Industry Insights
Read the latest cloud security news, trends, and thought leadership from subject matter experts.

Plugging "Cloud Identity Leaks" - Why Your Business Should Become an Identity Provider
By Mark O’Neill VP Innovation – API & Identity Management, Axway (following Vordel acquisition)Most people have used the Facebook, Twitter, or Google Apps buttons located on Websites to log into third party services. This approach is useful within consumer IT as it enables the user to access vari...
Cloud-to-Ground, The Last Frontier?
Whilst Cloud-to-Cloud service integration is relatively straight forward, Cloud service to on premise integration presents more challenges for the enterprise architect By Ed King, VP Product Marketing – Axway (following acquisition of Vordel) Cloud-to-Cloud security integration is now a fairly...
Security Check List: An Ounce of Prevention is Better than a Pound of Cure
By Wolfgang KandekIt is common belief that buying more robust and expensive security products will offer the best protection from computer-based attacks; that ultimately the expenditure pays off by preventing data theft. According to Gartner, more than $50 billion is spent annually on security in...
Identity Management Plays a Key Role in Mobile Device Management (MDM)
By: Dan Dagnall, Chief Technology Strategist, Fischer International IdentityAs BYOD and other mobile device related initiatives take hold, sooner rather than later, identity management will once again be considered as an enforcement mechanism; and rightly it should.Identity and access management ...
How to Adopt the Public Cloud While Attaining Private Cloud Control and Security
Earlier this year, McKinsey & Company released an article titled “Protecting information in the cloud,” discussing the increased use of cloud computing by enterprises across several industries and the benefits and risks associated with cloud usage. The article recognizes that many organizations a...
Cloud-Based Identity Management: Best Practices for Rapid End-User Adoption
By Glenn Choquette, Director of Product Management, Fischer International Identity.Executive SummaryIdentity Management (IdM) is not new. Yet after all this time on the market, organizations still have mixed results for end-user adoption, as many organizations that rolled-out IdM years ago still ...
How secure is Mobile Device Management anyway?
Researchers have successfully breached the Good Technology container. MDM software can only be as secure as the underlying operating system.As the adoption of smartphones and tablets grows exponentially, one of the biggest challenges facing corporate IT organizations is not the threat of losing...
Cloud APIs - the Next Battleground for Denial-of-Service Attacks
by Mark O'Neill In recent months, there have been a number of highly publicized cyberattacks on U.S. banks. These attacks took the form of Distributed Denial of Service (DDoS) attacks, involving enormous amounts of traffic being sent to Internet-facing banking services, rendering them unusable...
Going up? Safety first, then send your data to the cloud
By: Joe Sturonas, CTO, PKWAREAs the proliferation of data continues to plague businesses, the pressure is on for companies to migrate away from their physical data centers. Cloud computing is being adopted at a rapid rate because it addresses not only the costs for physical space, but also rising...
How to Harden Your APIs
The market for APIs has experienced explosive growth in recent years, yet the major issues that providers still face are protection and hardening of the APIs that they expose to users. In particular, when you are exposing APIs from a cloud based platform, this becomes very difficult to achieve gi...
Three Critical Features That Define an Enterprise-Grade Cloud Service
By David Baker, CSO at OktaThe line between enterprise and consumer is fading as employees work from all manner of devices to access the on-premises, cloud and even consumer applications needed to get work done. But it’s important to not confuse enterprise and consumer services from a security st...
The Shrinking Security Model: Micro-perimeters
By Ed King, VP Product Marketing – Emerging Technologies, Axway (following acquisition of Vordel)As Cloud and mobile computing make enterprise IT ever more extended, the traditional security model of keeping the bad guys out and allowing only the good guys in no longer works well. While the reac...
Upcoming Cloud Security Training in EMEA - sign up today!
Securosis has recently updated the CCSK training curriculum to be in alignment with the Cloud Security Alliance Guidance V3.0, and the training class is much improved. Many of the hands-on exercises have been overhauled, and if you are looking to get familiar with cloud security you will want to ...
The Dark Side of Big Data: CSA Opens Peer Review Period for the “Top Ten Big Data and Privacy Challenges” Report
Big Data seems to be on the lips of every organization’s CXO these days. By exploiting Big Data, enterprises are able to gain valuable new insights into customer behavior via advanced analytics. However, what often gets lost amidst all the excitement are the very real and many security and privac...
CSA Releases CCM v 3.0
The Cloud Security Alliance (CSA) today has released a draft of the latest version of the Cloud Control Matrix, CCM v3.0. This latest revision to the industry standard for cloud computing security controls realigns the CCM control domains to achieve tighter integration with the CSA’s “Security Gu...
CSA Drafts New SOC Position Paper
Phil Agcaoili, Founding Member, Cloud Security AllianceDavid Barton, Principal, UHY AdvisorsIn June 2011, the American Institute of Certified Public Accountants (AICPA) eliminated SAS 70 which had been a commonly used reporting standard within the information technology industry for providing thi...
When Good Is Not Good Enough: NIST Raises the Bar for Cloud Data Protection Vendors
Earlier this year, the National Institute of Standards and Technology (NIST) released a publication titled Cloud Computing Synopsis & Recommendations (Special Publication 800-146) describing in detail the current cloud computing environment, explaining the economic opportunities and risks associa...
Critical Infrastructure and the Cloud
Cloud computing continues to be a hot topic. But so what if people are talking about it, who is actually adopting it? One of the questions I have been asking myself is, ‘Will cloud be adopted for critical infrastructure? And what is the security perspective on this?Naturally a blog to answer that...
Towards a “Permanent Certified Cloud”: Monitoring Compliance in the Cloud with CTP 3.0
Cloud services can be monitored for system performance but can they also be monitored for compliance? That’s one of the main questions that the Cloud Trust Protocol aims to address in 2013.Compliance and transparency go hand in hand.The Cloud Trust Protocol (CTP) is designed to allow cloud custom...
Assurance for Tomorrow’s Cloud
Cloud computing, and Big Data are natural bedfellows. Add to that mix, Critical infrastructure, and consumers and all of a sudden the need for greater assurance only increases. We will soon witness convergence of these technological advancements on a monumental scale, with previously disconnect...
Browse by Topic
Write for the CSA blog
Submit your blog proposalSign up to receive CSA's latest blogs
This list receives 1-2 emails a month.