Fortinet Blog | News and Threat Research

  • Products
  • Solutions
  • Service & Support
  • Partners
  • Corporate
  • Resources
  • How to Buy

Cloud Security Alliance (CSA) says Data Breach, Loss Top Cloud Threat List

by RSS Stefanie Hoffman  |  March 08, 2013  |  Category: Industry Trends & News

A new survey of industry experts from the Cloud Security Alliance (CSA) finds data breach and data loss at the top of nine critical threats to cloud security.

Cloud computing is more mainstream among businesses and government now than ever before. CSA’s “The Notorious Nine: Cloud Computing Top Threats in 2013” report details the development of the cloud service model and how it delivers business-supporting technology more efficiently. The shift from server to service-based thinking is transforming the way technology departments think about, design and deliver computing technology and applications.

Yet, the authors of the report acknowledge, these advances have created security vulnerabilities, some of whose full impact is still emerging. CSA committee members note that, among the most significant security risks associated with cloud computing is the tendency to bypass IT departments and information officers.

Although shifting to exclusively cloud technologies is affordable and fast, the report’s authors caution that doing so undermines important business-level security policies, processes and best practices. In the absence of these standards, businesses are vulnerable to security breaches that can quickly erase any gains made by the switch to software-as-a-service (SaaS).

“To effectively manage risks in cloud computing, it is essential for companies to understand today’s and tomorrow’s threats specific to the cloud, and that comes with education and proper due diligence,” said J.R. Santos, global research director of the CSA, in releasing the February 2013 report.

Companies are still not doing their proper due diligence – a real issue, said Santos. CSA notes the report reflects the consensus among experts about the most significant threats to cloud security. The focus: threats specifically related to the shared, on-demand nature of cloud computing.

The top spot goes to data breaches. CSA authors call it every CIO’s worst nightmare: the organization’s sensitive internal data falling into the hands of competitors. While the scenario isn’t new, cloud computing introduces a significant avenue of attack. For instance, if a multi-tenant cloud service database is not properly designed, a flaw in one client’s application could allow an attacker access not only to that client’s data, but every other client’s data as well.

Unfortunately, say CSA experts, while data loss and data leakage are serious threats to cloud computing, the measures to mitigate one of these threats can exacerbate the other. For instance, you may encrypt your data to reduce the impact of a data breach, but if you lose your encryption key, you’ll lose your data. Conversely, you may decide to keep offline backups to reduce the impact of a catastrophic data loss, but this increases your exposure to data breaches.

In the number two spot is data loss – not just at the hands of malicious attackers, though. CSA experts caution any accidental deletion by the cloud service provider – or worse, a physical catastrophe such as a fire – could lead to the permanent loss of customers’ data unless adequate measures are taken to back it up. It’s important to remember the burden of avoiding data loss is a shared responsibility between providers and businesses.

Here is a full list of the report’s critical threats to cloud security:

  1. Data Breaches

  2. Data Loss

  3. Account Hijacking

  4. Insecure APIs

  5. Denial of Service

  6. Malicious Insiders

  7. Abuse and Nefarious Use

  8. Insufficient Due Diligence

  9. Shared Technology Issues

For more information on the survey and more details about these critical threats, check CSA’s complete Top Threats Working Group report “The Notorious Nine: Cloud Computing Top Threats in 2013.”

by RSS Stefanie Hoffman  |  March 08, 2013  |  Category: Industry Trends & News
comments powered by Disqus

Category

  • All
  • RSS Subscribe
  • Security Research
  • RSS Subscribe
  • Industry Trends & News
  • RSS Subscribe

FortiGuard Labs on the Web

  • Twitter Twitter
  • Facebook Facebook
  • LinkedIn LinkedIn
  • Youtube Youtube

Monthly Archives

  • May 2013 7
  • April 2013 17
  • March 2013 12
  • February 2013 11
  • January 2013 12
  • December 2012 8
  • November 2012 7
  • October 2012 4
  • September 2012 7
  • August 2012 7
  • July 2012 9
  • June 2012 17
  • May 2012 14
  • April 2012 16
  • March 2012 15
  • February 2012 11
  • January 2012 6
  • December 2011 4
  • November 2011 6
  • October 2011 11
  • September 2011 2
  • August 2011 2
  • July 2011 4
  • June 2011 6
  • May 2011 6
  • April 2011 5
  • March 2011 7
  • February 2011 5
  • January 2011 7
  • December 2010 8
  • November 2010 11
  • October 2010 3
  • September 2010 8
  • August 2010 4
  • July 2010 9
  • June 2010 9
  • May 2010 9
  • April 2010 6
  • March 2010 8
  • February 2010 6
  • January 2010 9
  • December 2009 8
  • November 2009 6
  • October 2009 6
  • September 2009 8
  • August 2009 5
  • July 2009 8
  • June 2009 7
  • May 2009 4
  • April 2009 7
  • March 2009 9
  • February 2009 4
  • January 2009 1
  • Older

Popular topics

Cryptography network security symbianos trojan mobile malware Security Anti-Spam apple hashdays google mobile phone microsoft mobile bredolab Threat Landscape Zeus BYOD Research reversing botnet mobile phones exploit facebook zitmo Malware Anonymous FortiGate sms iphone Mac OS X Fortinet symbos/yxes adobe stuxnet derek manky hacking challenge Windows Mobile Security symbian UTM Antivirus Firewall conference webinar android reverse engineering challenge SpyEye virut privacy