CloudEnterprise.info

Can cloud make you MORE compliant?

Posted by: Dmitry Sotnikov on: April 6, 2009

The common word out there about cloud computing/SaaS and security/regulatory compliance are that these don’t go well together. However, things don’t have to be that way. Doing security right can cost a lot of money and public cloud services could carry some of these costs. Thus, there probably will be a point in time when paradoxically cloud may become a cost-effective way to compliance.

With these thoughts in mind, I was delighted to find a report by Scott Crawford from Enterprise Management Associates – “The Security Paradox of Cloud: Five Questions for Cloud Providers“.

This is a great report in a sense that it not only talks about that same paradox but also formulates the 5 questions which need to be answered by the cloud vendors to make these happen:

  1. “How much visibility do I have into how you manage my risks?”
  2. “What risks do your other tenants pose to me… or to you?”
  3. “Are your tools and techniques for managing risk mature enough?”
  4. “Is my data safe with you?”
  5. “How will turning to cloud impact my current approach to management?”

For each of the questions Scott provides a good discussion – so the report is well worth checking out.

Here are a few comments which I had on the paper:

In my opinion, “cloud” is inevitable because it offers better economics than do-it-yourself on-premises approach: think market economy specialization vs. natural household. This does not mean that no IT services will remain on premise but we are most likely up to some kind of hybrid model. How far we go there does depend on the ability by the industry to answer Scott’s questions.

Scott’s notes on how cloud with its separation of duties could also become a more viable security solution are spot on. With proper legal and certification framework cloud approach would let companies split liability risks with the cloud provider – as opposed to having to deal with liability all by themselves. Adhering to retention policies is costly – outsourcing multiyear document/communications retention to Microsoft/Google/etc. and sharing not only storage costs but liability and risks with them is a pretty good deal.

  • Certifications (such as SAS 70) are a good step in ensuring better security. Scott seems skeptical about certifications (and rightly so) but these are one of the components of the solution because they provide a vendor-independent common set of standards.
  • Publicly disclosed industry-proven identity management, authentication and authorization architectures (such as “Geneva” for example) is another good step – security by obscurity will not cut it here.
  • There will probably be a bigger place of encryption/DRM in the picture. These do come at a price though and if the limits are pushed too hard the cloud systems may become useless: not being able to provide valuable functionality without access to data.
  • Legal frameworks providing for shared liability.

With all that said, this will not happen overnight. Kids are sick more often than adults, and the cloud industry is still in its infancy so 2009 and 2010 will bring us quite a few outages and security breaches.

Read Scott’s report here.

Technorati Tags:
, , , ,

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

RSS My company’s main blog

  • The Jelastic Spotlight May 25, 2012
    We are starting something new here on the blog for Fridays. Up until now, we were doing more light-hearted stuff but as we were sitting around talking about the different sweet apps that you, our customers, are deploying, we realized that we should be showcasing the apps and the developers! So, as of today, Fridays [...]
  • Remote Access to MySQL in Jelastic: Import/Export Dump Files in a Few Minutes May 24, 2012
    Recently, we told you about that another cool feature that you have access to in the commercial version of Jelastic, Public IPv4. With a single click you access to a number of cool new capabilities. One of the most important opportunity you get with this feature is the ability to work with your databases remotely and [...]
  • The Jelastic Newsletter – May 23, 2012 May 23, 2012
    Java 7 adoption, Commercial releases in Europe and Russia and Software stack market share. . . The Jelastic newsletter is a weekly round-up of news, how-to’s and contribution opportunities. Here’s what’s happening this week: Commercial Releases in Europe and Russia As we continue to grow and add partners, we are happy to say that, as of yes […]
  • We are now available commercially in Europe! May 22, 2012
    In partnership with dogado, we are now available commercially in Germany The last few weeks have been hectic here at Jelastic! We launched commercially in the US with ServInt; then we did the same in Russian with Rusonyx; and now we have launched commercially in Europe with Germany. Now in Europe Our commercial release with [...]
  • Software stacks market share: May 2012 May 21, 2012
    Every month we share stats on the usage and popularity of different software stacks within Jelastic PaaS with you. This month it’s even more interesting, because the scope of our stats has grown: we have a new hosting partner in Russia, Rusonyx. So, let’s check out the stats on databases, servers and JVMs for May and analyze the differences betwe […]
  • Geek Project of the Day May 18, 2012
    Just in time for the weekend. Here is your geek project of the day. Because sometimes, a regular grill is not enough. We want one. Going to “borrow” a friend’s car and turn it into a grill.
  • Jelastic announces the commercial availability of its Java cloud hosting platform with Rusonyx May 17, 2012
    Rusonyx’s Jelastic offering provides Cloud Java hosting with no lock-in or code changes required PALO ALTO, Ca. – Jelastic, the world’s first standards-based Platform-as-a-Service, today announced its commercial availability in Russia through its partner, Rusonyx, one of Russia’s leading web hosting service providers. Rusonyx is the exclusive provider […]

My Recent Tweets

Blogroll

Legal

The posts on this blog are provided “as is” with no warranties and confer no rights. The opinions expressed on this site are mine and mine alone, and do not necessarily represent those of my employer Jelastic or anyone else for that matter. All trademarks acknowledged.

© 2008-2012 Dmitry Sotnikov

Follow

Get every new post delivered to your Inbox.