the cloud

22
The Cloud Earl C. Rich, CRM

Upload: deidra

Post on 09-Jan-2016

84 views

Category:

Documents


0 download

DESCRIPTION

The Cloud. Earl C. Rich, CRM. We’re Gonna Talk About:. Define what The Cloud is Review Cloud service-types Discuss the different types of Clouds Data Security issues in The Cloud Legal challenges with The Cloud RIM issues in The Cloud Why IT likes The Cloud Cloud Horror Stories - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: The Cloud

The Cloud

Earl C. Rich, CRM

Page 2: The Cloud

We’re Gonna Talk About:

• Define what The Cloud is

• Review Cloud service-types

• Discuss the different types of Clouds

• Data Security issues in The Cloud

• Legal challenges with The Cloud

• RIM issues in The Cloud

• Why IT likes The Cloud

• Cloud Horror Stories

• Contracts are the key

• Review Cloud Computing Agreements

• Open Discussion / Questions

IT Stuff

RIM Topics

Contracts

More IT Stuff

Page 3: The Cloud

What is “The Cloud”?

“The Cloud” is a metaphor inspired by the cloud symbol used to represent the Internet in flow charts and diagrams.

Real-World Definition:

Cloud is a style of computing where scalable and elastic IT-related capabilities are provided as a service to external customers using Internet technologies.¹

Techie Definition:

Cloud computing describes the disruptive transformation of IT toward a service-based economy, driven by economic, technological, and cultural conditions.²

1: Gartner.com2: Tom Jenkins, “Managing Content in the Cloud” (2011, October)

Page 4: The Cloud

Cloud Service-Types

Infrastructure as a Service (IaaS)

The capability provided to the consumer is to provision processing, storage, networks, and other fundamental computing resources. Apple iCloud or Google Drive

Platform as a Service (PaaS)

PaaS offerings typically include workflow facilities for application design, application development, testing, deployment and hosting. Google App Engine or Amazon EC2

Software as a Service (SaaS)

Software is accessible via the client’s Web browser Instead of on a local network or hard-drive. Google Apps or webmail

Page 5: The Cloud

Cloud Computing Diagram

Page 6: The Cloud

Types of Clouds

Page 7: The Cloud

Types of Cloud Computing

• Public Cloud – Traditional model where vendors dynamically allocate resources through web applications.

• Private Cloud – Computing platform is dedicated to a single customer and can be housed internally or externally.

• Hybrid Cloud – Your organization’s hardware interacts with a vendor-hosted service (e-mail archiving, web filtering, etc...). This model can also be used for “Cloud Bursting” where an organization’s infrastructure is used for normal computing needs, but cloud resources are used to carry peak loads.

• Community Cloud – Infrastructure is shared between similar organizations (i.e., all agencies within a government), but not with other outside parties. This model may also be referred to as a “government cloud”.

Page 8: The Cloud

Public, Private and Hybrid Clouds

Page 9: The Cloud

So Far, So Good… right?

Page 10: The Cloud

“Cloud computing sounds so sweet and wonderful and safe ... we should just be aware of the terminology, if we go around for a week calling it swamp computing I think you might have the right mind-set.”

- Ronald Rivest, MIT Computer Science Professor

Source: computerworld.com

Page 11: The Cloud

The Notorious Nine:

Cloud Computing Top Threats in 2013

1. Data Breaches

2. Data Loss

3. Account Hijacking

4. Insecure APIs

5. Denial of Service (DOS) Attacks

6. Malicious Insiders

7. Abuse and Nefarious Use

8. Insufficient Due Diligence

9. Shared Technology Issues

Page 12: The Cloud

Data Security Concerns

• HIPAA:

– If the data contains Protected Health Information (45 C.F.R. §160.103), then the two groups (yours and theirs) must enter into a “business associate contract” (45 C.F.R. §164.504(e)(2))

• FMLA and the ADA:

– Both contain confidentiality provisions that restrict access to first aid and safety personnel, supervisors/managers, government officials, etc... (29 C.F.R. §825.500(g); 29 C.F.R. §1630.14 (c)(1))

• Section 817.5681, Florida Statutes:

– Breach of security for “personal information” (§817.5681(5), Fla Stat.) must be noticed to the owner of the data (you) within 10 days, and to residents of Florida within 45 days (§817.5681(1)(a); §817.5681(2)(a), Fla. Stat.)

Page 13: The Cloud

Legal Matters

• Subpoenas:

– Cloud vendors may be directly served a subpoena (Section 215 of the U.S. Patriot Act) and may not be allowed to disclose the existence or nature of the subpoena.

• E-Discovery/Rule 26 and Destruction Holds:

– All data, regardless of where it is stored, must be disclosed (Rule 26(a), F.R.C.P. (2010)). A party is required to produce data in a reasonably usable form, and is required to preserve electronically stored information [ESI] once litigation is anticipated or has commenced (Rule 37(f), F.R.C.P. (2010)).

• Jurisdiction:

– Both parties should agree on a “home” jurisdiction. If a cloud computing provider is located outside of the United States, it may be difficult to enforce any judgement of a U.S. court.

Page 14: The Cloud

RIM Issues

• Public Records Issues:

– Data stored or created in The Cloud are records (whether F.O.R. or duplicate)!

– The entity that “owns” the data is responsible for adhering to Chapter 119

– The data must be retrievable and in a meaningful format to fulfil PRR standards

• 1B-26.003, F.A.C. (1B-26):

– If the items are File of Record (F.O.R.), then 1B-26 requirements must be met (storage methods, security standards, maintenance methods, etc...)

• Records Retention and Destruction:

– The Cloud provider must be able to maintain records for the prescribed lifecycle

– The user (you, not them) must have the ability to initiate destruction of records

Page 15: The Cloud

Cloud Outages/Issues

• Dropbox: January 10, 2013

– Length of Outage: 16 hoursUsers Impacted: 175,000,000+

• Facebook: January 28, 2013

– Length of Outage: 3 hoursUsers Impacted: 4,500,000 (estimated)

• Amazon.com: January 31, 2013

– Length of Outage: 49 minutesUsers Impacted: 2,600,000 (estimated)

• Microsoft’s Bing.com: February 2 & 22, 2013

– Length of Outage: 2 hours & 12 hoursUsers Impacted: 313,000 (estimated)

• Google Drive: March 18 - 19, 2013

– Length of Outage: 17 hoursUsers Impacted: 120,000,000+

Source: infoworld.com

Page 16: The Cloud

Quote of the Day

“Clearly you’re not in control of your data, your information. It’s a major business interruption. I’m getting business interruption insurance tomorrow, believe me.”

- Campbell McKellar, founder of Loosecubes.com

Source: NYTimes.com

Page 17: The Cloud

Why IT Likes the Cloud

1.

2.

Page 18: The Cloud

Cloud Computing Value

Page 19: The Cloud

Pros & Cons of Cloud Computing

Page 20: The Cloud

A Good Contract is your Key to the Clouds

The main point of this entire presentation is that care should be taken during the contracting process to make sure that RIM issues and concerns are addressed and fully negotiated in any contract or SLA.

Review of two real-life Cloud Computing agreements

Page 21: The Cloud

Cloud Computing Roadmap

Page 22: The Cloud

Questions