Board logo

subject: How Role Based Permissions Improve Your Cloud Seciruty [print this page]


Considerable amount of time, money, effort, and innovation is spent by many organizations in trying to come up with very complicated, so often redundant, internet security measures. As the internet is an open portal, it is the responsibility of every single organization to ensure the high levels of security of its proprietary information from hackers.

Loss of critical data or inability to control one's own equipment is the proverbial nightmare scenario. Should this data, if you are a government agency, fall into the hands of an unfriendly organization it may very well have national security consequences. Because of market-based and other reasons mentioned, agencies and organizations are already cautious in handling proprietary information and with the integration of systems.

The trend towards cloud computing will continue and questions will be continuously asked about security for the cloud. Just how secure is "the cloud?" While it is possible to be able to benefit economically and logistically when it comes to cloud computing, compromise is never an option when it pertains to the integrated security of important data. Large scale and highly complex cryptography does exist but is it enough. There are several ways of approaching the security problem, including the introduction of role-based security to the cloud computing model.

As a matter of fact, role-based cloud security is an innovative capability that will secure your data at the highest levels and could integrate systems for those organization which have large cloud implementations. Individual people are assigned levels of security based on their ability to access key information and the possible impact or the need they have on this information.

Cloud-enabled organizations of today are able to create, manage, route, manipulate, and even report modifications, use, and access of data which are within protected resources in a public or private cloud network. It should be noted that individuals are not assigned permissions directly, but only as a consequence of their role to the appropriate data. Within an organization the definition of a cloud role is constant, yet individuals may be assigned or reassigned to the role, for flexibility, enhanced security, and logistical control.

In developing protocols for cloud security, there are specific languages for authentication like Security Assertion Markup Language (SAML) which are applied for authentication levels between related domains. Further layers of cloud security may be provided by LDAP integration and a host of other interrelated technologies.

It is through the integration of this protocol and extending it into a cloud scenario that an existing set of trusted user models can be secured and defined. In short, these specialized languages, of which there are several emerging, are used by the cloud security service provider to develop security-focused applications that work in partnership with cloud computing providers like Amazon or Rackspace.

Cloud security specialists often have an independent credentials system that is simply not accessible from the Internet in any direct manner. The access to specific portions of the security application related to key management, user accounts, or actual data are completely separate. Authentication and encryption credentials are established according to customer specific encryption keys and these keys are never stored within the file system, or otherwise accessible.

The all-important keys are encrypted outside the cloud on an inaccessible server. This technology is able to maintain complete separation and organizations, which is enough assurance that any unwanted intrusion by a third party or any tools shall not be granted to your very important data. Cloud security will continue to evolve and improve and be of the highest priority to an enterprise that places security above all else.

by: George Hadjiyanis




welcome to loan (http://www.yloan.com/) Powered by Discuz! 5.5.0