It’s time to reconsider cloud-based security

With support for three of the major pillars of application development and deployment — Oracle 11g, Microsoft SQL, and open source MySQL – under its belt, appears to be anticipating a major move by the enterprise into the cloud.

Plus, provisions Microsoft Windows Server, Oracle Fusion middleware, three Oracle backup and data recovery tools, and the open source LAMP stack.

When announcing Microsoft’s own cloud platform, Azure, this week at the Professional Developer Conference, Microsoft chief software architect Ray Ozzie tipped his hat to CEO Jeff Bezos and crew at Amazon for leading the charge into the cloud.

And both IBM and Oracle have announced their versions of a cloud computing center. Oracle will use Amazon’s EC2 (Elastic Cloud Computing) infrastructure, while IBM will deploy based on its own in-house development.

Why IT is wary of the cloud: Mission-critical fears

Yet CIOs and CTOs that InfoWorld has spoken to typically describe the cloud as not ready for enterprise-class applications. So why are Oracle and Microsoft putting enterprise platforms and apps on’s cloud?

David Mitchell, senior vice president for IT research at Ovum, says enterprises are simply not ready to deploy mission-critical apps in the cloud. “Would you be comfortable having taxation records online in the cloud? I wouldn’t,” he says.

When it comes to security, “with the cloud model the bar goes up dramatically,” says Vince Biddlecombe, CTO of Transplace, a logistics provider for the transportation industry. “Everybody’s concerned that their data gets protected.”

Transplace does use cloud-based applications from as well as HR on-demand and hosted expense management, but that’s because these apps aren’t mission-critical operational systems and don’t hold sensitive data, Biddlecombe says.

“It’s all about protecting the data. We want to hold onto it. It’s proprietary and we want to maintain control over it,” says Glenn Trommer, director of e-commerce and implementation services for Office Depot. “I wouldn’t feel comfortable with cloud computing on a large scale at this point in time.”

Just what is cloud computing’s role?

Cloud computing is usually sold as a way to dramatically reduce costs by outsourcing both the infrastructure and the management of that infrastructure. And it’s true that the average IT department has a great deal of wasted equipment. For example, the load of doing the books in the fourth quarter requires a certain capacity that will largely sit idle the rest of the year.

But are the savings of shifting to cloud computing big enough for the enterprise to risk relying on an external provider, especially when deploying complex business processes that require data to go in and out of the cloud, back behind the firewall, and back again to the cloud?

For some applications, this would require a lot of reengineering, says Ovum analyst Mitchell. “If you have a custom-built CRM application in the cloud and an in-house ERP application, it may require some expensive integration that would be more than the cost savings,” he says.

Many enterprise adopters of cloud computing thus use it either for fairly separate, low-risk applications such as expense reporting and contact management, or for trial and peripheral projects where it makes more sense to rent someone else’s infrastructure than to stand up and maintain your own. The New York Times and Nasdaq OMX have both experimented with’s cloud services this way.

Adam Selipsky, vice president of product management and developer relations for Amazon Web Services, acknowledges that most cloud users today are startups and small businesses looking for a quick, easy way to ramp up infrastructure, or experimental, non-mission-critical projects at larger companies. “We provide a customer with a base-level infrastructure.”

But Selipsky says enterprises are moving, albeit slowly, to doing more with the cloud. He cites Eli Lilly, which uses EC2 to process research data. That’s why will continue to ramp up its cloud services, Selipsky says. In the coming months, Selipsky predicts, customers can expect the release of applications for load balancing, EC2 environment monitoring, and automatic scaling.

Over time, as, Google, Hewlett-Packard, IBM, and Microsoft all have cloud offerings, they may become commodities with enterprise-level security, service levels, and compliance requirements baked in and proven. That appears to be the bet the major enterprise providers are taking by making their technology available over

Ephraim Schwartz is an editor at large at InfoWorld. He also writes the Reality Check blog. He can be reached at [email protected].  

Editor-at-large Tom Sullivan writes features, as well as produces the InfoWorld Daily podcast. He can be reached at [email protected].

Would you recommend this article?


Thanks for taking the time to let us know what you think of this article!
We'd love to hear your opinion about this or any other story you read in our publication.

Jim Love, Chief Content Officer, IT World Canada

Featured Download

Featured Story

How the CTO can Maintain Cloud Momentum Across the Enterprise

Embracing cloud is easy for some individuals. But embedding widespread cloud adoption at the enterprise level is...

Related Tech News

Get ITBusiness Delivered

Our experienced team of journalists brings you engaging content targeted to IT professionals and line-of-business executives delivered directly to your inbox.

Featured Tech Jobs