Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

New Cloud Security Certification Launched

The Cloud Security Alliance (CSA), an industry group seeking to promote security standards for cloud computing, is offering an online certification program beginning September 1st.

With companies fretting about the risks of cloud computing, the nonprofit Cloud Security Alliance thinks it's time to start selling a certification test for cloud security skills. Dubbed the Certificate of Cloud Security Knowledge, it's a Web-based test for competency in CSA standards to secure private, public, and hybrid cloud environments.

CSA, a nonprofit founded early last year, has 11,000 individual and 60 corporate members, including Cisco Systems, Dell, Google, Hewlett-Packard, Microsoft, and Oracle. The test costs $195 through the end of the year, then rises to $295. Security and risk management are major concerns for companies considering adopting public cloud services (see chart above).

But verifying the skills of individuals in cloud security isn't the top challenge for companies right now, says Greg Shipley, CTO of information security and risk management firm Neohapsis. The bigger challenge is getting cloud providers to agree to be audited and provide evidence that they're doing what they say they do. "Most cloud providers either have some basic evidence of their controls in the form of a SAS 70 Type II audit--which they may or may not share with you--or they have nothing at all," Shipley says, adding that visibility is the main problem.

CSA also provides a Cloud Controls Matrix that describes 98 cloud computing control specifications, helping identify the presence of appropriate security controls in a cloud environment. Version 2.0 is expected to be available in November.

Another CSA effort is the Trusted Cloud Initiative, which helps cloud providers develop their own standards for secure and interoperable identity, access, and compliance management. An initial version of the Trusted Cloud Initiative is due in the fourth quarter. --Robert J. Mullins

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18202
PUBLISHED: 2019-10-19
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.
CVE-2019-18209
PUBLISHED: 2019-10-19
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
CVE-2019-18198
PUBLISHED: 2019-10-18
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
CVE-2019-18197
PUBLISHED: 2019-10-18
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclo...
CVE-2019-4409
PUBLISHED: 2019-10-18
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message that includes the entere...