Flying confidently through the clouds

Alastair MacWillson outlines a strategic approach for channel players in the cloud

By Alastair MacWillson

22 Dec 2009

Comments:1

  • Digg
  • Tweet
Alastair MacWillson
MacWillson: Chart a course to protect data in the cloud

Growth for many cloud services will accelerate as the services mature. Progress has got caught up on fears about IT security. Data theft and compromise, loss of service and phishing incursions are all very real threats.

Channel partners must address business customer concerns. Customers must be sure that cloud providers will handle customer data with care. Where exactly is the data being stored?

Customers may also question whether cloud providers have the levels of infrastructure security to ward off cyber-attacks. Are the providers able to manage, measure and report on industry regulations, and can they be accountable if they fail to comply?

Finally, who will be held responsible for the service level guarantees and business continuity?

Accenture’s empirical IT security work over many years with a wide range of organisations suggests that certain fundamentals apply in cloud computing initiatives.

IT leaders must weigh up applications and data and decide what is appropriate for the cloud. They must gauge what risks they are willing to take. For example, whether to move new product data or customer data to the cloud, in context of the benefits of doing so and the regulations that apply to the data’s new location.

You must carry out detailed due diligence on cloud provider performance, including their financials. Cloud computing providers vary in market position and approach; different vendors have different levels of IT security and data management.

Confirm that they meet key standards, guidelines, and codes of practice such as ISO 27001.

Chart the lifecycle of the relevant data assets, from development to destruction. IT managers must know where data is at all times so they know if it is being stored and shared in compliance with local laws and industry regulations at appropriate levels of IT security.

Using proven IT security principles, IT leaders must define the key security elements, knowing where encryption is needed, for example, and understanding which transport layers are important.

The regulatory complexities are enormous when doing business in multiple nations: some governments regulate the physical locations of the servers where organisations keep their data.

IT leaders cannot expect their cloud providers to be compliant for them. But they must expect them to provide what is needed to help achieve compliance.

What happens if something breaks while in the cloud? How is the data owner notified, and how quickly? How is the data recovered? These are the basics of best practice in business continuity, and they apply just as much to cloud computing as to any IT outsourcing arrangement.

Again, of course, they must align with regulatory mandates.

Educate employees on IT security policies and procedures and be very clear about how those policies and procedures relate to the cloud. For example, employees must stick to corporate IT security policies when exploring cloud services for any work-related activities, such as testing a new IT service or storing data in the cloud.

At this point, what is needed in the channel is a rebuilding of trust as well as a renewed sense of perspective. As with any other technology development, cloud computing initiatives come with their own set of risks and rewards.

But the cloud must not be treated as a threat. Implemented and managed properly, it should not add risk. It should do the opposite.

The fundamental question is one of balance: weighing, as accurately and in as much detail as possible, the risks of a data security breach against the power of the cloud to directly address many pressing business issues.

Alastair MacWillson is managing director for the global security practice at Accenture

Security in the cloud is as real as Santa Claus

Cloud Security Evangelists May Have Heads Stuck In Clouds

http://www.theaeonsolution.com/security/?p=101

Posted by James McDonald | 24 Dec 2009

display:none
Loading
We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions

Your comment will be moderated before publication.

Will Apple's attitude to the channel change in 2012?

54%

19%

26%

1%

CRN Partner Connect 2012

CRN Partner Connect logo

CRN's premier networking event is back on 17 May at the Ricoh Arena

Date: Thu 17 May 2012

CRN Fight Night 2012

One of the fights from CRN Fight Night 2010

Channel fighters preparing to square up once more on 24 May

Date: Thu 24 May 2012

Sign up for our range of FREE newsletters:

Submit your email address and we'll send a link to a personal newsletter control panel

fragment image

The mobile enterprise: Secure the data, not the device

The proliferation of endpoint devices within the enterprise has highlighted the shortcomings of one of the traditional approaches to data security

fragment image

Measuring the ROI of Google Apps

This Forrester report compares the costs and benefits of legacy email and productivity software with Google Apps


Dave the dealer blog

Dave the dealer

Clocking off

Dave discovers that rozzers are seemingly living in the technology dark ages

View from the channel

Views from the Channel

Departing CEO has done Dixons a service

Mark Needham, founder of distributor Widget, argues that John Browett leaves for Apple with Dixons in better shape than when he arrived

To send to more than one email address, simply separate each address with a comma.