Cloud Security WebForum Brief
The Cloud Security session was good with over 100 participants. Although most of the participants indicated a limited usage of the cloud currently, the interest in the topic we see during WebForums and Roundtables shows that cloud usage is increasing.
Much of the discussion centered on the security standards that cloud providers should be able to adhere to, such as
SOC 1 and SOC 2 (Service Organization Controls which involve security audits)
ISO27002 (International Organization for Standardization’s Information Security Standard)
FIPS (Federal Information Processing Standards)
21CFR (Code of Federal Regulations section effecting organizations subject to FDA controls)
HIPAA BAA (Health Information Portability and Accountability Act Business Associate Agreement effecting organizations that must secure PHI-Private Health Information)
Basically these are the various security-related standards that organizations must adhere to and are important to address in contracts with cloud providers.
Recommended tools included:
DataSafe as a cloud provider that can adhere to HIPAA and will sign a BAA.
Netskope as a tool to evaluate the risk of putting specific applications in the cloud.
Box was recommended for cloud file sharing and online collaboration. One member said it has saved his organization significant dollars by reducing the need to purchase on-premises storage.
Encryption was another big issue. In many cases, it is recommended that data be encrypted at both ends…by the cloud provider and the organization using the cloud…for an extra measure of security.











