Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

Compliance and Cloud Computing at Enterprise 2.0

Posted on June 22, 2009November 20, 2009 by Doug Cornelius
Print Friendly, PDF & Email

enterprise 2.0 conference

Monday night, I am heading over to the The Evening in the Cloud program at this year’s Enterprise 2.0 Conference. They asked me to help grill the vendors on compliance issue

More software and business operations are being pushed into the cloud.  Why buy the hardware and software when someone else will run them for you?

I thought I would put together my thoughts on some of the compliance issues I think about when it comes to cloud computing.

Records Management.

One aspect of records management is ensuring that important records are kept. Importance can be either because of a business need or a regulatory requirement. The other aspect is data destruction. Once that record is not important and no longer required to be kept, you want to make sure it is destroyed and destroyed forever. Multiple backups in multiple places of old records is huge headache when forced into e-discovery and the delivery of records as part of litigation.

Compliance Logs.

Whether you’re in the midst of an audit or an investigation, thorough logs are the key to proving compliance. So how do you prove your organization is (or was) compliant when you aren’t able to maintain logs? Audit trails must be auditable.

Terms of Service.

Consumers are used to clicking through the Terms of Service without reading it. Businesses will read it and want to negotiate it. If the vendor’s Terms of Service has a typical consumer provision allowing the vendor to unilaterally change it, throw that vendor out the door and don’t bother talking with them.

Investigations

You need to address how a forensic examination of the systems can be run as part of government or internal investigation of wrongdoing.

Geography

It is not truly a cloud. There are physical servers that are sitting in a building somewhere. That physical location subjects them to the law of that jurisdiction. There are obviously some countries that you do not want. (Anyone in North Korea?) There are also some questionable locations. There are some companies that don’t want their operations being run on servers located in China. You should not be surprised that some companies do not want their servers in the United States because of the confiscatory provisions of the US PATRIOT Act.

Data Privacy

Geography also implicates personal data privacy. If you are using the cloud service to host information about people (employees or customers) you need to think about how the service compliance with the multitude of personal data privacy laws. The most difficult is probably the EU Data Protection Directive.

Multi-User

If your information is combined with another company’s information on the same server, you risk being subject to their wrongdoing. There was a well-publicized raid of a server farm, with law enforcement seizing servers, shutting down businesses with their operations running on those servers.

Credit Card Processing

If you are processing payments, you need to be PCI DSS compliant. If the vendor asks what PCI means, throw them out.

Vendor should have a SAS 70 Type II Audit.

SAS 70 was designed to provide a highly specialized audit of an organization’s internal controls to ensure the proper handling of client data. SAS 70 Type II certification ensures that client data is protected in a data center that is using industry-leading best practices in information technology and security. Vendors that undergo a SAS 70 Type II audit are stringently evaluated on such elements as systems, technology, facilities, personnel management, and detailed processes for handling client data. At the end of a six-month process, vendors receive a comprehensive audit report that includes a description of their operational controls and a description of the auditor’s tests of operating effectiveness. At regular intervals after the initial audit, vendors go through additional audits to maintain their SAS 70 Type II status. In brief, SAS 70 provides assurance that a vendor has put in place comprehensive systems to ensure data security.

Of course, there are other issues.  Depending on your industry, some of these may be more of a concern than others.

References:

  • Gartner and CA on addressing compliance requirements in cloud computing
  • Cloud computing providers debate compliance, security and transparency
  • Cloud compliance: Will PCI be applied to cloud computing by the FTC?
  • NIST on Cloud Computing
  • Portals and KM: What Is the Best Business Model When Data and Content Storage Becomes a Utility?
  • Open Could Manifesto

Share this:

  • Print (Opens in new window) Print
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on X (Opens in new window) X
  • Email a link to a friend (Opens in new window) Email

7 thoughts on “Compliance and Cloud Computing at Enterprise 2.0”

  1. Pingback: Evening in the Cloud and Compliance | Compliance Building
  2. itaudit says:
    June 23, 2009 at 9:55 pm

    Another issue is how to ensure you get the data back if the vendor fails or you cancel the contract. This should be part of the contract itself, but is often overlooked.

    Reply
  3. Webhost says:
    July 30, 2009 at 8:11 am

    Hi,
    I found your blog on google and read a few of your other posts. I just added you to my Google News Reader. Keep up the good work. Look forward to reading more from you in the future.
    Regards,
    Jane

    Reply
  4. Cloud Computing News says:
    August 19, 2009 at 8:25 pm

    Thanks for the info. Telstra – Australia’s biggest telco has just announced (on 17th August) a $500m investment into cloud computing which is pretty huge.

    Reply
  5. Pingback: @ Enterprise 2.0 Evening in the Cloud Panel discussion : elemental cloud computing
  6. cheap vps says:
    June 19, 2010 at 4:52 pm

    found your blog from bing while finding good deals for cloud computing nice one

    Reply
  7. Pingback: @ Enterprise 2.0 Evening in the Cloud Panel discussion : Elemental Links

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search for Stuff

Recent Stories

  • Neither Admit Nor Deny To Be No Longer
  • What Will Form PF Look Like Next Year?
  • Is It a Chipset or Is It a Security?
  • When the Lawyer Is Breaking Bad
  • Will Investors Have an Appetite for Semi-Annual Reporting?
  • Special Forces Trading on Insider Knowledge
  • Prediction Markets and Compliance Programs
  • The One with the Line That Goes Straight Up and Right
  • The One with the Crypto Paying for a Mega-Shilling Package
  • The Performance of the SEC in 2025

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.