Скачиваний:
50
Добавлен:
20.06.2019
Размер:
50.48 Mб
Скачать

Chapter 14

Cloud Compliance: A Framework for Using Cloud Computing in a Regulated World

Shawn R. Chaput and Katarina Ringwood

AbstractCloud computing is quickly becoming a significant IT resource, which a typical organization will likely consider at some point. Be it Software-as-a-Service or Infrastructure-as-a-Service, the implications can be significant with respect to compliance with a variety of laws or regulations. The intention of this chapter is to give some insight into the potential compliance pitfalls an organization may exp­ erience if ill-prepared, and provide the tools to plan for and navigate around these obstacles before they become insurmountable.

14.1  Using the Cloud

Cloud computing has both advocates and naysayers, each with a variety of reasons for their respective positions. This chapter does not intend to side specifically with either. Rather, the purpose is to demonstrate an organization’s minimum requirements with respect to handling the data. It will also be demonstrated that the tasks required are far from trivial and potentially expensive to implement and manage. Thus, whether cloud computing should be considered by an organization is contingent on understanding the costs and obligations.

14.1.1  Overview

First off, using Cloud Providers or Cloud Services (herein referred to as “the cloud”), is neither inherently insecure nor secure. It is highly doubted that a turnkey cloud solution could prove to be the security panacea an organization hopes it

S.R. Chaput (*)

Privity Systems Inc307, 425 West 8th AvenueVancouver, British ColumbiaV5Y, 3Z5Canada e-mail: schaput@privityinc.com

N. Antonopoulos and L. Gillam (eds.), Cloud Computing: Principles,

241

Systems and Applications, Computer Communications and Networks,

DOI 10.1007/978-1-84996-241-4_14, © Springer-Verlag London Limited 2010

Соседние файлы в папке CLOUD COMPUTING