<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Private Clouds and Phishy Clouds</title>
	<atom:link href="http://blogs.gartner.com/greg_young/2009/10/06/private-clouds-and-phishy-clouds/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.gartner.com/greg_young/2009/10/06/private-clouds-and-phishy-clouds/</link>
	<description>A member of the Gartner Blog Network</description>
	<lastBuildDate>Fri, 11 Feb 2011 21:13:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
	<item>
		<title>By: Danger. Danger, Will Robinson! (enough with the panic, please) &#171; Hyperguarding your Web Applications</title>
		<link>http://blogs.gartner.com/greg_young/2009/10/06/private-clouds-and-phishy-clouds/comment-page-1/#comment-520</link>
		<dc:creator>Danger. Danger, Will Robinson! (enough with the panic, please) &#171; Hyperguarding your Web Applications</dc:creator>
		<pubDate>Tue, 13 Oct 2009 19:04:17 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2009/10/06/private-clouds-and-phishy-clouds/#comment-520</guid>
		<description>[...] things to people. Is your cloud provider being transparent with bugs, glitches, etc? Do you have provider options (Google, Amazon, DISA’s RACE)? How id your data handled and protected? Is the cloud application [...]</description>
		<content:encoded><![CDATA[<p>[...] things to people. Is your cloud provider being transparent with bugs, glitches, etc? Do you have provider options (Google, Amazon, DISA’s RACE)? How id your data handled and protected? Is the cloud application [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay Heiser</title>
		<link>http://blogs.gartner.com/greg_young/2009/10/06/private-clouds-and-phishy-clouds/comment-page-1/#comment-490</link>
		<dc:creator>Jay Heiser</dc:creator>
		<pubDate>Thu, 08 Oct 2009 10:30:34 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2009/10/06/private-clouds-and-phishy-clouds/#comment-490</guid>
		<description>“For its cloud-based applications, DISA conducts a full SAS 70 audit.”  

Why would the US military, with a 40-year history of computer security research and practice, use an auditing standard that is explicitly not intended to be applied to technical evaluations? 

Can it really be the case that the GSA wants to apply FISMA to the cloud-based apps that are purchased from Google, SFDC, etc (see apps.gov), while the military wants to apply Statement of Accounting Standards Seven Zero to their in-house systems?</description>
		<content:encoded><![CDATA[<p>“For its cloud-based applications, DISA conducts a full SAS 70 audit.”  </p>
<p>Why would the US military, with a 40-year history of computer security research and practice, use an auditing standard that is explicitly not intended to be applied to technical evaluations? </p>
<p>Can it really be the case that the GSA wants to apply FISMA to the cloud-based apps that are purchased from Google, SFDC, etc (see apps.gov), while the military wants to apply Statement of Accounting Standards Seven Zero to their in-house systems?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

