Risk
7/23/2013
03:06 PM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%

CSA Unveils PRISM Survey Results

In light of recent revelations about government access to customer information, 56% of non-U.S. residents are now less likely to use U.S.-based cloud providers

Seattle, WA ­ July 23, 2013 ­ The Cloud Security Alliance (CSA) today announced a number of milestones in its continued efforts to spearhead global transparency for cloud services. The CSA announced that over 30 entries, from major cloud providers, have been made to its Security, Trust and Assurance Registry (STAR). Later this fall, the CSA, along with the BSI (British Standards Institution), will unveil details of the STAR Certification effort. This week the CSA also published the results of it survey on government access to information, in light of recent concerns over ownership and access to cloud-based data.

³With over 48,000 individual members, and 70 chapters globally, the CSA has become the global authoritative source for trust in the cloud,² said Dave Cullinane, Chairman of the CSA Board of Directors. ³As we look to the future, we believe that enabling assurance in a global compute utility is one of the greatest challenges facing the industry, if we want cloud computing to meet its potential. As a result, we continue to focus our efforts on enabling transparency among cloud providers, for the benefit of consumers around the world.²

STAR Registry Grows to Over 30 Entries from Major Cloud Providers

In late 2011, the CSA introduced the Security, Trust and Assurance Registry (STAR), the first step in improving transparency and assurance in the cloud. The CSA has seen tremendous growth in STAR, with major cloud players including Amazon Web Services, Box.com, HP, Microsoft, Ping Identity, Red Hat, Skyhigh Networks, Symantec and Terremark submitting entries into the registry. These cloud providers recognize the need to provide transparency and assurance of their cloud services to corporations and end users, who are increasingly requesting visibility into the security controls provided by various cloud computing offerings. The CSA STAR is open to all cloud providers.

At the CSA EMEA Congress, to be held in September, the CSA and BSI will also officially launch the STAR Certification effort, the next step in the CSA STAR program, designed to provide an incremental level of visibility and transparency into the operations of the cloud service provider.

Survey Finds Concern with Government Access to Information

The CSA today also published the results of its recent survey on government access to information. The survey received almost 500 responses from CSA members around the world. It found that 56% of non-US residents were now less likely to use US-based cloud providers, in light of recent revelations about government access to customer information. An overwhelming 90% of respondents said that companies who have been subpoenaed through provisions of the Patriot Act should be able to publish summary information about the amount of responses they have made.

Full results of the survey can be found at https://cloudsecurityalliance.org/research/surveys/#_nsa_prism.

Jim Reavis, co-founder and executive director of the CSA, will be highlighting these results in a SC Magazine eConference on Securing the Cloud, today, July 23rd, at noon ET. The CSA also plans to host a Cloud Bytes panel in the coming weeks to discuss the issues facing cloud providers and consumers.

³Transparency has always been a significant part of the CSA¹s vision, and today this objective is more critical than ever,² said Reavis. ³Our goal with our research efforts, and with the CSA STAR program, is to continue to encourage transparency of security practices within cloud providers. By educating both consumers and providers of cloud services, we strive to provide the tools needed to make informed decisions that take advantage of all the benefits cloud computing has to offer.²

Tweet this: CSA releases results of NSA/PRISM survey; over 30 major cloud vendors have now submitted to @cloudsa STAR #transparency http://ow.ly/neplI

About Cloud Security Alliance

The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3090
Published: 2014-09-23
IBM Rational ClearCase 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVE-2014-3101
Published: 2014-09-23
The login form in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not insert a delay after a failed authentication attempt, which makes it easier for remote attackers to obtain access via a brute-force attack.

CVE-2014-3103
Published: 2014-09-23
The Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http...

CVE-2014-3104
Published: 2014-09-23
IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVE-2014-3105
Published: 2014-09-23
The OSLC integration feature in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account n...

Best of the Web
Dark Reading Radio