Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

Agiliance Introduces Cloud Risk Management Tool for Private, Public, and Hybrid Cloud Environments

Company Announces New Solution for Cloud Risk Assessment, Monitoring and Assurance Target Compliance, Security and Threats in Private, Public and Hybrid Cloud Environments

As Global 2000 private and large public sector organizations face increasing compliance and security demands, they are virtualizing more of their IT operations through private and public cloud environments. In this transition, organizations still need to “gracefully lose control” without undermining governance, risk management and compliance requirements.

Company Announces New Solution for Cloud Risk Assessment, Monitoring and Assurance Target Compliance, Security and Threats in Private, Public and Hybrid Cloud Environments

As Global 2000 private and large public sector organizations face increasing compliance and security demands, they are virtualizing more of their IT operations through private and public cloud environments. In this transition, organizations still need to “gracefully lose control” without undermining governance, risk management and compliance requirements.

A newly announced Cloud Risk Management solution from San Jose, CA based Agiliance Inc., will provide compliance, security and threat risk transparency for these fast-evolving private, public and hybrid cloud virtualized environments.

Agiliance’s Cloud Risk Management offering mirrors cloud risk governance stages that experts anticipate will be adopted in the market:

Cloud Risk Readiness – This assessment service is for private cloud project and operator risk assessments, and public cloud project and provider risk assessments, inclusive of third and fourth party providers. The service uses the RiskVision platform, compliance controls assessment frameworks and content from PCI DSS 2.0, FISMA 2010, SOX, NIST, ISO, CSA, SANS and BITS, threat controls content from CSA, and cloud risk dashboards and reports.

Cloud Risk Operations –  Using Agiliance RiskVision as the base platform, this monitoring service is for private cloud virtualization security policy compliance, cloud threats and vulnerabilities and offline image re-compliance. Public cloud uses include compliance, segregation and virtualization provisioning management. For continuous compliance, NIST SCAP protocols, CIS benchmarks and secure configuration management integrations with VMware vShield, McAfee ePO and netIQ SCM are automated. For threat management, zero-day feeds from Verisign and the National Vulnerability Database (NVD), and virtualized vulnerability integrations with eEye Retina and Tenable Nessus are automated.

Cloud Risk Audit – This assurance service targets emerging CloudAudit and other guidelines for private cloud operators and public cloud providers to perform automated regulatory health checks and provide transparency in their infrastructure (IaaS), platform (PaaS) and software (SaaS) environments. Agiliance RiskVision is the base platform that will articulate multi-party data flows and asset locations with real-time risk analytics.

According to a report by Forrester Research, Inc., “To take full advantage of the power of cloud computing, end users need to attain assurance of the cloud’s treatment of security, privacy, and compliance issues.” Another report by Forrester Research, Inc. also states that, “Instead of waiting for the cloud industry to step up its support for regulatory compliance, security professionals should look beyond their providers for compensating controls to aid cloud sourcing.”

Advertisement. Scroll to continue reading.

Cloud Risk Management

“What has been holding back the adoption of cloud computing in large organizations are consistent and standardized frameworks, open standards and interfaces that address security controls and easy to implement processes to provide assurances on levels of GRC and security in cloud environments,” said Jim Reavis, co-founder and executive director of the Cloud Security Alliance.

In a recent Novell sponsored survey of more than 200 IT professionals at large enterprises, 89 percent of respondents see private clouds as the next logical stop for organizations already using virtualization and 93 percent feel private cloud platforms should offer a management framework that can span a heterogeneous infrastructure. In addition, 91 percent of the survey respondents noted concern about the inherent security risks public clouds present.

Agiliance Cloud Risk Readiness Service and Cloud Risk Operations Service will be available December 2010. The Agiliance RiskVision platform and applications are available on-demand, starting at $37,500 per year. Agiliance also plans to release Cloud Risk Audit Service in 2011.

< Be Informed. Subscribe to the SecurityWeek Email Briefing Here >

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

CISO Conversations

SecurityWeek talks to Billy Spears, CISO at Teradata (a multi-cloud analytics provider), and Lea Kissner, CISO at cloud security firm Lacework.

Cloud Security

Cloud security researcher warns that stolen Microsoft signing key was more powerful and not limited to Outlook.com and Exchange Online.

CISO Strategy

Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Application Security

A CSRF vulnerability in the source control management (SCM) service Kudu could be exploited to achieve remote code execution in multiple Azure services.

Cloud Security

VMware described the bug as an out-of-bounds write issue in its implementation of the DCE/RPC protocol. CVSS severity score of 9.8/10.