Risk
7/23/2013
03:06 PM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%

CSA Unveils PRISM Survey Results

In light of recent revelations about government access to customer information, 56% of non-U.S. residents are now less likely to use U.S.-based cloud providers

Seattle, WA ­ July 23, 2013 ­ The Cloud Security Alliance (CSA) today announced a number of milestones in its continued efforts to spearhead global transparency for cloud services. The CSA announced that over 30 entries, from major cloud providers, have been made to its Security, Trust and Assurance Registry (STAR). Later this fall, the CSA, along with the BSI (British Standards Institution), will unveil details of the STAR Certification effort. This week the CSA also published the results of it survey on government access to information, in light of recent concerns over ownership and access to cloud-based data.

³With over 48,000 individual members, and 70 chapters globally, the CSA has become the global authoritative source for trust in the cloud,² said Dave Cullinane, Chairman of the CSA Board of Directors. ³As we look to the future, we believe that enabling assurance in a global compute utility is one of the greatest challenges facing the industry, if we want cloud computing to meet its potential. As a result, we continue to focus our efforts on enabling transparency among cloud providers, for the benefit of consumers around the world.²

STAR Registry Grows to Over 30 Entries from Major Cloud Providers

In late 2011, the CSA introduced the Security, Trust and Assurance Registry (STAR), the first step in improving transparency and assurance in the cloud. The CSA has seen tremendous growth in STAR, with major cloud players including Amazon Web Services, Box.com, HP, Microsoft, Ping Identity, Red Hat, Skyhigh Networks, Symantec and Terremark submitting entries into the registry. These cloud providers recognize the need to provide transparency and assurance of their cloud services to corporations and end users, who are increasingly requesting visibility into the security controls provided by various cloud computing offerings. The CSA STAR is open to all cloud providers.

At the CSA EMEA Congress, to be held in September, the CSA and BSI will also officially launch the STAR Certification effort, the next step in the CSA STAR program, designed to provide an incremental level of visibility and transparency into the operations of the cloud service provider.

Survey Finds Concern with Government Access to Information

The CSA today also published the results of its recent survey on government access to information. The survey received almost 500 responses from CSA members around the world. It found that 56% of non-US residents were now less likely to use US-based cloud providers, in light of recent revelations about government access to customer information. An overwhelming 90% of respondents said that companies who have been subpoenaed through provisions of the Patriot Act should be able to publish summary information about the amount of responses they have made.

Full results of the survey can be found at https://cloudsecurityalliance.org/research/surveys/#_nsa_prism.

Jim Reavis, co-founder and executive director of the CSA, will be highlighting these results in a SC Magazine eConference on Securing the Cloud, today, July 23rd, at noon ET. The CSA also plans to host a Cloud Bytes panel in the coming weeks to discuss the issues facing cloud providers and consumers.

³Transparency has always been a significant part of the CSA¹s vision, and today this objective is more critical than ever,² said Reavis. ³Our goal with our research efforts, and with the CSA STAR program, is to continue to encourage transparency of security practices within cloud providers. By educating both consumers and providers of cloud services, we strive to provide the tools needed to make informed decisions that take advantage of all the benefits cloud computing has to offer.²

Tweet this: CSA releases results of NSA/PRISM survey; over 30 major cloud vendors have now submitted to @cloudsa STAR #transparency http://ow.ly/neplI

About Cloud Security Alliance

The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6306
Published: 2014-08-22
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.

CVE-2014-0232
Published: 2014-08-22
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1)...

CVE-2014-3525
Published: 2014-08-22
Unspecified vulnerability in Apache Traffic Server 4.2.1.1 and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

CVE-2014-3563
Published: 2014-08-22
Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.

CVE-2014-3587
Published: 2014-08-22
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists bec...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.