41
Security in the Cloud Cloud Control 5 September 2013

Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Security in the Cloud Cloud Control 5 September 2013

Page 2: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

The Procurement View

Carol-Anne Stonefield

Technology Procurement Manager

Direct Line Group

Page 3: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Topics for Today

• Why opt for cloud?

• Understanding the Risks

• Proliferation and Control

• Data and Security

• Disaster Recovery and Back-up

• Standardisation

• Capacity and Integration

• Term, Exit and Lock-in

• Reliability and Remedies

• Costs

• Conclusion

Page 4: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Why opt for cloud?

• Speed

• Flexibility

• Easy

• During periods of change/freeze

• Avoids direct infrastructure investment

• Bypass IT

Page 5: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Understanding the Risks

Understand what you are putting in the cloud!

Page 6: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Proliferation and Control

• How many cloud providers do you have? Are you sure?

• Duplication

• Who has your data?

• Due diligence

• Management and administration

• Tactical (long-term) solutions

CONTROL!

Page 7: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Data and Security

• How is the data stored?

• Who is storing the data?

• What type of data is stored?

• Where is the data stored?

• DPA, PCI and your organisation’s responsibilities

• Data retention

• Security testing and audits

• Reputational damage

Page 8: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Disaster Recovery and Back-up

• Provider’s DR processes

• Impact of a DR event

• DR recovery times

• DR location

• Back-up frequency obligations

Page 9: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Standardisation

One size does fit all!

Page 10: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Capacity and Integration

• Capacity

• Understand the limits

• Capacity overload – what happens next?

• Integration

• Is it really plug and play?

• Compatibility

• Upgrades

Page 11: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Term, Exit and Lock-in

• Choosing the right term

• Understanding the supplier’s investments

• Migration of data

• Return of data

• Exit obligations

Page 12: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Reliability and Remedies

• Reliability and availability

• Calculating availability

• Reporting

• Service credits

• Regulatory implications

• Reputational risk

Page 13: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Costs

• Understanding the complete package

• Volumes, users, capacity and set-up

• Committed volumes

• Flexible options

• Volume/capacity increases

• Reaching maximum capacity or volumes

• Term commitments

• Renewal fees

Page 14: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Advice from within

You’re not alone!

• IT Security

• Information specialists

• Project members

• Business users

• CIPS papers

Page 15: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Conclusion

Cloud solutions will continue to grow and evolve

Understand the risks

Go in with your eyes open!

Page 16: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

The Legal View

Jason McQuillen

Principal at radiant.law

+44 751 358 5596

[email protected]

Page 17: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

16

Page 18: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

17

Page 19: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

18

Page 20: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

19

Encryption

Penetration testing

Page 21: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

20

Page 22: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

21

Page 23: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

22

Page 24: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

23

Page 25: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

24

Page 26: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

25

Page 27: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

The art of the possible

Alex Hamilton

Principal at radiant.law

+44 7734 908 207

[email protected]

Page 28: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

You can have any colour….

…. as long as it’s black

Page 29: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Private Cloud Public Cloud

£ Large/ High Leverage

£ Small/ Low Leverage

Page 30: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Private Cloud Public Cloud

£ Large/ High Leverage

IT Outsourcing Agreement - Negotiable

Customer paper

£ Small/ Low Leverage

IT Services Agreement - Negotiable

Supplier paper

Page 31: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Private Cloud Public Cloud

£ Large/ High Leverage

IT Outsourcing Agreement - Negotiable

Customer paper

£ Small/ Low Leverage

IT Services Agreement - Negotiable

Supplier paper

Risk analysis Supplier paper

Page 32: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Private Cloud Public Cloud

£ Large/ High Leverage

IT Outsourcing Agreement - Negotiable

Customer paper

Negotiable Supplier paper

£ Small/ Low Leverage

IT Services Agreement - Negotiable

Supplier paper

Risk analysis Supplier paper

Page 33: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Supplier Customer

standardisation policy requirements

Page 34: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Supplier Customer

standardisation policy requirements

margins total cost of ownership

Page 35: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Supplier Customer

standardisation policy requirements

margins total cost of ownership

systemic exposure material penalties

Page 36: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Supplier Customer

standardisation policy requirements

margins total cost of ownership

systemic exposure material penalties

guaranteed revenue flexibility

Page 37: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Supplier Customer

standardisation policy requirements

margins total cost of ownership

systemic exposure material penalties

guaranteed revenue flexibility

ability to evolve certainty

Page 38: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Supplier Customer

standardisation policy requirements

margins total cost of ownership

systemic exposure material penalties

guaranteed revenue flexibility

ability to evolve certainty

speed to contract fitness for purpose

Page 39: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve
Page 40: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

Panel Discussion

• Khurram Ijaz

• Carol-Anne Stonefield

• Alex Hamilton

• Anna Cook

Page 41: Security in the Cloud - CIPS and Events/CIPS Cloud Control... · • Project members • Business users • CIPS papers Conclusion Cloud solutions will continue to grow and evolve

www.radiantlaw.com