This best practice might seem obvious, but it can never be over-emphasized. Here are the five must-dos of Cloud Computing security…
Evaluate Cloud service providers’ security with these questions:
What access control model do you use? Who chooses the authoritative sources of access control policy and user profile information — you, or us, or a third party?
Do you support retrieval of access control policies and user profile information from external sources? If so, via what formats and transmission mechanisms?
Where do our accounts reside? How are they provisioned and deprovisioned? How do you protect the integrity of my data?
What authentication mechanisms do you support? (These should be appropriate for the sensitivity of the data use.) Do you support federated authentication or single sign-on model(s)?
What support do you provide for delegated administration by policy administration services?
What log information do you provide? Can it be imported into our operational analysis and reporting tools?
Can we specify external entities with whom to share information? If so, how is that accomplished?





