IBM improves cloud security
IBM unveiled a new security initiative focused on making cloud computing safer. IBM aims to help both users and providers of cloud computing more easily navigate security challenges through new cloud security planning and assessment services, managed services to help clients secure their clouds, and the introduction of several technology innovations.
According to an IBM study, cloud computing raised serious concerns among respondents about the use, access and control of data: 77 percent of respondents believe that adopting cloud computing makes protecting privacy more difficult; 50 percent are concerned about a data breach or loss; and 23 percent indicate that weakening of corporate network security is a concern. As the study illustrates, businesses see the promise of the cloud model, but security remains an inhibitor to adoption.
While an IT foundation pertains to all cloud computing, providers and users do not generally rely on one generic model for data security.
Both cloud providers and users should consider a variety of factors, including the kind of work a client wants to do in the cloud and the mechanisms and controls used. For example, clients who have collaboration tools and email work in the cloud should think about access and policy controls, while clients focused on healthcare in the cloud should be concerned with data isolation and encryption.
“IBM understands the “one size fits all’ cloud security strategy will not work for most businesses,” said Steve Robinson, general manager, IBM Security Solutions. “Our enterprise clients are looking for a trusted advisor to provide the right mix of security consulting services and offerings to match. By offering these new services and innovations, we aim to help clients create tailored solutions that will allow them to get the most out of their cloud environments.”
New IBM cloud security infrastructure and services
IBM is using its expertise to outline a two-pronged approach for clients seeking to dramatically improve cloud security:
1. Plan and assess the security strategy for the cloud
IBM Cloud Security Strategy Roadmap – For clients who are embarking on a cloud strategy as either a provider or subscriber, the new roadmap is designed to help organizations understand, establish and outline the steps for realizing their security goals in relation to their cloud computing strategy. IBM security experts conduct an onsite working session with clients to help define the cloud computing initiative and goals, identify associated security and privacy concerns, determine appropriate vulnerability mitigation strategies and develop a high-level security strategy roadmap designed to achieve their cloud security objectives.
IBM Cloud Security Assessment – For clients with cloud infrastructure in place or planning their cloud environment, the new assessment is designed to help provide an in-depth understanding of the current state of a current or planned cloud solution’s security controls, mechanisms and architecture. IBM assessment professionals help compare the cloud solution’s security program against industry best practices and the client’s own cloud security objectives, then identifies steps to help improve the overall security environment.
IBM Application Security Services for Cloud – The new offering allows CIOs to have a clear picture of how and where sensitive data will circulate in a cloud environment. It assesses current or proposed cloud application environments to help ensure that the appropriate information, security, and privacy controls are in place for a client’s specific business requirements. By identifying and prioritizing cloud-specific security vulnerabilities, internally and within their service providers, the offering can help clients determine the right balance of internal control and service provider autonomy required to maintain efficiency and service level requirements before implementing the solution.
2. Obtain security services from the cloud
IBM Managed Security Services Hosted Security Event and Log Management – This enhanced offering is a cloud-based solution for security incident and event management that consolidates the security event and log data of operating systems, applications and infrastructure equipment, providing a seamless platform from which to assess and respond to real-time and historical traffic. It improves the speed of security investigations and compliance initiatives, offering the full life cycle of security information and event management, and provides options to outsource these tasks to security experts located in IBM’s worldwide Security Operation Centers.
IBM Managed Security Services Hosted Vulnerability Management – This enhanced cloud-based scanning service helps companies to identify vulnerabilities across network devices, servers, web applications and databases to help manage concerns and reduce the cost of security operations. This service is available to companies of all sizes who want to quickly and more easily address compliance mandates.