Brussels, 24/11/2009 (Agence Europe) - The European Network and Information Security Agency (ENISA) has recently published a new report on “cloud computing”, a new policy that, for enterprise, consists of making digital resources available to third companies over the internet. This new procedure is an obvious source of profit for companies, but can also be to the detriment of the organisations in question from the information security point of view. The report speaks of the technical, political and legal implications of cloud computing but, in particular, gives practical advice about how to manage risks and maximise advantages for users. It sets out a list of detailed criteria that each company can use to determine whether a cloud provider, via internet, takes the question of security seriously. The greatest risks tackled in the list of points to be verified include lock-in, failures in mechanisms separating customers' data and applications, and legal risks such as the failure to comply with data protection legislation. Once the risks have been assessed and processed, cloud computing becomes a way to ensure information security. “The scale and flexibility of cloud computing gives the providers a security edge. For example, providers can instantly call on extra defensive resources like filtering and re-routing. They can also roll out new security patches more efficiently and keep more comprehensive evidence for diagnostics”, says Udo Helmbrecht, ENISA Executive Director. (I.L./transl.jl)