Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - CSA Summit At RSA 2014
Articles

CSA Summit At RSA 2014

ISBuzz TeamBy ISBuzz TeamFebruary 27, 20145 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Major Canadian Liquor Distributor’s Website Infected With Skimmer
Major Canadian Liquor Distributor’s Website Infected With Skimmer
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Governments are an important factor in the cloud computing eco-system.  This is a feature of Cloud computing that differentiate Cloud Computing from traditional IT. Governments promote standards, regulations and laws which are essential for trust, and Governments can adopt cloud computing for their IT needs and create cloud friendly environment.  And they can also damage the trust and eco-system with ungoverned cloud surveillance, as Snowden revealed.

With that said, no wonder that the two opening keynotes at the RSA 2014 Cloud Security Alliance summit were about governments and their policies regarding cloud computing: Richard Clarke, a member of President Obama’s Review Group on Intelligence and Communications Technology, and Professor Udo Helmbrecht, Executive Director, European Union Agency for Network and Information Security (ENISA) – were the two distinguished guests that in turn elaborated on their governments plans and actions for Cloud Computing.

Starting early in the morning, Mr. Clarke gave a very interesting brief about his role in the group that was called by President Obama in order to establish new policy for NSA surveillance.  While describing the events behind the scenes, Mr. Clarke elaborated on some of the 46 recommendations that the group handed out to the president:  increasing internal security of the data, stop attempts to weaken encryption standards (which were exaggerated according to Mr. Clarke), and appointing a strong oversight committee with real enforcements capabilities.

The NSA is a good force, he complimented; they are working day and night for stopping terror, drugs and mass destruction weapons.  But the public good require us to put road blocks in order stop now and then to make sure we are not giving up on too many civil rights in this intensive race of fighting terror.

Similar laws and actions exist outside of the US, Mr. Clarke added, so people who criticize US actions usually doing so for economical profit  (to be gained from localizing cloud services) ,  or they are simply hypocrites, he concluded.

And in order to complete the picture, the next talk was from ENISA Executive Director, Professor Udo Helmbrecht, who reviewed the efforts from the EU commission to increase trust and adoption of cloud computing.  The EU commission is investing great efforts in cloud adoption, and ENISA is there to help this process. Cloud computing brings security risks but also opportunities, especially for SMB sectors who are unable to purchase the protection as enterprises do, he explained. ENISA strategy in the EU efforts is to become a cloud security hub and assist in setting standards and laws, creating new business models and help in creating the required trust. And, there is no reason that an e-mail from Germany to other EU country will pass through the US, he added in reference to his preceding speaker criticism about EU efforts for localization of cloud services.

In next sessions, the summit drifted away from governments and espionage affects with two different panels. The first discussing about the perimeter challenges organizations are facing and the second one about managing risks and increasing trust between cloud provider and consumer. Trend Micro and Vodafone shared presentation described a research about critical infrastructure and SCADA protection: During the research, 12 honeypots were placed and configured to look like exposed water or electricity management systems. The presentation described the various attacks attempts and the life cycle of the hacks that involved 74 different attacks, mostly from Russia and China.

As a closing key note, Alan Boehme, Chief of Enterprise Architecture for The Coca-Cola Company, gave a first pick of the software define perimeter concept.  The SDP is a concept taken from DoD and some NIST publications, and aims at replacing the traditional physical perimeter with software based one.  Utilizing the SDP technology will eliminate many attacks vectors such DDOS, man in the middle and various malwares and other attacks. The idea in SDP is that each server is able to self-protect itself even if it located in an untrusted environment. Several security technologies such as VPN, Identity management, federation, device attestation and strong authentication been grouped into that software component. The result is servers with ability to establish a secure link with users or other servers only after applying certain policy.  This interesting concept is still very new and is currently being in the center of hacking contest in order to check its resilience. It will not solve all cloud computing threats, but it can certainly provide efficient mechanism for the open enterprise to eliminate certain attacks. The CSA is investing heavily on the SDP concept hoping it will solve some of the security challenges presented by cyber criminals, insider threats, and governments.

Moshe Ferber www.onlinecloudsec.com 

Moshe FerberMoshe Ferber is a Cloud Security entrepreneur and lecturer, with over 20 years’ experience in information security. In the past managed the security department for Ness Technologies, a global IT service provider and founder of Cloud7, a Managed Security Services Provider (acquired by Matrix LTD).  In the last couple of years, Mr. Ferber has focused on various aspects of cloud technology as entrepreneur, private investor and as co-Chairman for the Cloud Security Alliance, Israeli chapter.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Tenable warns AI adoption is outpacing governance as cloud exposure risks surge

May 15, 20264 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}