<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>CloudEnterprise.info &#187; Security</title>
	<atom:link href="http://cloudenterprise.info/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://cloudenterprise.info</link>
	<description>Cloud Computing and SaaS for the Enterprise</description>
	<lastBuildDate>Fri, 11 May 2012 22:56:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='cloudenterprise.info' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>CloudEnterprise.info &#187; Security</title>
		<link>http://cloudenterprise.info</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://cloudenterprise.info/osd.xml" title="CloudEnterprise.info" />
	<atom:link rel='hub' href='http://cloudenterprise.info/?pushpress=hub'/>
		<item>
		<title>Cloud with an eagle eye</title>
		<link>http://cloudenterprise.info/2010/10/21/cloud-with-an-eagle-eye/</link>
		<comments>http://cloudenterprise.info/2010/10/21/cloud-with-an-eagle-eye/#comments</comments>
		<pubDate>Thu, 21 Oct 2010 22:17:47 +0000</pubDate>
		<dc:creator>Dmitry Sotnikov</dc:creator>
				<category><![CDATA[Quest OnDemand]]></category>
		<category><![CDATA[alerts]]></category>
		<category><![CDATA[auditing]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[Quest Software]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SEIM]]></category>

		<guid isPermaLink="false">http://cloudenterprise.info/?p=440</guid>
		<description><![CDATA[Cloud can make your environment *more* secure. A new cloud service alerts IT pros when specific events happen in their environment. For example, you might want to receive an email when a sensitive resource gets accessed, certain permissions get granted, membership for a privileged group gets changed and so on. This all is now part of the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=440&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Cloud can make your environment <strong>*more*</strong> secure. A new cloud service alerts IT pros when specific events happen in their environment. For example, you might want to receive an email when a sensitive resource gets accessed, certain permissions get granted, membership for a privileged group gets changed and so on. This all is now part of the <a href="http://www.quest.com/ondemand-log-management/">Quest OnDemand Log Management service</a> &#8211; just watch this two-minute video to see how it works:</p>
<span style="text-align:center; display: block;"><a href="http://cloudenterprise.info/2010/10/21/cloud-with-an-eagle-eye/"><img src="http://img.youtube.com/vi/C6iiTfYs_ls/2.jpg" alt="" /></a></span>
<p><em>(Full disclosure: I work for Quest Software and participate in our Quest OnDemand efforts.)</em></p>
<p>What&#8217;s best is that this is a cloud service &#8211; so no local deployment or additional infrastructure is required. You can just go to the website, sign-up for a free trial, download a small agent, and start getting alerts for the events you care about!</p>
<p>Cloud is good for you! <a href="http://www.quest.com/ondemand-log-management/">Sign-up for a free trial now</a> and have the cloud help you keep your environment secure.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cloudenterprise.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cloudenterprise.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cloudenterprise.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cloudenterprise.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cloudenterprise.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cloudenterprise.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cloudenterprise.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cloudenterprise.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cloudenterprise.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cloudenterprise.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cloudenterprise.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cloudenterprise.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cloudenterprise.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cloudenterprise.wordpress.com/440/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=440&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cloudenterprise.info/2010/10/21/cloud-with-an-eagle-eye/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6ecc57e2c1be48013620bf85fb983dbf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dmitrysotnikov</media:title>
		</media:content>
	</item>
		<item>
		<title>Cloud or On-Premise: Which is more secure?</title>
		<link>http://cloudenterprise.info/2010/10/15/cloud-or-on-premise-which-is-more-secure/</link>
		<comments>http://cloudenterprise.info/2010/10/15/cloud-or-on-premise-which-is-more-secure/#comments</comments>
		<pubDate>Fri, 15 Oct 2010 19:03:35 +0000</pubDate>
		<dc:creator>Dmitry Sotnikov</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Data breach]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[Data theft]]></category>

		<guid isPermaLink="false">http://cloudenterprise.info/?p=426</guid>
		<description><![CDATA[It bugs me that for some irrational reason there is still a common-sense believe that data is more protected when kept in someone&#8217;s own datacenter and not with a trusted cloud provider. US Department of Health and Human Services (HHS) has just published data on past year data breaches in the medical industry. These only [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=426&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://commons.wikimedia.org/wiki/File:DHHS2_by_Matthew_Bisanz.JPG"><img class="alignleft" title="The Department of Health and Human Services headquarters by the National Mall, image from wikipedia" src="http://upload.wikimedia.org/wikipedia/commons/thumb/7/73/DHHS2_by_Matthew_Bisanz.JPG/120px-DHHS2_by_Matthew_Bisanz.JPG" alt="The Department of Health and Human Services headquarters by the National Mall, image from wikipedia" width="120" height="67" /></a>It bugs me that for some irrational reason there is still a common-sense believe that data is more protected when kept in someone&#8217;s own datacenter and not with a trusted cloud provider.</p>
<p><a href="http://www.hhs.gov">US Department of Health and Human Services (HHS)</a> has just published <a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html">data on past year data breaches in the medical industry</a>. These only include breaches affecting 500 or more individuals and reaching the “harm” threshold defined by the current rules. Yet, there <strong>166 </strong>of those affecting the total of <strong>4,905,768</strong> patients.</p>
<p>PHIPrivacy.net does a good job <a href="http://www.phiprivacy.net/?p=4182">analyzing the breach data</a>, and you can see that even in the industry which is highly regulated and paranoid about data security and privacy &#8211; data being stored locally is getting stolen or lost all the time.</p>
<p>Compare that to a cloud provider (pick any cloud service which you like: <a href="http://Salesforce.com">Salesforce.com</a>, <a href="http://www.microsoft.com/online/business-productivity.aspx">Microsoft BPOS</a>, <a href="http://aws.amazon.com/">Amazon</a>, <a class="zem_slink" title="Google Apps" rel="homepage" href="http://www.google.com/apps/">Google Apps</a>, <a href="http://www.quest.com/ondemand/">Quest OnDemand</a>) &#8211; have you heard of 166 breaches for any of those? There are good reasons why you have not:</p>
<ul>
<li><strong>High security standards of the datacenters</strong>: a lot of these are compliant with <strong><a class="zem_slink" title="Statement on Auditing Standards No. 70: Service Organizations" rel="wikipedia" href="http://en.wikipedia.org/wiki/Statement_on_Auditing_Standards_No._70%3A_Service_Organizations">SAS 70</a> Type I and Type II</strong> and <strong><a class="zem_slink" title="ISO/IEC 27001" rel="wikipedia" href="http://en.wikipedia.org/wiki/ISO/IEC_27001">ISO/IEC 27001:2005</a></strong> &#8211; does your datacenter get formally certified that high?</li>
<li><strong>Clear <a class="zem_slink" title="Separation of duties" rel="wikipedia" href="http://en.wikipedia.org/wiki/Separation_of_duties">segregation of duties</a></strong>: people running the datacenter are not your employees, they have no idea what kind of data is getting stored by who and no vested interest in seeing that data,</li>
<li><strong><a href="http://en.wikipedia.org/wiki/Needle_in_a_haystack">Needle in a haystack</a> effect</strong>: public clouds have multiple customers, so even if a squad of ninjas attack the datacenter and manage to steel a harddrive it will just have some bits from data from various customers in format specific to a particular application and probably encrypted &#8211; making the whole exersize completely meaningless,</li>
<li><strong>No local device data</strong>: your local laptops or mobile devices only work with remote cloud data &#8211; so if the device gets lost or stolen you loose the device, not the data.</li>
<li><strong>Security is in the cloud business model</strong>: for any credible SaaS vendor security is number one concern (see for example <a href="http://www.quest.com/ondemand/security.aspx">Quest OnDemand security FAQ</a>). They implement specific security measures such as data isolation, audit trails, and so on.</li>
</ul>
<p>It is just incredibly hard and costly to set all these measures and maintain them, and I find it hard to see how (apart from really select few companies) these days will have the resources to provide that level of protection and security for on-premise systems. Cloud makes things <em>more</em> secure. Cloud is good for you.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cloudenterprise.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cloudenterprise.wordpress.com/426/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cloudenterprise.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cloudenterprise.wordpress.com/426/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cloudenterprise.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cloudenterprise.wordpress.com/426/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cloudenterprise.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cloudenterprise.wordpress.com/426/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cloudenterprise.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cloudenterprise.wordpress.com/426/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cloudenterprise.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cloudenterprise.wordpress.com/426/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cloudenterprise.wordpress.com/426/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cloudenterprise.wordpress.com/426/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=426&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cloudenterprise.info/2010/10/15/cloud-or-on-premise-which-is-more-secure/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6ecc57e2c1be48013620bf85fb983dbf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dmitrysotnikov</media:title>
		</media:content>

		<media:content url="http://upload.wikimedia.org/wikipedia/commons/thumb/7/73/DHHS2_by_Matthew_Bisanz.JPG/120px-DHHS2_by_Matthew_Bisanz.JPG" medium="image">
			<media:title type="html">The Department of Health and Human Services headquarters by the National Mall, image from wikipedia</media:title>
		</media:content>
	</item>
		<item>
		<title>Gartner case study on transition from software to services</title>
		<link>http://cloudenterprise.info/2010/09/30/gartner-case-study-on-transition-from-software-to-services/</link>
		<comments>http://cloudenterprise.info/2010/09/30/gartner-case-study-on-transition-from-software-to-services/#comments</comments>
		<pubDate>Thu, 30 Sep 2010 12:00:41 +0000</pubDate>
		<dc:creator>Dmitry Sotnikov</dc:creator>
				<category><![CDATA[Analysts]]></category>
		<category><![CDATA[case-study]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Gartner]]></category>
		<category><![CDATA[Information technology]]></category>
		<category><![CDATA[Quest Software]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security event manager]]></category>
		<category><![CDATA[SEIM]]></category>

		<guid isPermaLink="false">http://cloudenterprise.info/?p=417</guid>
		<description><![CDATA[Ruggero Contu has published a case study which he created after studying Quest Software&#8216;s transition from being a pure software vendor to also a SaaS cloud-based IT management company: &#8220;Case Study: Quest Leverages Cloud Services to Introduce SaaS-Based Log Management Product&#8221; (registration required to access the page): Although new business opportunities can justify a SaaS [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=417&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-418" title="Gartner-Logo" src="http://cloudenterprise.files.wordpress.com/2010/09/gartner-logo.jpg?w=480" alt=""   />Ruggero Contu has published a case study which he created after studying <a href="http://www.quest.com">Quest Software</a>&#8216;s transition from being a pure software vendor to also a <a href="http://www.quest.com/ondemand">SaaS cloud-based IT management company</a>: &#8220;<a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=260&amp;mode=2&amp;PageID=3460702&amp;resId=1440071">Case Study: Quest Leverages Cloud Services to Introduce SaaS-Based Log Management Product</a>&#8221; (registration required to access the page):</p>
<blockquote><p>Although new business opportunities can justify a SaaS project, implementation of a new cloud-based offering is not a straightforward task. CTOs, development managers, and sales, marketing and service delivery managers should plan for the far-reaching changes needed across the organization to reach a successful implementation.</p>
<p>&#8230;</p>
<p>SaaS-based security products have been gaining popularity and adoption within organizations over the past few years. Although demand for SaaS-based security information event management (<a class="zem_slink" title="Security event manager" rel="wikipedia" href="http://en.wikipedia.org/wiki/Security_event_manager">SIEM</a>) products is not as high as for other security areas, such as messaging security and remote vulnerability assessment, SaaS-based SIEM is a valuable option for those enterprises that cannot implement security information tools. An on-premises SIEM implementation may not be justified, particularly in those cases where there are limited resources available to be dedicated to deploying and managing SIEM products; the cost of SIEM implementation may be unjustified also in those instances with well-defined but limited technology needs, such as to meet a specific regulatory requirement. As a result, there are interesting market opportunities for SIEM vendors willing to embark on the launch of a <a href="http://www.quest.com/ondemand-log-management/">SaaS-based log management solution</a>. This Case Study discusses how Quest Software developed and implemented a SaaS-based product offering.</p></blockquote>
<p>Ruggero goes into the details of why and how Quest went from software to SaaS, what was involved in the transition, and which benefits did this move bring to both the vendor and its customers.</p>
<p>If you work for a software company considering a similar move, or if you are an IT professional considering starting to use SaaS in your environment, I would recommend obtaining and reading the full document <a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=260&amp;mode=2&amp;PageID=3460702&amp;resId=1440071">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cloudenterprise.wordpress.com/417/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cloudenterprise.wordpress.com/417/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cloudenterprise.wordpress.com/417/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cloudenterprise.wordpress.com/417/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cloudenterprise.wordpress.com/417/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cloudenterprise.wordpress.com/417/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cloudenterprise.wordpress.com/417/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cloudenterprise.wordpress.com/417/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cloudenterprise.wordpress.com/417/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cloudenterprise.wordpress.com/417/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cloudenterprise.wordpress.com/417/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cloudenterprise.wordpress.com/417/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cloudenterprise.wordpress.com/417/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cloudenterprise.wordpress.com/417/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=417&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cloudenterprise.info/2010/09/30/gartner-case-study-on-transition-from-software-to-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6ecc57e2c1be48013620bf85fb983dbf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dmitrysotnikov</media:title>
		</media:content>

		<media:content url="http://cloudenterprise.files.wordpress.com/2010/09/gartner-logo.jpg" medium="image">
			<media:title type="html">Gartner-Logo</media:title>
		</media:content>
	</item>
		<item>
		<title>When federation does not work</title>
		<link>http://cloudenterprise.info/2010/09/21/when-federation-does-not-work/</link>
		<comments>http://cloudenterprise.info/2010/09/21/when-federation-does-not-work/#comments</comments>
		<pubDate>Tue, 21 Sep 2010 11:00:35 +0000</pubDate>
		<dc:creator>Dmitry Sotnikov</dc:creator>
				<category><![CDATA[Quest OnDemand]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Active Directory Federation Services]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Federation]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows Live ID]]></category>

		<guid isPermaLink="false">http://cloudenterprise.info/?p=391</guid>
		<description><![CDATA[One of the leading providers of IT management SaaS &#8211; Quest OnDemand &#8211; has decided to stop using federation with Live ID as its main user authentication method and switched to simple email address/password way. In the age of everyone trying to federate with everyone else this move seems to be going into the opposite [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=391&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/File:WLIDLogo.PNG"><img class="alignleft" title="The official Windows Live ID logo. Opaque back..." src="http://upload.wikimedia.org/wikipedia/en/6/67/WLIDLogo.PNG" alt="The official Windows Live ID logo. Opaque back..." width="90" height="90" /></a></p>
<p>One of the leading providers of IT management <a class="zem_slink" title="Software as a Service" rel="wikinvest" href="http://www.wikinvest.com/concept/Software_as_a_Service">SaaS</a> &#8211; <a href="http://www.quest.com/ondemand">Quest OnDemand</a> &#8211; has decided to stop using federation with <a href="http://login.live.com">Live ID</a> as its main user <a class="zem_slink" title="Authentication" rel="wikipedia" href="http://en.wikipedia.org/wiki/Authentication">authentication</a> method and switched to simple email address/password way.</p>
<p>In the age of everyone trying to federate with everyone else this move seems to be going into the opposite direction. It turned out that in this particular case &#8211; IT professionals signing up for a service &#8211; found having to use a third-party identity to be not intuitive and had privacy concerns about the same identity being used for different levels of access to various services from different vendors.</p>
<p>Let&#8217;s have a look at what was the rationale behind choosing Live ID initially and then abandoning it. I hope that these lessons learnt will help more thoughtful discussion of when and what kind of federation is the right one to use as opposed to someone one-sided perspective the industry seems to have at the moment.</p>
<p><strong>Why Live ID?</strong></p>
<p>Quest OnDemand is a set of online services for Windows IT professionals. The services currently available include<a href="http://www.quest.com/ondemand/on-demand-log-mgmt.aspx"> eventlog management</a> and <a href="http://www.quest.com/ondemand/on-demand-rmad.aspx">AD backup and recovery</a>. Considering that these are primarily used by IT professionals in the Microsoft world, and that Microsoft uses Live ID (also known as Microsoft Passport or MSN Passport) as a way to authenticate for all Microsoft&#8217;s services, it made total sense to let users sign into the new service with their existing Live ID accounts instead of making them register new ones.</p>
<p>When we launched Quest OnDemand in June 2010, anyone interested in any of its services could just come to<a href="http://portal.ondemand.quest.com"> portal.ondemand.quest.com</a> and sign in with Live ID credentials.</p>
<p><strong>What went wrong?</strong></p>
<p>Once we launched we got overwhelmed by our users telling us how confused and frustrated they were.</p>
<p>The complaints seemed to fall into a few categories:</p>
<p><em>Confusion about Live ID</em></p>
<p>Surprisingly enough, a lot of people don&#8217;t realize that Live ID is an authentication system which can be used across other web properties from various companies. A lot of people don&#8217;t know that what they are using to post to Microsoft&#8217;s forums or access their hotmail account is indeed Windows Live ID.</p>
<p>Users signing up or deciding to try a service from your company want that to be a business between them and your company, and are not expecting a third party to get into the mix.</p>
<p><em>Broken workflow</em></p>
<p>User experience suffered from users being taken away to another site with different look and feel during their registration process. When user already had a Live ID and used it to sign-in this was not as bad &#8211; she was taken back to Quest OnDemand upon authentication. However, if a new ID had to be created user was taken away completely, asked a lot of unrelated questions such as date of birth, and then not brought back to the original site.</p>
<p>If you want your customers to survive your sign-up procedure you need to control the account creation experience &#8211; just redirecting them to a third-party site does not work.</p>
<p><em>Privacy concerns</em></p>
<p>Even though all Quest OnDemand wanted to know about customers were their Live ID logon names (for example, to be then used as handles for delegation purposes) Live ID in theory holds keys to a lot more data including for example hotmail address book. From the web user interfaces customers could not clearly see that they are not accidentally providing access to their private data and as result did not want to proceed with the delegation.</p>
<p><a href="http://cloudenterprise.files.wordpress.com/2010/09/live-id-delegation.png"><img class="aligncenter size-medium wp-image-394" title="Live ID delegation" src="http://cloudenterprise.files.wordpress.com/2010/09/live-id-delegation.png?w=300&h=147" alt="" width="300" height="147" /></a></p>
<p><em>Using primary ID seems to be a big commitment</em></p>
<p>Email address is a much smaller commitment for a service sign-up than some sort of credentials you are actively using as your core identity. If I try a service and I don&#8217;t like it worst case &#8211; the vendor will send me some email from which I will need to unsubscribe. If I share the ID I am actively using it kind of feels like I am committing myself in a bigger way and will not have the flexibility to easily go away, and then maybe come again some other day and so on.</p>
<p>The industry has trained customers to supply email addresses pretty much for any sort of access &#8211; now this is what people are expecting to use for sign-ups.</p>
<p><strong>What&#8217;s there now?</strong></p>
<p>Starting last Friday, Live ID is gone (obviously with all existing customer profiles and data migrated) and we are back to simple email address and password sign-in process.</p>
<p><a href="http://cloudenterprise.files.wordpress.com/2010/09/quest-ondemand-sign-up.png"><img class="aligncenter size-medium wp-image-396" title="Quest OnDemand sign-up" src="http://cloudenterprise.files.wordpress.com/2010/09/quest-ondemand-sign-up.png?w=300&h=209" alt="" width="300" height="209" /></a></p>
<p>The benefit is that although there is indeed yet another password to keep in mind (or to reset every now and then when you forget it), the web site behavior is completely expected and well understood by anyone, and the sign-up process includes way smaller number of steps and is easier to follow.</p>
<p><strong>Is federation dead?</strong></p>
<p>Not at all. There are multiple other cases in which identity federation makes total sense and makes users&#8217; lives easier and solutions more secure. For example, while dropping Live ID, Quest OnDemand still has <a href="http://en.wikipedia.org/wiki/Active_Directory_Federation_Services">Active Directory Federation Services</a> (ADFS) authentication option for enterprises federating their local Active Directory with Quest&#8217;s cloud. In fact, this is the only way Quest&#8217;s own employees (for example, technical support) can log onto Quest OnDemand. In this case, federation has clear advantage because it provides tight access control and ensures that only authorized Quest employees access the service and the access happens under strict corporate control.</p>
<p>There are cases in which federation works great and is the best way to implement user access to your system. There are cases in which it is not. Carefully evaluate your options and find which solutions works best for your customers!</p>
<p>Did you have similar experience on federation either not working or quite opposite solving your problems? If so &#8211; please share.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cloudenterprise.wordpress.com/391/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cloudenterprise.wordpress.com/391/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cloudenterprise.wordpress.com/391/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cloudenterprise.wordpress.com/391/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cloudenterprise.wordpress.com/391/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cloudenterprise.wordpress.com/391/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cloudenterprise.wordpress.com/391/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cloudenterprise.wordpress.com/391/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cloudenterprise.wordpress.com/391/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cloudenterprise.wordpress.com/391/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cloudenterprise.wordpress.com/391/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cloudenterprise.wordpress.com/391/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cloudenterprise.wordpress.com/391/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cloudenterprise.wordpress.com/391/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=391&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cloudenterprise.info/2010/09/21/when-federation-does-not-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6ecc57e2c1be48013620bf85fb983dbf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dmitrysotnikov</media:title>
		</media:content>

		<media:content url="http://upload.wikimedia.org/wikipedia/en/6/67/WLIDLogo.PNG" medium="image">
			<media:title type="html">The official Windows Live ID logo. Opaque back...</media:title>
		</media:content>

		<media:content url="http://cloudenterprise.files.wordpress.com/2010/09/live-id-delegation.png?w=300" medium="image">
			<media:title type="html">Live ID delegation</media:title>
		</media:content>

		<media:content url="http://cloudenterprise.files.wordpress.com/2010/09/quest-ondemand-sign-up.png?w=300" medium="image">
			<media:title type="html">Quest OnDemand sign-up</media:title>
		</media:content>
	</item>
		<item>
		<title>IT Management as a Service: Discussion and Demo</title>
		<link>http://cloudenterprise.info/2010/03/18/it-management-as-a-service-discussion-and-demo/</link>
		<comments>http://cloudenterprise.info/2010/03/18/it-management-as-a-service-discussion-and-demo/#comments</comments>
		<pubDate>Thu, 18 Mar 2010 12:27:04 +0000</pubDate>
		<dc:creator>Dmitry Sotnikov</dc:creator>
				<category><![CDATA[Quest OnDemand]]></category>
		<category><![CDATA[architecture]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[demo]]></category>
		<category><![CDATA[Federation]]></category>
		<category><![CDATA[Interview]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Systems Management as a Service]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[Windows Azure]]></category>

		<guid isPermaLink="false">http://cloudenterprise.info/?p=358</guid>
		<description><![CDATA[Microsoft&#8217;s TechNet EDGE posted a video with quite detailed discussion of Systems Management as a Service concept, example of such a service (Quest OnDemand), how it uses Windows Azure as the underlying technology, the security model behind it, and so on. Obviously a demo is in there as well. Check out the video here.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=358&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Microsoft&#8217;s TechNet EDGE <a href="http://edge.technet.com/Media/IT-Software-as-a-Service-on-Windows-Azure">posted a video</a> with quite detailed discussion of Systems Management as a Service concept, example of such a service (<a href="http://www.quest.com/ondemand">Quest OnDemand</a>), how it uses <a href="http://www.microsoft.com/windowsazure">Windows Azure</a> as the underlying technology, the security model behind it, and so on. Obviously a demo is in there as well.</p>
<p><a href="http://edge.technet.com/Media/IT-Software-as-a-Service-on-Windows-Azure"><img src="http://cloudenterprise.files.wordpress.com/2010/03/technet-edge-ondemand.jpg?w=480" alt="" title="TechNet-EDGE-OnDemand"   class="aligncenter size-full wp-image-359" /></a></p>
<p>Check out the video <a href="http://edge.technet.com/Media/IT-Software-as-a-Service-on-Windows-Azure">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cloudenterprise.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cloudenterprise.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cloudenterprise.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cloudenterprise.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cloudenterprise.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cloudenterprise.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cloudenterprise.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cloudenterprise.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cloudenterprise.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cloudenterprise.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cloudenterprise.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cloudenterprise.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cloudenterprise.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cloudenterprise.wordpress.com/358/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=358&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cloudenterprise.info/2010/03/18/it-management-as-a-service-discussion-and-demo/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6ecc57e2c1be48013620bf85fb983dbf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dmitrysotnikov</media:title>
		</media:content>

		<media:content url="http://cloudenterprise.files.wordpress.com/2010/03/technet-edge-ondemand.jpg" medium="image">
			<media:title type="html">TechNet-EDGE-OnDemand</media:title>
		</media:content>
	</item>
		<item>
		<title>Case-Study on Secure SaaS</title>
		<link>http://cloudenterprise.info/2010/01/15/case-study-on-secure-saas/</link>
		<comments>http://cloudenterprise.info/2010/01/15/case-study-on-secure-saas/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 15:40:21 +0000</pubDate>
		<dc:creator>Dmitry Sotnikov</dc:creator>
				<category><![CDATA[Quest OnDemand]]></category>
		<category><![CDATA[ADFS]]></category>
		<category><![CDATA[case-study]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Federation]]></category>
		<category><![CDATA[Quest Software]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows Identity Foundation]]></category>

		<guid isPermaLink="false">http://cloudenterprise.info/?p=344</guid>
		<description><![CDATA[Security and data protection are key concerns for any cloud solution. I truly believe that this is also one aspect that you cannot just improve over time. No matter how agile you are security needs to be there by design. Unfortunately most cloud vendors/SaaS-providers still don&#8217;t tell enough about the way they protect customer data [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=344&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Security and data protection are key concerns for any cloud solution. I truly believe that this is also one aspect that you cannot just improve over time. No matter how agile you are security needs to be there by design.</p>
<p>Unfortunately most cloud vendors/SaaS-providers still don&#8217;t tell enough about the way they protect customer data &#8211; which <a href="http://en.wikipedia.org/wiki/Security_through_obscurity">we know is a bad idea</a>.</p>
<p>From that perspective you might find this case study which Microsoft has just posted worth reading: <a href="http://www.microsoft.com/casestudies/Case_Study_Detail.aspx?CaseStudyID=4000006270">Systems Manager Offers Security-Enhanced, Hosted Solutions with Programming Framework</a>. The case study lists some of the technologies used in <strong>Quest OnDemand</strong> &#8211; <a href="http://cloudenterprise.info/2010/01/08/details-on-quest-ondemand/">Quest Software&#8217;s Systems Management as a Service product family</a>.</p>
<p>There&#8217;s more to security than just encrypting internet traffic. The case study discusses how latest technology such as <a href="Windows Identity Foundation">Windows Identity Foundation</a> and <a href="http://www.microsoft.com/windowsserver2008/en/us/ad-fs.aspx">Active Directory Federation Services 2.0</a> helped us make sure that customers are always in control of their data, which includes not just protecting data from those who should not have access (including Quest&#8217;s own engineers!) to it but also a convenient and secure way to delegate access to those who should.</p>
<p>I hope this helps you get a good overview to one of the approaches to cloud security. Read the case study <a href="http://www.microsoft.com/casestudies/Case_Study_Detail.aspx?CaseStudyID=4000006270">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cloudenterprise.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cloudenterprise.wordpress.com/344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cloudenterprise.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cloudenterprise.wordpress.com/344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cloudenterprise.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cloudenterprise.wordpress.com/344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cloudenterprise.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cloudenterprise.wordpress.com/344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cloudenterprise.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cloudenterprise.wordpress.com/344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cloudenterprise.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cloudenterprise.wordpress.com/344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cloudenterprise.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cloudenterprise.wordpress.com/344/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=344&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cloudenterprise.info/2010/01/15/case-study-on-secure-saas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6ecc57e2c1be48013620bf85fb983dbf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dmitrysotnikov</media:title>
		</media:content>
	</item>
		<item>
		<title>Can cloud make you MORE compliant?</title>
		<link>http://cloudenterprise.info/2009/04/06/can-cloud-make-you-more-compliant/</link>
		<comments>http://cloudenterprise.info/2009/04/06/can-cloud-make-you-more-compliant/#comments</comments>
		<pubDate>Mon, 06 Apr 2009 10:13:00 +0000</pubDate>
		<dc:creator>Dmitry Sotnikov</dc:creator>
				<category><![CDATA[Analysts]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cloudenterprise.info/?p=234</guid>
		<description><![CDATA[The common word out there about cloud computing/SaaS and security/regulatory compliance are that these don&#8217;t go well together. However, things don&#8217;t have to be that way. Doing security right can cost a lot of money and public cloud services could carry some of these costs. Thus, there probably will be a point in time when [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=234&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Scott Crawford" src="http://www.enterprisemanagement.com/images/research/photos/Scott_Crawford.jpg" alt="" width="68" height="76" />The common word out there about cloud computing/SaaS and security/regulatory compliance are that these don&#8217;t go well together. However, things don&#8217;t have to be that way. Doing security right can cost a lot of money and public cloud services could carry some of these costs. Thus, there probably will be a point in time when paradoxically cloud may become a cost-effective way to compliance.</p>
<p>With these thoughts in mind, I was delighted to find a report by <a href="http://www.enterprisemanagement.com/about/team/Scott_Crawford.php">Scott Crawford</a> from Enterprise Management Associates &#8211; &#8220;<a href="http://www.enterprisemanagement.com/research/asset.php?id=1134">The Security Paradox of Cloud: Five Questions for Cloud Providers</a>&#8220;.</p>
<p>This is a great report in a sense that it not only talks about that same paradox but also formulates the 5 questions which need to be answered by the cloud vendors to make these happen:</p>
<ol>
<li>“How much visibility do I have into how you manage my risks?”</li>
<li>“What risks do your other tenants pose to me… or to you?”</li>
<li>“Are your tools and techniques for managing risk mature enough?”</li>
<li>“Is my data safe with you?”</li>
<li>“How will turning to cloud impact my current approach to management?”</li>
</ol>
<p>For each of the questions Scott provides a good discussion &#8211; so <a href="http://www.enterprisemanagement.com/research/asset.php?id=1134">the report</a> is well worth checking out.</p>
<p>Here are a few comments which I had on the paper:</p>
<p>In my opinion, “cloud” is inevitable because it offers better economics than do-it-yourself on-premises approach: think market economy specialization vs. natural household. This does not mean that no IT services will remain on premise but we are most likely up to some kind of hybrid model. How far we go there does depend on the ability by the industry to answer Scott&#8217;s questions.</p>
<p>Scott&#8217;s notes on how cloud with its separation of duties could also become a more viable security solution are spot on. With proper legal and certification framework cloud approach would let companies split liability risks with the cloud provider – as opposed to having to deal with liability all by themselves. Adhering to retention policies is costly – outsourcing multiyear document/communications retention to Microsoft/Google/etc. and sharing not only storage costs but liability and risks with them is a pretty good deal.</p>
<ul>
<li>Certifications (such as SAS 70) are a good step in ensuring better security. Scott seems skeptical about certifications (and rightly so) but these are one of the components of the solution because they provide a vendor-independent common set of standards.</li>
<li>Publicly disclosed industry-proven identity management, authentication and authorization architectures (such as “Geneva” for example) is another good step – security by obscurity will not cut it here.</li>
<li>There will probably be a bigger place of encryption/DRM in the picture. These do come at a price though and if the limits are pushed too hard the cloud systems may become useless: not being able to provide valuable functionality without access to data.</li>
<li>Legal frameworks providing for shared liability.</li>
</ul>
<p>With all that said, this will not happen overnight. Kids are sick more often than adults, and the cloud industry is still in its infancy so 2009 and 2010 will bring us quite a few outages and security breaches.</p>
<p>Read Scott&#8217;s report <a href="http://www.enterprisemanagement.com/research/asset.php?id=1134">here</a>.</p>
<p><span class="technoratitag">Technorati Tags:<br />
<a href="http://www.technorati.com/tag/SaaS" target="_blank" rel="tag" title="Link to Technorati Tag category for SaaS">SaaS</a>, <a href="http://www.technorati.com/tag/Cloud+Computing" target="_blank" rel="tag" title="Link to Technorati Tag category for Cloud Computing">Cloud Computing</a>, <a href="http://www.technorati.com/tag/Compliance" target="_blank" rel="tag" title="Link to Technorati Tag category for Compliance">Compliance</a>, <a href="http://www.technorati.com/tag/Analysts" target="_blank" rel="tag" title="Link to Technorati Tag category for Analysts">Analysts</a>, <a href="http://www.technorati.com/tag/Security" target="_blank" rel="tag" title="Link to Technorati Tag category for Security">Security</a></span><br /><span class="sociallinks">Add to: | <a href="http://technorati.com/faves?add=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F04%2F06%2Fcan%2Dcloud%2Dmake%2Dyou%2Dmore%2Dcompliant%2F" target="_blank">Technorati</a> |  <a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F04%2F06%2Fcan%2Dcloud%2Dmake%2Dyou%2Dmore%2Dcompliant%2F" target="_blank">Digg</a> |  <a href="http://del.icio.us/post?url=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F04%2F06%2Fcan%2Dcloud%2Dmake%2Dyou%2Dmore%2Dcompliant%2F;title=Can%20cloud%20make%20you%20MORE%20compliant%3F" target="_blank">del.icio.us</a> |  <a href="http://myweb2.search.yahoo.com/myresults/bookmarklet?t=Can%20cloud%20make%20you%20MORE%20compliant%3F&amp;u=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F04%2F06%2Fcan%2Dcloud%2Dmake%2Dyou%2Dmore%2Dcompliant%2F" target="_blank">Yahoo</a> |  <a href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F04%2F06%2Fcan%2Dcloud%2Dmake%2Dyou%2Dmore%2Dcompliant%2F&amp;Title=Can%20cloud%20make%20you%20MORE%20compliant%3F" target="_blank">BlinkList</a> |  <a href="http://www.spurl.net/spurl.php?url=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F04%2F06%2Fcan%2Dcloud%2Dmake%2Dyou%2Dmore%2Dcompliant%2F&amp;title=Can%20cloud%20make%20you%20MORE%20compliant%3F" target="_blank">Spurl</a> |  <a href="http://reddit.com/submit?url=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F04%2F06%2Fcan%2Dcloud%2Dmake%2Dyou%2Dmore%2Dcompliant%2F&amp;title=Can%20cloud%20make%20you%20MORE%20compliant%3F" target="_blank">reddit</a> |   <a href="http://www.furl.net/storeIt.jsp?t=Can%20cloud%20make%20you%20MORE%20compliant%3F&amp;u=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F04%2F06%2Fcan%2Dcloud%2Dmake%2Dyou%2Dmore%2Dcompliant%2F" target="_blank">Furl</a> |  </span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cloudenterprise.wordpress.com/234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cloudenterprise.wordpress.com/234/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cloudenterprise.wordpress.com/234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cloudenterprise.wordpress.com/234/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cloudenterprise.wordpress.com/234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cloudenterprise.wordpress.com/234/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cloudenterprise.wordpress.com/234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cloudenterprise.wordpress.com/234/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cloudenterprise.wordpress.com/234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cloudenterprise.wordpress.com/234/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cloudenterprise.wordpress.com/234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cloudenterprise.wordpress.com/234/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cloudenterprise.wordpress.com/234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cloudenterprise.wordpress.com/234/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=234&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cloudenterprise.info/2009/04/06/can-cloud-make-you-more-compliant/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6ecc57e2c1be48013620bf85fb983dbf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dmitrysotnikov</media:title>
		</media:content>

		<media:content url="http://www.enterprisemanagement.com/images/research/photos/Scott_Crawford.jpg" medium="image">
			<media:title type="html">Scott Crawford</media:title>
		</media:content>
	</item>
		<item>
		<title>Can I insure my Google Apps, please?</title>
		<link>http://cloudenterprise.info/2009/03/11/can-i-insure-my-google-apps/</link>
		<comments>http://cloudenterprise.info/2009/03/11/can-i-insure-my-google-apps/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 10:48:21 +0000</pubDate>
		<dc:creator>Dmitry Sotnikov</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[business opportunities]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Apps]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cloudenterprise.info/?p=221</guid>
		<description><![CDATA[Are online services ever going to be 100% secure? If not should the insurance industry kick in? A few days ago Google Apps had an issue with some Google Docs became accessible to other Google users beyond the security set on the docs. To quote from Google: As we noted in the Google Docs Help [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=221&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Are online services ever going to be 100% secure? If not should the insurance industry kick in?</p>
<p>A few days ago Google Apps had an issue with some Google Docs became accessible to other Google users beyond the security set on the docs. To <a href="http://googledocs.blogspot.com/2009/03/on-yesterdays-email.html">quote from Google</a>:</p>
<blockquote><p>As we noted in the Google Docs Help Forum yesterday, we&#8217;ve identified and fixed a bug where a very small percentage of users shared some of their documents inadvertently. The inadvertent sharing was limited to people with whom the document owner, or a collaborator with sharing rights, had previously shared a document&#8230; We believe the issue affected less than 0.05% of all documents&#8230;</p></blockquote>
<p>This obviously is not fun, and 0.05% can be a pretty big number of documents and who knows how these got spread across customers. However, what I wonder is whether this is actually an insurance industry rather than just technology opportunity.</p>
<p>Seriously, you install fire alarms, etc. in your house but you probably still insure it against fire (and not, say, live in the middle of a field because houses can burn). Does this make sense?</p>
<p><span class="technoratitag">Tags: <a href="http://www.technorati.com/tag/business+opportunities" target="_blank" rel="tag" title="Link to Technorati Tag category for business opportunities">business opportunities</a>, <a href="http://www.technorati.com/tag/Google" target="_blank" rel="tag" title="Link to Technorati Tag category for Google">Google</a>, <a href="http://www.technorati.com/tag/Google+Apps" target="_blank" rel="tag" title="Link to Technorati Tag category for Google Apps">Google Apps</a>, <a href="http://www.technorati.com/tag/SaaS" target="_blank" rel="tag" title="Link to Technorati Tag category for SaaS">SaaS</a>, <a href="http://www.technorati.com/tag/Security" target="_blank" rel="tag" title="Link to Technorati Tag category for Security">Security</a></span><br /><span class="sociallinks">Add to: | <a href="http://technorati.com/faves?add=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F03%2F11%2Fcan%2Di%2Dinsure%2Dmy%2Dgoogle%2Dapps%2F" target="_blank">Technorati</a> |  <a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F03%2F11%2Fcan%2Di%2Dinsure%2Dmy%2Dgoogle%2Dapps%2F" target="_blank">Digg</a> |  <a href="http://del.icio.us/post?url=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F03%2F11%2Fcan%2Di%2Dinsure%2Dmy%2Dgoogle%2Dapps%2F;title=Can%20I%20insure%20my%20Google%20Apps%2C%20please%3F" target="_blank">del.icio.us</a> |  <a href="http://myweb2.search.yahoo.com/myresults/bookmarklet?t=Can%20I%20insure%20my%20Google%20Apps%2C%20please%3F&amp;u=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F03%2F11%2Fcan%2Di%2Dinsure%2Dmy%2Dgoogle%2Dapps%2F" target="_blank">Yahoo</a> |  <a href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F03%2F11%2Fcan%2Di%2Dinsure%2Dmy%2Dgoogle%2Dapps%2F&amp;Title=Can%20I%20insure%20my%20Google%20Apps%2C%20please%3F" target="_blank">BlinkList</a> |  <a href="http://www.spurl.net/spurl.php?url=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F03%2F11%2Fcan%2Di%2Dinsure%2Dmy%2Dgoogle%2Dapps%2F&amp;title=Can%20I%20insure%20my%20Google%20Apps%2C%20please%3F" target="_blank">Spurl</a> |  <a href="http://reddit.com/submit?url=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F03%2F11%2Fcan%2Di%2Dinsure%2Dmy%2Dgoogle%2Dapps%2F&amp;title=Can%20I%20insure%20my%20Google%20Apps%2C%20please%3F" target="_blank">reddit</a> |   <a href="http://www.furl.net/storeIt.jsp?t=Can%20I%20insure%20my%20Google%20Apps%2C%20please%3F&amp;u=http%3A%2F%2Fcloudenterprise%2Einfo%2F2009%2F03%2F11%2Fcan%2Di%2Dinsure%2Dmy%2Dgoogle%2Dapps%2F" target="_blank">Furl</a> |  </span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cloudenterprise.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cloudenterprise.wordpress.com/221/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cloudenterprise.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cloudenterprise.wordpress.com/221/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cloudenterprise.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cloudenterprise.wordpress.com/221/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cloudenterprise.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cloudenterprise.wordpress.com/221/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cloudenterprise.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cloudenterprise.wordpress.com/221/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cloudenterprise.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cloudenterprise.wordpress.com/221/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cloudenterprise.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cloudenterprise.wordpress.com/221/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=221&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cloudenterprise.info/2009/03/11/can-i-insure-my-google-apps/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6ecc57e2c1be48013620bf85fb983dbf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dmitrysotnikov</media:title>
		</media:content>
	</item>
		<item>
		<title>Gartner on Cloud and information control</title>
		<link>http://cloudenterprise.info/2009/02/18/gartner-on-cloud-and-information-control/</link>
		<comments>http://cloudenterprise.info/2009/02/18/gartner-on-cloud-and-information-control/#comments</comments>
		<pubDate>Wed, 18 Feb 2009 18:37:22 +0000</pubDate>
		<dc:creator>Dmitry Sotnikov</dc:creator>
				<category><![CDATA[Analysts]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Gartner]]></category>
		<category><![CDATA[Guidelines]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cloudenterprise.info/?p=212</guid>
		<description><![CDATA[Jay Heiser and David Gootzit from Gartner have just published an excellent report on &#8220;Trusted SaaS Offerings for Secure Collaboration&#8220;. The report is really valuable for anyone either building clouds or cloud-related products, or considering to move sensitive data to a SaaS application. The key areas they look into are: List of typical SaaS applications [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=212&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Jay Heiser and David Gootzit from Gartner <a href="http://www.gartner.com/DisplayDocument?id=869131">have just published</a> an excellent report on &#8220;<strong>Trusted SaaS Offerings for Secure Collaboration</strong>&#8220;.</p>
<p>The report is really valuable for anyone either building clouds or cloud-related products, or considering to move sensitive data to a SaaS application.</p>
<p>The key areas they look into are:</p>
<ul>
<li>List of typical SaaS applications which have high trust requirements.</li>
<li>Key security features which such applications should possess.</li>
<li>Transparency measures which cloud computing/SaaS providers need to implement.</li>
</ul>
<p>Excellent report: short, to the point, and with material you can use while developing or evaluating SaaS application with trust requirements. Get the report <a href="http://www.gartner.com/DisplayDocument?id=869131">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cloudenterprise.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cloudenterprise.wordpress.com/212/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cloudenterprise.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cloudenterprise.wordpress.com/212/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cloudenterprise.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cloudenterprise.wordpress.com/212/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cloudenterprise.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cloudenterprise.wordpress.com/212/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cloudenterprise.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cloudenterprise.wordpress.com/212/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cloudenterprise.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cloudenterprise.wordpress.com/212/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cloudenterprise.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cloudenterprise.wordpress.com/212/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cloudenterprise.info&#038;blog=4988729&#038;post=212&#038;subd=cloudenterprise&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cloudenterprise.info/2009/02/18/gartner-on-cloud-and-information-control/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6ecc57e2c1be48013620bf85fb983dbf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dmitrysotnikov</media:title>
		</media:content>
	</item>
	</channel>
</rss>
