Jay Heiser

A member of the Gartner Blog Network

Entries Categorized as 'Cloud'


Bulletproof Contracts

by Jay Heiser  |  November 28, 2011  |  2 Comments

With the understanding that I am not a lawyer, and Gartner is not a law firm, here’s my brief summary of the contractual language dealing with SaaS security as provided by a prominent vendor: We believe that we obey the law.  If there are any questions pertaining to how your data is handled within our [...]

2 Comments »

Category: Cloud risk management security Vendor Contracts     Tags:

SLA feather allows you to fly in the cloud

by Jay Heiser  |  November 17, 2011  |  2 Comments

An SLA from a public cloud service promising some sort of recoverability is a crow feather, clutched in the trunk of the enterprise elephant, providing them the false courage to be willing to fly in the public cloud.

2 Comments »

Category: Cloud risk management Vendor Contracts     Tags: , , , , ,

Data without Borders: DRM as a consumer lock-in mechanism

by Jay Heiser  |  November 9, 2011  |  1 Comment

In the olden days, the business viability of your local book store had absolutely no impact on your ability to read whatever you might have bought from them. In the digital world, your continued ability to use rights-managed content, be it music, video, or books, is completely dependent upon the willingness and ability of a service to support it on your device.

1 Comment »

Category: Applications Cloud risk management security     Tags: , ,

Uh, oh, Mumboe! You have 2 weeks to get your data

by Jay Heiser  |  November 2, 2011  |  1 Comment

Its easy to imagine a smallish procurement shop in which the only person to have been sent a warning was on a 2-week vacation, and won’t get around to reading about it until it is several days too late to download their only copy of several years worth of past and current purchasing data.

1 Comment »

Category: Applications Cloud risk management     Tags: , , , , , , , ,

Scooters & flashlights means your data is secure with us

by Jay Heiser  |  October 10, 2011  |  1 Comment

I ask you to take a silent moment to try to visualize the sort of infosec security failure that would be solved with scooters.

1 Comment »

Category: Cloud risk management security     Tags: , , , ,

You’ll guarantee that cloud, won’t you?

by Jay Heiser  |  October 5, 2011  |  1 Comment

The truth of the matter is that the provider actually has no idea of the likelihood of a loss event within their own offering. If a failure occurred, it could impact all of their customers simultaneously. No cloud service provider has enough cash on hand to cover that portfolio risk, and they can’t find any insurer willing to underwrite it.

1 Comment »

Category: Cloud risk management security     Tags: , , ,

We’ve forgotten our computer security history lessons

by Jay Heiser  |  September 29, 2011  |  1 Comment

What good is a fresh password if it is sitting on top of stale security technology? The history of computer security suggests that attention to the code is at least as important as operational processes.

1 Comment »

Category: Applications Cloud IT Governance risk management security     Tags: , , ,

For want of a nail, the cloud was lost

by Jay Heiser  |  August 10, 2011  |  3 Comments

A common natural disaster strikes, the high availability mechanisms don’t work, a recovery mechanism turns out to be broken, and fixing it takes a long time….because it is a cloud.

3 Comments »

Category: Cloud risk management     Tags: , ,

Bach to Basics: Why You Should Care About Cloud Internals

by Jay Heiser  |  July 8, 2011  |  1 Comment

Just as the transition from a physically-secure batch-oriented environment to a remotely-accessible multi-tasking/multi-user environment had huge implications for security, the evolution from multi-user host-based environments to multi-tenant cloud-based environments represents an equally significant security challenge.

1 Comment »

Category: Cloud risk management security Virtualization     Tags: ,

Are you the SaaS Scapegoat?

by Jay Heiser  |  July 5, 2011  |  1 Comment

I get a never-ending stream of questions that usually amounts to something like “What control tasks do I need to do to be sure that this SaaS service we are going to use will be adequately secure?” Unfortunately, at this point in time, SaaS providers offer relatively little support for enterprise control over anything.  Assuming that the [...]

1 Comment »

Category: Applications Cloud IAM IT Governance risk management security Vendor Contracts     Tags: , , , , , , , , , ,