Risk
7/23/2013
03:06 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

CSA Unveils PRISM Survey Results

In light of recent revelations about government access to customer information, 56% of non-U.S. residents are now less likely to use U.S.-based cloud providers

Seattle, WA ­ July 23, 2013 ­ The Cloud Security Alliance (CSA) today announced a number of milestones in its continued efforts to spearhead global transparency for cloud services. The CSA announced that over 30 entries, from major cloud providers, have been made to its Security, Trust and Assurance Registry (STAR). Later this fall, the CSA, along with the BSI (British Standards Institution), will unveil details of the STAR Certification effort. This week the CSA also published the results of it survey on government access to information, in light of recent concerns over ownership and access to cloud-based data.

³With over 48,000 individual members, and 70 chapters globally, the CSA has become the global authoritative source for trust in the cloud,² said Dave Cullinane, Chairman of the CSA Board of Directors. ³As we look to the future, we believe that enabling assurance in a global compute utility is one of the greatest challenges facing the industry, if we want cloud computing to meet its potential. As a result, we continue to focus our efforts on enabling transparency among cloud providers, for the benefit of consumers around the world.²

STAR Registry Grows to Over 30 Entries from Major Cloud Providers

In late 2011, the CSA introduced the Security, Trust and Assurance Registry (STAR), the first step in improving transparency and assurance in the cloud. The CSA has seen tremendous growth in STAR, with major cloud players including Amazon Web Services, Box.com, HP, Microsoft, Ping Identity, Red Hat, Skyhigh Networks, Symantec and Terremark submitting entries into the registry. These cloud providers recognize the need to provide transparency and assurance of their cloud services to corporations and end users, who are increasingly requesting visibility into the security controls provided by various cloud computing offerings. The CSA STAR is open to all cloud providers.

At the CSA EMEA Congress, to be held in September, the CSA and BSI will also officially launch the STAR Certification effort, the next step in the CSA STAR program, designed to provide an incremental level of visibility and transparency into the operations of the cloud service provider.

Survey Finds Concern with Government Access to Information

The CSA today also published the results of its recent survey on government access to information. The survey received almost 500 responses from CSA members around the world. It found that 56% of non-US residents were now less likely to use US-based cloud providers, in light of recent revelations about government access to customer information. An overwhelming 90% of respondents said that companies who have been subpoenaed through provisions of the Patriot Act should be able to publish summary information about the amount of responses they have made.

Full results of the survey can be found at https://cloudsecurityalliance.org/research/surveys/#_nsa_prism.

Jim Reavis, co-founder and executive director of the CSA, will be highlighting these results in a SC Magazine eConference on Securing the Cloud, today, July 23rd, at noon ET. The CSA also plans to host a Cloud Bytes panel in the coming weeks to discuss the issues facing cloud providers and consumers.

³Transparency has always been a significant part of the CSA¹s vision, and today this objective is more critical than ever,² said Reavis. ³Our goal with our research efforts, and with the CSA STAR program, is to continue to encourage transparency of security practices within cloud providers. By educating both consumers and providers of cloud services, we strive to provide the tools needed to make informed decisions that take advantage of all the benefits cloud computing has to offer.²

Tweet this: CSA releases results of NSA/PRISM survey; over 30 major cloud vendors have now submitted to @cloudsa STAR #transparency http://ow.ly/neplI

About Cloud Security Alliance

The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6501
Published: 2015-03-30
The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_s...

CVE-2014-9652
Published: 2015-03-30
The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote atta...

CVE-2014-9653
Published: 2015-03-30
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory ...

CVE-2014-9705
Published: 2015-03-30
Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of multiple dictionaries.

CVE-2014-9709
Published: 2015-03-30
The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.