Before users move from desktop to Cloud, Cloud providers require to dealing with consumers’ worry about confidentiality, authentication, authorization, availability, performance, backup, disaster recovery and SLAs. Security, availability and quality are among the most commonly addressed issues. Current security approaches make use of Public Key Infrastructure (PKI) and X.509 SSL certificates for authentication and authorization. Due to the lack of Cloud computing standards that address these issues, Cloud security, data privacy and ownership policies are handled differently by each Cloud provider.

According to Foundstone, security assessments can be addressed in many directions: (A) Architecture and design assessment (B) Cloud infrastructure security assessment (C) Governance, policies and procedures review. (A) Architecture and design assessment include Network topology, key assets, data storage and operation, input and output end points in system, trust boundaries, access controls, system and network isolation, administrative controls for Cloud vendor, administrative controls for business owner. (B) Cloud infrastructure security assessment include Internal and external penetration assessment, application or product penetration assessment, host security configuration assessment, Firewall security assessment, VPN/ remote access security assessment, physical security assessment, attack and penetration, information retrieval, pillage and cleanup.

