Welcome to BookBoardz.com!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

REVIEW: "Cloud Security and Privacy", Tim Mather/Subra Kum..

 
   Book Forums (Home) -> Technical RSS
Next:  MBR: The Sports Shelf  
Author Message
Rob Slade, doting grandpa

External


Since: Oct 24, 2008
Posts: 33



(Msg. 1) Posted: Sat Jul 03, 2010 8:25 pm
Post subject: REVIEW: "Cloud Security and Privacy", Tim Mather/Subra Kumaraswamy/Shahed Latif
Archived from groups: misc>books>technical, others (more info?)

BKCLSEPR.RVW 20091113

"Cloud Security and Privacy", Tim Mather/Subra Kumaraswamy/Shahed
Latif, 2009, 978-0-596-802769, U$34.99/C$43.99
%A Tim Mather
%A Subra Kumaraswamy
%A Shahed Latif
%C 103 Morris Street, Suite A, Sebastopol, CA 95472
%D 2009
%G 978-0-596-802769 0-596-802765
%I O'Reilly & Associates, Inc.
%O U$34.99/C$43.99 800-998-9938 707-829-0515 nuts.TakeThisOut@ora.com
%O http://www.amazon.com/exec/obidos/ASIN/0596802765/robsladesinterne
http://www.amazon.co.uk/exec/obidos/ASIN/0596802765/robsladesinte-21
%O http://www.amazon.ca/exec/obidos/ASIN/0596802765/robsladesin03-20
%O Audience i- Tech 1 Writing 1 (see revfaq.htm for explanation)
%P 312 p.
%T "Cloud Security and Privacy"

The preface tells how the authors met, and that they were interested
in writing a book on clouds and security. It provides no definition
of cloud computing. (It also emphasizes an interest in being "first
to market" with a work on this topic.)

Chapter one is supposed to be an introduction. It is very brief, and,
yet again, doesn't say what a cloud is. (The authors aren't very
careful about building background information: the acronym SPI is
widely used and important to the book, but is used before it is
defined. It stands for Saas/Paas/Iaas, or software-as-a-service,
platform-as-a-service, and infrastructure-as-a-service. More simply,
this refers to applications, management/development utilities, and
storage.) A delineation of cloud computing is finally given in
chapter two, stating that it is characterized by multitenancy,
scalability, elasticity, pay-as-you-go options, and self-provisioning.
(As these aspects are expanded, it becomes clear that the scalability,
elasticity, and self-provisioning characteristics the authors describe
are essentially the same thing: the ability of the user or client to
manage the increase or decrease in services used.) The fact that the
authors do not define the term "cloud" becomes important as the guide
starts to examine security considerations. Interoperability is listed
as a benefit of the cloud, whereas one of the risks is identified as
vendor lock-in: these two factors are inherently mutually exclusive.

Chapter three talks about infrastructure security, but the advice
seems to reduce to a recommendation to review the security of the
individual components, including Saas, Paas, and network elements,
which seems to ignore the emergent risks arising from any complex
environment. Encryption is said to be only a small part of data
security in storage, as addressed in chapter four, but most of the
material discusses encryption. The deliberation on cryptography is
superficial: the authors have managed to include the very recent
research on homomorphic encryption, and note that the field will
advance rapidly, but do not mention that homomorphic encryption is
only useful for a very specific subset of data representations. The
identity management problem is outlined in chapter five, and protocols
for managing new systems are reviewed, but the issue of integrating
these protocols with existing systems is not. "Security management in
the Cloud," as examined in chapter six, is a melange of general
security management and operations management, with responsibility
flipping back and forth between the customer and the provider.
Chapter seven provides a very good overview of privacy, but with
almost no relation to the cloud as such. Audit and compliance
standards are described in chapter eight: only one is directed at the
cloud. Various cloud service providers (CSP) are listed in chapter
nine. The terse description of security-as-a-service (confusingly
also listed as Saas), in chapter ten, is almost entirely restricted to
spam and Web filtering. The impact of the use of cloud technology is
dealt with in chapter eleven. It lists the pros and cons, but again,
some of the points are presented without noting that they are mutually
exclusive. Chapter twelve finishes off the book with a precis of the
foregoing chapters.

The authors do raise a wide variety of the security problems and
concerns related to cloud computing. However, since these are the
same issues that need to be examined in any information security
scenario it is hard to say that any cloud-specific topics are
addressed. Stripped of excessive verbiage, the advice seems to reduce
to a) know what you want, b) don't make assumptions about what the
provider provides, and c) audit the provider.

copyright Robert M. Slade, 2009 BKCLSEPR.RVW 20091113

--
======================
rslade.TakeThisOut@vcn.bc.ca slade.TakeThisOut@victoria.tc.ca rslade.TakeThisOut@computercrime.org
"Dictionary of Information Security," Syngress 1597491152
http://blogs.securiteam.com/index.php/archives/author/p1/
http://blog.isc2.org/isc2_blog/slade/index.html
http://twitter.com/rslade http://twitter.com/NoticeBored
============= for back issues:
[Base URL] site http://victoria.tc.ca/techrev/
CISSP refs: [Base URL]mnbksccd.htm
Book reviews: [Base URL]mnbk.htm
Review mailing list: send mail to techbooks-subscribe.TakeThisOut@egroups.com
or techbooks-subscribe.TakeThisOut@topica.com

 >> Stay informed about: REVIEW: ""Cloud Security and Privacy"", Tim Mather/Subra Kum.. 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
REVIEW: "Web Site Privacy with P3P", Helena Lindskog/Stefa.. - BKWSPP3P.RVW 20031019 "Web Site Privacy with P3P", Helena Lindskog/Stefan Lindskog, 2003, 0-471-21677-1, U$40.00/C$61.95/UK#27.95 %A Helena Lindskog %A Stefan Lindskog %C 5353 Dundas Street West, 4th Floor, Etobicoke, ON M9B 6H8 %D ...

REVIEW: "Security Assessment", Greg Miles et al - BKSACSNI.RVW 20040721 "Security Assessment", Greg Miles et al, 2004, 1-932266-96-8, U$69.95/C$89.95 %A Greg Miles gmiles@securityhorizon.com %A Russ Rogers rrogers@securityhorizon.com %A Ed Fuller %A Matthew Paul Hoagberg %A Ted Dy...

REVIEW: "Effective Security Management", Charles A. Sennew.. - BKEFSCMN.RVW 20031006 "Effective Security Management", Charles A. Sennewald, 2003, 0-7506-7454-7, U$49.95/C$72.50 %A Charles A. Sennewald %C 225 Wildwood Street, Woburn, MA 01801 %D 2003 %G 0-7506-7454-7 %I Butterworth-Heinemann/C...

REVIEW: "The Myth of Homeland Security", Marcus J. Ranum - BKMYHLSC.RVW 20031124 "The Myth of Homeland Security", Marcus J. Ranum, 2004, 0-471-45879-1, U$24.99/C$37.50 %A Marcus J. Ranum mjr@ranum.com %C 5353 Dundas Street West, 4th Floor, Etobicoke, ON M9B 6H8 %D 2004 %G 0-471-45879-1 %I ...

REVIEW: "PKI Security Solutions for the Enterprise", Kapil.. - BKPKISSE.RVW 20031025 "PKI Security Solutions for the Enterprise", Kapil Raina, 2003, 0-471-31529-X, U$40.00/C$61.95/UK#27.95 %A Kapil Raina %C 5353 Dundas Street West, 4th Floor, Etobicoke, ON M9B 6H8 %D 2003 %G 0-471-31529-X %I ...
   Book Forums (Home) -> Technical All times are: Pacific Time (US & Canada)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]