New Tool Exposes Cloud Security Holes
Added 19th May 2010The Readiness Scorecard is effectively a free add-on for the company's software assurance products, Fortify 360, and the online Fortify on Demand assurance service, able to give companies a vulnerability rating for software as if it was running in a cloud environment.
Aren't code vulnerabilities the same whether they are in the cloud or inside a corporate network?
According to Fortify chief scientist and founder, Brian Chess, the cloud questions coding assumptions that would have been reasonable when an application was originally written. Applications can communicate with one another using insecure protocols, while assumed infrastructure such as DNS servers will in the cloud model be shared and beyond the oversight of the IT department.
In short, software has to assume less trust and the vulnerability of data must be pinpointed precisely. "When you move to the cloud, your risk profile changes," said Chess.
The point of the Readiness Scorecard is to give in-house teams a list of both minor and major fixes needed before a given application can be run in the cloud in a way that minimises such risk, he said.
"Like immunising themselves against infection, cloud providers can use Fortify 360 or Fortify on Demand to ensure that bad code introduced by one or more customers doesn't contaminate their cloud offering," said Chess.
Current Fortify customers would get access to the Scorecard free of cost from later this quarter while new users would have the feature bundled with subscriptions.
latest news
-
Gearing IT for the Rains: What CIOs Need to Know
Here's how CIOs can prepare their organizations for monsoons, when faced by flooded basements, stranded employees, and disrupted services.
-
Why Microsoft Office for iPad is Inevitable
New reports have surfaced that Microsoft is developing Office apps for iOS and Android. If true, it's a very smart move by Microsoft.
-
Mobile Workers Work Longer Hours
Almost two-thirds of mobile employees say they are working 50 to 60 hour-plus weeks, with most working weekends too, according to research.
-
IBM: Only 16% CEOs Using Social Media to Connect with Customers
IBM says a study it did of some 1,700 Chief Executive Officers worldwide found that many indeed - or should be -- grasping social media as a key enabler of collaboration and innovation.




