Cloud Encryption: How to Choose an IaaS Encryption Solution
May 28, 2013Grazed from Sys Con Media. Author: Gilad Parann-Nissany.
During the past month or so, Rich Mogull, analyst and CEO of securosis has published multiple blogs on cloud encryption best practices, specifically in infrastructure clouds. The final blog IaaS Encryption: How to Choose, provides a good opportunity for us to touch and expand on some of the volume storage cloud security points highlighted on Rich’s article:
“Always use external key management. Instance-managed encryption is only acceptable for test/development systems you know will never go into production”
Instance managed encryption means the encryption keys are kept on the virtual disk. In other words, anyone with access to your cloud instance, has access to your encryption keys – hence to your data. In addition, specific cloud operations, such as disk snapshots, will snapshot the encryption keys with it…
“For sensitive data in public cloud computing choose a system with protection for keys in volatile memory (RAM). Don’t use a cloud’s native encryption capabilities if you have any concern that a cloud administrator is a risk”…
Read more from the source @ http://cloudcomputing.sys-con.com/node/2674854


