9
CLOUD RISK ASSESSMENT B Ribbeck, J Grochow, A Crosswell, M Scarborough, J Denune, A Keating

CLOUD RISK ASSESSMENT B Ribbeck, J Grochow, A Crosswell, M Scarborough, J Denune, A Keating

Embed Size (px)

DESCRIPTION

Risk Case #1  Flight Risk: Exiting faculty with personally owned cloud service containing institutional data purchased with institutional funds.  John Denune

Citation preview

Page 1: CLOUD RISK ASSESSMENT B Ribbeck, J Grochow, A Crosswell, M Scarborough, J Denune, A Keating

CLOUD RISK ASSESSMENTB Ribbeck, J Grochow, A Crosswell, M Scarborough, J Denune, A Keating

Page 2: CLOUD RISK ASSESSMENT B Ribbeck, J Grochow, A Crosswell, M Scarborough, J Denune, A Keating

AGENDA

Five + quick use cases defining RISK in cloud services for discussion.

These Risks are not usually defined in Risk Assessment Frameworks

RISK = P(something bad happens) Rules of discussion:

10 minutes total per risk case Not necessarily a search for a solution.

Discussion round up the last few minutes or ask the audience for to write in a Risk case of their own for sharing on the list.

Page 3: CLOUD RISK ASSESSMENT B Ribbeck, J Grochow, A Crosswell, M Scarborough, J Denune, A Keating

Risk Case #1

Flight Risk: Exiting faculty with personally owned cloud service containing institutional data purchased with institutional funds. John Denune

Page 4: CLOUD RISK ASSESSMENT B Ribbeck, J Grochow, A Crosswell, M Scarborough, J Denune, A Keating

Risk Case #2

Financial Risk: OpEX vs CapEx i.e. cloud != free J Grochow

Page 5: CLOUD RISK ASSESSMENT B Ribbeck, J Grochow, A Crosswell, M Scarborough, J Denune, A Keating

Risk Case #3

Risk Ownership: Balancing speed of deployment and management with scalability by offloading RA to service owner. Barry Ribbeck

Page 6: CLOUD RISK ASSESSMENT B Ribbeck, J Grochow, A Crosswell, M Scarborough, J Denune, A Keating

Risk #4

Failure Risk: Not with my data, Faculty Governance slowing down the move to the cloud. Not presented at CSG

Page 7: CLOUD RISK ASSESSMENT B Ribbeck, J Grochow, A Crosswell, M Scarborough, J Denune, A Keating

Risk #5

Technology can’t solve social issues: Not all problems can be resolved by IT by using a cloud solution. Not presented at CSG

Page 8: CLOUD RISK ASSESSMENT B Ribbeck, J Grochow, A Crosswell, M Scarborough, J Denune, A Keating

Risk #6

Change Detected: Keeping up with TOS changes. Cloud solutions often come with a condition for changes of the Terms

Of Service that are evolutionarily fast paced. Who keeps up with the changes and how is the institution protected.

A Crosswell

Page 9: CLOUD RISK ASSESSMENT B Ribbeck, J Grochow, A Crosswell, M Scarborough, J Denune, A Keating

Risk #7

Asset Management Risk: Cloud services empower user to be their own IT shops but even cloud services can be poorly managed. How do we as IT help customers manage cloud resources and be

responsible cloud users. Not presented at CSG but some discussions tangential were

presented