US lawmakers question cloud security

Large clouds could make for a tempting target for cybercriminals, Lungren says

A rush by President Barack Obama's administration to move U.S. government agencies to cloud computing services may lead to unintended security problems and other headaches, some lawmakers said Thursday.

While agency adoption of cloud computing could save money, it may also lead to questions about control of agency data, about data portability and about whether cloud vendors will be prime targets for cybercriminals, several members of the U.S. House of Representatives Homeland Security Committee's cybersecurity subcommittee said during a hearing.

"Our concern is that the cloud offers a rich target for hackers, criminals, terrorists and rogue nations," said Representative Dan Lungren, a California Republican and subcommittee chairman. "With cyber-espionage affecting every sector of our economy, aggregating important information in one location is a legitimate security concern. You might say it's a target-rich environment."

Many cloud providers spread data across servers and data centers to reduce risk, said Timothy Brown, senior vice president and chief architect for security at CA Technologies. "Little pieces of your data are stored in little pieces on servers all over the world," he said. "Therefore, they can't be reconstituted into one piece."

Other subcommittee members questioned whether agencies should use the services of foreign cloud providers and what will happen to an agency's data if its cloud provider goes out of business. Lawmakers need to examine cloud computing's benefits and risks after the Obama administration issued a "cloud first" strategy for IT deployment in February, Lungren said.

Five of seven witnesses before the subcommittee defended cloud computing, saying it can save U.S. agencies significant money and allow them to upgrade their technology much faster than they can with in-house systems.

"By leveraging shared computing resources, higher utilization rates of computing hardware, and economies of scale, cloud computing is ushering in an IT revolution which promises far lower costs while greatly improving capacity and performance," said James Sheaffer, president of the North American public sector division of Computer Sciences.

The U.S. Department of Homeland Security could save 8 to 10 percent of IT costs by moving to cloud infrastructure services, and by using the cloud, the agency can add new network and storage services in one week, compared to up to 18 months if done in house, said Richard Spires, CIO at DHS.

DHS is moving 12 IT services to the cloud, including email, mobile support and project management, he said. Agencies need to demand strong reporting and auditing requirements in contracts with cloud providers as a way to ensure security and service, he said.

"The benefits of cloud computing far outweigh the challenges," Spires said.

Representative Yvette Clarke, a New York Democrat, asked witnesses if there are government applications or services that should not be moved to a cloud environment.

Some classified information should not be put on the public Internet-based cloud right now, said Greg Wilshusen, director of information security issues U.S. Government Accountability Office.

Clarke asked if some government information should "never" be moved to the cloud.

"I was taught from a very early age never to say never," Wilshusen said.

Technology changes rapidly, and what's inappropriate today may be acceptable in a few years, Spires added. Still, it will be "quite awhile before we have any comfort putting any classified information into a public cloud environment," he said.

Security of data stored in the cloud is a shared responsibility between the vendor and the customer, said CA's Brown.

"IT organizations must take a very focused and methodical approach to evaluating what should or should not be moved to the cloud," he said. "The cloud is not a panacea, and may not be appropriate for all workloads."

Other witnesses raised concerns about cloud computing. Some federal agencies may be concerned about the physical location of their data and whether it's being stored overseas, said John Curran, CEO of the American Registry of Internet Numbers. Data interoperability standards, to guard against cloud providers going out of business, are not yet established, he added.

Lungren said he sees benefits to cloud computing, but also potential risks. "Sometimes, things sound too good to be true," he said.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.

Join the PC World newsletter!

Error: Please check your email address.

Tags CA TechnologiesU.S. House of Representatives Homeland Security CommitteeYvette ClarkeDan Lungren: Greg WilshusenGovernment use of ITComputer SciencesAmerican Registry of Internet Numbers.U.S. Department of Homeland Securitycloud computingBarack ObamainternetTimothy BrownsecurityJames SheaffergovernmentRichard SpiresJohn Curran

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Grant Gross

IDG News Service
Show Comments

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?