The Cloud and Security Concerns The most common issue perceived by customers while adopting SaaS is the security/confidentiality of their data as the data resides outside their direct control.
Even SalesForce.com has been hit by high-impact data security issues with clients. These concerns are even more applicable in an Indian context, especially with financial/accounting data.
Some high-profile data security breach has been seen in the recent past, including leak/misuse of financial information of a large British bank and Citibank from some of the leading BPO companies of the country.
Possible solutions may be: Enterprises must carefully manage trust, authentication, and authorization to applications and data in the cloud, especially with "cloud to cloud" and "hybrid cloud" inter – application authorizations
Enterprises that manage sensitive information, such as social security numbers, credit card numbers, and patient health information must implement protection measures and policies when using the cloud.
Financial institutions must protect consumers from fraud and identity theft.
Loss of confidential information can result in compliance infractions, lawsuits from customer and/or patients, potential identity theft, and significant harm to an organization’s credibility and reputation.
Compliance standards assurance will be needed: SAS70, ISO27001, SysTrust.
Enterprises need incident and breach response policies for cloud computing.
Records management and eDiscovery implications must be considered.
Portfolio Management and Data Governance requirements.
Looking at the above, it might be a good idea to put certain applications/data stores on the cloud and manage the rest in-house.
Types of information that must be closely managed when using vendor cloud service providers include: Personal information Patent or trade secret Customer information Corporate information Medical information Financial information Other sensitive information
No matter what the technology, enterprises need to adequately protect data throughout its life cycle in the enterprise and into the cloud.
The author is Executive Director at Deloitte.
Get most out of your technology infrastructure investments with Dell
About CIOL | Media Kit | Site Map | Contact Us | Help | Write to us | Jobs@CyberMedia | Privacy Policy
Copyright © CyberMedia India Online Ltd. All rights reserved. Usage of content from web site is subject to Terms and Conditions.