<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Ken+Huang</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Ken+Huang"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Ken_Huang"/>
		<updated>2026-05-30T19:15:42Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cloud_Top_5_Risks_with_IAAS&amp;diff=72022</id>
		<title>Cloud Top 5 Risks with IAAS</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cloud_Top_5_Risks_with_IAAS&amp;diff=72022"/>
				<updated>2009-10-23T00:14:28Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: moved Top 5 Risks with IAAS to Cloud Top 5 Risks with IAAS:&amp;amp;#32;Cloud&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;IAAS serves as the foundation layer for the cloud computing. The Top security concerns are: &lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;span class=&amp;quot;Apple-style-span&amp;quot; style=&amp;quot;line-height: normal; -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px;&amp;quot; /&amp;amp;gt; &lt;br /&gt;
&lt;br /&gt;
1) If the business mission critical application is hosted in IAAS environment, the down time due to man mad or nature disaster could introduce significant business risks. There are examples of some companies went bankrupt due to FBI investigation of data breach in IAAS enviroement. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
2) Physical security of the IAAS environment.&amp;amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
3) The Service Level Agreement &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
4) Compatibility of IAAS and internal legacy infrastructure. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
5) Regulatory compliance &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Cloud ‐ 10 Project]]&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Top_5_Risks_with_IAAS&amp;diff=72023</id>
		<title>Top 5 Risks with IAAS</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Top_5_Risks_with_IAAS&amp;diff=72023"/>
				<updated>2009-10-23T00:14:28Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: moved Top 5 Risks with IAAS to Cloud Top 5 Risks with IAAS:&amp;amp;#32;Cloud&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[Cloud Top 5 Risks with IAAS]]&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cloud_Top_5_Risks_with_IAAS&amp;diff=72021</id>
		<title>Cloud Top 5 Risks with IAAS</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cloud_Top_5_Risks_with_IAAS&amp;diff=72021"/>
				<updated>2009-10-23T00:13:02Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;IAAS serves as the foundation layer for the cloud computing. The Top security concerns are: &lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;span class=&amp;quot;Apple-style-span&amp;quot; style=&amp;quot;line-height: normal; -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px;&amp;quot; /&amp;amp;gt; &lt;br /&gt;
&lt;br /&gt;
1) If the business mission critical application is hosted in IAAS environment, the down time due to man mad or nature disaster could introduce significant business risks. There are examples of some companies went bankrupt due to FBI investigation of data breach in IAAS enviroement. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
2) Physical security of the IAAS environment.&amp;amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
3) The Service Level Agreement &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
4) Compatibility of IAAS and internal legacy infrastructure. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
5) Regulatory compliance &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Cloud ‐ 10 Project]]&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cloud_Top_5_Risks_with_IAAS&amp;diff=72020</id>
		<title>Cloud Top 5 Risks with IAAS</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cloud_Top_5_Risks_with_IAAS&amp;diff=72020"/>
				<updated>2009-10-23T00:11:50Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: Created page with '&amp;lt;span class=&amp;quot;Apple-style-span&amp;quot; style=&amp;quot;line-height: normal; -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px;&amp;quot;&amp;gt;IAAS serves as the foundation layer for …'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;span class=&amp;quot;Apple-style-span&amp;quot; style=&amp;quot;line-height: normal; -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px;&amp;quot;&amp;gt;IAAS serves as the foundation layer for the cloud computing. The Top security concerns are:&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span class=&amp;quot;Apple-style-span&amp;quot; style=&amp;quot;line-height: normal; -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px;&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1) If the business mission critical application is hosted in IAAS environment, the down time due to man mad or nature disaster could introduce significant business risks. There are examples of some companies went bankrupt due to FBI investigation of data breach in IAAS enviroement.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2) Physical security of the IAAS environment.&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3) The Service Level Agreement&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4) Compatibility of IAAS and internal legacy infrastructure.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
5) Regulatory compliance&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span class=&amp;quot;Apple-style-span&amp;quot; style=&amp;quot;line-height: normal; -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px;&amp;quot; /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71963</id>
		<title>Category:OWASP Cloud ‐ 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71963"/>
				<updated>2009-10-21T20:33:01Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
== Goal  ==&lt;br /&gt;
&lt;br /&gt;
Goal of the project is to maintain a list of top 10 security risks faced with the Cloud Computing and SaaS Models. List will be maintained by input from community, security experts and security incidences at cloud/SaaS providers. &lt;br /&gt;
&lt;br /&gt;
== Audience  ==&lt;br /&gt;
&lt;br /&gt;
Audience for the project will be organizations planning on leveraging external cloud environment to host their applications or rent application in a SaaS model (Software as a Service). Aim of the &amp;quot;OWASP Cloud-10&amp;quot; list is to help balance security risks with the cost advantage that the Cloud and SaaS model provides. We expect the Cloud and SaaS providers to be indirect audience for &amp;quot;OWASP Cloud-10&amp;quot;, when they try to showcase their security controls to potential customers against this list. &lt;br /&gt;
&lt;br /&gt;
== Managing OWASP Cloud-10 List (Pre-Alpha)  ==&lt;br /&gt;
&lt;br /&gt;
“OWASP Cloud-10” list will be maintained by input from, community, security experts and security incidences at cloud/SaaS providers. &lt;br /&gt;
&lt;br /&gt;
Each of the identified risk in &amp;quot;OWASP Cloud-10&amp;quot; will provide details on: &lt;br /&gt;
&lt;br /&gt;
*Various Risk Scenarios &lt;br /&gt;
*Real World Examples &lt;br /&gt;
*Possible Mitigations and Security Controls &lt;br /&gt;
*Reference to any related Incident&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== OWASP Cloud-10 List  ====&lt;br /&gt;
&lt;br /&gt;
== Initial pre-alpha list of OWASP Cloud-10 Security Risks  ==&lt;br /&gt;
&lt;br /&gt;
{| cellpadding=&amp;quot;2&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| C1 - Privacy of Users &lt;br /&gt;
| [Placeholder] - User's private and PII data gets stored in the cloud&lt;br /&gt;
|-&lt;br /&gt;
| C2 - Enterprise Data Hosted Outside in Cloud &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C3 - Accountability and Ownership of Data Security &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C4 - Federating User Identity &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C5 - Secondary Usage of Data &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C6 - Demonstrating Regulatory Compliance &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C7 - SLA - Building Right Level of insurance and accountability &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C8 - Vendor Lock-In &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C9 - Data Backup and Disaster Recovery &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C10 - Direct Exposure to Development and Production Environments &lt;br /&gt;
| &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
'''&amp;lt;center&amp;gt;Table 1: Top 10 Cloud - Security Risks&amp;lt;/center&amp;gt;'''&lt;br /&gt;
&lt;br /&gt;
== Other OWASP Cloud-10 Candidates  ==&lt;br /&gt;
&lt;br /&gt;
*Service Availability Risk &lt;br /&gt;
*Multi-Tenancy &lt;br /&gt;
*Integration between cloud and internally hosted services &lt;br /&gt;
*Patching and Vulnerability Management &lt;br /&gt;
*Lack of Transparency in Internal Security Controls and difficulty/complexity of auditing &lt;br /&gt;
*Enterprise Intranets exposed directly on Internet (if they move on a Public Cloud)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; This needs to be debated and for each of these we may need to add a separate page-holder with the following details. &lt;br /&gt;
&lt;br /&gt;
*Various Risk Scenarios &lt;br /&gt;
*Real World Examples &lt;br /&gt;
*Possible Mitigation and Security Controls &lt;br /&gt;
*Reference to any related Incident&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Roadmap (Status)  ====&lt;br /&gt;
&lt;br /&gt;
== Alpha State  ==&lt;br /&gt;
&lt;br /&gt;
#'''Identify and publish a first draft of potential &amp;quot;OWASP Cloud-10&amp;quot; candidates (July 2009)''' &lt;br /&gt;
#Ask contributors to collect more data and details on each of the risk item. (till Aug 2009) &lt;br /&gt;
#Get initial community feedback by discussing it in various blogs, discussion forums etc. (till Aug-Sept 2009)&lt;br /&gt;
&lt;br /&gt;
== Beta State  ==&lt;br /&gt;
&lt;br /&gt;
#Publish the first (beta) list of &amp;quot;OWASP Cloud-10&amp;quot; (Oct 2009) &lt;br /&gt;
#Identify additional candidates &lt;br /&gt;
#……. (repeat steps as in Alpha)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Reference  ====&lt;br /&gt;
&lt;br /&gt;
== Related Efforts  ==&lt;br /&gt;
&lt;br /&gt;
#Cloud Security Alliance - http://www.cloudsecurityalliance.org/ &lt;br /&gt;
#IDC Aug 2008 Survey (Security #1) Challenge for Cloud/On-Demand Models - http://blogs.idc.com/ie/?p=210&lt;br /&gt;
&lt;br /&gt;
== Related OWASP Projects  ==&lt;br /&gt;
&lt;br /&gt;
#OWASP Top Ten Project &lt;br /&gt;
#OWASP Legal Project&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Contributors  ====&lt;br /&gt;
&lt;br /&gt;
== Project Leaders  ==&lt;br /&gt;
&lt;br /&gt;
[[:User:vinaykbansal|'''Vinay Bansal''']]&amp;lt;br&amp;gt;[[User:Shankar Babu Chebrolu|Shankar Babu Chebrolu]]&amp;lt;br&amp;gt; [[User:Martin G. Nystrom|Martin G. Nystrom]]&amp;lt;br&amp;gt; [[User:Jim Born|Jim Born]] &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/User:Ken_Huang Ken Huang] &lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
#[https://lists.owasp.org/mailman/listinfo/owasp-cloud-10 Subscribe or read the Cloud-10 mail archives]&lt;br /&gt;
&lt;br /&gt;
==== Project Details  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC Project Details/OWASP Cloud ‐ 10 Project | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:Cloud_-_Top_5_Risks_with_PAAS|&amp;lt;br&amp;gt;]]&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cloud_-_Top_5_Risks_with_PAAS&amp;diff=71962</id>
		<title>Cloud - Top 5 Risks with PAAS</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cloud_-_Top_5_Risks_with_PAAS&amp;diff=71962"/>
				<updated>2009-10-21T20:32:01Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;According to wikipedia, Platform as a service' (PaaS) is the delivery of a computing platform and solution stack as a service. It facilitates deployment of applications without the cost and complexity of buying and managing the underlying hardware and software layers providing all of the facilities required to support the complete life cycle of building and delivering web applications and services entirely available from the Internet—with no software downloads or installation for developers, IT managers or end-users. PaaS offerings include workflow facilities for application design, application development, testing, deployment and hosting as well as application services such as team collaboration, web service integration and marshalling, database integration, security, scalability, storage, persistence, state management, application versioning, application instrumentation and developer community facilitation. These services are provisioned as an integrated solution over the web.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The top 5 security concerns are:&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
1: Business Continuity Planning and Disastor Recovery with PAAS vendor. Example: Windows Azure platform, Microsoft's cloud computing platform, suffered an outage one weekend in March, 2009. Had your enterprise been using the service, how would the outage have affected the organization's ability to conduct business? Alternatively, it would have been Microsoft's responsibility to fix it, not your IT team's (but be careful; your executive team may not see the distinction).&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
2: Lack of Secure Software Development Process with PAAS vendor. One PAAS offering is the SDLC. The Secure SDLC (SSDLC) is still new and not widely used. The lack of SSDLC could mean insecure code. &lt;br /&gt;
&lt;br /&gt;
3: Vendor Lock In: Platform as a Service (PaaS) vendors tend to dictate the database, storage and application framework used, so what about those legacy applications? Enterprises will still require the skills and infrastructure to be able to run them. &lt;br /&gt;
&lt;br /&gt;
4: Lack of adequate provisions in SLA. the Cloud Computing Bill of Rights provides a useful checklist of protection with which to benchmark a supplier's offering. The upcoming National Institute of Standards and Technology (NIST) Cloud Computing Security publication will do a lot to standardize federal-compliant cloud infrastructures and need to be followed. &lt;br /&gt;
&lt;br /&gt;
5: How to meet compliance demands and control risks when work with a PAAS Vendor&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Reference&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://searchsecurity.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid14_gci1361723,00.html&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://en.wikipedia.org/wiki/Platform_as_a_service&amp;lt;br&amp;gt;http://www.cloudsecurityalliance.org/ &lt;br /&gt;
&lt;br /&gt;
http://social.msdn.microsoft.com/Forums/en-US/windowsazure/thread/6c1cd8a2-8d9d-43e9-a1d8-928e0ca4de78&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Cloud ‐ 10 Project]]&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:Cloud_-_Top_5_Risks_with_PAAS&amp;diff=71961</id>
		<title>Category:Cloud - Top 5 Risks with PAAS</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:Cloud_-_Top_5_Risks_with_PAAS&amp;diff=71961"/>
				<updated>2009-10-21T20:28:34Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: Created page with 'Category:OWASP Cloud ‐ 10 Project'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:OWASP Cloud ‐ 10 Project]]&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71960</id>
		<title>Category:OWASP Cloud ‐ 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71960"/>
				<updated>2009-10-21T20:27:28Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
== Goal  ==&lt;br /&gt;
&lt;br /&gt;
Goal of the project is to maintain a list of top 10 security risks faced with the Cloud Computing and SaaS Models. List will be maintained by input from community, security experts and security incidences at cloud/SaaS providers. &lt;br /&gt;
&lt;br /&gt;
== Audience  ==&lt;br /&gt;
&lt;br /&gt;
Audience for the project will be organizations planning on leveraging external cloud environment to host their applications or rent application in a SaaS model (Software as a Service). Aim of the &amp;quot;OWASP Cloud-10&amp;quot; list is to help balance security risks with the cost advantage that the Cloud and SaaS model provides. We expect the Cloud and SaaS providers to be indirect audience for &amp;quot;OWASP Cloud-10&amp;quot;, when they try to showcase their security controls to potential customers against this list. &lt;br /&gt;
&lt;br /&gt;
== Managing OWASP Cloud-10 List (Pre-Alpha)  ==&lt;br /&gt;
&lt;br /&gt;
“OWASP Cloud-10” list will be maintained by input from, community, security experts and security incidences at cloud/SaaS providers. &lt;br /&gt;
&lt;br /&gt;
Each of the identified risk in &amp;quot;OWASP Cloud-10&amp;quot; will provide details on: &lt;br /&gt;
&lt;br /&gt;
*Various Risk Scenarios &lt;br /&gt;
*Real World Examples &lt;br /&gt;
*Possible Mitigations and Security Controls &lt;br /&gt;
*Reference to any related Incident&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== OWASP Cloud-10 List  ====&lt;br /&gt;
&lt;br /&gt;
== Initial pre-alpha list of OWASP Cloud-10 Security Risks  ==&lt;br /&gt;
&lt;br /&gt;
{| cellpadding=&amp;quot;2&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| C1 - Privacy of Users &lt;br /&gt;
| [Placeholder] - User's private and PII data gets stored in the cloud&lt;br /&gt;
|-&lt;br /&gt;
| C2 - Enterprise Data Hosted Outside in Cloud &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C3 - Accountability and Ownership of Data Security &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C4 - Federating User Identity &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C5 - Secondary Usage of Data &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C6 - Demonstrating Regulatory Compliance &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C7 - SLA - Building Right Level of insurance and accountability &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C8 - Vendor Lock-In &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C9 - Data Backup and Disaster Recovery &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C10 - Direct Exposure to Development and Production Environments &lt;br /&gt;
| &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
'''&amp;lt;center&amp;gt;Table 1: Top 10 Cloud - Security Risks&amp;lt;/center&amp;gt;'''&lt;br /&gt;
&lt;br /&gt;
== Other OWASP Cloud-10 Candidates  ==&lt;br /&gt;
&lt;br /&gt;
*Service Availability Risk &lt;br /&gt;
*Multi-Tenancy &lt;br /&gt;
*Integration between cloud and internally hosted services &lt;br /&gt;
*Patching and Vulnerability Management &lt;br /&gt;
*Lack of Transparency in Internal Security Controls and difficulty/complexity of auditing &lt;br /&gt;
*Enterprise Intranets exposed directly on Internet (if they move on a Public Cloud)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; This needs to be debated and for each of these we may need to add a separate page-holder with the following details. &lt;br /&gt;
&lt;br /&gt;
*Various Risk Scenarios &lt;br /&gt;
*Real World Examples &lt;br /&gt;
*Possible Mitigation and Security Controls &lt;br /&gt;
*Reference to any related Incident&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Roadmap (Status)  ====&lt;br /&gt;
&lt;br /&gt;
== Alpha State  ==&lt;br /&gt;
&lt;br /&gt;
#'''Identify and publish a first draft of potential &amp;quot;OWASP Cloud-10&amp;quot; candidates (July 2009)''' &lt;br /&gt;
#Ask contributors to collect more data and details on each of the risk item. (till Aug 2009) &lt;br /&gt;
#Get initial community feedback by discussing it in various blogs, discussion forums etc. (till Aug-Sept 2009)&lt;br /&gt;
&lt;br /&gt;
== Beta State  ==&lt;br /&gt;
&lt;br /&gt;
#Publish the first (beta) list of &amp;quot;OWASP Cloud-10&amp;quot; (Oct 2009) &lt;br /&gt;
#Identify additional candidates &lt;br /&gt;
#……. (repeat steps as in Alpha)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Reference  ====&lt;br /&gt;
&lt;br /&gt;
== Related Efforts  ==&lt;br /&gt;
&lt;br /&gt;
#Cloud Security Alliance - http://www.cloudsecurityalliance.org/ &lt;br /&gt;
#IDC Aug 2008 Survey (Security #1) Challenge for Cloud/On-Demand Models - http://blogs.idc.com/ie/?p=210&lt;br /&gt;
&lt;br /&gt;
== Related OWASP Projects  ==&lt;br /&gt;
&lt;br /&gt;
#OWASP Top Ten Project &lt;br /&gt;
#OWASP Legal Project&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Contributors  ====&lt;br /&gt;
&lt;br /&gt;
== Project Leaders  ==&lt;br /&gt;
&lt;br /&gt;
[[:User:vinaykbansal|'''Vinay Bansal''']]&amp;lt;br&amp;gt;[[User:Shankar Babu Chebrolu|Shankar Babu Chebrolu]]&amp;lt;br&amp;gt; [[User:Martin G. Nystrom|Martin G. Nystrom]]&amp;lt;br&amp;gt; [[User:Jim Born|Jim Born]] &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/User:Ken_Huang Ken Huang] &lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
#[https://lists.owasp.org/mailman/listinfo/owasp-cloud-10 Subscribe or read the Cloud-10 mail archives]&lt;br /&gt;
&lt;br /&gt;
==== Project Details  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC Project Details/OWASP Cloud ‐ 10 Project | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:Cloud_-_Top_5_Risks_with_PAAS]]&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71958</id>
		<title>Category:OWASP Cloud ‐ 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71958"/>
				<updated>2009-10-21T20:26:38Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
== Goal  ==&lt;br /&gt;
&lt;br /&gt;
Goal of the project is to maintain a list of top 10 security risks faced with the Cloud Computing and SaaS Models. List will be maintained by input from community, security experts and security incidences at cloud/SaaS providers. &lt;br /&gt;
&lt;br /&gt;
== Audience  ==&lt;br /&gt;
&lt;br /&gt;
Audience for the project will be organizations planning on leveraging external cloud environment to host their applications or rent application in a SaaS model (Software as a Service). Aim of the &amp;quot;OWASP Cloud-10&amp;quot; list is to help balance security risks with the cost advantage that the Cloud and SaaS model provides. We expect the Cloud and SaaS providers to be indirect audience for &amp;quot;OWASP Cloud-10&amp;quot;, when they try to showcase their security controls to potential customers against this list. &lt;br /&gt;
&lt;br /&gt;
== Managing OWASP Cloud-10 List (Pre-Alpha)  ==&lt;br /&gt;
&lt;br /&gt;
“OWASP Cloud-10” list will be maintained by input from, community, security experts and security incidences at cloud/SaaS providers. &lt;br /&gt;
&lt;br /&gt;
Each of the identified risk in &amp;quot;OWASP Cloud-10&amp;quot; will provide details on: &lt;br /&gt;
&lt;br /&gt;
*Various Risk Scenarios &lt;br /&gt;
*Real World Examples &lt;br /&gt;
*Possible Mitigations and Security Controls &lt;br /&gt;
*Reference to any related Incident&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== OWASP Cloud-10 List  ====&lt;br /&gt;
&lt;br /&gt;
== Initial pre-alpha list of OWASP Cloud-10 Security Risks  ==&lt;br /&gt;
&lt;br /&gt;
{| cellpadding=&amp;quot;2&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| C1 - Privacy of Users &lt;br /&gt;
| [Placeholder] - User's private and PII data gets stored in the cloud&lt;br /&gt;
|-&lt;br /&gt;
| C2 - Enterprise Data Hosted Outside in Cloud &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C3 - Accountability and Ownership of Data Security &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C4 - Federating User Identity &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C5 - Secondary Usage of Data &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C6 - Demonstrating Regulatory Compliance &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C7 - SLA - Building Right Level of insurance and accountability &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C8 - Vendor Lock-In &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C9 - Data Backup and Disaster Recovery &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C10 - Direct Exposure to Development and Production Environments &lt;br /&gt;
| &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
'''&amp;lt;center&amp;gt;Table 1: Top 10 Cloud - Security Risks&amp;lt;/center&amp;gt;'''&lt;br /&gt;
&lt;br /&gt;
== Other OWASP Cloud-10 Candidates  ==&lt;br /&gt;
&lt;br /&gt;
*Service Availability Risk &lt;br /&gt;
*Multi-Tenancy &lt;br /&gt;
*Integration between cloud and internally hosted services &lt;br /&gt;
*Patching and Vulnerability Management &lt;br /&gt;
*Lack of Transparency in Internal Security Controls and difficulty/complexity of auditing &lt;br /&gt;
*Enterprise Intranets exposed directly on Internet (if they move on a Public Cloud)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; This needs to be debated and for each of these we may need to add a separate page-holder with the following details. &lt;br /&gt;
&lt;br /&gt;
*Various Risk Scenarios &lt;br /&gt;
*Real World Examples &lt;br /&gt;
*Possible Mitigation and Security Controls &lt;br /&gt;
*Reference to any related Incident&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Roadmap (Status)  ====&lt;br /&gt;
&lt;br /&gt;
== Alpha State  ==&lt;br /&gt;
&lt;br /&gt;
#'''Identify and publish a first draft of potential &amp;quot;OWASP Cloud-10&amp;quot; candidates (July 2009)''' &lt;br /&gt;
#Ask contributors to collect more data and details on each of the risk item. (till Aug 2009) &lt;br /&gt;
#Get initial community feedback by discussing it in various blogs, discussion forums etc. (till Aug-Sept 2009)&lt;br /&gt;
&lt;br /&gt;
== Beta State  ==&lt;br /&gt;
&lt;br /&gt;
#Publish the first (beta) list of &amp;quot;OWASP Cloud-10&amp;quot; (Oct 2009) &lt;br /&gt;
#Identify additional candidates &lt;br /&gt;
#……. (repeat steps as in Alpha)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Reference  ====&lt;br /&gt;
&lt;br /&gt;
== Related Efforts  ==&lt;br /&gt;
&lt;br /&gt;
#Cloud Security Alliance - http://www.cloudsecurityalliance.org/ &lt;br /&gt;
#IDC Aug 2008 Survey (Security #1) Challenge for Cloud/On-Demand Models - http://blogs.idc.com/ie/?p=210&lt;br /&gt;
&lt;br /&gt;
== Related OWASP Projects  ==&lt;br /&gt;
&lt;br /&gt;
#OWASP Top Ten Project &lt;br /&gt;
#OWASP Legal Project&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Contributors  ====&lt;br /&gt;
&lt;br /&gt;
== Project Leaders  ==&lt;br /&gt;
&lt;br /&gt;
[[:User:vinaykbansal|'''Vinay Bansal''']]&amp;lt;br&amp;gt;[[User:Shankar Babu Chebrolu|Shankar Babu Chebrolu]]&amp;lt;br&amp;gt; [[User:Martin G. Nystrom|Martin G. Nystrom]]&amp;lt;br&amp;gt; [[User:Jim Born|Jim Born]] &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/User:Ken_Huang Ken Huang] &lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
#[https://lists.owasp.org/mailman/listinfo/owasp-cloud-10 Subscribe or read the Cloud-10 mail archives]&lt;br /&gt;
&lt;br /&gt;
==== Project Details  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC Project Details/OWASP Cloud ‐ 10 Project | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:Cloud - Top 5 Risks with PAAS]]&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71957</id>
		<title>Category:OWASP Cloud ‐ 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71957"/>
				<updated>2009-10-21T20:22:45Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
== Goal  ==&lt;br /&gt;
&lt;br /&gt;
Goal of the project is to maintain a list of top 10 security risks faced with the Cloud Computing and SaaS Models. List will be maintained by input from community, security experts and security incidences at cloud/SaaS providers. &lt;br /&gt;
&lt;br /&gt;
== Audience  ==&lt;br /&gt;
&lt;br /&gt;
Audience for the project will be organizations planning on leveraging external cloud environment to host their applications or rent application in a SaaS model (Software as a Service). Aim of the &amp;quot;OWASP Cloud-10&amp;quot; list is to help balance security risks with the cost advantage that the Cloud and SaaS model provides. We expect the Cloud and SaaS providers to be indirect audience for &amp;quot;OWASP Cloud-10&amp;quot;, when they try to showcase their security controls to potential customers against this list. &lt;br /&gt;
&lt;br /&gt;
== Managing OWASP Cloud-10 List (Pre-Alpha)  ==&lt;br /&gt;
&lt;br /&gt;
“OWASP Cloud-10” list will be maintained by input from, community, security experts and security incidences at cloud/SaaS providers. &lt;br /&gt;
&lt;br /&gt;
Each of the identified risk in &amp;quot;OWASP Cloud-10&amp;quot; will provide details on: &lt;br /&gt;
&lt;br /&gt;
*Various Risk Scenarios &lt;br /&gt;
*Real World Examples &lt;br /&gt;
*Possible Mitigations and Security Controls &lt;br /&gt;
*Reference to any related Incident&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== OWASP Cloud-10 List  ====&lt;br /&gt;
&lt;br /&gt;
== Initial pre-alpha list of OWASP Cloud-10 Security Risks  ==&lt;br /&gt;
&lt;br /&gt;
{| cellpadding=&amp;quot;2&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| C1 - Privacy of Users &lt;br /&gt;
| [Placeholder] - User's private and PII data gets stored in the cloud&lt;br /&gt;
|-&lt;br /&gt;
| C2 - Enterprise Data Hosted Outside in Cloud &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C3 - Accountability and Ownership of Data Security &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C4 - Federating User Identity &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C5 - Secondary Usage of Data &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C6 - Demonstrating Regulatory Compliance &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C7 - SLA - Building Right Level of insurance and accountability &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C8 - Vendor Lock-In &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C9 - Data Backup and Disaster Recovery &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C10 - Direct Exposure to Development and Production Environments &lt;br /&gt;
| &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
'''&amp;lt;center&amp;gt;Table 1: Top 10 Cloud - Security Risks&amp;lt;/center&amp;gt;'''&lt;br /&gt;
&lt;br /&gt;
== Other OWASP Cloud-10 Candidates  ==&lt;br /&gt;
&lt;br /&gt;
*Service Availability Risk &lt;br /&gt;
*Multi-Tenancy &lt;br /&gt;
*Integration between cloud and internally hosted services &lt;br /&gt;
*Patching and Vulnerability Management &lt;br /&gt;
*Lack of Transparency in Internal Security Controls and difficulty/complexity of auditing &lt;br /&gt;
*Enterprise Intranets exposed directly on Internet (if they move on a Public Cloud)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; This needs to be debated and for each of these we may need to add a separate page-holder with the following details. &lt;br /&gt;
&lt;br /&gt;
*Various Risk Scenarios &lt;br /&gt;
*Real World Examples &lt;br /&gt;
*Possible Mitigation and Security Controls &lt;br /&gt;
*Reference to any related Incident&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Roadmap (Status)  ====&lt;br /&gt;
&lt;br /&gt;
== Alpha State  ==&lt;br /&gt;
&lt;br /&gt;
#'''Identify and publish a first draft of potential &amp;quot;OWASP Cloud-10&amp;quot; candidates (July 2009)''' &lt;br /&gt;
#Ask contributors to collect more data and details on each of the risk item. (till Aug 2009) &lt;br /&gt;
#Get initial community feedback by discussing it in various blogs, discussion forums etc. (till Aug-Sept 2009)&lt;br /&gt;
&lt;br /&gt;
== Beta State  ==&lt;br /&gt;
&lt;br /&gt;
#Publish the first (beta) list of &amp;quot;OWASP Cloud-10&amp;quot; (Oct 2009) &lt;br /&gt;
#Identify additional candidates &lt;br /&gt;
#……. (repeat steps as in Alpha)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Reference  ====&lt;br /&gt;
&lt;br /&gt;
== Related Efforts  ==&lt;br /&gt;
&lt;br /&gt;
#Cloud Security Alliance - http://www.cloudsecurityalliance.org/ &lt;br /&gt;
#IDC Aug 2008 Survey (Security #1) Challenge for Cloud/On-Demand Models - http://blogs.idc.com/ie/?p=210&lt;br /&gt;
&lt;br /&gt;
== Related OWASP Projects  ==&lt;br /&gt;
&lt;br /&gt;
#OWASP Top Ten Project &lt;br /&gt;
#OWASP Legal Project&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Contributors  ====&lt;br /&gt;
&lt;br /&gt;
== Project Leaders  ==&lt;br /&gt;
&lt;br /&gt;
[[:User:vinaykbansal|'''Vinay Bansal''']]&amp;lt;br&amp;gt;[[User:Shankar Babu Chebrolu|Shankar Babu Chebrolu]]&amp;lt;br&amp;gt; [[User:Martin G. Nystrom|Martin G. Nystrom]]&amp;lt;br&amp;gt; [[User:Jim Born|Jim Born]] &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/User:Ken_Huang Ken Huang] &lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
#[https://lists.owasp.org/mailman/listinfo/owasp-cloud-10 Subscribe or read the Cloud-10 mail archives]&lt;br /&gt;
&lt;br /&gt;
==== Project Details  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC Project Details/OWASP Cloud ‐ 10 Project | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cloud_-_Top_5_Risks_with_PAAS&amp;diff=71956</id>
		<title>Cloud - Top 5 Risks with PAAS</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cloud_-_Top_5_Risks_with_PAAS&amp;diff=71956"/>
				<updated>2009-10-21T20:17:32Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;According to wikipedia, Platform as a service' (PaaS) is the delivery of a computing platform and solution stack as a service. It facilitates deployment of applications without the cost and complexity of buying and managing the underlying hardware and software layers providing all of the facilities required to support the complete life cycle of building and delivering web applications and services entirely available from the Internet—with no software downloads or installation for developers, IT managers or end-users. PaaS offerings include workflow facilities for application design, application development, testing, deployment and hosting as well as application services such as team collaboration, web service integration and marshalling, database integration, security, scalability, storage, persistence, state management, application versioning, application instrumentation and developer community facilitation. These services are provisioned as an integrated solution over the web.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The top 5 security concerns are:&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
1: Business Continuity Planning and Disastor Recovery with PAAS vendor. Example: Windows Azure platform, Microsoft's cloud computing platform, suffered an outage one weekend in March, 2009. Had your enterprise been using the service, how would the outage have affected the organization's ability to conduct business? Alternatively, it would have been Microsoft's responsibility to fix it, not your IT team's (but be careful; your executive team may not see the distinction).&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
2: Lack of Secure Software Development Process with PAAS vendor. One PAAS offering is the SDLC. The Secure SDLC (SSDLC) is still new and not widely used. The lack of SSDLC could mean insecure code. &lt;br /&gt;
&lt;br /&gt;
3: Vendor Lock In: Platform as a Service (PaaS) vendors tend to dictate the database, storage and application framework used, so what about those legacy applications? Enterprises will still require the skills and infrastructure to be able to run them. &lt;br /&gt;
&lt;br /&gt;
4: Lack of adequate provisions in SLA. the Cloud Computing Bill of Rights provides a useful checklist of protection with which to benchmark a supplier's offering. The upcoming National Institute of Standards and Technology (NIST) Cloud Computing Security publication will do a lot to standardize federal-compliant cloud infrastructures and need to be followed. &lt;br /&gt;
&lt;br /&gt;
5: How to meet compliance demands and control risks when work with a PAAS Vendor&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Reference&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://searchsecurity.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid14_gci1361723,00.html&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://en.wikipedia.org/wiki/Platform_as_a_service&amp;lt;br&amp;gt;http://www.cloudsecurityalliance.org/ &lt;br /&gt;
&lt;br /&gt;
http://social.msdn.microsoft.com/Forums/en-US/windowsazure/thread/6c1cd8a2-8d9d-43e9-a1d8-928e0ca4de78&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cloud_-_Top_5_Risks_with_PAAS&amp;diff=71955</id>
		<title>Cloud - Top 5 Risks with PAAS</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cloud_-_Top_5_Risks_with_PAAS&amp;diff=71955"/>
				<updated>2009-10-21T20:01:29Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;According to wikipedia, Platform as a service' (PaaS) is the delivery of a computing platform and solution stack as a service. It facilitates deployment of applications without the cost and complexity of buying and managing the underlying hardware and software layers providing all of the facilities required to support the complete life cycle of building and delivering web applications and services entirely available from the Internet—with no software downloads or installation for developers, IT managers or end-users. PaaS offerings include workflow facilities for application design, application development, testing, deployment and hosting as well as application services such as team collaboration, web service integration and marshalling, database integration, security, scalability, storage, persistence, state management, application versioning, application instrumentation and developer community facilitation. These services are provisioned as an integrated solution over the web.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The top 5 security concerns are:&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
1: Business Continuity Planning and Disastor Recovery with PAAS vendor. Example: Windows Azure platform, Microsoft's cloud computing platform, suffered an outage one weekend in March, 2009. Had your enterprise been using the service, how would the outage have affected the organization's ability to conduct business? Alternatively, it would have been Microsoft's responsibility to fix it, not your IT team's (but be careful; your executive team may not see the distinction).&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
2: Lack of Secure Software Development Process with PAAS vendor. One PAAS offering is the SDLC. The Secure SDLC (SSDLC) is still new and not widely used. The lack of SSDLC could mean insecure code. &lt;br /&gt;
&lt;br /&gt;
3: Vendor Lock In: Platform as a Service (PaaS) vendors tend to dictate the database, storage and application framework used, so what about those legacy applications? Enterprises will still require the skills and infrastructure to be able to run them. &lt;br /&gt;
&lt;br /&gt;
4: Lack of adequate provisions in SLA. the Cloud Computing Bill of Rights provides a useful checklist of protection with which to benchmark a supplier's offering. The upcoming National Institute of Standards and Technology (NIST) Cloud Computing Security publication will do a lot to standardize federal-compliant cloud infrastructures and need to be followed. &lt;br /&gt;
&lt;br /&gt;
5: How to meet compliance demands and control risks when work with a PAAS Vendor&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Reference&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://searchsecurity.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid14_gci1361723,00.html&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://en.wikipedia.org/wiki/Platform_as_a_service&amp;lt;br&amp;gt;http://www.cloudsecurityalliance.org/&lt;br /&gt;
&lt;br /&gt;
http://social.msdn.microsoft.com/Forums/en-US/windowsazure/thread/6c1cd8a2-8d9d-43e9-a1d8-928e0ca4de78&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cloud_-_Top_5_Risks_with_PAAS&amp;diff=71953</id>
		<title>Cloud - Top 5 Risks with PAAS</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cloud_-_Top_5_Risks_with_PAAS&amp;diff=71953"/>
				<updated>2009-10-21T20:00:43Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: moved Cloud-10 Risks with PAAS to Cloud - Top 5 Risks with PAAS&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;According to wikipedia, Platform as a service' (PaaS) is the delivery of a computing platform and solution stack as a service. It facilitates deployment of applications without the cost and complexity of buying and managing the underlying hardware and software layers providing all of the facilities required to support the complete life cycle of building and delivering web applications and services entirely available from the Internet—with no software downloads or installation for developers, IT managers or end-users. PaaS offerings include workflow facilities for application design, application development, testing, deployment and hosting as well as application services such as team collaboration, web service integration and marshalling, database integration, security, scalability, storage, persistence, state management, application versioning, application instrumentation and developer community facilitation. These services are provisioned as an integrated solution over the web.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The top 5 security concerns are:&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1: Business Continuity Planning and Disastor Recovery with PAAS vendor. Example: Windows Azure platform, Microsoft's cloud computing platform, suffered an outage one weekend in March, 2009. Had your enterprise been using the service, how would the outage have affected the organization's ability to conduct business? Alternatively, it would have been Microsoft's responsibility to fix it, not your IT team's (but be careful; your executive team may not see the distinction).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2: Lack of Secure Software Development Process with PAAS vendor. One PAAS offering is the SDLC. The Secure SDLC (SSDLC) is still new and not widely used. The lack of SSDLC could mean insecure code.&lt;br /&gt;
&lt;br /&gt;
3: Vendor Lock In: Platform as a Service (PaaS) vendors tend to dictate the database, storage and application framework used, so what about those legacy applications? Enterprises will still require the skills and infrastructure to be able to run them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4: Lack of adequate provisions in SLA. the Cloud Computing Bill of Rights provides a useful checklist of protection with which to benchmark a supplier's offering. The upcoming National Institute of Standards and Technology (NIST) Cloud Computing Security publication will do a lot to standardize federal-compliant cloud infrastructures and need to be followed.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
5: How to meet compliance demands and control risks when work with a PAAS Vendor&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Reference&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
http://searchsecurity.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid14_gci1361723,00.html&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
http://en.wikipedia.org/wiki/Platform_as_a_service&amp;lt;br&amp;gt;http://www.cloudsecurityalliance.org/&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
http://social.msdn.microsoft.com/Forums/en-US/windowsazure/thread/6c1cd8a2-8d9d-43e9-a1d8-928e0ca4de78&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cloud-10_Risks_with_PAAS&amp;diff=71954</id>
		<title>Cloud-10 Risks with PAAS</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cloud-10_Risks_with_PAAS&amp;diff=71954"/>
				<updated>2009-10-21T20:00:43Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: moved Cloud-10 Risks with PAAS to Cloud - Top 5 Risks with PAAS&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[Cloud - Top 5 Risks with PAAS]]&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cloud_-_Top_5_Risks_with_PAAS&amp;diff=71952</id>
		<title>Cloud - Top 5 Risks with PAAS</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cloud_-_Top_5_Risks_with_PAAS&amp;diff=71952"/>
				<updated>2009-10-21T19:59:21Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: Created page with 'According to wikipedia, Platform as a service' (PaaS) is the delivery of a computing platform and solution stack as a service. It facilitates deployment of applications without t…'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;According to wikipedia, Platform as a service' (PaaS) is the delivery of a computing platform and solution stack as a service. It facilitates deployment of applications without the cost and complexity of buying and managing the underlying hardware and software layers providing all of the facilities required to support the complete life cycle of building and delivering web applications and services entirely available from the Internet—with no software downloads or installation for developers, IT managers or end-users. PaaS offerings include workflow facilities for application design, application development, testing, deployment and hosting as well as application services such as team collaboration, web service integration and marshalling, database integration, security, scalability, storage, persistence, state management, application versioning, application instrumentation and developer community facilitation. These services are provisioned as an integrated solution over the web.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The top 5 security concerns are:&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1: Business Continuity Planning and Disastor Recovery with PAAS vendor. Example: Windows Azure platform, Microsoft's cloud computing platform, suffered an outage one weekend in March, 2009. Had your enterprise been using the service, how would the outage have affected the organization's ability to conduct business? Alternatively, it would have been Microsoft's responsibility to fix it, not your IT team's (but be careful; your executive team may not see the distinction).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2: Lack of Secure Software Development Process with PAAS vendor. One PAAS offering is the SDLC. The Secure SDLC (SSDLC) is still new and not widely used. The lack of SSDLC could mean insecure code.&lt;br /&gt;
&lt;br /&gt;
3: Vendor Lock In: Platform as a Service (PaaS) vendors tend to dictate the database, storage and application framework used, so what about those legacy applications? Enterprises will still require the skills and infrastructure to be able to run them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4: Lack of adequate provisions in SLA. the Cloud Computing Bill of Rights provides a useful checklist of protection with which to benchmark a supplier's offering. The upcoming National Institute of Standards and Technology (NIST) Cloud Computing Security publication will do a lot to standardize federal-compliant cloud infrastructures and need to be followed.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
5: How to meet compliance demands and control risks when work with a PAAS Vendor&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Reference&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
http://searchsecurity.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid14_gci1361723,00.html&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
http://en.wikipedia.org/wiki/Platform_as_a_service&amp;lt;br&amp;gt;http://www.cloudsecurityalliance.org/&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
http://social.msdn.microsoft.com/Forums/en-US/windowsazure/thread/6c1cd8a2-8d9d-43e9-a1d8-928e0ca4de78&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71948</id>
		<title>Category:OWASP Cloud ‐ 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71948"/>
				<updated>2009-10-21T18:38:10Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
== Goal ==&lt;br /&gt;
&lt;br /&gt;
Goal of the project is to maintain a list of top 10 security risks faced with the Cloud Computing and SaaS Models. List will be maintained by input from community, security experts and security incidences at cloud/SaaS providers. &lt;br /&gt;
&lt;br /&gt;
== Audience ==&lt;br /&gt;
&lt;br /&gt;
Audience for the project will be organizations planning on leveraging external cloud environment to host their applications or rent application in a SaaS model (Software as a Service). Aim of the &amp;quot;OWASP Cloud-10&amp;quot; list is to help balance security risks with the cost advantage that the Cloud and SaaS model provides. We expect the Cloud and SaaS providers to be indirect audience for &amp;quot;OWASP Cloud-10&amp;quot;, when they try to showcase their security controls to potential customers against this list. &lt;br /&gt;
&lt;br /&gt;
== Managing OWASP Cloud-10 List (Pre-Alpha) ==&lt;br /&gt;
&lt;br /&gt;
“OWASP Cloud-10” list will be maintained by input from, community, security experts and security incidences at cloud/SaaS providers. &lt;br /&gt;
&lt;br /&gt;
Each of the identified risk in &amp;quot;OWASP Cloud-10&amp;quot; will provide details on: &lt;br /&gt;
&lt;br /&gt;
*Various Risk Scenarios &lt;br /&gt;
*Real World Examples &lt;br /&gt;
*Possible Mitigations and Security Controls &lt;br /&gt;
*Reference to any related Incident&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== OWASP Cloud-10 List  ====&lt;br /&gt;
&lt;br /&gt;
== Initial pre-alpha list of OWASP Cloud-10 Security Risks ==&lt;br /&gt;
&lt;br /&gt;
{| cellpadding=&amp;quot;2&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| C1 - Privacy of Users &lt;br /&gt;
| [Placeholder] - User's private and PII data gets stored in the cloud&lt;br /&gt;
|-&lt;br /&gt;
| C2 - Enterprise Data Hosted Outside in Cloud &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C3 - Accountability and Ownership of Data Security &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C4 - Federating User Identity &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C5 - Secondary Usage of Data &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C6 - Demonstrating Regulatory Compliance &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C7 - SLA - Building Right Level of insurance and accountability &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C8 - Vendor Lock-In &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C9 - Data Backup and Disaster Recovery &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| C10 - Direct Exposure to Development and Production Environments &lt;br /&gt;
| &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
'''&amp;lt;center&amp;gt;Table 1: Top 10 Cloud - Security Risks&amp;lt;/center&amp;gt;'''&lt;br /&gt;
&lt;br /&gt;
== Other OWASP Cloud-10 Candidates ==&lt;br /&gt;
&lt;br /&gt;
*Service Availability Risk &lt;br /&gt;
*Multi-Tenancy &lt;br /&gt;
*Integration between cloud and internally hosted services &lt;br /&gt;
*Patching and Vulnerability Management &lt;br /&gt;
*Lack of Transparency in Internal Security Controls and difficulty/complexity of auditing &lt;br /&gt;
*Enterprise Intranets exposed directly on Internet (if they move on a Public Cloud)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; This needs to be debated and for each of these we may need to add a separate page-holder with the following details. &lt;br /&gt;
&lt;br /&gt;
*Various Risk Scenarios &lt;br /&gt;
*Real World Examples &lt;br /&gt;
*Possible Mitigation and Security Controls &lt;br /&gt;
*Reference to any related Incident&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Roadmap (Status)  ====&lt;br /&gt;
&lt;br /&gt;
== Alpha State ==&lt;br /&gt;
&lt;br /&gt;
#'''Identify and publish a first draft of potential &amp;quot;OWASP Cloud-10&amp;quot; candidates (July 2009)''' &lt;br /&gt;
#Ask contributors to collect more data and details on each of the risk item. (till Aug 2009) &lt;br /&gt;
#Get initial community feedback by discussing it in various blogs, discussion forums etc. (till Aug-Sept 2009)&lt;br /&gt;
&lt;br /&gt;
== Beta State ==&lt;br /&gt;
&lt;br /&gt;
#Publish the first (beta) list of &amp;quot;OWASP Cloud-10&amp;quot; (Oct 2009) &lt;br /&gt;
#Identify additional candidates &lt;br /&gt;
#……. (repeat steps as in Alpha)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Reference  ====&lt;br /&gt;
&lt;br /&gt;
== Related Efforts ==&lt;br /&gt;
&lt;br /&gt;
#Cloud Security Alliance - http://www.cloudsecurityalliance.org/ &lt;br /&gt;
#IDC Aug 2008 Survey (Security #1) Challenge for Cloud/On-Demand Models - http://blogs.idc.com/ie/?p=210&lt;br /&gt;
&lt;br /&gt;
== Related OWASP Projects ==&lt;br /&gt;
&lt;br /&gt;
#OWASP Top Ten Project &lt;br /&gt;
#OWASP Legal Project&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Contributors  ====&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[[:User:vinaykbansal|'''Vinay Bansal''']]&amp;lt;br&amp;gt;[[User:Shankar Babu Chebrolu|Shankar Babu Chebrolu]]&amp;lt;br&amp;gt; [[User:Martin G. Nystrom|Martin G. Nystrom]]&amp;lt;br&amp;gt; [[User:Jim Born|Jim Born]]&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/User:Ken_Huang Ken Huang]&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
#[https://lists.owasp.org/mailman/listinfo/owasp-cloud-10 Subscribe or read the Cloud-10 mail archives]&lt;br /&gt;
&lt;br /&gt;
==== Project Details  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC Project Details/OWASP Cloud ‐ 10 Project | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71946</id>
		<title>Category:OWASP Cloud ‐ 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71946"/>
				<updated>2009-10-21T18:28:26Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: /* Contributors */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main ====&lt;br /&gt;
&lt;br /&gt;
==Goal==&lt;br /&gt;
Goal of the project is to maintain a list of top 10 security risks faced with the Cloud Computing and SaaS Models. List will be maintained by input from community, security experts and security incidences at cloud/SaaS providers.&lt;br /&gt;
&lt;br /&gt;
==Audience==&lt;br /&gt;
Audience for the project will be organizations planning on leveraging external cloud environment to host their applications or rent application in a SaaS model (Software as a Service). Aim of the &amp;quot;OWASP Cloud-10&amp;quot; list is to help balance security risks with the cost advantage that the Cloud and SaaS model provides.  We expect the Cloud and SaaS providers to be indirect audience for &amp;quot;OWASP Cloud-10&amp;quot;, when they try to showcase their security controls to potential customers against this list.&lt;br /&gt;
&lt;br /&gt;
==Managing OWASP Cloud-10 List (Pre-Alpha)==&lt;br /&gt;
“OWASP Cloud-10” list will be maintained by input from, community,  security experts and security incidences at cloud/SaaS providers. &lt;br /&gt;
 &lt;br /&gt;
Each of the identified risk in &amp;quot;OWASP Cloud-10&amp;quot; will provide details on:&lt;br /&gt;
* Various Risk Scenarios &lt;br /&gt;
* Real World Examples &lt;br /&gt;
* Possible Mitigations and Security Controls&lt;br /&gt;
* Reference to any related Incident &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== OWASP Cloud-10 List ====&lt;br /&gt;
&lt;br /&gt;
==Initial pre-alpha list of OWASP Cloud-10 Security Risks== &lt;br /&gt;
&lt;br /&gt;
{| border='1' cellpadding='2' &lt;br /&gt;
|-	&lt;br /&gt;
|C1 - Privacy of Users&lt;br /&gt;
| [Placeholder] - User's private and PII data gets stored in the cloud&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C2 - Enterprise Data Hosted Outside in Cloud&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C3 - Accountability and Ownership of Data Security&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C4 - Federating User Identity&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C5 - Secondary Usage of Data&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C6 - Demonstrating Regulatory Compliance&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C7 - SLA - Building Right Level of insurance and accountability&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C8 - Vendor Lock-In&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C9 - Data Backup and Disaster Recovery&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C10 - Direct Exposure to Development and Production Environments&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
'''&amp;lt;center&amp;gt;Table 1: Top 10 Cloud - Security Risks&amp;lt;/center&amp;gt;'''&lt;br /&gt;
&lt;br /&gt;
==Other OWASP Cloud-10 Candidates==&lt;br /&gt;
* Service Availability Risk&lt;br /&gt;
* Multi-Tenancy&lt;br /&gt;
* Integration between cloud and internally hosted services&lt;br /&gt;
* Patching and Vulnerability Management&lt;br /&gt;
* Lack of Transparency in Internal Security Controls and difficulty/complexity of auditing &lt;br /&gt;
* Enterprise Intranets exposed directly on Internet (if they move on a Public Cloud)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This needs to be debated and for each of these we may need to add a separate page-holder with the following details.&lt;br /&gt;
&lt;br /&gt;
* Various Risk Scenarios &lt;br /&gt;
* Real World Examples &lt;br /&gt;
* Possible Mitigation and Security Controls&lt;br /&gt;
* Reference to any related Incident &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Roadmap (Status) ====&lt;br /&gt;
&lt;br /&gt;
==Alpha State==&lt;br /&gt;
#	'''Identify and publish a first draft of potential &amp;quot;OWASP Cloud-10&amp;quot; candidates (July 2009)'''&lt;br /&gt;
#	Ask contributors to collect more data and details on each of the risk item. (till Aug 2009)&lt;br /&gt;
#	Get initial community feedback by discussing it in various blogs, discussion forums etc. (till Aug-Sept 2009)&lt;br /&gt;
&lt;br /&gt;
==Beta State==&lt;br /&gt;
#	Publish the first (beta) list of &amp;quot;OWASP Cloud-10&amp;quot; (Oct 2009)&lt;br /&gt;
#	Identify additional candidates &lt;br /&gt;
#	……. (repeat steps as in Alpha)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Reference ====&lt;br /&gt;
&lt;br /&gt;
==Related Efforts==&lt;br /&gt;
# Cloud Security Alliance - http://www.cloudsecurityalliance.org/&lt;br /&gt;
# IDC Aug 2008 Survey (Security #1) Challenge for Cloud/On-Demand Models - http://blogs.idc.com/ie/?p=210&lt;br /&gt;
&lt;br /&gt;
==Related OWASP Projects==&lt;br /&gt;
#OWASP Top Ten Project&lt;br /&gt;
#OWASP Legal Project&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Contributors ====&lt;br /&gt;
&lt;br /&gt;
==Project Leaders== &lt;br /&gt;
[[:User:vinaykbansal|'''Vinay Bansal''']]&amp;lt;br&amp;gt;[[User:Shankar Babu Chebrolu|Shankar Babu Chebrolu]]&amp;lt;br&amp;gt; [[User:Martin G. Nystrom|Martin G. Nystrom]]&amp;lt;br&amp;gt; [[User:Jim Born|Jim Born]]&lt;br /&gt;
&lt;br /&gt;
== Contributors ==&lt;br /&gt;
&lt;br /&gt;
Ken Huang[[|]]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
#[https://lists.owasp.org/mailman/listinfo/owasp-cloud-10 Subscribe or read the Cloud-10 mail archives]&lt;br /&gt;
&lt;br /&gt;
==== Project Details  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC Project Details/OWASP Cloud ‐ 10 Project | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71944</id>
		<title>Category:OWASP Cloud ‐ 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Cloud_%E2%80%90_10_Project&amp;diff=71944"/>
				<updated>2009-10-21T18:26:19Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: /* Contributors */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main ====&lt;br /&gt;
&lt;br /&gt;
==Goal==&lt;br /&gt;
Goal of the project is to maintain a list of top 10 security risks faced with the Cloud Computing and SaaS Models. List will be maintained by input from community, security experts and security incidences at cloud/SaaS providers.&lt;br /&gt;
&lt;br /&gt;
==Audience==&lt;br /&gt;
Audience for the project will be organizations planning on leveraging external cloud environment to host their applications or rent application in a SaaS model (Software as a Service). Aim of the &amp;quot;OWASP Cloud-10&amp;quot; list is to help balance security risks with the cost advantage that the Cloud and SaaS model provides.  We expect the Cloud and SaaS providers to be indirect audience for &amp;quot;OWASP Cloud-10&amp;quot;, when they try to showcase their security controls to potential customers against this list.&lt;br /&gt;
&lt;br /&gt;
==Managing OWASP Cloud-10 List (Pre-Alpha)==&lt;br /&gt;
“OWASP Cloud-10” list will be maintained by input from, community,  security experts and security incidences at cloud/SaaS providers. &lt;br /&gt;
 &lt;br /&gt;
Each of the identified risk in &amp;quot;OWASP Cloud-10&amp;quot; will provide details on:&lt;br /&gt;
* Various Risk Scenarios &lt;br /&gt;
* Real World Examples &lt;br /&gt;
* Possible Mitigations and Security Controls&lt;br /&gt;
* Reference to any related Incident &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== OWASP Cloud-10 List ====&lt;br /&gt;
&lt;br /&gt;
==Initial pre-alpha list of OWASP Cloud-10 Security Risks== &lt;br /&gt;
&lt;br /&gt;
{| border='1' cellpadding='2' &lt;br /&gt;
|-	&lt;br /&gt;
|C1 - Privacy of Users&lt;br /&gt;
| [Placeholder] - User's private and PII data gets stored in the cloud&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C2 - Enterprise Data Hosted Outside in Cloud&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C3 - Accountability and Ownership of Data Security&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C4 - Federating User Identity&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C5 - Secondary Usage of Data&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C6 - Demonstrating Regulatory Compliance&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C7 - SLA - Building Right Level of insurance and accountability&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C8 - Vendor Lock-In&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C9 - Data Backup and Disaster Recovery&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|C10 - Direct Exposure to Development and Production Environments&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
'''&amp;lt;center&amp;gt;Table 1: Top 10 Cloud - Security Risks&amp;lt;/center&amp;gt;'''&lt;br /&gt;
&lt;br /&gt;
==Other OWASP Cloud-10 Candidates==&lt;br /&gt;
* Service Availability Risk&lt;br /&gt;
* Multi-Tenancy&lt;br /&gt;
* Integration between cloud and internally hosted services&lt;br /&gt;
* Patching and Vulnerability Management&lt;br /&gt;
* Lack of Transparency in Internal Security Controls and difficulty/complexity of auditing &lt;br /&gt;
* Enterprise Intranets exposed directly on Internet (if they move on a Public Cloud)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This needs to be debated and for each of these we may need to add a separate page-holder with the following details.&lt;br /&gt;
&lt;br /&gt;
* Various Risk Scenarios &lt;br /&gt;
* Real World Examples &lt;br /&gt;
* Possible Mitigation and Security Controls&lt;br /&gt;
* Reference to any related Incident &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Roadmap (Status) ====&lt;br /&gt;
&lt;br /&gt;
==Alpha State==&lt;br /&gt;
#	'''Identify and publish a first draft of potential &amp;quot;OWASP Cloud-10&amp;quot; candidates (July 2009)'''&lt;br /&gt;
#	Ask contributors to collect more data and details on each of the risk item. (till Aug 2009)&lt;br /&gt;
#	Get initial community feedback by discussing it in various blogs, discussion forums etc. (till Aug-Sept 2009)&lt;br /&gt;
&lt;br /&gt;
==Beta State==&lt;br /&gt;
#	Publish the first (beta) list of &amp;quot;OWASP Cloud-10&amp;quot; (Oct 2009)&lt;br /&gt;
#	Identify additional candidates &lt;br /&gt;
#	……. (repeat steps as in Alpha)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Reference ====&lt;br /&gt;
&lt;br /&gt;
==Related Efforts==&lt;br /&gt;
# Cloud Security Alliance - http://www.cloudsecurityalliance.org/&lt;br /&gt;
# IDC Aug 2008 Survey (Security #1) Challenge for Cloud/On-Demand Models - http://blogs.idc.com/ie/?p=210&lt;br /&gt;
&lt;br /&gt;
==Related OWASP Projects==&lt;br /&gt;
#OWASP Top Ten Project&lt;br /&gt;
#OWASP Legal Project&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Contributors ====&lt;br /&gt;
&lt;br /&gt;
==Project Leaders== &lt;br /&gt;
[[:User:vinaykbansal|'''Vinay Bansal''']]&amp;lt;br&amp;gt;[[User:Shankar Babu Chebrolu|Shankar Babu Chebrolu]]&amp;lt;br&amp;gt; [[User:Martin G. Nystrom|Martin G. Nystrom]]&amp;lt;br&amp;gt; [[User:Jim Born|Jim Born]]&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
Ken Huang&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# [https://lists.owasp.org/mailman/listinfo/owasp-cloud-10 Subscribe or read the Cloud-10 mail archives]&lt;br /&gt;
&lt;br /&gt;
==== Project Details ====&lt;br /&gt;
{{:GPC Project Details/OWASP Cloud ‐ 10 Project | OWASP Project Identification Tab}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_for_Kids&amp;diff=71921</id>
		<title>OWASP for Kids</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_for_Kids&amp;diff=71921"/>
				<updated>2009-10-21T16:43:43Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The goal of this project is to contribute teaching material for teaching Kids on the web application security. The teaching material can be in the format of Power Point, Video, World document or any other format. The goal is to teach kids to use search tool, e-mail, facebook, blog, or general browsing safely. As an initial attempt, I will upload an initial power point document (coming soon) as the reference and I welcome any new contributors to this project.&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_for_Kids&amp;diff=71920</id>
		<title>OWASP for Kids</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_for_Kids&amp;diff=71920"/>
				<updated>2009-10-21T16:15:25Z</updated>
		
		<summary type="html">&lt;p&gt;Ken Huang: OWASP for Kids is the place where you can find or contribute teaching material for web appliation security for kids&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The goal of this project is to contribute teaching material for teaching Kids on the web application security. The teaching material can be in the format of Power Point, Video, World document or any other format. The goal is to teach kids to use search tool, e-mail, facebook, blog, or general browsing safely. As an initial attempt, I upload the following power point as the reference and I welcome any new contributors to this project.&lt;/div&gt;</summary>
		<author><name>Ken Huang</name></author>	</entry>

	</feed>