On-demand security issues raised

Software-as-a-service vendors need to allow customers to carry out penetration testing

Written by Phil Muncaster

Firms running on-demand applications on their networks could be exposing themselves to security risks because most on-demand software vendors do not allow access to their applications for testing, according to IT training specialist The Training Camp.

Although penetration testers are able to work with firms to spot weaknesses in the corporate network, legal restrictions mean that increasing areas of their customers' IT environments are out of bounds, explained The Training Camp's Nick Wells.

Advertisement

"It's not a massive issue because we've not seen a huge incident yet, but that's not to say it won't happen in the future," he added. "The potential is there for a massive breach to occur because people are not being allowed to go about their job in preventing it."

But Andy Kellett of analyst Butler Group argued that it is not practical for application service providers to be forced to provide access for their various customers. He added that allowing this to happen is not likely to increase the security of the service.

"Security is probably less a problem than in the end-user organisations because [on-demand app providers] are measured by the service they provide," Kellett argued. "I don't agree the end-user organisation's pen tester of choice should be doing the testing. The service provider should do it and make that information available."

Clarence So of Salesforce.com agreed, adding that most chief information officers today understand that software-as-a-service (SaaS) vendors are able to secure data more effectively than they can themselves.

"I'm sure training companies have their own motives for advocating the need for in-house skills such as penetration testing," he argued. "But any suggestions the SaaS model is less secure than client-server software are well wide of the mark."

But Daryl Cornelius of comms testing specialist Spirent Communications said that some on-demand apps providers could be shying away from allowing their customers to test their services in case it highlights any vulnerabilities.

"It could be quite a powerful weapon for businesses to have," he added. "It would be interesting to see customers start to demand more than just latency measurements but also performance under attack and other measurements."

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Online shopping

E-retailers urged to prepare for Christmas

Credit crunch sending shoppers online for cheaper presents   More...

Mobile phone

Emerging markets drive mobile growth

Mobile penetration rates expected to reach 95 per cent by...  More...

Digital information

Poor data classification costing companies dear

Millions wasted on searching through clutter, says analyst   More...

Primary Navigation