Economic arguments for cloud services migration

profileuntamedghost1
UKL1_CKIT_523_Wk8_LaureateEducation_CloudServicesComplianceIssues.pdf

Cloud Services Compliance Issues

Compliance is a system or organisation’s accreditation for meeting the conditions of particular standards, recognised legislation, regulatory guidelines or industry best practices that can be jointly classified as a compliance framework. A compliance framework can include business processes and internal controls the organisation has in place to adhere to these standards and requirements. The compliance framework should also map different requirements to internal controls and processes to eliminate redundancies. Why is compliance important for the cloud? When moving to the cloud, the organisation moves from an internal security and operational environment (that may not be formally defined) to external operational security that will become a part of an SLA (or business requirement) with the CSP. Compliance in this case will imply a defined, expected level of security and assurance for the cloud-based system. The table below depicts a set of standards and regulatory requirements that are commonly considered for cloud compliance. They are separated into two groups: ‘General standards & recommendations’ and ‘Sectoral ones related to industry and government’ –

Standards/Regulation Name (with Description) Acronym

(if applicable)

General standards and recommendations

ISO/IEC 27001:2005 Certification on security infrastructure

Industry standard: the risk-based information security management program that follows a plan-do-check-act process

ISO/IEC 27001

Service Organization Control SOC 1 (SSAE 16/ISAE 3402) and SOC 2 and 3 (AT 101)

• SOC 2 is a new attestation report for service organisations that

contains rigorous standards for security, availability, processing

integrity, confidentiality and privacy.

• SOC 3 report which summarizes the SOC 2 audit

SOC 1 (SSAE

16/ISAE 3402) SOC 2

SOC 3

NIST SP 800-144 Guidelines for Security and Privacy in Cloud Computing NIST SP 800-144 Cloud Security Alliance, Security Guidance for Critical Area of focus in

Cloud Computing

ENISA Cloud Computing Security Risk Assessment ENISA European Union Data Protection Directive Content Protection and Security Standard (CPS) is sponsored by the

Content Delivery & Security Association (CDSA).

The CPS framework focuses primarily on the security management of media content in all of its forms across the entire supply chain. It is composed of an independent and impartial audit of risk management, personnel resources, asset management, logical and physical security and disaster recovery planning.

CPS CDSA

Industry and government related (Sectoral) Payment Card Industry Data Security Standard (PCI-DSS) PCI DSS Cloud Addendum

PCI-DSS

Sarbanes-Oxley Act (SOX)

‘Public Company Accounting Reform and Investor Protection Act’ and

‘Corporate and Auditing Accountability and Responsibility Act’

SOX

HIPAA/HITECH - The US Health Insurance Portability and Accountability

Act (HIPAA) and HITECH (Health Information Technology for Economic and Clinical Health)

Act created by the US federal government includes provisions to protect

patients' private information.

HIPAA/HITECH

FISMA Certification and Accreditation - The Federal Information Security

Management Act of 2002 (FISMA)

Describes security requirements which US federal agencies expect to be in place for the protection of information and information systems.

FISMA

Gramm-Leach-Bliley Act (FGLBA) FGLBA

Federal Risk and Authorization Management Program (FedRAMP) FedRAMP

Department of Defense Information Certification Accreditation Process

(DIACAP)

DIACAP

DOD

Table 1: Major cloud compliance standards and regulations

All of the major CSPs provide indications of the various standards that they comply with, as follows – AWS cloud certification and compliance: The AWS cloud infrastructure has been designed and managed in alignment with regulations, standards and best practices, including: • ISO/IEC 27001:2005 • SOC 1, SOC2, SOC3 • FIPS 140-2 • CSA • PCI DSS Level 1 • HIPAA • ITAR • DIACAP and FISMA • FedRAMP (SM) • MPAA Amazon AWS Cloud is also certified for hosting US governmental services. Microsoft Azure cloud certification and compliance: Microsoft services/infrastructure meets the following key certifications, attestations and compliance capabilities: • ISO/IEC 27001:2005 certification on security infrastructure • SOC 1 (SSAE 16/ISAE 3402) and SOC 2 and 3 (AT 101); obtained in 2008 and 2012 • Cloud Security Alliance (CSA) Cloud Controls Matrix • NIST SP 800-144 Guidelines for Security and Privacy in Cloud Computing • PCI Data Security Standard Certification level 1 • HIPAA and HITECH • FISMA Certification and Accreditation – since 2010 • Various state, federal, and international Privacy Laws (95/46/EC, e.g. EU Data Protection Directive, California SB 1386, etc.) Rackspace Open Cloud certification and compliance: Rackspace lists the following standards compliance: • ISO 27001 • ISO 27002 • PCI-DSS SSAE16 • SOC 1 • SOC 2 • SOC 3 • Safe Harbor • Content Protection and Security Standard (CPS) Verizon Terremark: Verizon Terremark lists the following standards compliance: • ISO 27000 • NIST 800-53 • FIPS • PCI DSS • HIPAA • SAS70 Type II • HB 1386

  • Cloud Services Compliance Issues
  • Table 1: Major cloud compliance standards and regulations
  • AWS cloud certification and compliance:
  • Microsoft Azure cloud certification and compliance:
  • Rackspace Open Cloud certification and compliance:
  • Verizon Terremark: