Скачиваний:
50
Добавлен:
20.06.2019
Размер:
50.48 Mб
Скачать

244

S.R. Chaput and K. Ringwood

be secretly examined, copied, or seized under the auspices of the Act. Again, not only do organizations need to be aware of the laws that directly affect them, they also need to be aware of the ones to which they do not wish to be privy and make their business decisions accordingly.

14.1.3.2  Industry Regulations

Like the regional laws, industry regulations are wide reaching, complicated, and at times potentially overlapping. Retail and credit card processing are a hot topic of late within the Information Security community, allowing most to become familiar with PCI DSS, American Express’ Data Security Operating Policies (DSOP),7 or Visa’s Cardholder Information Security Program (CISP).8 Similarly, energy producers within North America may need to concern themselves more with North American Energy Reliability Council (NERC)9 or Federal Energy Regulatory Commission (FERC).10 Investment Dealers may be subject to the Investment Dealers Association Uniform Securities Legislation (IDA USL).11 Healthcare has more laws and regulations than most would care to read. The list goes on.

Despite a limited scope of certain laws being mapped to specific types of industries, the awareness in itself is not sufficient to help determine benefits or negative implications on the organization prior to considering using the cloud.

14.2  Cloud Compliance

14.2.1  Information Security Organization

A company’s Information Security Organization (ISO) – assuming one is established – has likely already determined which of these laws and regulations are relevant and have documented the requirements thoroughly. The ISO will work towards achieving the information security maturity for the organization, helping on an ongoing basis to establish the best course of action a company needs to take to become or stay compliant. Failing the existence of an ISO, it will likely be incumbent on the company to establish one prior to using the cloud. At a minimum, the ISO can help with the identification of relevant laws and regulations, ensuring

7 https://www209.americanexpress.com/merchant/singlevoice/pdfs/en_GB/American%20 Express%20DSOP%20for%20Merchants%20-%20UK.pdf

8 http://visa.com/cisp

9 http://www.nerc.com/

10 http://www.ferc.gov/

11 http://www.iiroc.ca/English/Pages/home.aspx

Соседние файлы в папке CLOUD COMPUTING