Comments
93% of Cloud Applications Aren't Enterprise-Ready
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/26/2018 | 9:32:09 PM
Re: 93% of cloud apps
@Brian: It might be even smaller than 7%. Don't forget that studies like that often have a "don't know/aren't sure" third option.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/26/2018 | 7:56:37 PM
Re: 93% of cloud apps
I don't get how an organization can hope to document the details of how an app does what it does. I agree, most organizations have to go through a consolidation because they start deploying the apps to cloud.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/26/2018 | 7:54:51 PM
Re: 93% of cloud apps
You can outsource, to a degree For me that is partially what is happening in the could, Wen basically outsource the responsibilities assuming all will work out.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/26/2018 | 7:52:54 PM
Re: 93% of cloud apps
The goal is to provide and expose data only as it is required to accomplish specific tasks, on a per instance basis. This would do be a good deal for security experts. At the end of the day we need to protect the data.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/26/2018 | 7:51:31 PM
Re: 93% of cloud apps
the details of how each app does what it does? This is a good questions, if the are not enterprise ready maybe they are not for enterprises.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/26/2018 | 7:49:33 PM
Re: 93% of cloud apps
I don't know how comfortable we should even be with the 7% that are deemed "enterprise ready" I am surprise with the percentages too. That may also tell us that most apps in cloud are not that useful either.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/26/2018 | 7:47:48 PM
Re: 93% of cloud apps
there's an app for that" Yes. A could app to make sure cloud apps are easy to enterprise.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/26/2018 | 7:43:06 PM
93%?
That sounds a very high number. Most of the enterprises are using cloud currently. So are they at risk?
247locksmith
50%
50%
247locksmith,
User Rank: Apprentice
2/25/2018 | 12:23:11 PM
93% of cloud apps
I completely agree! I don't get how an organization can hope to document the details of how an app does what it does. Although organizations like <a href="https://www.24-7locksmith.org/">24-7 Locksmith</a> do a really good job at stuff like this, so I don't think it's entirely futile. That's just me though!
BrianN060
50%
50%
BrianN060,
User Rank: Ninja
2/24/2018 | 2:09:12 PM
93% of cloud apps
Concerned that so much of your organization's data and operations are dependent on services beyond your control?  Don't worry - "there's an app for that

I don't know how comfortable we should even be with the 7% that are deemed "enterprise ready".  At best, these have a good track record (up to the point when the survey was taken); but all are born of a dynamic process.  All we can say is that they've been Ok, so far - but that far might not reach the next update, compliance regulation or newly discovered vulnerability.  It's fair to credit some providers with having demonstrated effective remediation, when things have gone south, and for doing a better job of vetting their own providers and partners.  Yet, there are too many interdependencies to warrant unqualified trust.

With the quoted usage from hundreds to thousands, how can an organization hope to document, let alone comprehend, the details of how each app does what it does? 

The only viable recourse is to do a better job of data governance.  The goal is to provide and expose data only as it is required to accomplish specific tasks, on a per instance basis.  Before you can do that, you need a fact-based information system's model, at the conceptual level - one that reflects how your specific organization actually  processes data to carry out its business. 

You won't find that in a template, even one that's "customizable".  It's also not a process you can automate: it requires comprehension and judgement.  You can outsource, to a degree; but that service will have to know your business at least as well as you do - so only chose those with whom you feel comfortable being business partners, in the fullest sense.  One thing is certain - you won't find an app for that. 


WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17141
PUBLISHED: 2018-09-21
HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit enabled, which is mishandled in FaxModem::writeECMData() in the faxd/CopyQuality.c++ file.
CVE-2018-17173
PUBLISHED: 2018-09-21
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
CVE-2018-17174
PUBLISHED: 2018-09-21
A stack-based buffer overflow was discovered in the xtimor NMEA library (aka nmealib) 0.5.3. nmea_parse() in parser.c allows an attacker to trigger denial of service (even arbitrary code execution in a certain context) in a product using this library via malformed data.
CVE-2018-16822
PUBLISHED: 2018-09-21
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
CVE-2018-16833
PUBLISHED: 2018-09-21
Zoho ManageEngine Desktop Central 10.0.271 has XSS via the &quot;Features &amp; Articles&quot; search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.