Economic arguments for cloud services migration
Cloud Services Compliance Issues
Compliance is a system or organisation’s accreditation for meeting the conditions of particular standards, recognised legislation, regulatory guidelines or industry best practices that can be jointly classified as a compliance framework. A compliance framework can include business processes and internal controls the organisation has in place to adhere to these standards and requirements. The compliance framework should also map different requirements to internal controls and processes to eliminate redundancies. Why is compliance important for the cloud? When moving to the cloud, the organisation moves from an internal security and operational environment (that may not be formally defined) to external operational security that will become a part of an SLA (or business requirement) with the CSP. Compliance in this case will imply a defined, expected level of security and assurance for the cloud-based system. The table below depicts a set of standards and regulatory requirements that are commonly considered for cloud compliance. They are separated into two groups: ‘General standards & recommendations’ and ‘Sectoral ones related to industry and government’ –
Standards/Regulation Name (with Description) Acronym
(if applicable)
General standards and recommendations
ISO/IEC 27001:2005 Certification on security infrastructure
Industry standard: the risk-based information security management program that follows a plan-do-check-act process
ISO/IEC 27001
Service Organization Control SOC 1 (SSAE 16/ISAE 3402) and SOC 2 and 3 (AT 101)
• SOC 2 is a new attestation report for service organisations that
contains rigorous standards for security, availability, processing
integrity, confidentiality and privacy.
• SOC 3 report which summarizes the SOC 2 audit
SOC 1 (SSAE
16/ISAE 3402) SOC 2
SOC 3
NIST SP 800-144 Guidelines for Security and Privacy in Cloud Computing NIST SP 800-144 Cloud Security Alliance, Security Guidance for Critical Area of focus in
Cloud Computing
ENISA Cloud Computing Security Risk Assessment ENISA European Union Data Protection Directive Content Protection and Security Standard (CPS) is sponsored by the
Content Delivery & Security Association (CDSA).
The CPS framework focuses primarily on the security management of media content in all of its forms across the entire supply chain. It is composed of an independent and impartial audit of risk management, personnel resources, asset management, logical and physical security and disaster recovery planning.
CPS CDSA
Industry and government related (Sectoral) Payment Card Industry Data Security Standard (PCI-DSS) PCI DSS Cloud Addendum
PCI-DSS
Sarbanes-Oxley Act (SOX)
‘Public Company Accounting Reform and Investor Protection Act’ and
‘Corporate and Auditing Accountability and Responsibility Act’
SOX
HIPAA/HITECH - The US Health Insurance Portability and Accountability
Act (HIPAA) and HITECH (Health Information Technology for Economic and Clinical Health)
Act created by the US federal government includes provisions to protect
patients' private information.
HIPAA/HITECH
FISMA Certification and Accreditation - The Federal Information Security
Management Act of 2002 (FISMA)
Describes security requirements which US federal agencies expect to be in place for the protection of information and information systems.
FISMA
Gramm-Leach-Bliley Act (FGLBA) FGLBA
Federal Risk and Authorization Management Program (FedRAMP) FedRAMP
Department of Defense Information Certification Accreditation Process
(DIACAP)
DIACAP
DOD
Table 1: Major cloud compliance standards and regulations
All of the major CSPs provide indications of the various standards that they comply with, as follows – AWS cloud certification and compliance: The AWS cloud infrastructure has been designed and managed in alignment with regulations, standards and best practices, including: • ISO/IEC 27001:2005 • SOC 1, SOC2, SOC3 • FIPS 140-2 • CSA • PCI DSS Level 1 • HIPAA • ITAR • DIACAP and FISMA • FedRAMP (SM) • MPAA Amazon AWS Cloud is also certified for hosting US governmental services. Microsoft Azure cloud certification and compliance: Microsoft services/infrastructure meets the following key certifications, attestations and compliance capabilities: • ISO/IEC 27001:2005 certification on security infrastructure • SOC 1 (SSAE 16/ISAE 3402) and SOC 2 and 3 (AT 101); obtained in 2008 and 2012 • Cloud Security Alliance (CSA) Cloud Controls Matrix • NIST SP 800-144 Guidelines for Security and Privacy in Cloud Computing • PCI Data Security Standard Certification level 1 • HIPAA and HITECH • FISMA Certification and Accreditation – since 2010 • Various state, federal, and international Privacy Laws (95/46/EC, e.g. EU Data Protection Directive, California SB 1386, etc.) Rackspace Open Cloud certification and compliance: Rackspace lists the following standards compliance: • ISO 27001 • ISO 27002 • PCI-DSS SSAE16 • SOC 1 • SOC 2 • SOC 3 • Safe Harbor • Content Protection and Security Standard (CPS) Verizon Terremark: Verizon Terremark lists the following standards compliance: • ISO 27000 • NIST 800-53 • FIPS • PCI DSS • HIPAA • SAS70 Type II • HB 1386
- Cloud Services Compliance Issues
- Table 1: Major cloud compliance standards and regulations
- AWS cloud certification and compliance:
- Microsoft Azure cloud certification and compliance:
- Rackspace Open Cloud certification and compliance:
- Verizon Terremark: