Risk
7/23/2013
03:06 PM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%

CSA Unveils PRISM Survey Results

In light of recent revelations about government access to customer information, 56% of non-U.S. residents are now less likely to use U.S.-based cloud providers

Seattle, WA ­ July 23, 2013 ­ The Cloud Security Alliance (CSA) today announced a number of milestones in its continued efforts to spearhead global transparency for cloud services. The CSA announced that over 30 entries, from major cloud providers, have been made to its Security, Trust and Assurance Registry (STAR). Later this fall, the CSA, along with the BSI (British Standards Institution), will unveil details of the STAR Certification effort. This week the CSA also published the results of it survey on government access to information, in light of recent concerns over ownership and access to cloud-based data.

³With over 48,000 individual members, and 70 chapters globally, the CSA has become the global authoritative source for trust in the cloud,² said Dave Cullinane, Chairman of the CSA Board of Directors. ³As we look to the future, we believe that enabling assurance in a global compute utility is one of the greatest challenges facing the industry, if we want cloud computing to meet its potential. As a result, we continue to focus our efforts on enabling transparency among cloud providers, for the benefit of consumers around the world.²

STAR Registry Grows to Over 30 Entries from Major Cloud Providers

In late 2011, the CSA introduced the Security, Trust and Assurance Registry (STAR), the first step in improving transparency and assurance in the cloud. The CSA has seen tremendous growth in STAR, with major cloud players including Amazon Web Services, Box.com, HP, Microsoft, Ping Identity, Red Hat, Skyhigh Networks, Symantec and Terremark submitting entries into the registry. These cloud providers recognize the need to provide transparency and assurance of their cloud services to corporations and end users, who are increasingly requesting visibility into the security controls provided by various cloud computing offerings. The CSA STAR is open to all cloud providers.

At the CSA EMEA Congress, to be held in September, the CSA and BSI will also officially launch the STAR Certification effort, the next step in the CSA STAR program, designed to provide an incremental level of visibility and transparency into the operations of the cloud service provider.

Survey Finds Concern with Government Access to Information

The CSA today also published the results of its recent survey on government access to information. The survey received almost 500 responses from CSA members around the world. It found that 56% of non-US residents were now less likely to use US-based cloud providers, in light of recent revelations about government access to customer information. An overwhelming 90% of respondents said that companies who have been subpoenaed through provisions of the Patriot Act should be able to publish summary information about the amount of responses they have made.

Full results of the survey can be found at https://cloudsecurityalliance.org/research/surveys/#_nsa_prism.

Jim Reavis, co-founder and executive director of the CSA, will be highlighting these results in a SC Magazine eConference on Securing the Cloud, today, July 23rd, at noon ET. The CSA also plans to host a Cloud Bytes panel in the coming weeks to discuss the issues facing cloud providers and consumers.

³Transparency has always been a significant part of the CSA¹s vision, and today this objective is more critical than ever,² said Reavis. ³Our goal with our research efforts, and with the CSA STAR program, is to continue to encourage transparency of security practices within cloud providers. By educating both consumers and providers of cloud services, we strive to provide the tools needed to make informed decisions that take advantage of all the benefits cloud computing has to offer.²

Tweet this: CSA releases results of NSA/PRISM survey; over 30 major cloud vendors have now submitted to @cloudsa STAR #transparency http://ow.ly/neplI

About Cloud Security Alliance

The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5485
Published: 2014-09-30
registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to the admin interface.

CVE-2012-5486
Published: 2014-09-30
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

CVE-2012-5487
Published: 2014-09-30
The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

CVE-2012-5488
Published: 2014-09-30
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.

CVE-2012-5489
Published: 2014-09-30
The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
In our next Dark Reading Radio broadcast, we’ll take a close look at some of the latest research and practices in application security.