
Pursuing an ISO certification makes more sense than a US-only standard, since they are widely recognized and accepted internationally. If Google and others want to give their customers a sense of security about their data, this seems logical. As with all technology, the products come before the standards. Companies like to be first out of the gate so they can claim they do it better than their competitors and so they can influence the coming standards. Hopefully a cloud security certification is coming soon.
As go Google and Microsoft, so goes the industry, but customers will ultimately decide. Salesforce.com already has ISO 27001 certification, so maybe they are the leader here. I think the important thing is that cloud providers adhere to security standards to make us all feel better about using their services. Interesting that there isn’t a common on-premise security standard either.
– Written by Ron Arden