TWO...

Google
I thank you for your attention on the previous post where we had a look at security considerations for the three main cloud service models commonly referred to as SPI (SaaS, PaaS, IaaS). As promised here’s part two looking at other cloud implementation considerations, namely:

  • Cloud deployment model: public vs. private vs community vs hybrid deployments,
  • Cloud location: internal vs. external hosting or combined,

19 February 2012

UNDERSTANDING CLOUD SECURITY: FINDING THE BOUNDARIES...

Google
It seems that my previous post on compliance and third parties struck a chord with a few of you... So I guess it’s about time I dedicated some time to “The Cloud” specifically! Over the past couple of years, we have seen a lot of hype and confusion as to what The Cloud really means and what it can do for you. I think we have now reached the stage where there is perhaps a bit of disappointment that The Cloud, due to inflated expectations, is perhaps not a miracle...

6 February 2012

INCIDENT RESPONSE & RISK MANAGEMENT GO HAND IN HAND...

Google
I was delighted with the level of interest generated by my last post on incident response so I thought I’d continue on the same theme... My thanks go yet again to the NIST report previously mentioned as I will explore some aspects of risk management and prioritisation that apply to incident response...

3 February 2012

INCIDENT RESPONSE – HAVE YOU GOT A PLAN?

Google
So, the National Institute of Standards and Technology (NIST) announced a couple of days ago the release for comments of draft Special Publication (SP) 800-61 Revision 2, Computer Security Incident Handling Guide. How very timely that was! With 2011 dubbed the year of the data breach, and the fact that it takes 3 to 8 months on average for an organisation to discover they have been breached, what better New Year’s resolution than to have an effective Incident Response Plan?...