Friday, March 25, 2011

Cloud Computing - The Risk Management Aspect

Cloud Computing is the Buzz Word that has caught the lime light in recent years and it is indeed interesting to see where does it go from here?  Will it be Hype or will it be a successful Marketing Gimmick by the Infrastructure Services Providers and the OEMs.  There has been a lot written and lot deliberated over the cloud security and cloud compliance, but the main case here is the case of Risk Management in Cloud Computing.  It is pretty important for the CIOs and the CFOs to understand the Risks as associated with the Cloud Computing Infrastructure.  Specifically in the Light of the Data Security and the Data Privacy requirements.  I am sure none of the CIOs and for that matter CXOs would ever want to fall in the trap where the data movement in cloud scenario would impact the Regulatory Compliance scenario with Cross Border Data movement on Cloud Infrastructure spanning across geographical locations.

I remember during one of my discussion with my colleagues, where I was skeptical about the data privacy issues.  It was one of the situation where I was pitted against the team of Architects who were pretty confident about building a solution providing the business benefit to the client.  But on my question - "What is the Geographical Span of the Cloud that you are looking at?" oops that was like a jolt from Blue for the Architects and they were looking for a definite answer, but to no avail.

In another offline discussion with one of the CSO friend of mine, the same question stumped him too.  His company was looking at Cloud Based Email Solution from a leading Service Provider.  My question to him was followed by another on the type of Data that flows on email.  It is interesting to note that Corporate emails carry attachments right from Employee details to Corporate Financial Performance and Business Strategies.  That means from Company HR, Marketing, Legal and Financial Data flows on Corporate Emails.  Interestingly, the organization didn't go for the Cloud Email Solution, as they could not find an answer to the question of Risk Management while going for Cloud based Email Solution.

I am still trying to look for an Answer from the Experts around on the questions a pitted above.  I would love to get an answer on the question of Managing Risks in a Cloud Based Computing Solution!!!