NIST Issues Set Of Guidelines For Managing Security, Privacy Issues In The Cloud

The National Institute of Standards and Technology (NIST) has issued two new draft documents on cloud computing for public comment, including the first set of guidelines for managing security and privacy issues in cloud computing. The agency also has set up a new NIST Cloud Computing Collaboration site on the Web to enable two-way communication among the cloud community and NIST cloud research working groups.

United States Chief Information Officer Vivek Kundra asked NIST to accelerate the federal government's secure adoption of cloud computing by leading efforts to develop standards and guidelines in collaboration with standards bodies, the private sector and other stakeholders. These new draft documents and the collaboration site are part of NIST's work to fulfill that mission.

NIST has been researching cloud computing for several years and has been documenting a definition of cloud computing on its web page. Researchers have now published A NIST Definition of Cloud Computing (NIST Special Publication (SP) 800-145). NIST scientists are looking for feedback to determine if this definition remains valid or needs modification. SP 800-145 may be downloaded for review from http://csrc.nist.gov/publications/nistpubs/800-145/SP800-145.pdf, and comments on suggested changes or enhancements should be sent to 800-145comments@nist.gov no later than February 28.

Guidelines on Security and Privacy in Public Cloud Computing (SP 800-144) provides an overview of the security and privacy challenges for public cloud computing and presents recommendations that organizations should consider when outsourcing data, applications and infrastructure to a public cloud environment. The key guidelines recommended to federal departments and agencies, and applicable to the private sector, include:

Carefully plan the security and privacy aspects of cloud computing solutions before engaging them.

Understand the public cloud computing environment offered by the cloud provider and ensure that a cloud computing solution satisfies organizational security and privacy requirements.

Ensure that the client-side computing environment meets organization security and privacy requirements for cloud computing.

Maintain accountability over the privacy and security of data and applications implemented and deployed in public cloud computing environments.

Public comments are requested on this publication. SP 800-144 may be downloaded for review from http://csrc.nist.gov/publications/nistpubs/800-144/SP800-144.pdf, and suggested changes or enhancements should be sent to 800-144comments@nist.gov no later than February 28.

To further foster the cloud community's collaboration aimed to enhance the federal government's secure adoption of cloud computing, NIST also has created the NIST Cloud Computing Collaboration Site at http://collaborate.nist.gov/twiki-cloud-computing/bin/view/CloudComputing/.

This site provides general information about NIST's cloud computing program and an up-to-date listing of cloud computing events. One set of pages are used by the NIST-sponsored Cloud Computing working groups. These groups, which are open to all those who wish to register and participate, were established during the November 2010 Cloud Computing Forum and Workshop II, and include Business Use Cases, Reference Architecture and Taxonomy, Standards Roadmap, Standards Acceleration to Jumpstart the Adoption of Cloud Computing (SAJACC), and Cloud Security.

Each working group's page provides descriptions of the group's task, weekly meeting information and working documents. To contribute to the TWiki, register from the link on the main NIST Cloud Computing Program website at http://www.nist.gov/itl/cloud/.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West
  • Live From ISC West 2024: Post-Show Recap

    ISC West 2024 is complete. And from start to finish, the entire conference was a huge success with almost 30,000 people in attendance. Read Now

    • Industry Events
    • ISC West
  • ISC West 2024 is a Rousing Success

    The 2024 ISC West security tradeshow marked a pivotal moment in the industry, showcasing cutting-edge technology and innovative solutions to address evolving security challenges. Exhibitors left the event with a profound sense of satisfaction, as they witnessed a high level of engagement from attendees and forged valuable connections with potential clients and partners. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge. 3

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation. 3