<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Fast Lane UK Blog</title>
	<atom:link href="http://www.flane.co.uk/blog/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.flane.co.uk/blog</link>
	<description>Sharing Ideas and Knowledge</description>
	<lastBuildDate>Sun, 23 Sep 2012 20:42:33 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>Comment on 3 in Demand Skills required for the DoD 8570 Cyber Security / IA Workforce by creatine</title>
		<link>http://www.flane.co.uk/blog/2010/06/04/3-in-demand-skills-required-for-the-dod-8570-cyber-security-ia-workforce/comment-page-1/#comment-454</link>
		<dc:creator>creatine</dc:creator>
		<pubDate>Sun, 23 Sep 2012 20:42:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.fastlaneus.com/blog/?p=156#comment-454</guid>
		<description>&lt;strong&gt;Title...&lt;/strong&gt;

Wonderful website. A lot of useful info here. I am sending it to several friends ans also sharing in delicious. And obviously, thanks for your effort!...</description>
		<content:encoded><![CDATA[<p><strong>Title&#8230;</strong></p>
<p>Wonderful website. A lot of useful info here. I am sending it to several friends ans also sharing in delicious. And obviously, thanks for your effort!&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Forum on Secure Borderless Networks by creatine monohydrate</title>
		<link>http://www.flane.co.uk/blog/2011/01/20/new-forum-on-secure-borderless-networks/comment-page-1/#comment-453</link>
		<dc:creator>creatine monohydrate</dc:creator>
		<pubDate>Sun, 23 Sep 2012 20:30:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.fastlaneus.com/blog/?p=238#comment-453</guid>
		<description>&lt;strong&gt;Title...&lt;/strong&gt;

Wow that was strange. I just wrote an really long comment but after I clicked submit my comment didn&#039;t appear. Grrrr... well I&#039;m not writing all that over again. Anyways, just wanted to say fantastic blog!...</description>
		<content:encoded><![CDATA[<p><strong>Title&#8230;</strong></p>
<p>Wow that was strange. I just wrote an really long comment but after I clicked submit my comment didn&#8217;t appear. Grrrr&#8230; well I&#8217;m not writing all that over again. Anyways, just wanted to say fantastic blog!&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cisco believes in cloud networking future by creatine monohydrate</title>
		<link>http://www.flane.co.uk/blog/2010/06/30/cisco-beliefs-in-cloud-networking-future/comment-page-1/#comment-452</link>
		<dc:creator>creatine monohydrate</dc:creator>
		<pubDate>Sun, 23 Sep 2012 20:04:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.fastlaneus.com/blog/2010/06/30/cisco-beliefs-in-cloud-networking-future/#comment-452</guid>
		<description>&lt;strong&gt;Title...&lt;/strong&gt;

You really make it appear so easy along with your presentation but I find this topic to be really something that I believe I would by no means understand. It kind of feels too complex and extremely wide for me. I am looking ahead in your subsequent sub...</description>
		<content:encoded><![CDATA[<p><strong>Title&#8230;</strong></p>
<p>You really make it appear so easy along with your presentation but I find this topic to be really something that I believe I would by no means understand. It kind of feels too complex and extremely wide for me. I am looking ahead in your subsequent sub&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on NetApp Storage Efficiencies: Flexible Volumes by NetApp Storage Efficiencies: FlexClones &#8211; Fast Lane US Blog</title>
		<link>http://www.flane.co.uk/blog/2010/04/28/netapp-storage-efficiencies-flexible-volumes/comment-page-1/#comment-46</link>
		<dc:creator>NetApp Storage Efficiencies: FlexClones &#8211; Fast Lane US Blog</dc:creator>
		<pubDate>Fri, 20 Aug 2010 15:11:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.fastlaneus.com/blog/?p=92#comment-46</guid>
		<description>[...] to install the FlexClone license. If you are not familiar with Flexible Volumes, please visit my Flexible Volumes blog post. FlexClone clones are based on Snapshots. Because snapshots share blocks with the active file [...]</description>
		<content:encoded><![CDATA[<p>[...] to install the FlexClone license. If you are not familiar with Flexible Volumes, please visit my Flexible Volumes blog post. FlexClone clones are based on Snapshots. Because snapshots share blocks with the active file [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Top 10 concerns facing Cloud Cyber Security Warriors by Barry Kaufman</title>
		<link>http://www.flane.co.uk/blog/2010/06/16/top-10-concerns-facing-cloud-cyber-security-warriors/comment-page-1/#comment-40</link>
		<dc:creator>Barry Kaufman</dc:creator>
		<pubDate>Tue, 06 Jul 2010 16:07:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.fastlaneus.com/blog/?p=180#comment-40</guid>
		<description>Hi Cloud Ninja,

I would say that the updated BP doc on the Azure Solution does in fact answer my concerns.  I will keep an eye on how Azure fairs in terms of Cloud Security.  

Thanks,

Barry</description>
		<content:encoded><![CDATA[<p>Hi Cloud Ninja,</p>
<p>I would say that the updated BP doc on the Azure Solution does in fact answer my concerns.  I will keep an eye on how Azure fairs in terms of Cloud Security.  </p>
<p>Thanks,</p>
<p>Barry</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cisco Cius, next generation tablet by World Wide News Flash</title>
		<link>http://www.flane.co.uk/blog/2010/06/30/cisco-cius-next-generation-tablet/comment-page-1/#comment-37</link>
		<dc:creator>World Wide News Flash</dc:creator>
		<pubDate>Wed, 30 Jun 2010 18:25:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.fastlaneus.com/blog/2010/06/30/cisco-cius-next-generation-tablet/#comment-37</guid>
		<description>&lt;strong&gt;Cisco Cius, next generation tablet ? Fast Lane US Blog...&lt;/strong&gt;

I found your entry interesting do I&#039;ve added a Trackback to it on my weblog :)...</description>
		<content:encoded><![CDATA[<p><strong>Cisco Cius, next generation tablet ? Fast Lane US Blog&#8230;</strong></p>
<p>I found your entry interesting do I&#8217;ve added a Trackback to it on my weblog <img src='http://www.flane.co.uk/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Top 10 concerns facing Cloud Cyber Security Warriors by Cloud Ninja</title>
		<link>http://www.flane.co.uk/blog/2010/06/16/top-10-concerns-facing-cloud-cyber-security-warriors/comment-page-1/#comment-35</link>
		<dc:creator>Cloud Ninja</dc:creator>
		<pubDate>Fri, 25 Jun 2010 20:10:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.fastlaneus.com/blog/?p=180#comment-35</guid>
		<description>Barry - you raise some great points - here&#039;s a refreshed Security BP doc [June 2010] &amp; addresses them. Let me know.
-cn
http://www.globalfoundationservices.com/security/documents/SecurityBestPracticesWindowsAzureApps.pdf</description>
		<content:encoded><![CDATA[<p>Barry &#8211; you raise some great points &#8211; here&#8217;s a refreshed Security BP doc [June 2010] &amp; addresses them. Let me know.<br />
-cn<br />
<a href="http://www.globalfoundationservices.com/security/documents/SecurityBestPracticesWindowsAzureApps.pdf" rel="nofollow">http://www.globalfoundationservices.com/security/documents/SecurityBestPracticesWindowsAzureApps.pdf</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Top 10 concerns facing Cloud Cyber Security Warriors by Barry Kaufman</title>
		<link>http://www.flane.co.uk/blog/2010/06/16/top-10-concerns-facing-cloud-cyber-security-warriors/comment-page-1/#comment-29</link>
		<dc:creator>Barry Kaufman</dc:creator>
		<pubDate>Thu, 17 Jun 2010 14:45:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.fastlaneus.com/blog/?p=180#comment-29</guid>
		<description>And to follow up on the standards issue raised in the previous post, for a couple of good looks at Vendor Neutral approaches to securing the cloud:

1. The CSA&#039;s Cloud Security Controls matrix does a nice job of attempting fill in the gaps regarding compliance initiatives like PCI and HIPAA, with this Matrix that guides cloud providers and customers on how to vet security controls in place:  http://www.cloudsecurityalliance.org/cm.html

2. The Cloud Audit group released some of this info as recently as last week, focused on the unique aspects of auditing the cloud:  http://bit.ly/cN9lnR</description>
		<content:encoded><![CDATA[<p>And to follow up on the standards issue raised in the previous post, for a couple of good looks at Vendor Neutral approaches to securing the cloud:</p>
<p>1. The CSA&#8217;s Cloud Security Controls matrix does a nice job of attempting fill in the gaps regarding compliance initiatives like PCI and HIPAA, with this Matrix that guides cloud providers and customers on how to vet security controls in place:  <a href="http://www.cloudsecurityalliance.org/cm.html" rel="nofollow">http://www.cloudsecurityalliance.org/cm.html</a></p>
<p>2. The Cloud Audit group released some of this info as recently as last week, focused on the unique aspects of auditing the cloud:  <a href="http://bit.ly/cN9lnR" rel="nofollow">http://bit.ly/cN9lnR</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Top 10 concerns facing Cloud Cyber Security Warriors by Barry Kaufman</title>
		<link>http://www.flane.co.uk/blog/2010/06/16/top-10-concerns-facing-cloud-cyber-security-warriors/comment-page-1/#comment-27</link>
		<dc:creator>Barry Kaufman</dc:creator>
		<pubDate>Thu, 17 Jun 2010 14:34:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.fastlaneus.com/blog/?p=180#comment-27</guid>
		<description>Hi Cloud Ninja, thanks for adding the MS dimension to the discussion.  Certainly MS security controls are a key part of the overall picture, and I am a big fan of the work done by MS on SDL and threat modeling.  I worked with your guys David LeBlanc and Michael Howard on turning their seminal work, Writing Secure Code, into several different courses.   On the project I had the good fortune of having Dinis Cruz, thought leader of OWASP on my team, and we all had robust discussions over a year or so on Application Security within the context of MS environments.

At the time, one contentious issue was perhaps a precursor to my key concern with Cloud Security:  the Secure Multi-Tenancy issue.  Back in those days (2003/2004) Dinis and others expressed a great deal of concern with the insecure design inherent in the Full Trust ASP.NET model, particularly as it relates to co-hosting of entities on the same servers (see http://bit.ly/aTbkBY for more info on this MS Security melodrama).  

From the links you sent me, I see your services are following general best practices, many that MS has had a good part in developing and evangelizing, but I am not seeing any detail beyond the generalities on how the physical aspects of MS cloud services are secured.  How do you deal with the lower layers of the IP stack? What standard are you working with in terms of the architecture in the data center? Is there any VMware behind the platform, or is it all HyperV?  How is MS dealing with the differences inherent in the cloud?  I also see that the documents you referred to bragging about being SAS 70 and ISO 27001 compliant, both of which, as I mentioned in the blog are not up to date in terms of Cloud Security&#039;s different set of concerns.  

Again, thanks for adding your comments, and hopefully we can keep a dialogue going.

Barry</description>
		<content:encoded><![CDATA[<p>Hi Cloud Ninja, thanks for adding the MS dimension to the discussion.  Certainly MS security controls are a key part of the overall picture, and I am a big fan of the work done by MS on SDL and threat modeling.  I worked with your guys David LeBlanc and Michael Howard on turning their seminal work, Writing Secure Code, into several different courses.   On the project I had the good fortune of having Dinis Cruz, thought leader of OWASP on my team, and we all had robust discussions over a year or so on Application Security within the context of MS environments.</p>
<p>At the time, one contentious issue was perhaps a precursor to my key concern with Cloud Security:  the Secure Multi-Tenancy issue.  Back in those days (2003/2004) Dinis and others expressed a great deal of concern with the insecure design inherent in the Full Trust ASP.NET model, particularly as it relates to co-hosting of entities on the same servers (see <a href="http://bit.ly/aTbkBY" rel="nofollow">http://bit.ly/aTbkBY</a> for more info on this MS Security melodrama).  </p>
<p>From the links you sent me, I see your services are following general best practices, many that MS has had a good part in developing and evangelizing, but I am not seeing any detail beyond the generalities on how the physical aspects of MS cloud services are secured.  How do you deal with the lower layers of the IP stack? What standard are you working with in terms of the architecture in the data center? Is there any VMware behind the platform, or is it all HyperV?  How is MS dealing with the differences inherent in the cloud?  I also see that the documents you referred to bragging about being SAS 70 and ISO 27001 compliant, both of which, as I mentioned in the blog are not up to date in terms of Cloud Security&#8217;s different set of concerns.  </p>
<p>Again, thanks for adding your comments, and hopefully we can keep a dialogue going.</p>
<p>Barry</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Top 10 concerns facing Cloud Cyber Security Warriors by Cloud Ninja</title>
		<link>http://www.flane.co.uk/blog/2010/06/16/top-10-concerns-facing-cloud-cyber-security-warriors/comment-page-1/#comment-26</link>
		<dc:creator>Cloud Ninja</dc:creator>
		<pubDate>Wed, 16 Jun 2010 22:03:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.fastlaneus.com/blog/?p=180#comment-26</guid>
		<description>This is a great outline of important security issues. IMHO, when considering security, 2 items need to be addressed:
1) Physical security of the hardware 2) Security of the Data - here are some resources I&#039;ve found that discuss this and act as guidelines when considering security and the cloud:

Physical security:
http://www.globalfoundationservices.com/security/index.html 
http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf 

 
Data Security:
http://www.research.microsoft.com/en-us/projects/cryptocloud/ 
http://www.research.microsoft.com/en-us/projects/secpal/ 

thoughts?

hope that helps
-cn</description>
		<content:encoded><![CDATA[<p>This is a great outline of important security issues. IMHO, when considering security, 2 items need to be addressed:<br />
1) Physical security of the hardware 2) Security of the Data &#8211; here are some resources I&#8217;ve found that discuss this and act as guidelines when considering security and the cloud:</p>
<p>Physical security:<br />
<a href="http://www.globalfoundationservices.com/security/index.html" rel="nofollow">http://www.globalfoundationservices.com/security/index.html</a><br />
<a href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf" rel="nofollow">http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf</a> </p>
<p>Data Security:<br />
<a href="http://www.research.microsoft.com/en-us/projects/cryptocloud/" rel="nofollow">http://www.research.microsoft.com/en-us/projects/cryptocloud/</a><br />
<a href="http://www.research.microsoft.com/en-us/projects/secpal/" rel="nofollow">http://www.research.microsoft.com/en-us/projects/secpal/</a> </p>
<p>thoughts?</p>
<p>hope that helps<br />
-cn</p>
]]></content:encoded>
	</item>
</channel>
</rss>
