Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 

Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

New report by EU Agency ENISA: The double-edged sword of Cloud computing in Critical Information Infrastructure Protection

February 2013 by Marc Jacob

20130214 Cloud CIIP FINAL-FRThe EU’s cyber security agency ENISA has launched a new report looking at Cloud computing from a Critical Information Infrastructure Protection (CIIP) perspective, and identifying that Cloud computing is critical given the concentration of users and data and its growing use in critical sectors, such as finance, health and insurance.

In a few years, a large majority of organisations will be dependent on Cloud computing. Large Cloud services will have tens of millions of end-users. What happens if one of these cloud services fails, or gets hacked?

“From a security perspective, the concentration of data is a ‘double-edged sword’; large providers can offer state-of-the-art security, and business continuity, spreading the costs across many customers. But if an outage or security breach occurs, the impact is bigger, affecting many organisations and citizens at once”, Dr Marnix Dekker says. Last years, there have been many examples of failures affecting very large sites with millions of users (for example, the leap year bug outage). This report looks at the threats from a CIIP perspective, i.e. how to prevent large cyber disruptions and large cyber-attacks. The key messages of the report are:

Critical infrastructure: Soon, the vast majority of organisations will use cloud computing notably also in critical sectors like finance, energy and transport. Cloud services are themselves becoming a critical information infrastructure.
Natural disasters and DDoS attacks: A benefit of Cloud computing is resilience in the face of natural disasters and Distributed Denial of Service (DDoS)-attacks, which are difficult to mitigate using traditional approaches (servers on site, or single data centre).

Cyber attacks: Cyber attacks exploiting software flaws can cause large data breaches, affecting millions of users, because of the large concentration of users and data. Physical redundancy does not safeguard against certain cyber attacks, such as data breaches exploiting software flaws.
The report also provides nine recommendations for bodies responsible for critical information infrastructures. Key points: Include large cloud services in national risk assessments, track cloud dependencies, and work with providers on incident reporting schemes.

The Executive Director of ENISA, Professor Udo Helmbrecht, commented: “Cloud computing is a reality and therefore we must prepare to prevent service failures and cyber attacks on cloud services. The European Cyber Security and Cloud Computing Strategies provide a roadmap for this.”

ENISA will launch a new working group focussing on CIIP and governmental Cloud security.

For full report and recommendations :
https://www.enisa.europa.eu/activities/Resilience-and-CIIP/cloud-computing/critical-cloud-computing/


See previous articles

    

See next articles


Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts