Advertisement
Promo

Online business Toolkit

Cloud Watch

Every cloud has a risky lining

Alan Calder

Published: 25 Jun 2009 12:31 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

...the basic starting point. When considering a SaaS subscription, look for organisations that are ISO27001 certified. Ask to see the supplier's Statement of Applicability to check the right controls are in place to meet your particular industry or organisational compliance needs.

Also check:

  1. What are the security arrangements at the vendor facility?
  2. What type of infrastructure is used to host client data?
  3. What virus protection is there and how regularly are vulnerability scans and penetration tests run?
  4. How often are the systems backed up and are system recovery processes in place?
  5. What level of data encryption is used to protect website transactions? How is compliance with relevant data privacy regulations ensured?
  6. Does the provider have a data back-up management process in place?
  7. Where and how are back-ups stored? And how are back-ups encrypted and secured?

You will also want to know what sort of continuity arrangements are in place — look for BS25999 certification. Check that there is a service-level agreement that guarantees a specific amount of uptime. Also, find out what happens in the case of equipment breakdown and power failure? In addition, is the facility scalable? And is it monitored continuously?

Finally, there are big challenges involved in getting any sort of IT service right, let alone a new one like SaaS. However flexible SaaS is, you still have a significant time investment to get your application set up and configured so that it meets your business needs. Never underestimate the time required: a move to the cloud will need a project team, with a clear timeline, and lots of end user participation.

Then there is the impact on users: remember you may have to change internal processes to accommodate the limitations of whatever you are deploying.

All in all, approached with some forethought the specific cloud and general IT good-practice issues can be resolved. The subscription-based computing model offers benefits that cannot easily be ignored, but do not ignore the associated risks either.

Alan Calder is chief executive of security and compliance organisation IT Governance. IT Governance is the publisher of Application security in the ISO27001 environment.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
10 out of 10 people found this useful


Full Talkback thread

0 comments

More in this Special Report

Roundup: Cloudwatch special report

Roundup: Cloudwatch special report

Untangle the hype and the promise, the good and the bad, the risks and the benefits of cloud computing more

Cloud clout: Who are the real powers in the cloud?

Cloud clout: Who are the real powers in the cloud?

Cloud computing looks like it will reshape the IT landscape, but which vendors are the real powerhouses behind that change. We pick out the Big Five — plus one to watch more

Five cloud computing myths exploded

Five cloud computing myths exploded

The cloud is providing a fertile habitat for the marketeers and their exaggerated claims. We examine the hokum and debunk the five most frequently peddled misconceptions about the cloud more

Cloud savings fail to make up for loss of control

Cloud savings fail to make up for loss of control

The price of a cloud service is not necessarily the most important factor. That's because cost is always trumped by control, says Rafe Needleman more

Amazon gives users more cloud control

Amazon gives users more cloud control

Amazon Web Services unveils new features that let users monitor, adjust and balance its cloud services more

Cloud won't become standard, says Kaspersky

Cloud won't become standard, says Kaspersky

At Infosecurity 2009, Eugene Kaspersky told ZDNet UK that businesses will use both traditional networks and cloud computing in the future more

Tech giants form open-cloud-standards group

Tech giants form open-cloud-standards group

A major systems-management standards body has formed a group dedicated to developing open management standards for cloud computing more

Q&A: HP plans reign of ink from the cloud

Q&A: HP plans reign of ink from the cloud

The company wants to move consumer printing away from PCs and onto the web, shedding drivers along the way more

Inside IBM's only European Cloud Centre

Inside IBM's only European Cloud Centre

IBM has set up its first cloud centre in Europe, and it is in Ireland, just outside Dublin more

What is the cloud's killer app?

What is the cloud's killer app?

SAP chief technology officer Vishal Sikka discusses the next big thing in cloud apps at the Interop conference in Las Vegas more

Video: Who is really moving to the cloud?

Video: Who is really moving to the cloud?

A panel of experts offer their take on what types of organisation are taking up cloud-computing services more

Four reasons why business will take to the cloud

Four reasons why business will take to the cloud

Over the next five years, there will be a huge financial incentive to make the switch to cloud computing — and it will be hard to resist, says Jason Hiner more

Company/Topic Alerts

Create a new alert from the list below:






Sentry Posts Blog

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

1 comment

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters