«

»

Feb 07

Cloud Security

Just what certification should you cloud provider have?

SAS-70, verifies the service providers control processes, but these are defined by the service provider!  Customers have to determine if these controls are adequate

ISO 27001, specifies how service providers should handle security controls & risk assessment, again, these controls are self-defined by the provider.

The Trusted Security Certification Program is being developed by the Cloud Security Alliance (CSA). It’s Vendor neutral and covers security, access & compliance management practises, it will include certification criteria & reference models from existing standards. 





Related Posts
Deploying vSphere 4.1?  Concerned about security and unsure where to look? VMware Communities: vSphere 4.1 Security Hardening Guide (draft).
READ MORE
VMware Communities: vSphere 4.1 Security Hardening Guide (draft)