Securely outsourcing to the cloud
Grazed from: ITWeb. Author: Ugan Naidoo.
Cloud providers should have a documented process for handling access rights, including employees entering or leaving the company, or changing roles. Regular audits should be performed to confirm that all privileges match current roles and needs.
Once access security is understood, it is important to determine how the systems housing your most sensitive information will be secured and the data itself controlled. This will mean considering how to secure virtual and multi-tenant environments.
Access control tools can be configured to restrict access to individual virtual machines based on the privileges of each hypervisor administrator identity. This helps ensure that even in a shared environment, only the appropriate administrators have access to an organisation’s virtual machines. Because virtual environments are so dynamic, security controls must be automated, and individual virtual machines must be managed in a way that conforms to their required security…

