Home > Ask the Security Experts > Platform Security Questions & Answers > Will a platform-as-a-service (PaaS) environment put data at risk?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Will a platform-as-a-service (PaaS) environment put data at risk?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 17 November 2007
What are the data protection risks of implementing a platform-as-a-service (PaaS) environment?

>
EXPERT RESPONSE
Time and time again, exciting new Internet technologies are developed that fail to properly address security and data protection. Before I look at the data protection issues surrounding PaaS, though, let's back up just a moment to its predecessor: SaaS or software-as-a-service.

SaaS has replaced the earlier acronym, ASP, or application service provider. Software-as-a-service is a Web-based application that is hosted and made available by a software vendor over the Internet. The key difference vs. regular software, however, is that SaaS users pay to rent the application, as opposed to owning it.

Platform-as-a-service is the next step in the evolution of Web services. PaaS provides an on-demand platform -- basically a modern version of the "thin client" -- where a PC receives its operating system and applications from a server. PaaS enables an organization and its developers to focus on what their applications do, rather than what software and infrastructure is needed to run them. Thanks to platform-as-a-service, business processes can become virtual, sharable, and organizations can benefit from economies of scale, uptime and flexibility. But like its predecessor SaaS, it has many of the same data protection issues, mainly that data is being processed or stored by or on third-party systems.

With these kinds of service, an enterprise customer's data security is reliant on the skill and ability of the SaaS or PaaS developers. For small organizations that only have one or two developers, platform-as-a-service is probably a safer alternative. Without discrediting the overworked developer, small teams, heavy workloads and tight deadlines tend to make security less of a priority. When considering SaaS or PaaS, be sure the provider's development team has the expertise -- and has been given the time -- to build applications with a strong information security foundation.

However, can larger organizations afford to assume that their data will be safe in the hands of a third-party provider? Ceding control of how data is stored and accessed requires a lot of confidence and understanding of where and how it is being handled. For me, the "where" is a critical issue.

Let's take an example of a UK-based company using PaaS offered by a U.S.-based company. Under the European Union Data Directive, companies have a responsibility to ensure that any third party managing their data has suitable security measures in place. Under the Safe Harbor data protection agreement between the U.S. and the European Union, UK companies can store their data in the U.S. only if the third party handling the data meets EU privacy protection standards. The data protection measures operating in a PaaS environment, therefore, need to be clearly understood; otherwise the UK company could be in breach of one or more laws.

Finally, data that can only be accessed via someone else's server requires guarantees of its uptime. The best possible uptime for an online service is 99.9% availability. Even then, that's still almost half a day of downtime per year. There will also be times when the service is up but suffering performance problems. PaaS providers probably deliver better uptime than most other organizations can, but service level agreements (SLAs) need to be understood and enforced more than ever in a PaaS environment.

More information:

  • Learn how to protect service level agreements and other intellectual property.
  • At Black Hat 2007, researchers exposed some vulnerabilities to software-as-a-service offerings


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Platform Security
    Are open recursive DNS servers inherently insecure?
    Should whole disk encryption products be used with data backup software?
    Which operating system can best secure an FTP site?
    Is desktop virtualization a realistic enterprise option?
    Does FTPS encrypt data packets at the hardware or software level?
    Should disks be encrypted at the hardware level?
    Is Triple DES a more secure encryption scheme than DUKPT?
    How to protect DNS servers
    How should the ipseccmd.exe tool be used in Windows Vista?
    What security issues can arise from unsynchronized system clocks?

    Enterprise Data Protection
    Are open recursive DNS servers inherently insecure?
    Penetration testing: Helping your compliance efforts
    Worst practices: Learning from bad security tips
    The ins and outs of database encryption
    RSA attendees see data classification, rights management projects stumble
    Worst practices: Encryption conniptions
    Does FTPS encrypt data packets at the hardware or software level?
    Should disks be encrypted at the hardware level?
    Is Triple DES a more secure encryption scheme than DUKPT?
    E-discovery management: How IT should interact with the legal team

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    cut-and-paste attack  (SearchSecurity.com)
    data splitting  (SearchSecurity.com)
    deperimeterization  (SearchSecurity.com)
    Google hacking  (SearchSecurity.com)
    masquerade  (SearchSecurity.com)
    snooping  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts