Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » Press Releases » Privacy and Security

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Ponemon Institute survey on cloud data security exposes gulf between IT security and compliance officers

November 01, 2011 | Prasad Dindigal, VP, Satyam Healthcare Practice
Source: Vormetric

Related Resources

  • Taking a Framework Approach to Securing Electronic Health Records (EHRs)
  • Where Information and Care Meet: Secure Mobile Healthcare Solutions that Drive Care Coordination
  • Moving Business Communication to the Cloud
  • Clinician Mobility: Leveraging Mobile Devices For Clinical Communications at Penn Medicine
  • Focus on Patient Care without Worrying about Underlying Technology

SAN JOSE, Calif. – Vormetric, Inc., the leader in enterprise systems encryption and key management, today announced the results from an independent research report conducted by the Ponemon Institute on how organizations manage data security risks in cloud computing environments. The survey of 1,000 IT security practitioners and enterprise compliance officers revealed that less than half of all respondents believe their organizations have adequate technologies to secure their cloud infrastructures. Meanwhile, the two groups sharply disagreed on whether the cloud is as secure as on-premise datacenters, who is responsible for cloud data security, and what security measures should be used.

According to the report entitled “Data Security in the Cloud Survey of U.S. IT Operations, IT Security and Compliance Practitioners”, only one third of IT security practitioners believe cloud infrastructure (IaaS) environments are as secure as on premise datacenters, while half of compliance officers think IaaS is as secure. Regarding cloud security roles, most (21 percent) compliance officers said they are responsible for defining security requirements, but the majority (22 percent) of IT respondents think this responsibility belongs to business unit leaders. When asked about the most important cloud security measure, IT practitioners cited the use of encryption to make data unreadable by cloud service providers, yet compliance officers said encryption should be used to enforce separation of duties to prevent IT administrators from accessing data they do not need to perform their jobs.

Larry Ponemon, Chairman and Founder of the Ponemon Institute, and Vormetric will unveil the report’s complete findings and discuss their implications in a webinar on Tuesday, November 1, 2011 at 2:00 pm Eastern Time. To register for Cloud Data Security from IT Security and Compliance Perspectives please visit this link. The report will be available for download here beginning Nov. 2nd.

“While we were surprised by the different attitudes towards cloud security among IT practitioners and compliance officers, the findings did reveal that security in the cloud is a concern for both groups, especially in IaaS environments,” said Larry Ponemon, Chairman and Founder of the Ponemon Institute.

“What is most troubling is the fact that while respondents feel they lack adequate technologies to secure their IaaS environments, ownership for security in the cloud is dispersed throughout the organization.”

Additional Findings

Ponemon Institute also identified the following key findings on Data Security in the Cloud:
• Less than half of IT practitioners (35%) and compliance officers (42%) believe their organizations have adequate technologies to secure their IaaS environments
• Less than one third of respondents said their organizations encrypt data and/or files in the cloud
• Data in IaaS (Infrastructure as a Service) cloud environments is perceived as a greater security risk. SaaS (Software as a Service) is considered by both groups to be more secure.
• More than half of respondents said their organization’s internal audit review does NOT provide feedback on the security in cloud infrastructures
• While both groups disagreed on who is responsible for defining cloud security requirements, they agreed that:
- Business unit leaders are responsible for enforcing cloud security requirements
- No one role is responsible for implementing security in the cloud

“The fact that both IT practitioners and compliance officers consider encryption to be one of the most important enabling technologies for securing cloud infrastructures, even though they disagree on its use case, reflects what we are seeing in the marketplace,” Richard Gorman, CEO of Vormetric. “Since we work with both security and compliance teams, we have experienced firsthand how ownership for security in the cloud is often times splintered. This makes it extremely difficult for organizations to implement an enterprise-wide data security strategy that incorporates protection for sensitive information in the cloud.”

About Vormetric

Vormetric is the leader in enterprise system encryption. The Vormetric Data Security product line provides a single, manageable and scalable solution to encrypt any file, any database, any application, anywhere it resides— without sacrificing application performance or creating key management complexity. Some of the largest and most security conscious organizations and government agencies in the world, including 7 of the Fortune 20, have standardized on Vormetric to provide strong, easily manageable data security.

Vormetric technology has previously been selected by IBM as the only database encryption solution for DB2 and Informix on LinuxTM, Unix® and Windows; by Symantec to provide the Symantec Veritas NetBackupTM Media Server Encryption Option; and by Oracle to secure the execution environment for Oracle® Database Vault. For more information visit, www.vormetric.com.

 

Related Topics:
  • California
  • computing
  • encryption
  • Larry Ponemon
  • Ponemon Institute
  • Prasad Dindigal
  • SAN Jose
  • Vormetric Inc.
  • Privacy and Security

Reader Comments (0)Login to Post a Comment

receive news by email

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • 6 things patients want from social media
  • FCC gives green light to wireless medical devices
  • Tablet adoption by docs soars
  • VeriTeQ Acquisition Corporation to offer implantable RFID Microchip
  • Kaiser Permanente adds iPhone app to its suite of mobile offerings
  • VeriTeQ Acquisition Corporation acquires implantable, FDA-Cleared VeriChip technology
  • Cooper Green Mercy Hospital implements OpenVista EHR
  • RelayHealth, Greenway accelerate health system data exchange
more Press Releases

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • UPCOMING WEBINARS
    June 6th @ 2PM ET--Healthcare Best Practices: 4 Critical IT Strategies to Avoid Data Breaches
  • UPCOMING WEBINARS
    June 5th @ 1PM ET--Get Control of Your Medical Images with a Cloud-Based Vendor-Neutral Archive
  • ON DEMAND WEBINARS
    A Smarter Approach to Healthcare PC Virtualization
  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
More Resources
Syndicate content

HIMSS JOBMINE

  • Clinical Informatics Physician - Epic - Verona, WI
  • Regional Senior Quality Analyst - Memorial Medical Center - Modesto, CA
  • Network Engineer II - Carilion Clinic - Roanoke, VA
  • EMR Implementation - Project Manager Rothman Specialty Hospital - Rothman Specialty Hospital - Bensalem, PA
  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy