Penetrating the cloud

Greg Jones · Network Security · 2013

Picture a hazy utopia, where data and resources are available to users irrespective of their location, mode of access or the device used. That was the future promised by the cloud and which has seen many organisations move at least some part of their operations across to these virtual networks. However, what we are only just beginning to be aware of is that the cloud may be just as insubstantial as its name suggests when it comes to security. It would seem the complexity of testing these virtual environments is only now becoming apparent. In the event of a cloud security breach there's only one real loser – the end user. With Cloud Service Providers (CSPs) dodging the security bullet, organisations need to step up to ensure their data and applications are made secure. Traditional approaches to penetration testing do not translate well to the cloud. However, virtualised penetration testing is capable of bridging the physical/virtual network divide. It gives back control over data in the cloud to the organisation and offers the security assurance that has been found wanting from many CSPs, says Greg Jones at Digital Assurance.

Read the paper · More papers on PaperTik