Cloud governance -- manage the cloud challenge | Features | ChannelWorld.in

PARTNER HOTLINES

Cloud governance -- manage the cloud challenge

By Puneet Kukreja

Whilst business adoption of cloud services will not decrease, understanding that it is just another services model to be managed and governed is required. Governance will ensure that the value of business decisions can be tracked, and impacts to service level agreements for availability of the service, incident management, and growth on demand including the security and protection of the organisation's data assets can be understood and improved over time.

The word governance derives from the Greek verb κυβερνάω [kubernáo], which means to steer, and was used for the first time in a metaphorical sense by Plato (according to Wikipedia). Wikipedia further expands on the term, rightly calling it "the act of governing". Governance relates to decisions that define expectations, grant power, or verify performance.

Governance is about consistent management, cohesive policies, guidance, processes and decision-rights for a given area of responsibility. For the purpose of this discussion we will use it for the management, use and adoption of Cloud Services. The adoption of Cloud Services is challenging, those involved often concentrate on the security of data assets and any legislative implications that an organisation might be subjected to in the event of data assets being compromised. We discussed the concept of cloud security and its implications in an earlier article "To Cloud or Not to Cloud".

Speaking with a number of industry people about peoples' appetite for cloud adoption made me wonder if cloud is no different to outsourcing or offshoring. We explored this idea last month when we discussed "Embracing the Cloud -- A Decision Framework" where a 4-step approach was outlined, enabling your organisation to begin to adopt cloud services. This is really no different to the activities involved in procurement of business and IT services, and facilitating a quick turn-around time. In the end, it's all about mitigating the risk associated with suppliers--onsite, offsite, outsourced, offshored or in the new lingo, Infrastructure-As-A-Service (IAAS), Platform-As-A-Service (PAAS), Software-As-A-Service (SAAS). Add an 'AAS' after any capability, and it's a cloud service.

Obviously, as the take up of this new model increases, the challenge for executives is to ensure that controls are in place around the availability and viability of the cloud service offering--ensuring a service is fit for purpose and use, without neglecting data security and integrity.

Whilst business adoption of cloud services will not decrease, understanding that it is just another services model to be managed and governed is required. Governance will ensure that the value of business decisions can be tracked, and impacts to service level agreements for availability of the service, incident management, and growth on demand including the security and protection of the organisation's data assets can be understood and improved over time.

To assist with the management of the cloud challenge a list of 25 considerations, dubbed "CloudAdopt25", has been compiled to assist with establishing governance of cloud services. The 25 considerations have been split into 4 areas: Contract Management, Services Reporting, Services Management and Data Security.

Contract Management

1. Ensure that the lawyers of your organisation have adequate time to review the contract of services, specifically for any grey areas in which the vendor can change the terms of contracted services at their discretion.
2. Ensure the choice of jurisdiction is documented and agreed. An approach may be to agree that the contract between the parties be filed in the jurisdiction of the defendant.
3. The cloud services contract is required to document the actions that will take place at the start and end of the agreement to ensure appropriate establishment and closure of contracted services.
4. Ensure SLA's are in place for e-discovery requests in the event of a litigation response, further understand the liability implication of actions by your employees when using cloud services.

Services Reporting

5. Provide the cloud services provider with a definition and understanding of the organisation's control requirements.
6. Document current state controls posture of the cloud services provider against organisational requirements.
7. Establish reporting against the organisation's compliance requirements.
8. Ensure organisational structures are in place to provide continuous real-time reporting for services being consumed.
9. Ensure independent verification of detective and preventative technology controls are in place to validate confidentiality, integrity and the availability of cloud sourced data and information assets.

Service Management

10. Establish clearly documented roles and responsibilities for service provisioning including access and identity services.
11. Establish and agree on change management procedures to ensure that critical dependencies on the cloud providers' systems are understood such that they do not impact the overall service.
12. Establish and agree on incident management and response procedures that will be enacted in the event of a breach.
13. Ensure service availability parameters and thresholds are appropriately defined and agreed.
14. Ensure the cloud service provider understands their data lifecycle management obligations including backup, recovery, storage and archive.
15. Ensure request fulfilment procedures and associated processes are in place for access to the organisation's data assets in non-proprietary format and the length of the transition period at the end of the contract.

Data Security

16. Ensure that the cloud services model you chose aligns with your risk tolerance and acceptance thresholds, and that the cloud services model is commensurate with the sensitivity and/or classification of the data being stored/processed in the cloud.
17. Understand and document clear data ownership obligations and accountability of actions in the event of a breach.
18. Ensure your legislative obligations for data protection and management are addressed.
19. Understand where your data is being hosted and any impact the host country's privacy laws will have on your data.
20. Understand the legislative obligations that foreign owned vendors may be subject to (with regard to their local country's laws) whilst operating within your country.
21. Understand the architecture of the cloud service and the proposed solution to ensure the isolation of tenant applications is appropriate and in line with your policies and data security standards.
22. Ensure the cloud services provider has a secure gateway environment that is certified by an authoritative third party and the infrastructure is using validated products meeting federal or national standards.
23. Ensure there is strong encryption at the gateway, further supported by robust threat monitoring and secure logging of all access to applications and infrastructure instances hosting your data assets.
24. Ensure and validate the cloud service provider's police check and employee vetting procedures.
25. Ensure the cloud services provider has robust incident response and breach notification processes in place that are in-line with your own security incident response processes, and that they will support forensic investigation if required.


Latest Features

  • Security threats, hackers and shadow IT still plague health IT

    Security threats, hackers and shadow IT still plague health IT

    Security has long been a primary challenge in the health IT market, and two new reports help illustrate the vulnerabilities surrounding some of the most sensitive consumer data.
  • Why integrated social suites are failing marketers

    Why integrated social suites are failing marketers

    Most enterprise technology eventually converges into a suite, as it did with ERP. Integration hassles, management headaches and training challenges arising from a mishmash of best-of-breed solutions drive frustrated enterprise software buyers to the suite life -- but not in marketing tech, at least not yet.
  • 3 steps to digitizing your work for maximum productivity

    3 steps to digitizing your work for maximum productivity

    From the earliest days as a marketing slogan, the elusive concept of the so-called paperless office may finally be taking shape, if anecdotal evidence is anything to go by. A growing number of small businesses and startups, unencumbered by legacy processes, are quietly ditching printouts for an all-digital ecosystem, buoyed by soaring BYOD ownership and growing familiarity with a plethora of cloud services.
  • Attracting millennials starts with digital tech

    Attracting millennials starts with digital tech

    The ways millennials use technology are changing how companies brand themselves to attract young talent. However, according to a new study from the CMO Council and Executive Networks, most marketing and HR leaders don't have brand strategies that align with millennial preferences.
Latest Videos

Vishal Dhupar: NVIDIA is taking Graphics Virtualization to the next level

Vishal Dhupar, MD - South Asia, NVIDIA, talks cloud GPU, the power of graphics virtualization and how NVIDIA is going to be one of the cornerstones of the smart city pie.

Revisiting Customer Strategy Pays: Ram Kumar R, Gemini Communication

R Ram Kumar, Director of Chennai’s Gemini Communication (GCL), explains at length why an overhaul of GCL’s customer strategy and re-establishing connect were vital in helping the company bounce back.

Praveen Sahai: EMC has Consolidated its Channel Partner Strategy

Praveen Sahai, VP Channels, India & SAARC is upbeat about EMC's 3 P channel strategy

EDITOR'S PICK

Why Flash Storage Will Rule: Analysts

Analysts say flash storage’s enviable speed and performance are stirring up a revolution in the Indian storage market, opening new opportunities for organizations. 

3 steps to digitizing your work for maximum productivity

From the earliest days as a marketing slogan, the elusive concept of the so-called paperless office may finally be taking shape, if anecdotal evidence is anything to go by. A growing number of small businesses and startups, unencumbered by legacy processes, are quietly ditching printouts for an all-digital ecosystem, buoyed by soaring BYOD ownership and growing familiarity with a plethora of cloud services.

Is the information security industry having a midlife crisis?

The information security industry is hot right now, but it's hot because it's failing. The daily announcements about breaches and lost data confirm that criminals are winning the security battle, but how can InfoSec reposition itself in order to win the war?

SLIDESHOWS

The State of the Internet

Akamai's Q1 2015 state of the internet report provides insights into key global statistics including connection speeds, broadband adoption (fixed and mobile networks), and IPv4 exhaustion and IPv6 implementation.

India Software Market on an Upswing

According to IDC, the Indian software market has witnessed consistent growth of 10 percent since the second half of 2014, showing signs of growth and revival. 

7 Jobs Technology Has Replaced

Albert Einstein said once that it has become appallingly obvious that our technology has exceeded our humanity. With every invention of technology some poor soul becomes vulnerable to losing his or her job in some corner of the world. Here are few jobs that will cease to exist soon.

Changing Fortunes of Top Tech Companies

The tech sector has been led by these companies for a long time. But how have they fared over the quarters?

India's Leading VADs

Why Channels Want to Partner With Inflow Technologies

Inflow Technologies’ tie up with 39 vendor companies, an extensive tech portfolio, and a services play, are great value propositions for enterprise channels, says its President and CEO, Byju Pillai.

iValue Creates Real Value for Channels in India

Focused on niche vendor alliances around data, network and app management backed by a robust channel ecosystem marked iValue's success in 2014. What clicked for the seven-year-old VAD?

RAH Infotech Shows Channels the Way Ahead

Mutual trust and long lasting bond with vendor companies and channel partners helps VADs to evolve and succeed in today’s aggressively competitive market. Leveraging competent channel partners and forge niche vendor alliances marks RAH Infotech’s success in 2014.

How Satcom Infotech is Adapting to New Security Landscape

As a leading value added distributor, Satcom Infotech is emerging as an end-to-end security player, helping both customers and partners grow.

How ComGuard Shields Channel Partners

As emerging technologies introduce new threats to the enterprise landscape, they are making channel partners anxious. But VADs like ComGuard are putting their worries to rest. Here's how.

Tech Chat

Collaborating To Outcome Based World: Priyadarshi Mohapatra, Avaya

Priyadarshi Mohapatra, Managing Director, India and SAARC, Avaya, on how IT is transitioning from a keep-the-lights-on role to one that enables customers to deliver results.

The Dawn of the Digital Age: Akhilesh Tuteja, KPMG

The development of digital infrastructure will be a key growth driver for technology and solution providers. 

Paradigm Shift from End-Users to User-First : Parag Arora,Citrix

Parag Arora, Area Vice President and India Head, India Sub-continent, Citrix, says new technologies will force organizations to take a user-first approach in 2015.

Mobile and Cloud Are Gamechangers of the Future: Karan Bajwa, Microsoft

Karan Bajwa, Managing Director, Microsoft India, says, in  2015, organizations will adopt a mobile-first and cloud-first strategy to get ahead of competition.

A Network for the Internet of Everything : Dinesh Malkani,Cisco

Dinesh Malkani, President, India and SAARC, Cisco, talks about IoT and the significant technology transitions in the networking world.

Moving to the Third Platform: Jaideep Mehta, IDC

Cloud and mobility are the two technologies that will fuel the rapid adoption of the third platform in India.

Envisaging a Holistic Security Strategy For 2015: Sanjay Rohatgi,Symantec

Sanjay Rohatgi, President–Sales, Symantec India, says the company has a set of holistic solutions in place to secure organizations from security threats. 

Beating the Bad Guys: Sivarama Krishnan, PwC

Organizations will need to turn inwards to establish robust information security strategies.

Building Capabilities for a Digital Tomorrow: Alok Ohrie,Dell

Alok Ohrie, President and Managing Director, Dell India, on the company’s investments to build end-to-end solutions and delivery capabilities for a digital world.

FAST TRACK

Kamtron Systems

Transitioning towards a service-oriented company will boost our growth, believes Kavita Singhal, director, Kamtron Systems.

TIM Infratech

Delivering ‘best of breed’ technologies to enterprises is key to success, says Monish Chhabria, MD, TIM Infratech

Mudra Electronics

A vendor-agnostic strategy helped us sustain business, says Bharat Shetty, CMD, Mudra Electronics.

Systematix Technologies

Our USP is a customer-friendly approach backed by services, says Akhilesh Khandelwal, Director, Systematix Technologies.

CorporateServe Solutions

Our ability to turnaround complex ERP projects in record time is what gets us customer referral, says Vinay Vohra, Founder & CEO, CorporateServe Solutions.

KernelSphere Technologies

We are emerging as an end-to-end systems integrator, says Vinod Kumar, MD, KernelSphere Technologies.

Uniware Systems

We constantly validate emerging technologies for first-mover advantage, says Vergis K.R., CEO, Uniware Systems.

Astek Networking & Solutions

An innovative approach helps us stay successful, says Ashish Agarwal, CEO, Astek Networking & Solutions.

CSM Technologies

Our approach is backed by innovation and simplicity, says Priyadarshi Nanu Pany, CEO, CSM Technologies.

SOCIAL MEDIA @ CW India
SIGNUP FOR OUR NEWSLETTER

Signup for our newsletter and get regular updates.