Jay Heiser

A member of the Gartner Blog Network

Jay Heiser
Research VP
6 years at Gartner
24 years IT industry

Jay Heiser is a research vice president specializing in the areas of IT risk management and compliance, security policy and organization, forensics, and investigation. Current research areas include cloud and SaaS computing risk and control, technologies and processes for the secure sharing of data… Read Full Bio

Coverage Areas:

Measuring Clouds

by Jay Heiser  |  January 26, 2010  |  1 Comment

I’ve spent a lot of the last 2 years researching the problem of making business decisions about the relative levels of risk associated with partners and service providers.  Externally provisioned services, such as Cloud Computing (whatever the service) and SaaS (whatever the computing model) are problematic.  We’ve learned a lot about security risk management over the last 4 decades, but it is difficult or impossible to apply those lessons learned to alternative delivery models.

A brand new Gartner survey supports this, with 28% responding that their organization does not allow use Software as a Service for sensitive data or services (curiously, 41% answered the same in regards to traditional outsourcing).

Its anybodies guess exactly what will happen, but can only envision 4 possibilities:

  1. At least 1/3 of potential buyers continue to avoid something that potentially offers business value.
  2. The infosec community develops a convenient method of assessing and expressing SaaS and public cloud risks.
  3. Everybody decides to use the things anyway, assuming that they are appropriately secure without defensible evidence.
  4. Everybody decides to use the things anyway, recognizing that security cannot be demonstrated.

1 Comment »

Category: Cloud risk management security     Tags: , , ,

1 response so far ↓