Compliance

Feature Article

The Element of Trust in Cloud Messaging

The traditional model of deploying email, security, archiving, backup and related solutions using on-premise servers and software (or appliances) requires a certain amount of trust—trust in the technology offered by the hardware and software vendors, trust in the quality of the ways these technologies have been implemented, trust in the responsiveness of their support when things go wrong, trust in the patches and upgrades that are offered, and so forth.

However, for those charged with managing these capabilities in the cloud, an almost quantum leap increase in the level of trust is required of the providers offering these services for the simple reason that data is now in the hands of a distant third party. Not only must decision makers place trust in the quality of the hardware and software deployed in the cloud providers’ data centers, the ways their technologies have been implemented, the responsiveness of support staff, etc., but now trust must be placed in several other attributes of the provider(s). These include the quality of the technical team managing the cloud data center, the quality of the management team that runs the business, the overall financial health of the cloud provider’s business, their integrity in managing sensitive and confidential customer data, and their responsiveness in migrating data back to their customers for any reason.

Fundamentally, this creates four primary responsibilities—two for prospective customers of cloud providers and two for the providers themselves:

  1. Customers must carefully define the service levels, migration strategy, archiving strategy, messaging policies and every aspect of their communication and collaboration capabilities that might move to the cloud. Many organizations have not yet established detailed and thorough messaging policies, for example, and so are simply not ready to migrate capabilities to the cloud.
  2. Due diligence is extraordinarily important in selecting cloud providers because of the high stakes involved. Cloud vendors must be vetted on a number of parameters, including their business model, financial health, uptime, backup strategies, and redundancy. While due diligence is important when selecting on-premise solutions, an order of magnitude more care must be applied when vetting cloud providers.
  3. Cloud providers must implement a range of technologies and best practices to ensure that customer data is maintained securely, it can be migrated from and back to customers with a minimum of time or pain, and they must be sufficiently capitalized to ensure that the business keeps running even in difficult economic times.
  4. Finally, cloud providers must offer a level of transparency into their operations that will satisfy decision makers charged with evaluating them.

It’s important to note that I’m not arguing against the use of small and/or startup cloud providers. Many of them have solid business models, provide excellent service and have a good record of uptime. Large does not necessarily imply that superior service will be offered, nor does small necessarily imply the opposite.

The bottom line is trust: successful use of the cloud to run critical business operations demands it.

A bill intended to control rogue Web sites that offer material that infringes on copyrights and trademarks made a comeback in May, reports the Center for Democracy & Technology. Formally known by...
A new report was made available last week from Trusted Computing Group (TCG), and Ponemon Institute entitled “Perceptions about Self-Encrypting Drives: A Study of IT Practitioners.” The...
Osterman Research
I had the privilege of attending a couple of sessions at the MAAWG (Messaging Anti-Abuse Working Group) conference in San Francisco yesterday. The keynote was given by Dr. Marcus Jakobsson, principal...
Eye on Messaging
While only half-way through the year, 2011 may be best remembered as the year of spectacular hacking and breaches. The headlines this year are full of well-known brands being attacked. From the RSA...
With severe consequences for non-compliance, email messaging security can no longer be ignored; more and more organizations and people contend, it is now a “must have.” But the...
Attackers are no longer targeting web and email servers, contends Zscaler, instead they are attacking enterprises from the inside out, by first compromising end-user systems and then leveraging them...
At FINRA’s 2011 Annual Conference this week, new survey results of compliance professionals in the financial services industry found extensive compliance gaps exist in electronic recordkeeping and...
On May 19, 2011 the ITU , the United Nations agency for information and communications technologies, cemented new global partnerships designed to make cyberspace a safer, more secure place to be...
Symantec Corp. announced it has signed a definitive agreement to acquire privately-held Clearwell Systems, Inc., a recognized leader in the eDiscovery market. The acquisition of Clearwell enhances...
Syndicate content