Untitled Document
 Register Now & Save!
Untitled Document
2009 Gold Sponsor
Untitled Document
2009 Silver Sponsor
Untitled Document
2009 Panel Sponsor
Untitled Document
2009 Exhibitors
Untitled Document
2009 Media Sponsors
Latest News
In 2011, Apache Hadoop received tremendous attenti...
AMD said late Tuesday that its chief sales officer...
Intel has finally seen the back of that 2009 antit...
On Tuesday, Clustrix announced the availability of...
What are the legal implications and consequences o...
EMC moved to make Hadoop safe for the Joe Blow big...
Amazon has reined in the price of its S3 storage a...
The focus of Java EE 7 is on the cloud, and specif...
2011 was a year of rapid adoption for public and p...
AMD Thursday told financial analysts it’s gonna tr...
Can't Miss RSS Feed
Subscribe to the RSS Feed & Get All The Conference News As It Happens!
A Service Auditor’s Letter to the Cloud
As an auditor (and former auditee), I will never be complacent about cloud security

SAS 70 Solutions Session at Cloud Expo

Dear Cloud:

Hello! Can you hear me? I know you can. Yes, yes...no one likes an auditor and I am even worse. I am that CPA who spent the last decade working in information security, both as a security consultant and as someone who managed the product lines of a global managed services business. So whether or not you want to open up those big APIs of yours and listen to me, this is what I have to say...

I know who you are and where you live.

Your name is "the cloud." I will admit that you are the catchiest IT buzzword since Java. Although you claim to live in the gated community called Web 2.0, I know better. You actually live in an unmarked windowless datacenter, with complex networks, servers, applications, policies, contracts, and worst of all, people!

You are unique, just like everyone else.

Your predecessors, such as the ASP, SaaS, and MSSP providers, have been providing customers with a vast array of multi-tenant solutions using the same underlying technology we now call "the cloud" for over a decade. I know because I was responsible for a managed security platform and your shared architecture model was our only path to profitability. From where I am standing, you look a lot like your predecessors, the only major exception being the amount of publicity you get from technology marketers as well as the security community as evidenced by the RSA Security Conference a few weeks ago.

You can be audited.

I have never met a technology that could not be audited...and you aren't going to be the first. Although I believe that many of my traditional methods are sufficient to gauge your control environment, my auditor and security friends are feverishly issuing new methods for assessing you. With time, there will be an army of IT auditors who will find very little about you to be "cloudy."

Like it or not... SAS 70 is the most widely adopted approach for Cloud Assurance

You know I work for a SAS 70 audit company. I do not claim independence on this matter. But lacking independence does not inherently make me wrong. You will also agree that there is no generally accepted standard for auditing you.

Contrary to what the security consultants tell you, Statement on Auditing Standard (SAS) No. 70 is not a weak security standard. It is not a security standard at all! It contains no mention of encryption, network segmentation, or password settings. It is, in fact, an auditing standard. Rather than attempt to tell you what to do, the standard tells you how to describe your services and related controls and tells me how I should test that description for the purposes of issuing results and an opinion. Security topics are normally included in the scope of SAS 70 audits (the extent of which is up to you, cloud), but security is not the primary objective of the audit. My security consulting friends continue to give themselves heartburn over this misconception.

What about the others standards and certifications?

ISO 27001 certification is sometimes mentioned as an alternative. However, with less than 100 certified companies in the United States, this certification has yet to hit mainstream service providers. Make no mistake, aligning with ISO 27001 and ISO 27002 will be both comprehensive and resource intensive. Vendor-specific certifications and seals are great for their specified purposes, but you must remember that they are focused on gauging compliance with static criteria. Such standards are prone to miss the forest for the trees and will disregard worthwhile controls beyond those contemplated by the standard.

PCI cannot provide cloud assurance either as it has a very specific application for providers who process or store credit card data. It is also a prescriptive standard, well liked by the security community but prone to the same cost issues as the ISO 27001/2 standards, which is why providers work so hard to reduce their card data footprints. The good news is that you can incorporate those commodity controls (such as physical security, access control, etc.) for PCI and other such standards into the SAS 70 audit scope such that if you have a comprehensive set of controls, you can potentially save significant time and assessment fees.

Why is SAS 70 more adopted than the others? One, it can adapt to your environment without excessive compliance cost that your end customers have not shown a willingness to share. In addition, it has utility. Only the SAS 70 audit can be leveraged for the purposes of customer assurance, financial auditor, Sarbanes Oxley compliance, regulators, and more. Last and unlike other assessments, the SAS 70 audit is regulated by both law and professional standards, so don't believe for a second that this is an easy undertaking for someone who maintains a CPA license along with CISSP, QSA, and other certifications!

There is always room for improvement.

As an auditor (and former auditee), I will never be complacent about cloud security. I was very excited about the Cloud Security Alliance announcement of the cloud controls matrix at RSA and anxiously await its release. I am also an active participant with Chris Hoff in the newly formed CloudAudit group. Even the AICPA and ISACA are working to make strides by updating their standards and modernizing with offerings such as WebTrust and SysTrust and an update to SAS 70 (SSAE 16), which also includes an international counterpart (ISAE 3402).

You see Cloud, it is unlikely that I will write any new standards, but I will contribute to groups that are focused on harnessing your potential (and addressing your risks). Most important, my day-to-day efforts will be focused on helping my clients understand, improve, and communicate the state of their internal controls to whoever needs to know and all within the bounds of economic reasonableness.

In the meantime, see you at 20,000 feet!

Yours Truly,

Doug

P.S. Want to discuss cloud assurance? Come find us at the 5th International Cloud Computing Expo in New York City. We will be at the SAS 70 Solutions booth in the exhibit hall and I am also presenting "Cloud Computing? There's an Audit for That!" on the Hot Topics! track (http://cloudcomputingexpo.com/event/session/768). Come by the booth or the presentation to register for a drawing for $200+ gift cards from Apple, American Express and more!

About Douglas Barbin
Doug Barbin is a Director at SAS 70 Solutions, a company that provides assurance and technology compliances services with an emphasis on SAS 70 audits, PCI validation, and ISO 27001/2 compliance. After starting his career with a "Big 4" global accounting firm, Doug has spent the last ten years working in the trenches of a wide variety of information security topics, and thus, understands the perspective of both the security consultant and the managed services / SaaS provider. Prior to joining SAS 70 Solutions, Barbin was Director of Product Management for VeriSign's Managed Security Services business, where he was responsible for the MSS "SaaS" platform architecture and compliance (including overseeing the conduct of the SAS 70 audit, PCI validation, and other types of compliance assessments). Prior to that, Doug was in charge of VeriSign's western US security consulting practice, where among other projects, he led some of the prototype PCI assessments. He has BS degrees in Accounting and Criminal Justice from Penn State University and an MBA from Pepperdine University.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

Untitled Document

Call 201 802-3021 or Click Here to Save $400!

Save $400

 Sponsorship Opportunities

SYS-CON's International Cloud Computing Conference & Expo, held each year in California, New York and Prague is the leading event covering the fast-emerging Cloud Computing market for Enterprise IT professionals. Co-located with the International Virtualization Conference & Expo, the combined event will surely deliver the #1 i-Technology educational and networking opportunity of the year for those seeking to establish a market lead anywhere in the multiple layers of the Cloud Computing ecosystem.





Who Should Attend?

Senior Technologists including CIOs, CTOs, VPs of technology, IT directors and managers, network and storage managers, network engineers, enterprise architects, communications and networking specialists, directors of infrastructure Business Executives including CEOs, CMOs, CIOs, presidents, VPs, directors, business development; product and purchasing managers.


Video Coverage of Cloud Computing Expo

Brian Stevens: The Opening of Virtualization
Jon Wallace: User Environment Management – The Third Layer of the Desktop
Brian Duckering & Ken Berryman: Managing Hybrid Endpoint Environments
Preeti Somal: Game-Changing Technology for Enterprise Cloud and Applications

 Conference Media Sponsor: Cloud Computing Journal

Cloud Computing Journal aims to help open the eyes of Enterprise IT professionals to the economics and strategies that utility/cloud computing provides. Cloud computing - the provision of scalable IT resources as a service, using Internet technologies - potentially impacts every aspect of how IT deploys and operates software.

Government IT Conference & Expo 2009
Allstar Conference Faculty Lineup Will Include...


CHEVALIER

Novell Canada

DICARLO

Sun Micosystems

FOXWELL

Sun Microsystems Federal

GABHART

Web Age Solutions

GREENBERG

Integralis

HAHN

Tranxition

WILLIAMS

Maxworks

JACKSON

Dataline, LLC

KHOSLA

IBM

KRZYSKO

US Departement of Defense

LIBERMAN

Lieberman Software

MARKS

AgilePath

MORGENTHAL

QinetiQ North America

RYAN

Asankya

TRAJMAN

Vertica

WHITE

BDNA


SYS-CON EVENTS


Past Events Archive

Cloud Computing Conference & Expo
2009 East

cloudcomputingexpo
2009east.sys-con.com/
Virtualization Conference & Expo
2009 East

virtualizationconference
2009east.sys-con.com/
Cloud Computing Conference & Expo
2008 West

cloudcomputingexpo
2008west.sys-con.com/
SOAWorld Conference & Expo 2008 West
soaworld2008.com/
Virtualization Conference & Expo 2008 West
virtualizationconference
2008west.sys-con.com
AJAXWorld Conference & Expo 2008 West
ajaxoct08.sys-con.com
SOAWorld Conference & Expo 2008 East
soa2008east.sys-con.com
Virtualization Conference & Expo 2008 East
virt2008east.sys-con.com
AJAXWorld 2008 Conference & Expo East
ajaxmar08.sys-con.com
SOAWorld Conference & Expo 2007 West
www.soaworld2007.com
Virtualization Conference & Expo 2007 West
virt2007west.sys-con.com
AJAXWorld 2007 Conference & Expo West
ajaxoct07.sys-con.com

Cloud Computing Expo Alumni Delegates Represents...

• AccuRev
• Adea Solutions
• Adobe Systems, Inc [3 delegates]
• ADP
• Aeropostale, Inc
• Aetna
• Akbank Training Center
• American Family Insurance
• American International College
• American Modern Insurance
• Amphion Innovations
• Amplify LLC, Clipmarks [2 delegates]
• Anderson Consulting
• Arrow Electronics [3 delegates]
• Ashcroft Inc
• Athabasca University
• ATS
• Audatex
• Avanade, Inc.
• Avaya Inc. [5 delegates]
• Azul [2 delegates]
• Backbase [2 delegates]
• Bank of America
• Bank of NY
• Barnes and Noble
• Barnex Investment International Limited
• BEA
• Bear Stearns [2 delegates]
• Bendel Newspaper Company Limited
• BizInnovative
• Bloomberg [2 delegates]
• BlueBrick Inc.
• BMC Software
• Boeing
• Bottomline Technologies [2 delegates]
• BP
• Broadcom

   read more...
Cloud Computing Blogs
In other words, VMware’s server density is higher. Boles suggests this means that customers should be “assessing virtualisation on a ‘cost per application’ basis. VM density has a sign
Traditionally, the way people have implemented high availability is by using a high-availability management package like Linux-HA[1], then configure it in detail for each application, file system moun