With the current state of the economy, budgets across organizations are being slashed and the IT/Security department budgets are no different. As a result, organizations are looking at ways to reduce their costs, yet remain or still try to become compliant with numerous regulatory mandates. So, what organization would not want to have free antivirus? Now, what if I threw in a smaller footprint and a reduced load on system resources than traditional antivirus applications? Snake Oil? Silver Bullet?
Last week, Panda Security announced the public beta release of their free cloud-based antivirus “thin-client” solution. Panda has stated that this solution will result in 50-percent less impact on PC performance when compared to fat-client signature-based antivirus programs. While this product is more intended for the home-user, several other services and products intended for commercial and government organizations exist. As such, one must look at the implications of moving security operations into the cloud before introducing them into the enterprise.
Cloud computing offers reduced hardware costs by moving hardware and administrative duties off-site. But as a side effect, your organization’s sensitive information is accessed and may be stored off-site. In this entry, I am not going to go through every question you should ask your cloud-services provider. However, before you start using these services, you should ensure the third-party address the following high-level issues that meet or exceed your own requirements:
- Data storage
- Data access methods
- Physical security
- Access control