21 April 2009

Web Application Security in the Cloud - Part 2

In Web Application Security in the Cloud Part 1, I mentioned some risks associated with "cloud computing", and other services provided online by third parties.

At my work, we sometimes use Infrastructure as a Service (IaaS) virtual hosting to undertake testing. These are not a business critical use and there is never any client, or business, data on the servers. One of these is GoGrid. A few weeks ago it seems their services were offline for an extended period (significant if the service is a vital process), due to a combination of denial of service (DoS) attack and scheduled maintenance, culminating in this Update from GoGrid Founders:

Partial screen capture showing blog posting by the GoGrid founders on 31 March 2009 - full text content available via the link above

I applaud the efforts undertaken by service providers such as these, rather than being unable to recover like Ma.gnolia after a, much less complex, database and backup loss:

Partial screen capture showing the Ma.gnolia home page on 17 February 2009 - full text content available via the link above

The video on the Ma.gnolia home page is worth watching before signing contracts with third party providers.

For further discussion of the issues, some further blog posts which I recommend, are:

Look before you leap!

Update 27th November 2009: See also Cloud Computing Risks.

Posted on: 21 April 2009 at 09:00 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Web Application Security in the Cloud - Part 2
http://www.clerkendweller.com/2009/4/21/Web-Application-Security-in-the-Cloud-2
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2009/4/21/Web-Application-Security-in-the-Cloud-2
Requested by 38.107.191.106 on Wednesday, 8 September 2010 at 00:34 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2009-2010 clerkendweller.com