<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>Speaking of Security - The RSA Blog and Podcast &#187; Nirav Mehta</title>
	<atom:link href="http://blogs.rsa.com/author/mehta/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.rsa.com</link>
	<description>The Security Blog for Security Professionals</description>
	<lastBuildDate>Fri, 17 May 2013 12:30:58 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5</generator>
<!-- podcast_generator="Blubrry PowerPress/4.0.7" -->
	<itunes:summary>The Speaking of Security podcast features lively discussion with industry experts on the latest issues and trends in the security industry.</itunes:summary>
	<itunes:author>RSA, The Security Division of EMC</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://blogs.rsa.com/wp-content/uploads/userphoto/sos.png" />
	<itunes:owner>
		<itunes:name>RSA, The Security Division of EMC</itunes:name>
		<itunes:email>podcast@rsa.com</itunes:email>
	</itunes:owner>
	<managingEditor>podcast@rsa.com (RSA, The Security Division of EMC)</managingEditor>
	<itunes:subtitle>The Security Blog for Security Professionals</itunes:subtitle>
	<itunes:keywords>Security, Cyber Crime, APTs, Sam Curry, RSA, EMC, Advanced Persistant Threats, Fraud</itunes:keywords>
	<image>
		<title>Speaking of Security - The RSA Blog and Podcast &#187; Nirav Mehta</title>
		<url>http://blogs.rsa.com/wp-content/uploads/userphoto/sos.png</url>
		<link>http://blogs.rsa.com</link>
	</image>
	<itunes:category text="Technology">
		<itunes:category text="Tech News" />
		<itunes:category text="Podcasting" />
	</itunes:category>
		<item>
		<title>Darkness Lies Directly Under the Candle</title>
		<link>http://blogs.rsa.com/darkness-lies-directly-under-the-candle/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=darkness-lies-directly-under-the-candle</link>
		<comments>http://blogs.rsa.com/darkness-lies-directly-under-the-candle/#comments</comments>
		<pubDate>Thu, 01 Nov 2012 13:07:55 +0000</pubDate>
		<dc:creator>Nirav Mehta</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[encryption]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=7084</guid>
		<description><![CDATA[Far too often, we fail to see the obvious weaknesses in our defenses.  Over 50 million consumer passwords have been reported stolen in 2012 alone in highly visible ‘smash and grab’ attacks.  Yahoo, LinkedIN, Zappos, eHarmony…the list goes on.   This is the equivalent of robbery in broad daylight.  How did we as an industry let [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://blogs.rsa.com/wp-content/uploads/candle.jpg"><img class="alignleft size-medium wp-image-7085" title="candle" src="http://blogs.rsa.com/wp-content/uploads/candle-300x200.jpg" alt="" width="300" height="200" /></a></p>
<p>Far too often, we fail to see the obvious weaknesses in our defenses.  Over 50 million consumer passwords have been reported stolen in 2012 alone in highly visible ‘smash and grab’ attacks.  Yahoo, LinkedIN, Zappos, eHarmony…the list goes on.   This is the equivalent of robbery in broad daylight.  How did we as an industry let this happen?   The answer reminds me a lot like the title of this post which is also an ancient saying that has rung true for ages. </p>
<p>First, let’s give credit where it is due.   Website operators have been proactive in shoring up their defenses including: </p>
<ul>
<li>Web application firewalls and a variety of network defenses to thwart attacks</li>
<li>Advanced forensic tools to detect and trace malicious activity</li>
<li>Multifactor and risk-based authentication tools to augment the quality of authentication provided by passwords</li>
</ul>
<p>But, the simple truth is that good old passwords remain at the foundation of this multi-layered defense.  We failed to ask a simple question – ‘Are the passwords properly secured where they are stored?’ We have the equivalent of installing a digital motion sensing alarm at the front door while the backdoor is secured with string.    Why?   Because the technology used to protect the stored passwords has become outdated.   Several websites simply hash passwords while some store salted hashes.  Current state of the art of cryptography and the compute power available readily to attackers have made it possible to crack 100,000 passwords in just a matter of hours using <a href="http://arstechnica.com/security/2012/08/passwords-under-assault/">inexpensive hardware</a>.  Hashing and salted hashing are no longer adequate protection for stored passwords.   Attackers have taken full advantage of these advances to bring down the outdated defenses protecting stored passwords.</p>
<p>Granted, individual passwords are often weak and phishing attacks continue to threaten the security of the individual user.  But, the threat of en masse theft of millions of passwords is even bigger and too grave to be left unaddressed.  The impact of a realized threat is high because users tend to use the same passwords for multiple websites.  Compromise of one website can very quickly lead to multiple other websites falling like dominoes.  The damage done to consumer confidence and brands of consumer-facing businesses is too high to measure.</p>
<p>Passwords are not going away any time soon.  They are convenient and they are everywhere.  Consumer websites will continue to use passwords for a long time to come although we will try as an industry to foster adoption of other stronger authentication methods.  We have to solve the problem of unprotected passwords decisively and immediately.</p>
<p>At RSA, we have a legacy of innovation in authentication including PKI, multi-factor authentication techniques and layered risk-based authentication.  We continue to innovate in those fields but we felt it necessary to take a step back and deliver a strong solution for protecting stored passwords.  This is why we <a href="http://www.youtube.com/watch?v=C0k_EMf2qqw">announced</a> RSA Distributed Credential Protection last month at RSA Conference in London.  This is a product developed at RSA based on patented innovation from cryptographers at RSA Labs.   The technology behind the product employs the proven methods of threshold cryptography but applies it in practical ways to essentially split passwords into multiple random pieces stored on secure servers.   The <a href="http://www.youtube.com/watch?v=QyGTylPCsjQ">key innovation</a> is that passwords can be authenticated at runtime by the secure servers without any need for passwords to be reassembled. </p>
<p>With this simple solution, websites will be able to split their passwords across multiple locations and security domains.  An attacker would have to compromise and gain access to all servers to gain access to the passwords. With proper separation of security domains and networks, this would be very difficult.  We make it even harder by offering the option to periodically randomize the stored password pieces again to further reduce the window of time in which the attack has to be performed. </p>
<p>This simple but powerful technique would strengthen security where it really matters – at its foundation – where the passwords are stored.  Ultimately, the goal is to stay one step ahead of the attackers.  WithRSADistributed Credential Protection, we can raise the cost of attack exponentially.  </p>
<p>There is no better alternative to a layered defense.  We must secure both the ‘front door’ (multi-factor and risk-based authentication, fraud detection, application firewalls) and the ‘back door’ (stored passwords, privileged users/insiders, software security).    As an industry, we have spent disproportionate amount of our time on the front door.  With RSA Distributed Credential Protection, we hope to close the back door to the passwords and keep it shut tight! </p>
<p>***This blog was contributed to the <a href="https://blogs.rsa.com/author/idp-beat/">Identity and Data Protection Beat</a> by Nirav Mehta.***</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;t=Darkness%20Lies%20Directly%20Under%20the%20Candle%20"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Darkness%20Lies%20Directly%20Under%20the%20Candle%20%20-%20http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;title=Darkness%20Lies%20Directly%20Under%20the%20Candle%20&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=%0D%0A%0D%0AFar%20too%20often%2C%20we%20fail%20to%20see%20the%20obvious%20weaknesses%20in%20our%20defenses.%C2%A0%20Over%2050%20million%20consumer%20passwords%20have%20been%20reported%20stolen%20in%202012%20alone%20in%20highly%20visible%20%E2%80%98smash%20and%20grab%E2%80%99%20attacks.%C2%A0%20Yahoo%2C%20LinkedIN%2C%20Zappos%2C%20eHarmony%E2%80%A6the%20list%20goes"></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Darkness%20Lies%20Directly%20Under%20the%20Candle%20&body=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-7084')" id="sociable-post-7084" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;t=Darkness%20Lies%20Directly%20Under%20the%20Candle%20"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;title=Darkness%20Lies%20Directly%20Under%20the%20Candle%20&amp;notes=%0D%0A%0D%0AFar%20too%20often%2C%20we%20fail%20to%20see%20the%20obvious%20weaknesses%20in%20our%20defenses.%C2%A0%20Over%2050%20million%20consumer%20passwords%20have%20been%20reported%20stolen%20in%202012%20alone%20in%20highly%20visible%20%E2%80%98smash%20and%20grab%E2%80%99%20attacks.%C2%A0%20Yahoo%2C%20LinkedIN%2C%20Zappos%2C%20eHarmony%E2%80%A6the%20list%20goes"></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;title=Darkness%20Lies%20Directly%20Under%20the%20Candle%20&amp;bodytext=%0D%0A%0D%0AFar%20too%20often%2C%20we%20fail%20to%20see%20the%20obvious%20weaknesses%20in%20our%20defenses.%C2%A0%20Over%2050%20million%20consumer%20passwords%20have%20been%20reported%20stolen%20in%202012%20alone%20in%20highly%20visible%20%E2%80%98smash%20and%20grab%E2%80%99%20attacks.%C2%A0%20Yahoo%2C%20LinkedIN%2C%20Zappos%2C%20eHarmony%E2%80%A6the%20list%20goes"></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;title=Darkness%20Lies%20Directly%20Under%20the%20Candle%20"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&title=Darkness%20Lies%20Directly%20Under%20the%20Candle%20"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;title=Darkness%20Lies%20Directly%20Under%20the%20Candle%20&amp;annotation=%0D%0A%0D%0AFar%20too%20often%2C%20we%20fail%20to%20see%20the%20obvious%20weaknesses%20in%20our%20defenses.%C2%A0%20Over%2050%20million%20consumer%20passwords%20have%20been%20reported%20stolen%20in%202012%20alone%20in%20highly%20visible%20%E2%80%98smash%20and%20grab%E2%80%99%20attacks.%C2%A0%20Yahoo%2C%20LinkedIN%2C%20Zappos%2C%20eHarmony%E2%80%A6the%20list%20goes"></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;t=Darkness%20Lies%20Directly%20Under%20the%20Candle%20"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Darkness%20Lies%20Directly%20Under%20the%20Candle%20&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=%0D%0A%0D%0AFar%20too%20often%2C%20we%20fail%20to%20see%20the%20obvious%20weaknesses%20in%20our%20defenses.%C2%A0%20Over%2050%20million%20consumer%20passwords%20have%20been%20reported%20stolen%20in%202012%20alone%20in%20highly%20visible%20%E2%80%98smash%20and%20grab%E2%80%99%20attacks.%C2%A0%20Yahoo%2C%20LinkedIN%2C%20Zappos%2C%20eHarmony%E2%80%A6the%20list%20goes"></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;Title=Darkness%20Lies%20Directly%20Under%20the%20Candle%20"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;title=Darkness%20Lies%20Directly%20Under%20the%20Candle%20&amp;selection=%0D%0A%0D%0AFar%20too%20often%2C%20we%20fail%20to%20see%20the%20obvious%20weaknesses%20in%20our%20defenses.%C2%A0%20Over%2050%20million%20consumer%20passwords%20have%20been%20reported%20stolen%20in%202012%20alone%20in%20highly%20visible%20%E2%80%98smash%20and%20grab%E2%80%99%20attacks.%C2%A0%20Yahoo%2C%20LinkedIN%2C%20Zappos%2C%20eHarmony%E2%80%A6the%20list%20goes"></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;t=Darkness%20Lies%20Directly%20Under%20the%20Candle%20&amp;s=%0D%0A%0D%0AFar%20too%20often%2C%20we%20fail%20to%20see%20the%20obvious%20weaknesses%20in%20our%20defenses.%C2%A0%20Over%2050%20million%20consumer%20passwords%20have%20been%20reported%20stolen%20in%202012%20alone%20in%20highly%20visible%20%E2%80%98smash%20and%20grab%E2%80%99%20attacks.%C2%A0%20Yahoo%2C%20LinkedIN%2C%20Zappos%2C%20eHarmony%E2%80%A6the%20list%20goes"></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;title=Darkness%20Lies%20Directly%20Under%20the%20Candle%20&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fdarkness-lies-directly-under-the-candle%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-7084')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-7084',true)" class="close">

		  <img onclick="hide_sociable('post-7084',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/darkness-lies-directly-under-the-candle/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/darkness-lies-directly-under-the-candle/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Laying the foundation for tomorrow’s IAM</title>
		<link>http://blogs.rsa.com/laying-the-foundation-for-tomorrows-iam/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=laying-the-foundation-for-tomorrows-iam</link>
		<comments>http://blogs.rsa.com/laying-the-foundation-for-tomorrows-iam/#comments</comments>
		<pubDate>Wed, 12 Sep 2012 12:59:24 +0000</pubDate>
		<dc:creator>Nirav Mehta</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[identity and access management]]></category>
		<category><![CDATA[identity federation]]></category>
		<category><![CDATA[Risk-based Authentication]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=6359</guid>
		<description><![CDATA[The last time I witnessed a reboot of identity and access management (IAM) infrastructure was 1996.  Web applications had taken hold and intranets and extranets were buzz words. The security industry responded with web access management (WAM), provisioning, strong authentication and directory services.  The industry has since built on these technologies to deliver identity federation, risk-based authentication and identity and access governance.  All these IAM technologies have served us well but a wave of new developments has revealed the need for a rethink.]]></description>
				<content:encoded><![CDATA[<p>The last time I witnessed a reboot of identity and access management (IAM) infrastructure was 1996.  Web applications had taken hold and intranets and extranets were buzz words. The security industry responded with web access management (WAM), provisioning, strong authentication and directory services.  The industry has since built on these technologies to deliver identity federation, risk-based authentication and identity and access governance.  All these IAM technologies have served us well but a wave of new developments has revealed the need for a rethink:</p>
<ul>
<li>Web Access Management tools are struggling to keep up with exponential growth in number of users and applications (especially SaaS apps) as well as mobility of users. Static authentication and access policies are just not suitable for a highly dynamic set of access patterns and ever-changing risk profiles.</li>
</ul>
<ul>
<li>Provisioning technologies that operate on the principle of taking user information from one system and replicating it somewhere else are reaching their productivity limit as large numbers of applications are delivered from the cloud.  Provisioning systems were built to operate within a corporate network boundary.</li>
</ul>
<ul>
<li>Organizations are experiencing the substantial burden of integrating identity federation with dozens of cloud services.  Every organization is duplicating the repetitive tasks required to establish identity integration with every cloud service.</li>
</ul>
<p>Our challenge is to leverage and enrich the existing IAM tools to deliver the foundation for tomorrow’s IAM.  We believe this can be done.  We know this can be done.  Today, <a href="http://www.emc.com/about/news/press/2012/20120912-01.htm" target="_blank"><strong><span style="text-decoration: underline;">RSA has announced availability of three solutions</span></strong></a> that demonstrate how RSA is delivering the IAM infrastructure for the next 15 years.</p>
<ul>
<li>RSA has already integrated the <strong><a href="http://www.emc.com/security/rsa-identity-and-access-management/rsa-access-manager.htm">RSA Access Manager</a> (WAM)</strong> technology with <strong><a href="http://www.emc.com/security/rsa-identity-protection-and-verification/rsa-adaptive-authentication.htm">RSA Adaptive Authentication</a></strong> (risk-based authentication).  We are pleased to announce that this integration has been deepened to add the ability to authenticate users using one time passwords sent via out-of-band email.  The combination of WAM and risk-based authentication represents a new breed of risk-aware web access management that is enabling organizations to confidently roll out clouds for consumers and partners.</li>
</ul>
<ul>
<li>As identities grow in number and richness of context, the ability to provide a single source of truth about the user will become one of the most fundamental building blocks of IAM infrastructure. RSA has entered the identity management market by offering the <strong>RSA Adaptive Directory</strong>.   This is a familiar technology –virtual directory – that will be immensely important as the foundation upon which other IAM apps will depend.  In the context of the new IT, it will enable organizations to harvest identity information across the enterprise and expose it securely and flexibly to partners and cloud services.</li>
</ul>
<ul>
<li>Last year at RSA Conference, we announced the <strong>RSA Cloud Trust Authority</strong> (CTA) that would enable a new efficiency by providing the function of a cloud-based access broker.  Today, we have released the first component of the IAM component of CTA – <strong>RSA Adaptive Federation</strong>.  This is a federation-as-a-service product that would enable unprecedented ease of use and minimize the effort required for integration with SaaS apps.</li>
</ul>
<p>Seen in isolation, these technologies are very effective but the sum of these solutions is certainly larger than the parts.  We call this sum <a href="http://blogs.rsa.com/?p=6361" target="_blank"><strong>Adaptive IAM</strong></a>.  Adaptive in the face of cloud and mobile.  Adaptive in the face of ever-changing risk profiles. Adaptive in the face of the increasing number and richness of identities.</p>
<p>We, at RSA are lucky to have the opportunity to build on a great legacy and deliver the future.  These new solutions are only the beginning.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;t=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM%20-%20http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;title=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=The%20last%20time%20I%20witnessed%20a%20reboot%20of%20identity%20and%20access%20management%20%28IAM%29%20infrastructure%20was%201996.%20%20Web%20applications%20had%20taken%20hold%20and%20intranets%20and%20extranets%20were%20buzz%20words.%20The%20security%20industry%20responded%20with%20web%20access%20management%20%28WAM%29%2C%20provisioning%2C%20strong%20authentication%20and%20directory%20services.%20%20The%20industry%20has%20since%20built%20on%20these%20technologies%20to%20deliver%20identity%20federation%2C%20risk-based%20authentication%20and%20identity%20and%20access%20governance.%20%20All%20these%20IAM%20technologies%20have%20served%20us%20well%20but%20a%20wave%20of%20new%20developments%20has%20revealed%20the%20need%20for%20a%20rethink."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM&body=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-6359')" id="sociable-post-6359" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;t=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;title=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM&amp;notes=The%20last%20time%20I%20witnessed%20a%20reboot%20of%20identity%20and%20access%20management%20%28IAM%29%20infrastructure%20was%201996.%20%20Web%20applications%20had%20taken%20hold%20and%20intranets%20and%20extranets%20were%20buzz%20words.%20The%20security%20industry%20responded%20with%20web%20access%20management%20%28WAM%29%2C%20provisioning%2C%20strong%20authentication%20and%20directory%20services.%20%20The%20industry%20has%20since%20built%20on%20these%20technologies%20to%20deliver%20identity%20federation%2C%20risk-based%20authentication%20and%20identity%20and%20access%20governance.%20%20All%20these%20IAM%20technologies%20have%20served%20us%20well%20but%20a%20wave%20of%20new%20developments%20has%20revealed%20the%20need%20for%20a%20rethink."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;title=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM&amp;bodytext=The%20last%20time%20I%20witnessed%20a%20reboot%20of%20identity%20and%20access%20management%20%28IAM%29%20infrastructure%20was%201996.%20%20Web%20applications%20had%20taken%20hold%20and%20intranets%20and%20extranets%20were%20buzz%20words.%20The%20security%20industry%20responded%20with%20web%20access%20management%20%28WAM%29%2C%20provisioning%2C%20strong%20authentication%20and%20directory%20services.%20%20The%20industry%20has%20since%20built%20on%20these%20technologies%20to%20deliver%20identity%20federation%2C%20risk-based%20authentication%20and%20identity%20and%20access%20governance.%20%20All%20these%20IAM%20technologies%20have%20served%20us%20well%20but%20a%20wave%20of%20new%20developments%20has%20revealed%20the%20need%20for%20a%20rethink."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;title=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&title=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;title=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM&amp;annotation=The%20last%20time%20I%20witnessed%20a%20reboot%20of%20identity%20and%20access%20management%20%28IAM%29%20infrastructure%20was%201996.%20%20Web%20applications%20had%20taken%20hold%20and%20intranets%20and%20extranets%20were%20buzz%20words.%20The%20security%20industry%20responded%20with%20web%20access%20management%20%28WAM%29%2C%20provisioning%2C%20strong%20authentication%20and%20directory%20services.%20%20The%20industry%20has%20since%20built%20on%20these%20technologies%20to%20deliver%20identity%20federation%2C%20risk-based%20authentication%20and%20identity%20and%20access%20governance.%20%20All%20these%20IAM%20technologies%20have%20served%20us%20well%20but%20a%20wave%20of%20new%20developments%20has%20revealed%20the%20need%20for%20a%20rethink."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;t=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=The%20last%20time%20I%20witnessed%20a%20reboot%20of%20identity%20and%20access%20management%20%28IAM%29%20infrastructure%20was%201996.%20%20Web%20applications%20had%20taken%20hold%20and%20intranets%20and%20extranets%20were%20buzz%20words.%20The%20security%20industry%20responded%20with%20web%20access%20management%20%28WAM%29%2C%20provisioning%2C%20strong%20authentication%20and%20directory%20services.%20%20The%20industry%20has%20since%20built%20on%20these%20technologies%20to%20deliver%20identity%20federation%2C%20risk-based%20authentication%20and%20identity%20and%20access%20governance.%20%20All%20these%20IAM%20technologies%20have%20served%20us%20well%20but%20a%20wave%20of%20new%20developments%20has%20revealed%20the%20need%20for%20a%20rethink."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;Title=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;title=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM&amp;selection=The%20last%20time%20I%20witnessed%20a%20reboot%20of%20identity%20and%20access%20management%20%28IAM%29%20infrastructure%20was%201996.%20%20Web%20applications%20had%20taken%20hold%20and%20intranets%20and%20extranets%20were%20buzz%20words.%20The%20security%20industry%20responded%20with%20web%20access%20management%20%28WAM%29%2C%20provisioning%2C%20strong%20authentication%20and%20directory%20services.%20%20The%20industry%20has%20since%20built%20on%20these%20technologies%20to%20deliver%20identity%20federation%2C%20risk-based%20authentication%20and%20identity%20and%20access%20governance.%20%20All%20these%20IAM%20technologies%20have%20served%20us%20well%20but%20a%20wave%20of%20new%20developments%20has%20revealed%20the%20need%20for%20a%20rethink."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;t=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM&amp;s=The%20last%20time%20I%20witnessed%20a%20reboot%20of%20identity%20and%20access%20management%20%28IAM%29%20infrastructure%20was%201996.%20%20Web%20applications%20had%20taken%20hold%20and%20intranets%20and%20extranets%20were%20buzz%20words.%20The%20security%20industry%20responded%20with%20web%20access%20management%20%28WAM%29%2C%20provisioning%2C%20strong%20authentication%20and%20directory%20services.%20%20The%20industry%20has%20since%20built%20on%20these%20technologies%20to%20deliver%20identity%20federation%2C%20risk-based%20authentication%20and%20identity%20and%20access%20governance.%20%20All%20these%20IAM%20technologies%20have%20served%20us%20well%20but%20a%20wave%20of%20new%20developments%20has%20revealed%20the%20need%20for%20a%20rethink."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;title=Laying%20the%20foundation%20for%20tomorrow%E2%80%99s%20IAM&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Flaying-the-foundation-for-tomorrows-iam%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-6359')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-6359',true)" class="close">

		  <img onclick="hide_sociable('post-6359',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/laying-the-foundation-for-tomorrows-iam/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/laying-the-foundation-for-tomorrows-iam/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Achieving Ubiquitous and Continuous Trust in Identities on the Web</title>
		<link>http://blogs.rsa.com/achieving-ubiquitous-and-continuous-trust-in-identities-on-the-web/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=achieving-ubiquitous-and-continuous-trust-in-identities-on-the-web</link>
		<comments>http://blogs.rsa.com/achieving-ubiquitous-and-continuous-trust-in-identities-on-the-web/#comments</comments>
		<pubDate>Wed, 29 Feb 2012 21:18:49 +0000</pubDate>
		<dc:creator>Nirav Mehta</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[RSA Conference]]></category>
		<category><![CDATA[Zscaler]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=4631</guid>
		<description><![CDATA[At RSA, we have a legacy of authentication innovation from multifactor to risk-based, heuristic authentication.   We challenged ourselves with “What’s Next?”  As an industry we continue to conceive more usable yet stronger authentication but we have a bigger mandate to meet a need that has gone unmet for a long time.]]></description>
				<content:encoded><![CDATA[<p>At RSA, we have a legacy of authentication innovation from multifactor to risk-based, heuristic authentication.   We challenged ourselves with “What’s Next?”  As an industry we continue to conceive more usable yet stronger authentication but we have a bigger mandate to meet a need that has gone unmet for a long time.</p>
<p>How do we achieve <strong>ubiquitous</strong> and <strong>continuous</strong> trust in identities on the Internet?  How can we make the Internet pervasively identity-aware?  How can we extend the trust we gain in identities at the time of authentication throughout the user’s interaction with the Internet?  What if we can create a new trust index that is a composite of who the user is and how they interact with the Internet?</p>
<p>The last question led RSA to Zscaler and we found ways to answer these questions which led to the collaboration that we <strong><a href="http://www.emc.com/about/news/press/2012/20120228-02.htm">announced at RSA Conference this week</a></strong>.  RSA’s Cloud Trust Authority (CTA) is a set of security services spanning identity and access, data protection and compliance.    The identity and access capability of the <strong><span style="text-decoration: underline;"><a href="http://www.rsa.com/press_release.aspx?id=11320">RSA Cloud Trust Authority </a></span></strong> (currently in beta) is a cloud-based service that authenticates users dynamically based on a variety of risk-based criteria and uses standards-based identity federation to enable users to get where they want to in the cloud.   Zscaler’s inline security gateway monitors the user’s web session continually and protects the user’s session against infection that can lead to session hijack and loss of trust in the identity.   The marriage of the two will enable something bigger than the sum of the parts – a cloud-based solution for establishing and sustaining trust in identities in the cloud.</p>
<p><span style="text-decoration: underline;"><strong><a href="http://blogs.rsa.com/wp-content/uploads/Integration-of-Zscaler-and-RSA-clouds.pdf">Here’s how we do it</a></strong></span> – both, the RSA CTA and the Zscaler are cloud-based services.  Zscaler’s global cloud is used as an inline Internet security gateway that is available ubiquitously.  When users attempt to access the Internet, Zscaler transparently redirect them to the RSA CTA.  RSA CTA determines the risk posture of the user based on the location they are coming from (geo IP), the device they are using (whether known or unknown), the time and pattern of access, etc. to compute a risk score.  This score dynamically drives the strength of authentication of the user.   If a user is coming in from their usual office location and computing device and if they are logged into their corporate network (e.g., Microsoft Windows network), they don’t have to provide any additional authentication.</p>
<p>If the user is coming in from an unexpected location or unexpected device at an unexpected time, the RSA Adaptive Authentication risk engine dynamically adjusts the risk level and prompts the user for additional authentication.  The strength of the authentication is commensurate with the level of risk.    Once the user is authenticated, CTA sends the user back to Zscaler with an indication of the trust level of the user based on the facts and circumstances.  Zscaler dynamically alters where the user can go in the Internet based on this trust level.  Zscaler also monitors the user session for risky behavior that might lead to infection.  For example, if Zscaler sees signs of a bot on the user’s device that points to a potential session hijack, it redirects the user back to CTA for verification that the user behind the device is still the one that had authenticated at the CTA.</p>
<p>Further, Zscaler can randomly redirect users back to the CTA for authentication throughout the session.  If the environment in which the user is accessing the Internet has not changed, the user does not even notice anything as they are redirected right back to Zscaler.  If something has changed, the CTA will challenge the user to ensure that the trust in the identity is maintained.  Lastly, Zscaler will feed rich information about the user’s web access behavior to the RSA risk engine so that RSA can factor that into the risk level of the user and authenticate the user appropriately.</p>
<p>This notion of applying concepts of authentication and identity verification throughout the user’s interaction with the Internet and the composite risk posture determined by factoring the user’s environment and the user’s web browsing behavior will enable us to start delivering ubiquitous and continuous trust in identities.</p>
<p>Beyond this, we can imagine what we can achieve if every Internet request carries a dynamic trust index that can be consumed by any Internet destination. ‘It will take an ecosystem’.  Zscaler and RSA have laid the foundation.     Stay tuned for more.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;t=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web%20-%20http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;title=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=At%20RSA%2C%20we%20have%20a%20legacy%20of%20authentication%20innovation%20from%20multifactor%20to%20risk-based%2C%20heuristic%20authentication.%20%20%20We%20challenged%20ourselves%20with%20%E2%80%9CWhat%E2%80%99s%20Next%3F%E2%80%9D%20%20As%20an%20industry%20we%20continue%20to%20conceive%20more%20usable%20yet%20stronger%20authentication%20but%20we%20have%20a%20bigger%20mandate%20to%20meet%20a%20need%20that%20has%20gone%20unmet%20for%20a%20long%20time."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web&body=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-4631')" id="sociable-post-4631" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;t=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;title=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web&amp;notes=At%20RSA%2C%20we%20have%20a%20legacy%20of%20authentication%20innovation%20from%20multifactor%20to%20risk-based%2C%20heuristic%20authentication.%20%20%20We%20challenged%20ourselves%20with%20%E2%80%9CWhat%E2%80%99s%20Next%3F%E2%80%9D%20%20As%20an%20industry%20we%20continue%20to%20conceive%20more%20usable%20yet%20stronger%20authentication%20but%20we%20have%20a%20bigger%20mandate%20to%20meet%20a%20need%20that%20has%20gone%20unmet%20for%20a%20long%20time."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;title=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web&amp;bodytext=At%20RSA%2C%20we%20have%20a%20legacy%20of%20authentication%20innovation%20from%20multifactor%20to%20risk-based%2C%20heuristic%20authentication.%20%20%20We%20challenged%20ourselves%20with%20%E2%80%9CWhat%E2%80%99s%20Next%3F%E2%80%9D%20%20As%20an%20industry%20we%20continue%20to%20conceive%20more%20usable%20yet%20stronger%20authentication%20but%20we%20have%20a%20bigger%20mandate%20to%20meet%20a%20need%20that%20has%20gone%20unmet%20for%20a%20long%20time."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;title=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&title=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;title=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web&amp;annotation=At%20RSA%2C%20we%20have%20a%20legacy%20of%20authentication%20innovation%20from%20multifactor%20to%20risk-based%2C%20heuristic%20authentication.%20%20%20We%20challenged%20ourselves%20with%20%E2%80%9CWhat%E2%80%99s%20Next%3F%E2%80%9D%20%20As%20an%20industry%20we%20continue%20to%20conceive%20more%20usable%20yet%20stronger%20authentication%20but%20we%20have%20a%20bigger%20mandate%20to%20meet%20a%20need%20that%20has%20gone%20unmet%20for%20a%20long%20time."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;t=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=At%20RSA%2C%20we%20have%20a%20legacy%20of%20authentication%20innovation%20from%20multifactor%20to%20risk-based%2C%20heuristic%20authentication.%20%20%20We%20challenged%20ourselves%20with%20%E2%80%9CWhat%E2%80%99s%20Next%3F%E2%80%9D%20%20As%20an%20industry%20we%20continue%20to%20conceive%20more%20usable%20yet%20stronger%20authentication%20but%20we%20have%20a%20bigger%20mandate%20to%20meet%20a%20need%20that%20has%20gone%20unmet%20for%20a%20long%20time."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;Title=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;title=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web&amp;selection=At%20RSA%2C%20we%20have%20a%20legacy%20of%20authentication%20innovation%20from%20multifactor%20to%20risk-based%2C%20heuristic%20authentication.%20%20%20We%20challenged%20ourselves%20with%20%E2%80%9CWhat%E2%80%99s%20Next%3F%E2%80%9D%20%20As%20an%20industry%20we%20continue%20to%20conceive%20more%20usable%20yet%20stronger%20authentication%20but%20we%20have%20a%20bigger%20mandate%20to%20meet%20a%20need%20that%20has%20gone%20unmet%20for%20a%20long%20time."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;t=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web&amp;s=At%20RSA%2C%20we%20have%20a%20legacy%20of%20authentication%20innovation%20from%20multifactor%20to%20risk-based%2C%20heuristic%20authentication.%20%20%20We%20challenged%20ourselves%20with%20%E2%80%9CWhat%E2%80%99s%20Next%3F%E2%80%9D%20%20As%20an%20industry%20we%20continue%20to%20conceive%20more%20usable%20yet%20stronger%20authentication%20but%20we%20have%20a%20bigger%20mandate%20to%20meet%20a%20need%20that%20has%20gone%20unmet%20for%20a%20long%20time."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;title=Achieving%20Ubiquitous%20and%20Continuous%20Trust%20in%20Identities%20on%20the%20Web&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fachieving-ubiquitous-and-continuous-trust-in-identities-on-the-web%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-4631')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-4631',true)" class="close">

		  <img onclick="hide_sociable('post-4631',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/achieving-ubiquitous-and-continuous-trust-in-identities-on-the-web/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/achieving-ubiquitous-and-continuous-trust-in-identities-on-the-web/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RSA Cloud Trust Authority: To see things as they might be&#8230;.not as they are</title>
		<link>http://blogs.rsa.com/rsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=rsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are</link>
		<comments>http://blogs.rsa.com/rsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are/#comments</comments>
		<pubDate>Wed, 16 Feb 2011 22:57:50 +0000</pubDate>
		<dc:creator>Nirav Mehta</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Governance, Risk & Compliance (GRC)]]></category>
		<category><![CDATA[RSA Conference]]></category>
		<category><![CDATA[Cloud Trust Authority]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=2252</guid>
		<description><![CDATA[In his keynote this week, RSA's Executive Chairman Art Coviello challenged the security industry "...to jump ahead and intercept the future – to see things as they might be – not as they are".]]></description>
				<content:encoded><![CDATA[<p>In his keynote this week, RSA&#8217;s Executive Chairman Art Coviello challenged the security industry <em>&#8220;&#8230;to jump ahead and intercept the future – to see things as they might be – not as they are&#8221;</em>.</p>
<p><strong>The timing of this message is significant!</strong> We are at one of the most crucial points in the history of IT.  In the next five years, we will witness the most dramatic change in how IT is delivered and consumed.  Research from leading analysts and anecdotal evidence all around us is indicating that IT spending on cloud-based services (SaaS, PaaS, IaaS) will grown from 3% of total IT spending to 30-40%. Let&#8217;s pause for a moment &#8211; that is a MASSIVE shift in spending and an *unprecedented* shift in culture and attitude.  Never before have we witnessed such a shift of infrastructure and applications out of the organization&#8217;s hands and into the hands of external cloud service providers.</p>
<p><strong>This move is natural.</strong> Can you find a single organization out there with a mission statement that reads &#8220;We shall strive to own and operate our own IT&#8221;?  IT is a vital but supporting function that most companies would love to consume as a utility delivered by external, expert service providers so that they can focus on whatever their core business might be.   But this state is not easy to achieve.  It will take at least a decade because the cloud has not matured enough to address the complete and diverse range of enterprise IT needs of organizations across different sizes, vertical industries and geographies.  Despite this, it is quite clear that organizations are moving rapidly to the cloud.  The popularity of Salesforce, Google Apps, Amazon Web Services, ADP, Workday, Terremark, Savvis and a whole host of other SaaS/PaaS/IaaS services is proof.  These cloud services have permeated organizations virally through the users and often without the active involvement of the internal IT departments.</p>
<p><strong>The Problem</strong></p>
<p>The early success of cloud services has not yet translated in exponential and unbridled growth.  Two major security-related problems are preventing broad adoption of cloud-based services.</p>
<p>First, there is a general <strong>deficit of trust</strong> in external cloud services.  Trust is a big word but is appropriate here.  Trust comes with control and visibility.  Organizations recognize that they cannot have the same level of control and visibility over cloud services as they have over infrastructure that they own and operate.  But, they cannot achieve even remotely comparable levels today.  This is because service providers offer rudimentary security controls at best and these controls differ by service provider.</p>
<p>The second problem is a new one for the IT industry and is systemic.  Each organization and each service provider would have to establish and maintain large numbers of point-to-point integrations with each other.  Integrating with complex security infrastructure of one external entity is hard enough.  Doing it with dozens or hundreds of external service providers or tenants is very resource intensive and unsustainable.    No matter how much technology we throw at it, if the security industry does not offer a fundamentally new approach to solve many-to-many problem, widespread cloud computing will not take firm hold.</p>
<p><strong>RSA&#8217;s Answer</strong></p>
<p><a href="http://blogs.rsa.com/wp-content/uploads/RSA-CTA1.jpg"><img class="alignnone size-full wp-image-2265" title="RSA CTA" src="http://blogs.rsa.com/wp-content/uploads/RSA-CTA1.jpg" alt="" width="430" height="190" /></a></p>
<p>RSA answered the call this week with the <strong>RSA Cloud Trust Authority</strong> (hyperlink &#8211; <a href="http://rsa.com/press_release.aspx?id=11320">http://rsa.com/press_release.aspx?id=11320</a>), a set of cloud services spanning identity security, information security, infrastructure security and compliance for secure and compliant cloud computing.   I describe it in some detail in this video below:</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="350" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://www.youtube.com/v/F24Xu9XmPBc" /><embed type="application/x-shockwave-flash" width="425" height="350" src="http://www.youtube.com/v/F24Xu9XmPBc"></embed></object></p>
<p>How does this offering fundamentally address the problem describe above?  Why RSA?</p>
<p>1. We will enable a hub and spoke model for security integration and trust relationships.  By offering security services in the cloud and for the cloud, we will all but eliminate the need for point to point security integration between participating service providers and their tenants.  Each organization or service provider will only have to integrate with the Cloud Trust Authority for functions such as identity federation and compliance reporting.   They will not have to be aware of the complexity and diversity of each other&#8217;s security infrastructure freeing them up to focus on what they really set out to do &#8211; offer and consume the cloud service.</p>
<p>2.  RSA will offer a wide set of security capabilities thanks to its rich portfolio of leading technologies spanning identity, information and compliance.   We will leverage partner technologies where appropriate &#8211; for example, the initial beta offering in 2011 will leverage the Tricipher cloud service acquired by VMware.   Most importantly, RSA will link these technologies in meaningful ways just as we do with our on-premise solutions at our customer sites. Several identity federation services are available in the market today but none address data security, infrastructure security and compliance along with it.  The RSA Cloud Trust Authority is the first offering to target a comprehensive set of capabilities.   In fact, our initial offering in 2011 will offer both identity and compliance services.</p>
<p>3. Solving the problem will require an ecosystem approach.  If a dozen offerings like the cloud trust authority emerge, we will create a problem similar to the one we want to solve (limiting the number of entities and technologies with which organizations and service providers have to integrate).  For completeness of the offering and to create the necessary concentration of capabilities in a single cloud-based entity, RSA will leverage its industry partnerships with infrastructure and security vendors.   Also, to ensure the largest possible ecosystem of trust, RSA will recruit the key service providers.  Service providers will benefit by working with the most prominent security solutions provider rather than having to work with several.</p>
<p>4.  Last, RSA is a leader in virtualization and cloud computing.  We have delivered several industry firsts in the area of virtualization and cloud security over the last 2 years (monitoring, GRC, strong authentication, DLP, etc.).   RSA is also a major SaaS provider itself protection hundreds of millions of online identities and transactions with its cloud-based offerings.   In other words, RSA is a leader in delivering security solutions &#8216;in the cloud and for the cloud&#8217; already.  We feel strongly that we are well suited to step up to take this challenge and create the necessary strong ecosystem and innovation.</p>
<p>We know there is a long road ahead and we know we cannot do this alone. This is a call to action for the entire IT industry.   Please reach out to us with your views and join us in solving a problem that is bigger than all of us.  The biggest reward if we get this right would be the pride of having paved the way for the biggest IT transformation of our generation.</p>
<p>Let’s grab this opportunity to create a lasting legacy!</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;t=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are%20-%20http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;title=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=In%20his%20keynote%20this%20week%2C%20RSA%27s%20Executive%20Chairman%20Art%20Coviello%20challenged%20the%20security%20industry%20%22...to%20jump%20ahead%20and%20intercept%20the%20future%20%E2%80%93%20to%20see%20things%20as%20they%20might%20be%20%E2%80%93%20not%20as%20they%20are%22."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are&body=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-2252')" id="sociable-post-2252" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;t=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;title=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are&amp;notes=In%20his%20keynote%20this%20week%2C%20RSA%27s%20Executive%20Chairman%20Art%20Coviello%20challenged%20the%20security%20industry%20%22...to%20jump%20ahead%20and%20intercept%20the%20future%20%E2%80%93%20to%20see%20things%20as%20they%20might%20be%20%E2%80%93%20not%20as%20they%20are%22."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;title=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are&amp;bodytext=In%20his%20keynote%20this%20week%2C%20RSA%27s%20Executive%20Chairman%20Art%20Coviello%20challenged%20the%20security%20industry%20%22...to%20jump%20ahead%20and%20intercept%20the%20future%20%E2%80%93%20to%20see%20things%20as%20they%20might%20be%20%E2%80%93%20not%20as%20they%20are%22."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;title=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&title=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;title=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are&amp;annotation=In%20his%20keynote%20this%20week%2C%20RSA%27s%20Executive%20Chairman%20Art%20Coviello%20challenged%20the%20security%20industry%20%22...to%20jump%20ahead%20and%20intercept%20the%20future%20%E2%80%93%20to%20see%20things%20as%20they%20might%20be%20%E2%80%93%20not%20as%20they%20are%22."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;t=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=In%20his%20keynote%20this%20week%2C%20RSA%27s%20Executive%20Chairman%20Art%20Coviello%20challenged%20the%20security%20industry%20%22...to%20jump%20ahead%20and%20intercept%20the%20future%20%E2%80%93%20to%20see%20things%20as%20they%20might%20be%20%E2%80%93%20not%20as%20they%20are%22."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;Title=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;title=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are&amp;selection=In%20his%20keynote%20this%20week%2C%20RSA%27s%20Executive%20Chairman%20Art%20Coviello%20challenged%20the%20security%20industry%20%22...to%20jump%20ahead%20and%20intercept%20the%20future%20%E2%80%93%20to%20see%20things%20as%20they%20might%20be%20%E2%80%93%20not%20as%20they%20are%22."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;t=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are&amp;s=In%20his%20keynote%20this%20week%2C%20RSA%27s%20Executive%20Chairman%20Art%20Coviello%20challenged%20the%20security%20industry%20%22...to%20jump%20ahead%20and%20intercept%20the%20future%20%E2%80%93%20to%20see%20things%20as%20they%20might%20be%20%E2%80%93%20not%20as%20they%20are%22."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;title=RSA%20Cloud%20Trust%20Authority%3A%20To%20see%20things%20as%20they%20might%20be....not%20as%20they%20are&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Frsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-2252')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-2252',true)" class="close">

		  <img onclick="hide_sociable('post-2252',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/rsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/rsa-cloud-trust-authority-to-see-things-as-they-might-be-not-as-they-are/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Computing as a Public Utility: Closer than Ever</title>
		<link>http://blogs.rsa.com/computing-as-a-public-utility-closer-than-ever/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=computing-as-a-public-utility-closer-than-ever</link>
		<comments>http://blogs.rsa.com/computing-as-a-public-utility-closer-than-ever/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 15:35:02 +0000</pubDate>
		<dc:creator>Nirav Mehta</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Governance, Risk & Compliance (GRC)]]></category>

		<guid isPermaLink="false">http://rsablogdev.com/?p=571</guid>
		<description><![CDATA[There is no question cloud/utility computing has arrived and is here to stay. But, something is afoot that deserves special attention. On May 6, the Federal Communications Commission (FCC) of the United States announced a plan to <a href="http://www.nytimes.com/2010/05/07/technology/07broadband.html" target="_blank">reclassify broadband Internet transmission service</a> as a telecommunications service to be regulated as other 'common carriers' in the United States.]]></description>
				<content:encoded><![CDATA[<p>There is no question cloud/utility computing has arrived and is here to stay. But, something is afoot that deserves special attention. On May 6, the Federal Communications Commission (FCC) of the United States announced a plan to <a href="http://www.nytimes.com/2010/05/07/technology/07broadband.html" target="_blank">reclassify broadband Internet transmission service</a> as a telecommunications service to be regulated as other &#8216;common carriers&#8217; in the United States.</p>
<p>Whether or not one believes such regulation is appropriate or not, this development is very significant because it will bring Internet transmission closer to a public utility like telecommunications and electricity. Although the current move excludes any regulation of the &#8216;computing functionality&#8217; and content provided by the Internet services, it is only a matter of time before we get there. A &#8216;common carrier&#8217; in the United States (roughly equivalent to a public carrier in continental Europe) is a person or company that transports goods or people for any person or company and that is responsible for any possible loss of the goods during transport. Early common carriers were railroads, airlines, bus lines, etc. Telecommunications companies and wireless providers came under this category in the twentieth century and now, broadband Internet. Given the history, it would not be a stretch to say that virtualization-based compute services such as those from Terremark, Amazon and several others are likely to become regulated public utilities in the next 10 years. This is good for the consumer. Coupled with free and fair access to broadband Internet, it will bring affordable and widespread access to computing to the general public.</p>
<p>What does this mean from a security perspective? Any public utility is part of the nervous system of a nation. The importance of securing such computing services should be comparable to the importance of securing our water supplies and electrical grids. Governance of these services will also come under scrutiny. Establishing robust risk management, problem resolution and privacy protection will be minimum requirements. The upshot for service providers building an infrastructure-as-a-service business is to go beyond basic security controls and ensure that they invest in a framework, tools and skills for managing Governance, Risk and Compliance (GRC) right from the beginning. Service providers that act now to build their infrastructure and services with this in mind will have an unquestionable competitive edge when cloud computing gains foothold. Those who develop this core competency will be able to break out of the pack in a commodity market.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;t=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever%20-%20http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;title=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=There%20is%20no%20question%20cloud%2Futility%20computing%20has%20arrived%20and%20is%20here%20to%20stay.%20But%2C%20something%20is%20afoot%20that%20deserves%20special%20attention.%20On%20May%206%2C%20the%20Federal%20Communications%20Commission%20%28FCC%29%20of%20the%20United%20States%20announced%20a%20plan%20to%20reclassify%20broadband%20Internet%20transmission%20service%20as%20a%20telecommunications%20service%20to%20be%20regulated%20as%20other%20%27common%20carriers%27%20in%20the%20United%20States."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever&body=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-571')" id="sociable-post-571" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;t=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;title=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever&amp;notes=There%20is%20no%20question%20cloud%2Futility%20computing%20has%20arrived%20and%20is%20here%20to%20stay.%20But%2C%20something%20is%20afoot%20that%20deserves%20special%20attention.%20On%20May%206%2C%20the%20Federal%20Communications%20Commission%20%28FCC%29%20of%20the%20United%20States%20announced%20a%20plan%20to%20reclassify%20broadband%20Internet%20transmission%20service%20as%20a%20telecommunications%20service%20to%20be%20regulated%20as%20other%20%27common%20carriers%27%20in%20the%20United%20States."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;title=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever&amp;bodytext=There%20is%20no%20question%20cloud%2Futility%20computing%20has%20arrived%20and%20is%20here%20to%20stay.%20But%2C%20something%20is%20afoot%20that%20deserves%20special%20attention.%20On%20May%206%2C%20the%20Federal%20Communications%20Commission%20%28FCC%29%20of%20the%20United%20States%20announced%20a%20plan%20to%20reclassify%20broadband%20Internet%20transmission%20service%20as%20a%20telecommunications%20service%20to%20be%20regulated%20as%20other%20%27common%20carriers%27%20in%20the%20United%20States."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;title=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&title=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;title=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever&amp;annotation=There%20is%20no%20question%20cloud%2Futility%20computing%20has%20arrived%20and%20is%20here%20to%20stay.%20But%2C%20something%20is%20afoot%20that%20deserves%20special%20attention.%20On%20May%206%2C%20the%20Federal%20Communications%20Commission%20%28FCC%29%20of%20the%20United%20States%20announced%20a%20plan%20to%20reclassify%20broadband%20Internet%20transmission%20service%20as%20a%20telecommunications%20service%20to%20be%20regulated%20as%20other%20%27common%20carriers%27%20in%20the%20United%20States."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;t=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=There%20is%20no%20question%20cloud%2Futility%20computing%20has%20arrived%20and%20is%20here%20to%20stay.%20But%2C%20something%20is%20afoot%20that%20deserves%20special%20attention.%20On%20May%206%2C%20the%20Federal%20Communications%20Commission%20%28FCC%29%20of%20the%20United%20States%20announced%20a%20plan%20to%20reclassify%20broadband%20Internet%20transmission%20service%20as%20a%20telecommunications%20service%20to%20be%20regulated%20as%20other%20%27common%20carriers%27%20in%20the%20United%20States."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;Title=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;title=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever&amp;selection=There%20is%20no%20question%20cloud%2Futility%20computing%20has%20arrived%20and%20is%20here%20to%20stay.%20But%2C%20something%20is%20afoot%20that%20deserves%20special%20attention.%20On%20May%206%2C%20the%20Federal%20Communications%20Commission%20%28FCC%29%20of%20the%20United%20States%20announced%20a%20plan%20to%20reclassify%20broadband%20Internet%20transmission%20service%20as%20a%20telecommunications%20service%20to%20be%20regulated%20as%20other%20%27common%20carriers%27%20in%20the%20United%20States."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;t=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever&amp;s=There%20is%20no%20question%20cloud%2Futility%20computing%20has%20arrived%20and%20is%20here%20to%20stay.%20But%2C%20something%20is%20afoot%20that%20deserves%20special%20attention.%20On%20May%206%2C%20the%20Federal%20Communications%20Commission%20%28FCC%29%20of%20the%20United%20States%20announced%20a%20plan%20to%20reclassify%20broadband%20Internet%20transmission%20service%20as%20a%20telecommunications%20service%20to%20be%20regulated%20as%20other%20%27common%20carriers%27%20in%20the%20United%20States."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;title=Computing%20as%20a%20Public%20Utility%3A%20Closer%20than%20Ever&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fcomputing-as-a-public-utility-closer-than-ever%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-571')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-571',true)" class="close">

		  <img onclick="hide_sociable('post-571',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/computing-as-a-public-utility-closer-than-ever/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/computing-as-a-public-utility-closer-than-ever/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The New (Virtual) Stack Just Got Taller</title>
		<link>http://blogs.rsa.com/the-new-virtual-stack-just-got-taller/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-new-virtual-stack-just-got-taller</link>
		<comments>http://blogs.rsa.com/the-new-virtual-stack-just-got-taller/#comments</comments>
		<pubDate>Thu, 14 Jan 2010 16:09:27 +0000</pubDate>
		<dc:creator>Nirav Mehta</dc:creator>
				<category><![CDATA[Virtualization]]></category>

		<guid isPermaLink="false">http://rsablogdev.com/?p=344</guid>
		<description><![CDATA[<p>VMware&#8217;s acquisition of Zimbra is a big step towards delivering IT as a service and signals VMware&#8217;s intention to deliver the benefits of virtualization and cloud computing all the way from the infrastructure to the platform to the application layer.</p>]]></description>
				<content:encoded><![CDATA[<p>VMware&rsquo;s acquisition of Zimbra is a big step towards delivering IT as a service and signals VMware&rsquo;s intention to deliver the benefits of virtualization and cloud computing all the way from the infrastructure to the platform to the application layer.  Steve Herrod, VMware CTO provides good insight into the <a href="http://blogs.vmware.com/console/2010/01/vmware-to-acquire-zimbra.html" target="_blank">VMware rationale for the acquisition</a>. </p>
<p>So what implications does this have on security?  RSA believes that virtualization provides a clean slate to &lsquo;<a href="https://www.rsa.com/go/wpt/wpindex.asp?WPID=10393" target="_blank">get security right</a>&rsquo;. Upwards vertical integration of the VMware stack will extend the benefits of innovative security embedded in the virtualization layer to cloud-ready applications that are optimized for the stack.  For example, imagine creation of a new Zimbra e-mail account that in turn triggers the provisioning of virtual machines, security controls, and multitenancy controls in the vSphere and vCloud platforms. </p>
<p>In general, the real promise of the VMware acquisition of Zimbra will be unleashed as VMware systematically integrates its core services that enable availability, security, chargeback and multi-tenancy to the SpringSource and Zimbra assets.   These are exciting times at VMware and for those of us lucky enough to witness and shape the new IT. </p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;t=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller%20-%20http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;title=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=VMware%26rsquo%3Bs%20acquisition%20of%20Zimbra%20is%20a%20big%20step%20towards%20delivering%20IT%20as%20a%20service%20and%20signals%20VMware%26rsquo%3Bs%20intention%20to%20deliver%20the%20benefits%20of%20virtualization%20and%20cloud%20computing%20all%20the%20way%20from%20the%20infrastructure%20to%20the%20platform%20to%20the%20application%20layer."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller&body=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-344')" id="sociable-post-344" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;t=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;title=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller&amp;notes=VMware%26rsquo%3Bs%20acquisition%20of%20Zimbra%20is%20a%20big%20step%20towards%20delivering%20IT%20as%20a%20service%20and%20signals%20VMware%26rsquo%3Bs%20intention%20to%20deliver%20the%20benefits%20of%20virtualization%20and%20cloud%20computing%20all%20the%20way%20from%20the%20infrastructure%20to%20the%20platform%20to%20the%20application%20layer."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;title=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller&amp;bodytext=VMware%26rsquo%3Bs%20acquisition%20of%20Zimbra%20is%20a%20big%20step%20towards%20delivering%20IT%20as%20a%20service%20and%20signals%20VMware%26rsquo%3Bs%20intention%20to%20deliver%20the%20benefits%20of%20virtualization%20and%20cloud%20computing%20all%20the%20way%20from%20the%20infrastructure%20to%20the%20platform%20to%20the%20application%20layer."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;title=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&title=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;title=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller&amp;annotation=VMware%26rsquo%3Bs%20acquisition%20of%20Zimbra%20is%20a%20big%20step%20towards%20delivering%20IT%20as%20a%20service%20and%20signals%20VMware%26rsquo%3Bs%20intention%20to%20deliver%20the%20benefits%20of%20virtualization%20and%20cloud%20computing%20all%20the%20way%20from%20the%20infrastructure%20to%20the%20platform%20to%20the%20application%20layer."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;t=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=VMware%26rsquo%3Bs%20acquisition%20of%20Zimbra%20is%20a%20big%20step%20towards%20delivering%20IT%20as%20a%20service%20and%20signals%20VMware%26rsquo%3Bs%20intention%20to%20deliver%20the%20benefits%20of%20virtualization%20and%20cloud%20computing%20all%20the%20way%20from%20the%20infrastructure%20to%20the%20platform%20to%20the%20application%20layer."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;Title=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;title=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller&amp;selection=VMware%26rsquo%3Bs%20acquisition%20of%20Zimbra%20is%20a%20big%20step%20towards%20delivering%20IT%20as%20a%20service%20and%20signals%20VMware%26rsquo%3Bs%20intention%20to%20deliver%20the%20benefits%20of%20virtualization%20and%20cloud%20computing%20all%20the%20way%20from%20the%20infrastructure%20to%20the%20platform%20to%20the%20application%20layer."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;t=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller&amp;s=VMware%26rsquo%3Bs%20acquisition%20of%20Zimbra%20is%20a%20big%20step%20towards%20delivering%20IT%20as%20a%20service%20and%20signals%20VMware%26rsquo%3Bs%20intention%20to%20deliver%20the%20benefits%20of%20virtualization%20and%20cloud%20computing%20all%20the%20way%20from%20the%20infrastructure%20to%20the%20platform%20to%20the%20application%20layer."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;title=The%20New%20%28Virtual%29%20Stack%20Just%20Got%20Taller&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fthe-new-virtual-stack-just-got-taller%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-344')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-344',true)" class="close">

		  <img onclick="hide_sociable('post-344',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/the-new-virtual-stack-just-got-taller/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/the-new-virtual-stack-just-got-taller/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Security: &#039;Past Performance is Not an Indication of the Future&#039;</title>
		<link>http://blogs.rsa.com/cloud-security-past-performance-is-not-an-indication-of-the-future/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cloud-security-past-performance-is-not-an-indication-of-the-future</link>
		<comments>http://blogs.rsa.com/cloud-security-past-performance-is-not-an-indication-of-the-future/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 16:10:43 +0000</pubDate>
		<dc:creator>Nirav Mehta</dc:creator>
				<category><![CDATA[Cloud Security]]></category>

		<guid isPermaLink="false">http://rsablogdev.com/?p=346</guid>
		<description><![CDATA[A recent article in <a href="http://www.computerworld.com/s/article/9139404/How_data_security_can_vaporize_in_the_cloud_?taxonomyId=19&#038;pageNumber=1" target="_blank">Computer World</a> outlined several security and legal concerns that pertain to the current state of cloud computing and SaaS offerings of public service providers.]]></description>
				<content:encoded><![CDATA[<p>A recent article in <a href="http://www.computerworld.com/s/article/9139404/How_data_security_can_vaporize_in_the_cloud_?taxonomyId=19&#038;pageNumber=1" target="_blank">Computer World</a> outlined several security and legal concerns that pertain to the current state of cloud computing and SaaS offerings of public service providers. The major concerns discussed included:</p>
<ul>
<li>Authentication for cloud services is usually password-based. Organizations that typically require 2-factor authentication for their enterprise applications will have to accept weaker authentication.</li>
<li>Auditing of actions and events occuring within the cloud service provider&rsquo;s infrastructure is difficult because the service providers do not offer such visibility into their infrastructure to their customers.</li>
<li>Government authorities may have rights to serve a warrant and seize the information from the service provider without the permission of the customers of the service provider.</li>
<li>Customers of cloud services may not have any visibility or control over the hiring practices of their cloud service providers, leading to concerns related to abuse of privilege.</li>
</ul>
<p>These concerns do reflect the reality of early cloud computing and SaaS offerings, and organizations should consider these factors carefully before using cloud services for enterprise applications. But, to assume that these issues are unavoidable with the use of cloud services would be a mistake. All concerns outlined above can be addressed to ensure that organizations do not have to make a choice between the security and privacy of their information and the cost savings and flexibility made possible by cloud computing.</p>
<p>As the use of the cloud for enterprise applications becomes more prevalent, service providers can and will provide more sophisticated security architecture and models to meet the expectations of their customers. Examples include:</p>
<ul>
<li>Offering 2-factor authentication as an option for access to cloud services</li>
<li>Risk-based authentication to cloud services to ensure that strength of authentication is commensurate with the associated risk</li>
<li>Comprehensive logging in the cloud infrastructure, &nbsp;coupled with web-based reporting capability exposed to the tenants of the cloud</li>
<li>Encryption of data before it is sent to the cloud service provider to address concerns related to loss of confidentiality</li>
<li>Key managers, identity federation servers and certificate authorities offered as trusted third party security services in the cloud to ensure separation of duties between the service provider and the security provider</li>
</ul>
<p>These services are not revolutionary. They are well-established enterprise security technologies extended and optimized to secure the cloud. Security investment and sophistication has always been pegged to the risk associated with the IT infrastructure being secured. So far, cloud computing and SaaS has predominnantly been used for consumer or non-production use. As the use of cloud computing extends to enterprise applications and production environments, enterprise-grade security will be offered widely by major cloud service providers. The security industry will rise to provide &lsquo;Trust-as-a-Service&rsquo; or cloud-based security services to check and balance the privilege that cloud service providers can exert over their customer&rsquo;s information. Lack of adequate security capabilities in cloud services thus far is not an indication of where the industry is going. Cloud services are poised to enjoy a steep growth curve; we should expect cloud security to also rapidly grow in sophistication.</p>
<p>Organizations should not resist taking advantage of the tremendous business and operational advantages of cloud services, &nbsp;but rather look for service providers who offer enterprise-grade security with their cloud services.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;t=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B%20-%20http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;title=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=A%20recent%20article%20in%20Computer%20World%20outlined%20several%20security%20and%20legal%20concerns%20that%20pertain%20to%20the%20current%20state%20of%20cloud%20computing%20and%20SaaS%20offerings%20of%20public%20service%20providers."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B&body=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-346')" id="sociable-post-346" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;t=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;title=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B&amp;notes=A%20recent%20article%20in%20Computer%20World%20outlined%20several%20security%20and%20legal%20concerns%20that%20pertain%20to%20the%20current%20state%20of%20cloud%20computing%20and%20SaaS%20offerings%20of%20public%20service%20providers."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;title=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B&amp;bodytext=A%20recent%20article%20in%20Computer%20World%20outlined%20several%20security%20and%20legal%20concerns%20that%20pertain%20to%20the%20current%20state%20of%20cloud%20computing%20and%20SaaS%20offerings%20of%20public%20service%20providers."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;title=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&title=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;title=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B&amp;annotation=A%20recent%20article%20in%20Computer%20World%20outlined%20several%20security%20and%20legal%20concerns%20that%20pertain%20to%20the%20current%20state%20of%20cloud%20computing%20and%20SaaS%20offerings%20of%20public%20service%20providers."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;t=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=A%20recent%20article%20in%20Computer%20World%20outlined%20several%20security%20and%20legal%20concerns%20that%20pertain%20to%20the%20current%20state%20of%20cloud%20computing%20and%20SaaS%20offerings%20of%20public%20service%20providers."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;Title=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;title=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B&amp;selection=A%20recent%20article%20in%20Computer%20World%20outlined%20several%20security%20and%20legal%20concerns%20that%20pertain%20to%20the%20current%20state%20of%20cloud%20computing%20and%20SaaS%20offerings%20of%20public%20service%20providers."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;t=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B&amp;s=A%20recent%20article%20in%20Computer%20World%20outlined%20several%20security%20and%20legal%20concerns%20that%20pertain%20to%20the%20current%20state%20of%20cloud%20computing%20and%20SaaS%20offerings%20of%20public%20service%20providers."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;title=Cloud%20Security%3A%20%26%23039%3BPast%20Performance%20is%20Not%20an%20Indication%20of%20the%20Future%26%23039%3B&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fcloud-security-past-performance-is-not-an-indication-of-the-future%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-346')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-346',true)" class="close">

		  <img onclick="hide_sociable('post-346',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/cloud-security-past-performance-is-not-an-indication-of-the-future/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/cloud-security-past-performance-is-not-an-indication-of-the-future/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Getting started with security compliance for virtualization</title>
		<link>http://blogs.rsa.com/getting-started-with-security-compliance-for-virtualization/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=getting-started-with-security-compliance-for-virtualization</link>
		<comments>http://blogs.rsa.com/getting-started-with-security-compliance-for-virtualization/#comments</comments>
		<pubDate>Wed, 02 Sep 2009 16:12:55 +0000</pubDate>
		<dc:creator>Nirav Mehta</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Virtualization]]></category>

		<guid isPermaLink="false">http://rsablogdev.com/?p=348</guid>
		<description><![CDATA[<p>VMworld 2009 has been buzzing with   an infectious energy since it opened this week.&#160; One can see the very visible   and strong effect that virtualization is having on the entire IT industry.&#160; The   emergence of virtualization as a major mainstream paradigm across datacenters   has spawned a rich ecosystem of vendors and technologies that secure and manage   virtualization.</p>]]></description>
				<content:encoded><![CDATA[<p>VMworld 2009 has been buzzing with   an infectious energy since it opened this week.&nbsp; One can see the very visible   and strong effect that virtualization is having on the entire IT industry.&nbsp; The   emergence of virtualization as a major mainstream paradigm across datacenters   has spawned a rich ecosystem of vendors and technologies that secure and manage   virtualization.</p>
<p>As IT departments rapidly embrace   server and desktop virtualization, security departments of those organizations   are faced with the task of ensuring that the IT infrastructure continues to remain compliant to   internal and external security policies.&nbsp;&nbsp; Security officers are presented with   several products and technologies that extend VMware&#8217;s platform security,   replace it with something else or   offer some combination in between.&nbsp; Applying these products   effectively to address a bewilderingly complex compliance landscape can be a   daunting task.&nbsp; </p>
<p>Many organizations have correctly   recognized that establishing a solid foundation of security processes and   controls is the best place to start.&nbsp; EMC, through its RSA Security and EMC Ionix   divisions have come together with VMware to provide clear and pragmatic   guidance to security practioners who are responsible for maintaining security   compliance in virtualized environments.&nbsp; An RSA Security Brief entitled <a href="https://www.rsa.com/go/wpt/wpindex.asp?WPID=10393" title="https://www.rsa.com/go/wpt/wpindex.asp?WPID=10393" target="_blank">Security Compliance in   a Virtual World</a> was released this week and it can be downloaded from   ww.rsa.com.&nbsp; It focuses on five measures that would help organizations jumpstart   their security compliance efforts &#8211; platform hardening, configuration and change   management, administrative access management, network security and segmentation   and event reporting. The paper provides a framework and context within which   organizations can evaluate security technologies rather than simply putting focus on point products.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;t=Getting%20started%20with%20security%20compliance%20for%20virtualization"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Getting%20started%20with%20security%20compliance%20for%20virtualization%20-%20http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;title=Getting%20started%20with%20security%20compliance%20for%20virtualization&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=VMworld%202009%20has%20been%20buzzing%20with%20%20%20an%20infectious%20energy%20since%20it%20opened%20this%20week.%26nbsp%3B%20One%20can%20see%20the%20very%20visible%20%20%20and%20strong%20effect%20that%20virtualization%20is%20having%20on%20the%20entire%20IT%20industry.%26nbsp%3B%20The%20%20%20emergence%20of%20virtualization%20as%20a%20major%20mainstream%20paradigm%20across%20datacenters%20%20%20has%20spawned%20a%20rich%20ecosystem%20of%20vendors%20and%20technologies%20that%20secure%20and%20manage%20%20%20virtualization."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Getting%20started%20with%20security%20compliance%20for%20virtualization&body=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-348')" id="sociable-post-348" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;t=Getting%20started%20with%20security%20compliance%20for%20virtualization"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;title=Getting%20started%20with%20security%20compliance%20for%20virtualization&amp;notes=VMworld%202009%20has%20been%20buzzing%20with%20%20%20an%20infectious%20energy%20since%20it%20opened%20this%20week.%26nbsp%3B%20One%20can%20see%20the%20very%20visible%20%20%20and%20strong%20effect%20that%20virtualization%20is%20having%20on%20the%20entire%20IT%20industry.%26nbsp%3B%20The%20%20%20emergence%20of%20virtualization%20as%20a%20major%20mainstream%20paradigm%20across%20datacenters%20%20%20has%20spawned%20a%20rich%20ecosystem%20of%20vendors%20and%20technologies%20that%20secure%20and%20manage%20%20%20virtualization."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;title=Getting%20started%20with%20security%20compliance%20for%20virtualization&amp;bodytext=VMworld%202009%20has%20been%20buzzing%20with%20%20%20an%20infectious%20energy%20since%20it%20opened%20this%20week.%26nbsp%3B%20One%20can%20see%20the%20very%20visible%20%20%20and%20strong%20effect%20that%20virtualization%20is%20having%20on%20the%20entire%20IT%20industry.%26nbsp%3B%20The%20%20%20emergence%20of%20virtualization%20as%20a%20major%20mainstream%20paradigm%20across%20datacenters%20%20%20has%20spawned%20a%20rich%20ecosystem%20of%20vendors%20and%20technologies%20that%20secure%20and%20manage%20%20%20virtualization."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;title=Getting%20started%20with%20security%20compliance%20for%20virtualization"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&title=Getting%20started%20with%20security%20compliance%20for%20virtualization"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;title=Getting%20started%20with%20security%20compliance%20for%20virtualization&amp;annotation=VMworld%202009%20has%20been%20buzzing%20with%20%20%20an%20infectious%20energy%20since%20it%20opened%20this%20week.%26nbsp%3B%20One%20can%20see%20the%20very%20visible%20%20%20and%20strong%20effect%20that%20virtualization%20is%20having%20on%20the%20entire%20IT%20industry.%26nbsp%3B%20The%20%20%20emergence%20of%20virtualization%20as%20a%20major%20mainstream%20paradigm%20across%20datacenters%20%20%20has%20spawned%20a%20rich%20ecosystem%20of%20vendors%20and%20technologies%20that%20secure%20and%20manage%20%20%20virtualization."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;t=Getting%20started%20with%20security%20compliance%20for%20virtualization"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Getting%20started%20with%20security%20compliance%20for%20virtualization&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=VMworld%202009%20has%20been%20buzzing%20with%20%20%20an%20infectious%20energy%20since%20it%20opened%20this%20week.%26nbsp%3B%20One%20can%20see%20the%20very%20visible%20%20%20and%20strong%20effect%20that%20virtualization%20is%20having%20on%20the%20entire%20IT%20industry.%26nbsp%3B%20The%20%20%20emergence%20of%20virtualization%20as%20a%20major%20mainstream%20paradigm%20across%20datacenters%20%20%20has%20spawned%20a%20rich%20ecosystem%20of%20vendors%20and%20technologies%20that%20secure%20and%20manage%20%20%20virtualization."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;Title=Getting%20started%20with%20security%20compliance%20for%20virtualization"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;title=Getting%20started%20with%20security%20compliance%20for%20virtualization&amp;selection=VMworld%202009%20has%20been%20buzzing%20with%20%20%20an%20infectious%20energy%20since%20it%20opened%20this%20week.%26nbsp%3B%20One%20can%20see%20the%20very%20visible%20%20%20and%20strong%20effect%20that%20virtualization%20is%20having%20on%20the%20entire%20IT%20industry.%26nbsp%3B%20The%20%20%20emergence%20of%20virtualization%20as%20a%20major%20mainstream%20paradigm%20across%20datacenters%20%20%20has%20spawned%20a%20rich%20ecosystem%20of%20vendors%20and%20technologies%20that%20secure%20and%20manage%20%20%20virtualization."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;t=Getting%20started%20with%20security%20compliance%20for%20virtualization&amp;s=VMworld%202009%20has%20been%20buzzing%20with%20%20%20an%20infectious%20energy%20since%20it%20opened%20this%20week.%26nbsp%3B%20One%20can%20see%20the%20very%20visible%20%20%20and%20strong%20effect%20that%20virtualization%20is%20having%20on%20the%20entire%20IT%20industry.%26nbsp%3B%20The%20%20%20emergence%20of%20virtualization%20as%20a%20major%20mainstream%20paradigm%20across%20datacenters%20%20%20has%20spawned%20a%20rich%20ecosystem%20of%20vendors%20and%20technologies%20that%20secure%20and%20manage%20%20%20virtualization."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;title=Getting%20started%20with%20security%20compliance%20for%20virtualization&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fgetting-started-with-security-compliance-for-virtualization%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-348')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-348',true)" class="close">

		  <img onclick="hide_sociable('post-348',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/getting-started-with-security-compliance-for-virtualization/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/getting-started-with-security-compliance-for-virtualization/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Birth of the Virtual Datacenter Administrator</title>
		<link>http://blogs.rsa.com/the-birth-of-the-virtual-datacenter-administrator/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-birth-of-the-virtual-datacenter-administrator</link>
		<comments>http://blogs.rsa.com/the-birth-of-the-virtual-datacenter-administrator/#comments</comments>
		<pubDate>Wed, 01 Jul 2009 16:14:15 +0000</pubDate>
		<dc:creator>Nirav Mehta</dc:creator>
				<category><![CDATA[Virtualization]]></category>

		<guid isPermaLink="false">http://rsablogdev.com/?p=350</guid>
		<description><![CDATA[<p>I  recently spoke at a VMware user group conference about securing  virtualization.  The audience comprised datacenter  administrators and managers who are at the center of their organization's  virtualization initiatives.&#160; I was fortunate to be able to talk with  several of them at length about their experiences in virtualizing  datacenters.&#160; There are several trends to note.</p>]]></description>
				<content:encoded><![CDATA[<p>I  recently spoke at a VMware user group conference about securing  virtualization.  The audience comprised datacenter  administrators and managers who are at the center of their organization&#8217;s  virtualization initiatives.&nbsp; I was fortunate to be able to talk with  several of them at length about their experiences in virtualizing  datacenters.&nbsp; There are several trends to note.</p>
<ul>
<li>Almost everyone described some form of friction between the IT and security       departments related to virtualization.&nbsp;&nbsp; IT departments are       pursuing aggressive plans to virtualize servers and desktops with an eye       on cost savings and the security and risk departments are on the fence       while they cautiously examine additional risks introduced by       virtualization, if any.&nbsp; A few mature organizations have gone past       this phase and have IT and security departments working together to not       only save costs but also use virtualization to deliver better security.       But in most organizations, the lack of understanding of the security       implications of virtualization is causing many organizations to become       overly risk averse, causing unnecessary delay in the adoption of       virtualization or, organizations get too conservative and adopt architectures       that dilute the return on investment offered by       virtualization.&nbsp;&nbsp;&nbsp; For example, the lack of trust in       virtual firewalls and virtual network isolation is causing organizations       to leave physical network isolation in place which in turn adversely       affects the server consolidation ratios.
</li>
<li>The       biggest concern related to security was inadvertent       misconfiguration.&nbsp; With the consolidation of server, network and       storage services within the virtual infrastructure, server administrator       is also required to configure virtual networks and switches.&nbsp;&nbsp;       With increased consolidation of computers and networks, the impact of a       single mistake in configuration could lead to a major outage of servers or       failure of several network segments.
</li>
<li>The       convergence of server, network and security capabilities within the       virtual infrastructure is creating new demands on the traditional       datacenter administrators.&nbsp; Most server adminstrators I talked with       were responsible for creating and managing ESX images including the       networking, security and storage configuration.&nbsp; Consequently, server       teams have to collaborate more closely with network and security teams to       properly manage the converged infrastructure.&nbsp; There is strong demand       for administrators that have knowledge of computing, networking, storage       and security so that they can configure the virtual infrastructure with       full understanding of the impact to each domain.&nbsp; The advent of the       virtual datacenter is giving rise to a new breed of datacenter administrators       who will be capable of using the powerful tools offered by virtual       infrastructure vendors to create and manage the entire virtual       datacenter.&nbsp; This new breed of administrators will bridge the divide       between network and security operations.&nbsp; Administrators that do not       possess cross-domain expertise will be prone to expensive       misconfiguration.&nbsp; The virtual datacenter adminsitrator is born.</li>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;t=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator%20-%20http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;title=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=I%20%20recently%20spoke%20at%20a%20VMware%20user%20group%20conference%20about%20securing%20%20virtualization.%20%20The%20audience%20comprised%20datacenter%20%20administrators%20and%20managers%20who%20are%20at%20the%20center%20of%20their%20organization%27s%20%20virtualization%20initiatives.%26nbsp%3B%20I%20was%20fortunate%20to%20be%20able%20to%20talk%20with%20%20several%20of%20them%20at%20length%20about%20their%20experiences%20in%20virtualizing%20%20datacenters.%26nbsp%3B%20There%20are%20several%20trends%20to%20note."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator&body=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-350')" id="sociable-post-350" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;t=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;title=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator&amp;notes=I%20%20recently%20spoke%20at%20a%20VMware%20user%20group%20conference%20about%20securing%20%20virtualization.%20%20The%20audience%20comprised%20datacenter%20%20administrators%20and%20managers%20who%20are%20at%20the%20center%20of%20their%20organization%27s%20%20virtualization%20initiatives.%26nbsp%3B%20I%20was%20fortunate%20to%20be%20able%20to%20talk%20with%20%20several%20of%20them%20at%20length%20about%20their%20experiences%20in%20virtualizing%20%20datacenters.%26nbsp%3B%20There%20are%20several%20trends%20to%20note."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;title=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator&amp;bodytext=I%20%20recently%20spoke%20at%20a%20VMware%20user%20group%20conference%20about%20securing%20%20virtualization.%20%20The%20audience%20comprised%20datacenter%20%20administrators%20and%20managers%20who%20are%20at%20the%20center%20of%20their%20organization%27s%20%20virtualization%20initiatives.%26nbsp%3B%20I%20was%20fortunate%20to%20be%20able%20to%20talk%20with%20%20several%20of%20them%20at%20length%20about%20their%20experiences%20in%20virtualizing%20%20datacenters.%26nbsp%3B%20There%20are%20several%20trends%20to%20note."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;title=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&title=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;title=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator&amp;annotation=I%20%20recently%20spoke%20at%20a%20VMware%20user%20group%20conference%20about%20securing%20%20virtualization.%20%20The%20audience%20comprised%20datacenter%20%20administrators%20and%20managers%20who%20are%20at%20the%20center%20of%20their%20organization%27s%20%20virtualization%20initiatives.%26nbsp%3B%20I%20was%20fortunate%20to%20be%20able%20to%20talk%20with%20%20several%20of%20them%20at%20length%20about%20their%20experiences%20in%20virtualizing%20%20datacenters.%26nbsp%3B%20There%20are%20several%20trends%20to%20note."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;t=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=I%20%20recently%20spoke%20at%20a%20VMware%20user%20group%20conference%20about%20securing%20%20virtualization.%20%20The%20audience%20comprised%20datacenter%20%20administrators%20and%20managers%20who%20are%20at%20the%20center%20of%20their%20organization%27s%20%20virtualization%20initiatives.%26nbsp%3B%20I%20was%20fortunate%20to%20be%20able%20to%20talk%20with%20%20several%20of%20them%20at%20length%20about%20their%20experiences%20in%20virtualizing%20%20datacenters.%26nbsp%3B%20There%20are%20several%20trends%20to%20note."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;Title=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;title=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator&amp;selection=I%20%20recently%20spoke%20at%20a%20VMware%20user%20group%20conference%20about%20securing%20%20virtualization.%20%20The%20audience%20comprised%20datacenter%20%20administrators%20and%20managers%20who%20are%20at%20the%20center%20of%20their%20organization%27s%20%20virtualization%20initiatives.%26nbsp%3B%20I%20was%20fortunate%20to%20be%20able%20to%20talk%20with%20%20several%20of%20them%20at%20length%20about%20their%20experiences%20in%20virtualizing%20%20datacenters.%26nbsp%3B%20There%20are%20several%20trends%20to%20note."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;t=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator&amp;s=I%20%20recently%20spoke%20at%20a%20VMware%20user%20group%20conference%20about%20securing%20%20virtualization.%20%20The%20audience%20comprised%20datacenter%20%20administrators%20and%20managers%20who%20are%20at%20the%20center%20of%20their%20organization%27s%20%20virtualization%20initiatives.%26nbsp%3B%20I%20was%20fortunate%20to%20be%20able%20to%20talk%20with%20%20several%20of%20them%20at%20length%20about%20their%20experiences%20in%20virtualizing%20%20datacenters.%26nbsp%3B%20There%20are%20several%20trends%20to%20note."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;title=The%20Birth%20of%20the%20Virtual%20Datacenter%20Administrator&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fthe-birth-of-the-virtual-datacenter-administrator%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-350')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-350',true)" class="close">

		  <img onclick="hide_sociable('post-350',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/the-birth-of-the-virtual-datacenter-administrator/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/the-birth-of-the-virtual-datacenter-administrator/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Goby and the Shrimp</title>
		<link>http://blogs.rsa.com/the-goby-and-the-shrimp/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-goby-and-the-shrimp</link>
		<comments>http://blogs.rsa.com/the-goby-and-the-shrimp/#comments</comments>
		<pubDate>Thu, 23 Apr 2009 16:15:16 +0000</pubDate>
		<dc:creator>Nirav Mehta</dc:creator>
				<category><![CDATA[RSA Conference]]></category>
		<category><![CDATA[Virtualization]]></category>

		<guid isPermaLink="false">http://rsablogdev.com/?p=352</guid>
		<description><![CDATA[<p>What if virtualization makes security more effective and eficient?<br />
  What if virtualization actually reduces the cost of security?</p>
<p>The relationship between virtualization and security is indeed symbiotic.  It reminds me of the endearing mutualism between the <a href="http://en.wikipedia.org/wiki/Goby" target="_blank">goby fish</a> and the pistol shrimp.</p>]]></description>
				<content:encoded><![CDATA[<p>What if virtualization makes security more effective and eficient?<br />
  What if virtualization actually reduces the cost of security?</p>
<p>The relationship between virtualization and security is indeed symbiotic.  It reminds me of the endearing mutualism between the <a href="http://en.wikipedia.org/wiki/Goby" target="_blank">goby fish</a> and the pistol shrimp.</p>
<p>Virtualization (of server, desktop, storage or network)  improves resource utilization while offering unprecedented flexibility in  deploying and managing IT infrastructure.&nbsp;&nbsp;  Such flexibility and mobility of IT resources would not be acceptable  without security controls that enable organizations to virtualize their  infrastructure and yet retain control over their information assets.&nbsp; On the other hand, security applications,  like other applications, benefit vastly from the scalability and control  offered by virtualization technologies.</p>
<p>Given the state of the global economy, this symbiosis is  more relevant than ever.&nbsp;&nbsp; Shrinking IT  budgets, reduced workforces and the drive toward energy-efficient computing  have compelled organizations to pursue virtualization more aggressively.&nbsp;&nbsp; Security technologies are enabling  organizations to embrace virtualization with confidence.&nbsp;&nbsp; Security departments, on the other hand, are  under greater pressure to deliver more cost-effective security in an  increasingly regulated business environment.&nbsp;  The virtualization layer provides an excellent opportunity to build security  into the infrastructure cost-effectively (for example, by minimizing the need  to integrate with multiple operating systems or to deploy hardware appliances  on the network).</p>
<p>I have an example from the past and the present that I&#8217;d  like to share.&nbsp; A decade ago, the  emergence of virtual LANs and the 802.1Q tagging standard enabled complex  corporate networks with hundreds of network devices to be virtualized and  collapsed into a few massively scalable switches.&nbsp;&nbsp; Vendors snatched this opportunity to develop  firewalls that doubled as layer three switches or vice versa.&nbsp; As a result, IP security became integral to  the network backplane and near wirespeed firewalling became the norm rather  than the exception.&nbsp; The cost of security  fell just as it became more effective.</p>
<p>Today, server virtualization is creating a similar  opportunity.&nbsp; VMware&#8217;s <a href="http://www.vmware.com/technology/security/vmsafe.html" target="_blank">VMsafe technology</a> offers deep inspection of virtual machine CPU, memory, network and  storage.&nbsp; Security vendors are taking  advantage of this capability to not only secure VMware virtualization but also  to virtualize their security applications and deeply embed them into the  virtualization platform.&nbsp; As a result,  monolithic security appliances are turning into virtual appliances and becoming  one with the virtual infrastructure.&nbsp;&nbsp; An  example of this is the proof of concept integration between RSA Data Loss Prevention (RSA  DLP) and VMware vShield Zones that was announced at the RSA  Conference 2009 this week.&nbsp;&nbsp; The concept  is that RSA DLP would run as a  virtual machine on VMware ESX servers and would work in concert with VMsafe  technology to inspect virtual network data flow from VMware virtual machines.&nbsp; As a result, data loss would be detected and  plugged closer to the source (at the server rather than a network choke point)  and the need for deploying and maintaining dedicated network appliances for  data loss prevention would be minimized.</p>
<p> Co-deployment of security applications with virtualization  infrastructure provides mutual benefits and enables the delivery of a whole  greater than its parts.&nbsp;&nbsp; Like all other  things in IT, we should always separate hype from reality but in this case, the  writing is on the wall and the evidence from the past and present is clear.  Security and virtualization are meant for each other, much like the goby and  the shrimp.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;t=The%20Goby%20and%20the%20Shrimp"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=The%20Goby%20and%20the%20Shrimp%20-%20http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;title=The%20Goby%20and%20the%20Shrimp&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=What%20if%20virtualization%20makes%20security%20more%20effective%20and%20eficient%3F%0A%20%20What%20if%20virtualization%20actually%20reduces%20the%20cost%20of%20security%3F%0AThe%20relationship%20between%20virtualization%20and%20security%20is%20indeed%20symbiotic.%20%20It%20reminds%20me%20of%20the%20endearing%20mutualism%20between%20the%20goby%20fish%20and%20the%20pistol%20shrimp."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=The%20Goby%20and%20the%20Shrimp&body=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-352')" id="sociable-post-352" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;t=The%20Goby%20and%20the%20Shrimp"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;title=The%20Goby%20and%20the%20Shrimp&amp;notes=What%20if%20virtualization%20makes%20security%20more%20effective%20and%20eficient%3F%0A%20%20What%20if%20virtualization%20actually%20reduces%20the%20cost%20of%20security%3F%0AThe%20relationship%20between%20virtualization%20and%20security%20is%20indeed%20symbiotic.%20%20It%20reminds%20me%20of%20the%20endearing%20mutualism%20between%20the%20goby%20fish%20and%20the%20pistol%20shrimp."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;title=The%20Goby%20and%20the%20Shrimp&amp;bodytext=What%20if%20virtualization%20makes%20security%20more%20effective%20and%20eficient%3F%0A%20%20What%20if%20virtualization%20actually%20reduces%20the%20cost%20of%20security%3F%0AThe%20relationship%20between%20virtualization%20and%20security%20is%20indeed%20symbiotic.%20%20It%20reminds%20me%20of%20the%20endearing%20mutualism%20between%20the%20goby%20fish%20and%20the%20pistol%20shrimp."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;title=The%20Goby%20and%20the%20Shrimp"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&title=The%20Goby%20and%20the%20Shrimp"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;title=The%20Goby%20and%20the%20Shrimp&amp;annotation=What%20if%20virtualization%20makes%20security%20more%20effective%20and%20eficient%3F%0A%20%20What%20if%20virtualization%20actually%20reduces%20the%20cost%20of%20security%3F%0AThe%20relationship%20between%20virtualization%20and%20security%20is%20indeed%20symbiotic.%20%20It%20reminds%20me%20of%20the%20endearing%20mutualism%20between%20the%20goby%20fish%20and%20the%20pistol%20shrimp."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;t=The%20Goby%20and%20the%20Shrimp"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=The%20Goby%20and%20the%20Shrimp&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=What%20if%20virtualization%20makes%20security%20more%20effective%20and%20eficient%3F%0A%20%20What%20if%20virtualization%20actually%20reduces%20the%20cost%20of%20security%3F%0AThe%20relationship%20between%20virtualization%20and%20security%20is%20indeed%20symbiotic.%20%20It%20reminds%20me%20of%20the%20endearing%20mutualism%20between%20the%20goby%20fish%20and%20the%20pistol%20shrimp."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;Title=The%20Goby%20and%20the%20Shrimp"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;title=The%20Goby%20and%20the%20Shrimp&amp;selection=What%20if%20virtualization%20makes%20security%20more%20effective%20and%20eficient%3F%0A%20%20What%20if%20virtualization%20actually%20reduces%20the%20cost%20of%20security%3F%0AThe%20relationship%20between%20virtualization%20and%20security%20is%20indeed%20symbiotic.%20%20It%20reminds%20me%20of%20the%20endearing%20mutualism%20between%20the%20goby%20fish%20and%20the%20pistol%20shrimp."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;t=The%20Goby%20and%20the%20Shrimp&amp;s=What%20if%20virtualization%20makes%20security%20more%20effective%20and%20eficient%3F%0A%20%20What%20if%20virtualization%20actually%20reduces%20the%20cost%20of%20security%3F%0AThe%20relationship%20between%20virtualization%20and%20security%20is%20indeed%20symbiotic.%20%20It%20reminds%20me%20of%20the%20endearing%20mutualism%20between%20the%20goby%20fish%20and%20the%20pistol%20shrimp."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;title=The%20Goby%20and%20the%20Shrimp&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fthe-goby-and-the-shrimp%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-352')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-352',true)" class="close">

		  <img onclick="hide_sociable('post-352',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/the-goby-and-the-shrimp/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/the-goby-and-the-shrimp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
