Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, June 1, 2009

Do “Private Clouds” make sense?

I actually should better ask “is a Private Cloud really Cloud Computing?”

Quite frankly i do not think that what Gartner and many others call a <Private Cloud> is anything near Cloud Computing. Agreed there is a trend towards virtualization and this makes perfect sense for large corporations – but Cloud Computing for me implies that the user (and even the IT department) does not know where the application or service is running and where data is stored.

The reason to use a Private instead of the Public Cloud is most of the times security related, i.e. I want to assure that sensitive data is not leaving the company in order to reduce risk or ensure compliancy with corporate policy or laws. Distributing the available internal computing power and the available storage across many users, apps, departments and locations is more or like a task of clever load-balancing. Some of the technology is probably similar to the one used in the Cloud, but all this is still very much in the control of corporate IT.
The fact that I am sure that the data does not leave the companies firewall shows that I always know where it actually (and physically) is. Isn’t this is an antagonism to the concept of Cloud Computing?

Friday, March 13, 2009

Governance in the Cloud – who and how?

image One one side it is very attractive to put data and processing into the cloud and avoid the costs and problems of up- (and down-) scaling of the own IT. But there are some questions that need to be asked (and solved….) before mission critical data and functionality can be moved outside a controllable environment:

 

  • Who guarantees Data Security (and how)?
  • How are SLAs controlled and enforced?
  • Which law (i.e. which country) will apply?
  • Who will make sure the law is enforced (and how)?
  • What happens if the provider goes insolvent?
  • What if the provider is acquired (and HQ moves to a different country)?

As technology moves much faster than regulations and laws, there is a lot of uncertainty involved at the moment. As long as my datacenter resides in Germany, German law will apply and the CTO is (kind of) responsible for the compliance to the respective regulations. Even if the IT is outsourced, the company providing the hosting services is responsible and can be sued. In a Cloud Computing scenario, my data is theoretically distributed all over the world, which brings up the question which law applies and who is responsible for it.

Some of the data might reside in China or India while it is processed in Europe or North America. What if a country changes laws unexpected or the company providing the cloud services is acquired or insolvent? The missing control could easily bring a business down when relying on cloud services that do not deliver anymore or when mission critical data is inaccessible for a longer period.

Outages of Amazons Cloud Services or Google showed that this scenario is not so unrealistic and the risk is rather high. But what to do when cost reductions do not leave any other option other than Cloud Computing? What rights and possibilities do people and companies have if the provider of cloud services abuses my data? How would I even know where my data is and how I can get access to it?