Cloud computing may spawn compliance as a service
- 26 March, 2009 15:07
- Comments
With the growth of cloud computing, enterprises may soon be having conversations about compliance as a service as they seek to deal with the legislative and compliance requirements around protecting personally identifiable customer data.
According to Peter Coffee, director of platform research at Salesforce.com, no matter how much the IT industry thought government regimes were out of touch with their legislation when it came to technology, compliance and legislation could not be avoided when it came to cloud computing.
“[Governments] have the gun and can put us in jail if we fail to respect their rules, no matter how much we feel they may be out of date,” he said at IDC’s cloud computing summit in Sydney.
“There are composite solutions [to compliance issues]: build the application in the cloud using nothing but anonymous tokens to identify customers… but that is not trivially easy to do,” he said.
“Instead, compliance as a service maybe be offered where [the service provider] acts as an intermediate layer of your application that takes care of a variety of things. They could indemnify the customer against any issues around personally identifiable information crossing boundaries.”
Under such a compliance service, a service provider would accept the burden of knowing the rules, court precedents and regulations which are industry-specific, Coffee said. Responsibility to sanitise data wherever it left the country over a broadband link would move from the customer to the service provider.
“Layers upon layers of new services will emerge representing new layers of expertise and therefore new layers of profitability for those providing services with that kind of value. I think that’s happening now and more so all the time.”
Linus Lai, associate consulting director at IDC, said that the government, defence, health care and banking sectors in particular were subject to compliance issues around data privacy and protection laws and standards.
Given the potential liability costs for a compliance service provider and the sheer number of regulations enterprises faced, providing a one stop shop compliance service would be a significant challenge.
“Compliance with regard to cloud computing is largely around the location of customer data, but at last count there were more than 1000 different types of regulation and compliance standards that relate to IT,” he said.
It was more likely that the fact that compliance touched areas as broad as IT security, enterprise search, data retention and archiving, that service organisations would likely continue to provide specialised services around compliance, Lai said.
“There is no silver bullet for compliance,” he said.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- How to Choose an SMB - Unified Communications as a Service (UCAAS) Solution
- Pathways Advanced ICT Leadership Development Program Brochure and Course Outline 2012
- HP ALM YouTube channel – Demonstration videos
- IBM zEnterprise System Brings Hybrid Computing Capabilities to Midsize Organisations
- The Convergence of IT Operations Management
-
The 30 best Safari extensions -- so far
-
Apple and Google disagree over licensing of essential patents
-
Monash Uni reduces IT teams after consolidation project
-
FTC warns makers of background checking apps
-
QLD govt demands answers after pay glitch
-
Top 5 Threat Protection Best Practices
Small businesses are especially vulnerable to computer viruses and lost or stolen data, since they typically lack the IT resources to deal with these threats. Inadequately protected computers open the door to annoying infections, or worse, serious business disruption. Below are five simple and effective strategies to help you protect your business against an ever-increasing number of threats. -
Case Study: Keeping information on the move: Clearswift protects Maman, the logistics experts
Time is money. Every minute a consignment is held up in transit costs money and causes problems. Web and email are mission critical business tools that enable Maman, and their customers, to efficiently collaborate with partners across the globe. Spam, and other web based threats can result in delays that ultimately lead to missed deadlines - keeping the lines of communication open is therefore a key priority for Maman. Read on. -
Oracle IT Modernization Series Modernization: The Path to SOA
More and more organizations are looking to service-oriented architecture (SOA) as the basis of their future computer architecture. Recognizing that legacy application design and implementation approaches have led to applications that are costly to operate and maintain, hard to change, and rely on a dwindling set of skills, organizations are hoping that SOA provides a key component of the answer to these problems. Read on.
-
Java and Flex Integration Bible
-
Algorithms for Image Processing and Computer Vision
-
Teach Yourself Visually Mac OS X Snow Leopard
-
Red Hat Linux 9 Bible
-
Laptops Just the Steps for Dummies®
-
Teach Yourself Visually Excel 2007
-
Smartphone Operating System Concepts with Symbian OS - a Tutorial Guide
-
The Myth of Homeland Security
-
Drer All-In-One for Dummies











Comments
Post new comment