<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Extending the Concept: A Security API for Cloud Stacks</title>
	<atom:link href="http://www.rationalsurvivability.com/blog/?feed=rss2&#038;p=1177" rel="self" type="application/rss+xml" />
	<link>http://www.rationalsurvivability.com/blog/?p=1177</link>
	<description>Hoff&#039;s Ramblings about Information Survivability, Information Centricity, Risk Management and Disruptive Innovation. Oh, I have a fondness for virtualization and cloud computing security, too...</description>
	<lastBuildDate>Thu, 09 Sep 2010 02:54:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Follow-On: The Audit, Assertion, Assessment, and Assurance API (A6) &#124; Rational Survivability</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-37676</link>
		<dc:creator>Follow-On: The Audit, Assertion, Assessment, and Assurance API (A6) &#124; Rational Survivability</dc:creator>
		<pubDate>Thu, 11 Feb 2010 22:57:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-37676</guid>
		<description>[...] few weeks ago I penned a blog discussing an idea I presented at a recent Public Sector Cloud gathering that later inherited the [...]</description>
		<content:encoded><![CDATA[<p>[...] few weeks ago I penned a blog discussing an idea I presented at a recent Public Sector Cloud gathering that later inherited the [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-37676" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('37676', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-37676-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-37676" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('37676', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-37676-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; Blog Archive &#187; LegalCloud and the NIST Cloud Computing Definition</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-34166</link>
		<dc:creator>&#187; Blog Archive &#187; LegalCloud and the NIST Cloud Computing Definition</dc:creator>
		<pubDate>Mon, 21 Dec 2009 21:36:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-34166</guid>
		<description>[...] the security aspects. I have seen what is likely to be important and solid work going on around an initiative called A6. It discusses Audit, Assertion, Assessment, and Assurance API. This is also now known as A6. There [...]</description>
		<content:encoded><![CDATA[<p>[...] the security aspects. I have seen what is likely to be important and solid work going on around an initiative called A6. It discusses Audit, Assertion, Assessment, and Assurance API. This is also now known as A6. There [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-34166" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('34166', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-34166-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-34166" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('34166', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-34166-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: NIST Cloud Computing Definitions Final &#124; The Virtualization Practice</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-31787</link>
		<dc:creator>NIST Cloud Computing Definitions Final &#124; The Virtualization Practice</dc:creator>
		<pubDate>Wed, 25 Nov 2009 16:52:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-31787</guid>
		<description>[...] within any contract worked with a cloud provider. The answer to these questions is found in the A6 Initiative which is the development of an API to allow for audit and assessment scans within the cloud in an [...]</description>
		<content:encoded><![CDATA[<p>[...] within any contract worked with a cloud provider. The answer to these questions is found in the A6 Initiative which is the development of an API to allow for audit and assessment scans within the cloud in an [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-31787" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('31787', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-31787-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-31787" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('31787', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-31787-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: System Advancements at the Monastery &#187; Blog Archive &#187; Standardization and Interoperability in Security</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-11470</link>
		<dc:creator>System Advancements at the Monastery &#187; Blog Archive &#187; Standardization and Interoperability in Security</dc:creator>
		<pubDate>Mon, 10 Aug 2009 05:44:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-11470</guid>
		<description>[...] should also read Christofer Hoff&#8217;s rational Survivability blog. In Hoff&#8217;s post, &#8220;Extending the Concept: A Security API for Cloud Stacks&#8220;, he considers building on the capabilities of SCAP to embed a &#8220;standardized and open [...]</description>
		<content:encoded><![CDATA[<p>[...] should also read Christofer Hoff&#8217;s rational Survivability blog. In Hoff&#8217;s post, &#8220;Extending the Concept: A Security API for Cloud Stacks&#8220;, he considers building on the capabilities of SCAP to embed a &#8220;standardized and open [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-11470" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('11470', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-11470-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-11470" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('11470', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-11470-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Inter-Cloud Rock, Paper, Scissors: Service Brokers, Semantic Web or APIs? &#124; Digital Asset Management</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-10223</link>
		<dc:creator>Inter-Cloud Rock, Paper, Scissors: Service Brokers, Semantic Web or APIs? &#124; Digital Asset Management</dc:creator>
		<pubDate>Wed, 29 Jul 2009 07:49:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-10223</guid>
		<description>[...] In the broadest sense, Cloud is being positioned in the long term to allow for true utility.  This means that at a 30,000 foot view, consumers should be able to declare their business and technology requirements for workloads or application needs and TAMO! (then a miracle occurs,) that workload or application presents itself operating somewhere that meets those needs backed up by some form of attestation by the provider. Ultimately, I’d like to see a common way of auditing and validating those attestations.  Apropos for this discussion, I bring up the notion of an API [...]</description>
		<content:encoded><![CDATA[<p>[...] In the broadest sense, Cloud is being positioned in the long term to allow for true utility.  This means that at a 30,000 foot view, consumers should be able to declare their business and technology requirements for workloads or application needs and TAMO! (then a miracle occurs,) that workload or application presents itself operating somewhere that meets those needs backed up by some form of attestation by the provider. Ultimately, I’d like to see a common way of auditing and validating those attestations.  Apropos for this discussion, I bring up the notion of an API [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-10223" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('10223', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-10223-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-10223" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('10223', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-10223-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rational Survivability &#187; Inter-Cloud Rock, Paper, Scissors: Service Brokers, Semantic Web or APIs?</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-10117</link>
		<dc:creator>Rational Survivability &#187; Inter-Cloud Rock, Paper, Scissors: Service Brokers, Semantic Web or APIs?</dc:creator>
		<pubDate>Mon, 27 Jul 2009 18:00:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-10117</guid>
		<description>[...] In the broadest sense, Cloud is being positioned in the long term to allow for true utility.  This means that at a 30,000 foot view, consumers should be able to declare their business and technology requirements for workloads or application needs and TAMO! (then a miracle occurs,) that workload or application presents itself operating somewhere that meets those needs backed up by some form of attestation by the provider. Ultimately, I&#8217;d like to see a common way of auditing and validating those attestations.  Apropos for this discussion, I bring up the notion of an API [...]</description>
		<content:encoded><![CDATA[<p>[...] In the broadest sense, Cloud is being positioned in the long term to allow for true utility.  This means that at a 30,000 foot view, consumers should be able to declare their business and technology requirements for workloads or application needs and TAMO! (then a miracle occurs,) that workload or application presents itself operating somewhere that meets those needs backed up by some form of attestation by the provider. Ultimately, I&#8217;d like to see a common way of auditing and validating those attestations.  Apropos for this discussion, I bring up the notion of an API [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-10117" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('10117', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-10117-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-10117" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('10117', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-10117-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: s_crawford</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-9967</link>
		<dc:creator>s_crawford</dc:creator>
		<pubDate>Sun, 26 Jul 2009 17:11:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-9967</guid>
		<description>Having just recommend this to a management vendor in the past week, I obviously like this concept very much. I have long advocated greater integration of security and IT management tools and processes, and have highlighted SCAP as a tangible example of this over the past year. This would also address one of the most significant concerns we find in talking with enterprises: if they feel they are giving up control, they would like to have as much visibility as they can afford without trampling all over the fragile and still-evolving balance they are struggling to strike between cloud computing&#039;s values and its risks. This would be one potentially highly effective way to achieve this in a standardized (though still evolving) yet detailed way.

I will be very interested to see how concerns about this play out in this discussion.

-Scott</description>
		<content:encoded><![CDATA[<p>Having just recommend this to a management vendor in the past week, I obviously like this concept very much. I have long advocated greater integration of security and IT management tools and processes, and have highlighted SCAP as a tangible example of this over the past year. This would also address one of the most significant concerns we find in talking with enterprises: if they feel they are giving up control, they would like to have as much visibility as they can afford without trampling all over the fragile and still-evolving balance they are struggling to strike between cloud computing&#8217;s values and its risks. This would be one potentially highly effective way to achieve this in a standardized (though still evolving) yet detailed way.</p>
<p>I will be very interested to see how concerns about this play out in this discussion.</p>
<p>-Scott</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-9967" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('9967', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-9967-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-9967" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('9967', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-9967-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Arthur</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-9905</link>
		<dc:creator>Arthur</dc:creator>
		<pubDate>Sun, 26 Jul 2009 03:39:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-9905</guid>
		<description>Fucking brilliant. Wish I&#039;d thought of it.</description>
		<content:encoded><![CDATA[<p>Fucking brilliant. Wish I&#8217;d thought of it.</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-9905" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('9905', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-9905-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-9905" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('9905', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-9905-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Telematique, water and fire.</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-9834</link>
		<dc:creator>Telematique, water and fire.</dc:creator>
		<pubDate>Sat, 25 Jul 2009 17:38:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-9834</guid>
		<description>&lt;strong&gt;Hoff Kicks Up Dust with a Security API for Cloud...&lt;/strong&gt;

 The sense I get (from Hoff, the comments, and from speaking directly to cloud service providers) is that the RTA clauses have been just that... clauses in a contract, with very little actual planning and preparation by the individual service provider....</description>
		<content:encoded><![CDATA[<p><strong>Hoff Kicks Up Dust with a Security API for Cloud&#8230;</strong></p>
<p> The sense I get (from Hoff, the comments, and from speaking directly to cloud service providers) is that the RTA clauses have been just that&#8230; clauses in a contract, with very little actual planning and preparation by the individual service provider&#8230;.</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-9834" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('9834', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-9834-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-9834" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('9834', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-9834-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Blog &#187; Saturday morning reading, 07/25/09</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-9812</link>
		<dc:creator>Network Security Blog &#187; Saturday morning reading, 07/25/09</dc:creator>
		<pubDate>Sat, 25 Jul 2009 14:48:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-9812</guid>
		<description>[...] Extending the concept: A security API for Cloud Stacks &#8211; Chris Hoff posted this concept last night and caused quite a bruhaha.&#160; The basic idea is that the commonality of the various compliance structures should be built into a security control model that&#8217;s used to build Cloud infrastructure in a testable, open archetecture.&#160; Very interesting concept, I want to see how Chris develops it going forward. [...]</description>
		<content:encoded><![CDATA[<p>[...] Extending the concept: A security API for Cloud Stacks &#8211; Chris Hoff posted this concept last night and caused quite a bruhaha.&nbsp; The basic idea is that the commonality of the various compliance structures should be built into a security control model that&#8217;s used to build Cloud infrastructure in a testable, open archetecture.&nbsp; Very interesting concept, I want to see how Chris develops it going forward. [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-9812" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('9812', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-9812-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-9812" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('9812', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-9812-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: rybolov</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-9702</link>
		<dc:creator>rybolov</dc:creator>
		<pubDate>Sat, 25 Jul 2009 01:12:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-9702</guid>
		<description>This is the same problem for a managed service provider.  IE, how do I allow you to audit your system and the underlying infrastructure.  Actually, a cloud could make this much easier as a customer by providing an API to do this with because I really want to do that in a managed services environment but I&#039;m stuck with putting a scanner in each environment.

So what we have in SCAP is Common Platform Enumeration (CPE) which allows you to specify the hardware and software (ie, how the infrastructure that you don&#039;t know about is built) and eXtensible Configuration Checklist Description (XCCDF) which specifies the audit/compliance checks.  Package them together and you have a way of describing what the infrastructure looks like and the technical auditing standard to go along with it.</description>
		<content:encoded><![CDATA[<p>This is the same problem for a managed service provider.  IE, how do I allow you to audit your system and the underlying infrastructure.  Actually, a cloud could make this much easier as a customer by providing an API to do this with because I really want to do that in a managed services environment but I&#8217;m stuck with putting a scanner in each environment.</p>
<p>So what we have in SCAP is Common Platform Enumeration (CPE) which allows you to specify the hardware and software (ie, how the infrastructure that you don&#8217;t know about is built) and eXtensible Configuration Checklist Description (XCCDF) which specifies the audit/compliance checks.  Package them together and you have a way of describing what the infrastructure looks like and the technical auditing standard to go along with it.</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-9702" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('9702', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-9702-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-9702" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('9702', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-9702-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Christofer Hoff</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-9696</link>
		<dc:creator>Christofer Hoff</dc:creator>
		<pubDate>Sat, 25 Jul 2009 00:51:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-9696</guid>
		<description>&lt;a href=&quot;#comment-9681&quot; rel=&quot;nofollow&quot;&gt;@Armorguy &lt;/a&gt; 

1. Everything and anything can be gamed. This is why I mentioned open and standardized API across providers/platforms.  The fact is that you trust someone/something to give you this information in non-Cloud environments today, and in Cloud you have sometimes ZERO visibility.  This is an improvement.

2. Reduced cost of service to the provider in the long term means lower cost to you.  You also get easier audit, compliance and reporting capabilities -- that you could also delegate view to the auditor.

3. We already have these standards.  They exist in many forms.  One of them (as I mentioned) is SCAP.  Peter Mell from NIST who is heading up Cloud for them also is one of the father&#039;s of SCAP...

/Hoff</description>
		<content:encoded><![CDATA[<p><a href="#comment-9681" rel="nofollow">@Armorguy </a> </p>
<p>1. Everything and anything can be gamed. This is why I mentioned open and standardized API across providers/platforms.  The fact is that you trust someone/something to give you this information in non-Cloud environments today, and in Cloud you have sometimes ZERO visibility.  This is an improvement.</p>
<p>2. Reduced cost of service to the provider in the long term means lower cost to you.  You also get easier audit, compliance and reporting capabilities &#8212; that you could also delegate view to the auditor.</p>
<p>3. We already have these standards.  They exist in many forms.  One of them (as I mentioned) is SCAP.  Peter Mell from NIST who is heading up Cloud for them also is one of the father&#8217;s of SCAP&#8230;</p>
<p>/Hoff</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-9696" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('9696', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-9696-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-9696" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('9696', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-9696-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Online Storage Optimization &#187; Blog Archive &#187; It&#8217;s Getting Cloudy up There</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-9684</link>
		<dc:creator>Online Storage Optimization &#187; Blog Archive &#187; It&#8217;s Getting Cloudy up There</dc:creator>
		<pubDate>Fri, 24 Jul 2009 23:50:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-9684</guid>
		<description>[...] as &#8220;Beaker&#8221;) says such a standard is already available, as he sketches out in a recent post on his Rational Survivability [...]</description>
		<content:encoded><![CDATA[<p>[...] as &#8220;Beaker&#8221;) says such a standard is already available, as he sketches out in a recent post on his Rational Survivability [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-9684" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('9684', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-9684-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-9684" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('9684', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-9684-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Armorguy</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1177&#038;cpage=1#comment-9681</link>
		<dc:creator>Armorguy</dc:creator>
		<pubDate>Fri, 24 Jul 2009 23:36:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1177#comment-9681</guid>
		<description>A few thoughts...

1. I don&#039;t know if many auditors/assessors are going to buy off on a scan that scans via an API...too much of a chance for that to be gamed.

2. As a potential cloud user where&#039;s my interest in this?  Why am I making this &quot;easier&quot; for the cloud provider? And if I make it easier what do I get?  These are the questions that make or break this kind of model.

3. Lastly, this is going to require the different providers of cloud tech to agree on standards, etc.  I don&#039;t see this happening until well after the &quot;Cloud Wars&quot; are over and a single tech platform dominates.

I&#039;ll think more...</description>
		<content:encoded><![CDATA[<p>A few thoughts&#8230;</p>
<p>1. I don&#8217;t know if many auditors/assessors are going to buy off on a scan that scans via an API&#8230;too much of a chance for that to be gamed.</p>
<p>2. As a potential cloud user where&#8217;s my interest in this?  Why am I making this &#8220;easier&#8221; for the cloud provider? And if I make it easier what do I get?  These are the questions that make or break this kind of model.</p>
<p>3. Lastly, this is going to require the different providers of cloud tech to agree on standards, etc.  I don&#8217;t see this happening until well after the &#8220;Cloud Wars&#8221; are over and a single tech platform dominates.</p>
<p>I&#8217;ll think more&#8230;</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-9681" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('9681', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-9681-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-9681" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('9681', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-9681-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
</channel>
</rss>
