RSA President urging people to embrace Cloud Computing

author-image
DQChannels Bureau
New Update

During the opening keynote address at
RSA Conference 2010, Art Coviello, President of RSA, the Security
Division of EMC urged his colleagues in the security industry to
embrace the challenges and opportunities presented by increasingly
virtual infrastructures and adopt a more expansive security vision by
focusing on the IT transformations associated with cloud computing.
Industry leaders Dave Cullinane, Chief Information Security Officer,
eBay, and Paul Maritz, CEO, VMware provided commentary in the areas
of secure cloud and virtualized computing environments. “Something
is holding back the full realization of this href="http://www.dqweek.com/Cloud-computing-is-here-to-stay">cloud
vision. That is
security,” said Coviello. “With 51 percent of CIOs citing
security as their greatest concern surrounding cloud computing,
security has not kept pace with the evolution to the cloud reflected
in today's increasingly virtualized and hyper-extended enterprises.
We have severely diminished vision as a result and it shows. In
short, people everywhere must be able to trust the cloud even if they
literally and metaphorically can't see it,” he added.

Advertisment

The 15-year information security
veteran noted that having a virtual layer embedded in the technology
stack provides the industry with a rare opportunity to get a security
'do over' capable of providing even better security than we have
in physical infrastructures today. As a result, organizations can
shift from infrastructure-centric to information-centric policy and
concentrate on what is most the most important information and who
gets access, rather than a meaningless perimeter or mere plumbing.

During the address Coviello encouraged
the industry to work towards facilitating private cloud
infrastructures that are secure, compliant, and governed in a manner
that provides confidentiality, integrity, and availability of
information. He encouraged the audience to view the private cloud as
a journey that organizations will take at their own pace and gain
benefits at every step along the way. He went on to outline what RSA
sees as the four, well-defined stages on this journey to the private
cloud:

Initial adoption of virtualization
means to consolidate non-mission critical infrastructure, like test
and development systems as well as low risk applications. It compels
the enterprise to become adept with the tools of virtualization and
to begin the process of 'hardening' the virtual infrastructure.

Advertisment

Virtualize critical business
applications and ensure the organization maintains the same level of
visibility to the state of compliance in the virtual environment to
the physical infrastructure.

Develop internal clouds and operate
their information infrastructure as a utility consisting of a fully
virtualized and automated data center where application workloads are
policy and service-level driven.

Outsource infrastructure to external
service providers. This phase requires careful selection of service
providers based on their demonstrated ability to 'enforce policy,
prove compliance and manage multi-tenancy.'

Advertisment

Coviello concluded, “If we can get
security built into the virtual infrastructure from the get-go we can
not only have visibility and manageability but risk decision points,
and controls everywhere. In short, the cloud will turn the way we
deliver security inside out. And information security will enable
cloud computing to take full advantage of the Internet turning our
current IT models inside out as well. This means we can deliver new
waves of efficiency, agility and collaboration for organizations of
all sizes.”