AARNet submission to the Australian Computer Society Cloud Protocol Discussion Paper. James Sankar, Alex Reid August 2013

Size: px
Start display at page:

Download "AARNet submission to the Australian Computer Society Cloud Protocol Discussion Paper. James Sankar, Alex Reid August 2013"

Transcription

1 AARNet submission to the Australian Computer Society Cloud Protocol Discussion Paper James Sankar, Alex Reid August 2013 AARNet, Australia's Academic and Research Network (AARNet) is the not- for- profit company that operates Australia's National Research and Education Network (NREN). Our shareholders are 38 Australian universities and the Commonwealth Scientific and Industrial Research Organisation (CSIRO). We provide high capacity, leading edge internet and other advanced communications services to the nation's universities, health and other research organisations, schools, vocational training providers and cultural institutions. AARNet serves over one million end users who access the network and services for teaching, learning and research. Background AARNet understands that The Australian Computer Society has taken a lead role to coordinate industry and government consultation to fast track access to high quality, highly available, high performance cloud services. AARNet welcomes the opportunity to respond to the Australian Computer Society (ACS) Cloud Protocol Discussion Paper (July 2013). Cloud Computing has the potential to reduce costs by sharing expensive IT service platforms to deliver online services that can increase enterprise productivity and competitiveness. For cloud computing to be successful a combination of services need to be provided. These include: Access to high speed, reliable and secure data (Internet) network connectivity; Integration of suitably priced cloud services packages with business processes and systems; Appropriate regulation (especially for security and privacy); and Access to a competitive market of service providers for enterprise services and data storage solutions on a pay as you use basis. Under an appropriate framework, AARNet believes that cloud computing services should be embraced by Australian enterprises to complement local IT service and support delivery, via local and global providers. This will create new IT roles and innovation directly within Cloud Service Providers and indirectly through the business service productivity that cloud computing will offer. Strictly Commercial in Confidence Page 1 of 5

2 Question 1. Do you believe a voluntary protocol in which cloud suppliers provide undertakings and information about their services would improve confidence in the market and increase the adoption and take- up of cloud computing services? AARNet believes a protocol that embodies industry best practice is important for Small to Medium sized Enterprises (SMEs) and Not- For- Profit organisations (NFPs) to embrace the benefits of cloud computing. However the protocol needs to ensure Cloud Service Providers furnish open and transparent reporting of their service operations, so that customers are able to evaluate (or rank) product and service offerings, ideally employing assessments made by an independent organization. Page 10 of the ACS Cloud Protocol discussion paper suggests referencing cloud service resources as a one- stop shop for consumers, SMEs and NFPs. In order to achieve this goal, we would recommend results be provided online in an easily digestible format, with regular testing and ranking of service offerings, performance and cost as opposed to large often outdated reports. We believe that this will go furthest in improving confidence in the Cloud Computing and Services market. Regular independent audits of Cloud Service Provider contracts and hosted environments, to either meet an industry quality standard or a yet to be defined ongoing operational standard, would also be welcomed. Question 2a. If you are a potential user of cloud services, do you now have a better understanding of cloud computing and its benefits for your business or operations? What further information do you need to feel confident in deciding to adopt cloud services into your business? The table of benefits of Cloud Computing is a good start, and should help to improve enterprise appreciation of these benefits. We believe it could be enhanced with the addition of (a) some commentary on the potential dangers of Cloud services (with suitable rejoinders, of course), and (b) some real case studies. AARNet recommends enterprises undertake a cost benefit analysis of migrating services to cloud computing service providers. The total cost to purchase, deploy, operate, maintain and support a service and the degree of customization, flexibility, data provenance, security and privacy controls should be carefully examined. Should the provider be based outside Australia, the impact of the Australian dollar against other currencies such as the United States dollar and its fluctuation need to be accounted for, as well as the legislative jurisdictions in force in those countries, and any impact of increased network latency. Question 2b. If you are a provider of cloud services, is the description above of cloud services and the outline of its benefits accurate and comprehensive for prospective users who may know little of the details of cloud computing? We believe that the descriptions of Cloud services given in the Consultation paper represent a good starting point. See comments under Questions 1 and 2a. above as to how these descriptions can be improved. AARNet further believes that highly reliable, highly available and secure end- to- end network connectivity from the enterprise to cloud services is paramount, and that this has perhaps not been emphasized enough in the descriptions. We also believe that the customer will need to understand how to prioritize resources for specific service components (compute, storage, backup). These services can be provided to the enterprise as service packages (minimum, typical, premium), or as service components to activate as needed using a customer dashboard. Of course, customers may be tempted to adopt the minimum service levels, whilst expecting high performance or support for growth. Without careful configuration and tracking of usage, the enterprise may experience a sub- optimal experience based on its purchasing decisions. As enterprises move from fixed upfront capital costs for their computing services that can offer some buffer for the future growth, to pay as you use operating costs (often based on complex pricing models), the adage of you get what you pay for will become a more familiar one for cloud services. AARNet recommends that enterprises be mindful of the consequences of a growing dependency on Cloud Service Providers. They need to be able to forecast the growth of service consumption by customers, staff, and suppliers to determine a return on investment. They should be encouraged to establish a risk register and put in place a disaster recovery and data migration plan (for risk mitigation), which is regularly audited and tested to ensure any unforeseen service outages outside their control can be managed effectively. Data Sovereignty, Security and Privacy also need to be better understood so that enterprises can decide on whether to migrate to cloud services hosted in Australia or to other jurisdictions, in order to make realistic comparisons with current in- house solutions. Page 2 of 5

3 Question 3. If you are a potential or current user of cloud services, do you have other concerns about cloud computing that have not been outlined in this section? What are they? There are several aspects of Cloud Services that we believe need further elaboration, some of which we have included above under Questions 1, 2a. and 2b. We also raise a few more below. Cloud Service Performance the network access to and performance of Cloud Service Providers in the end- to- end delivery of services to end users is critical to the successful implementation and uptake of Cloud services within enterprises to support both the producers and consumers of content and services that rely on the cloud service platform. Availability of Services Cloud Providers, especially those in the US, tend to undertake scheduled maintenance outside US business hours that may impact Australian business hours. Furthermore, enterprises often have no opportunity to challenge or delay maintenance or any upgrades that may impact on the service interface or workflows. This may then require test and systems integration work, staff, supplier or consumer training and documentation changes at relatively short notice. Therefore the level of service integration with business processes may determine a greater or lesser impact of any such changes. AARNet recommends enterprises or third parties independently monitor the availability and performance of cloud services on a 24x7 basis to ensure Service Level Agreements are met. Copies of data data should be stored on multiple storage nodes with access to that data restricted to the customer. Backups of the data including versioning control should be supported to enable the rollback of data should data corruption occur. Termination of data Cloud Service Providers should provide enterprises with details of the process to be followed to migrate data away from the Provider s platform. They should also clearly state the time allowed for data to be migrated in the event that the either party chooses to do so. Security and Access Control - Cloud Service Providers should provide full details of the levels of physical and online access control, and of any supported data encryption capability available to prevent unauthorized access of username and passwords or any personal information, including credit card numbers. Cloud Service Providers may want to consider a loosely coupled model where the Cloud Service Provider operates the service platform, the platform accesses customer data hosted on the customer premise in a secure way and other data can be supported too, such as the services of a merchant bank to authorize credit cards, or the querying datasets hosted by a separate institution to provide a result. The decoupling of service from data that the enterprise staff, supplier or customer has requested may add complexity and integration challenges, but it does offer greater security and data ownership control back to the enterprise. Uncertainty about long- term service continuity many potential users of Cloud Services may be deterred by uncertainty about the long- term viability of Cloud Service Providers. Australian enterprises may well prefer to use Australian Cloud Service Providers (for instance, because they are worried about their data being held off- shore, or simply for network latency issues), but these local providers may not survive the intense competition (lower prices, stronger marketing) from bigger international providers, and may be forced out of business. This places enterprises in an invidious position: they have moved to the Cloud precisely to avoid having to worry about how well their data is being stored (for example), but suddenly they do have a very serious worry about the future of their data. This scenario has already been played out in the Australian research sector, where a Cloud storage service ( Data Fabric ) was fairly abruptly terminated when funding ceased in early 2013, leaving researchers who had relied on it having to discover alternatives for themselves. This does not induce confidence in moving to the Cloud. The same may be in the minds of enterprises considering moving to the Cloud. Page 3 of 5

4 Question 4. Are there other disclosures from cloud vendors that have not been outlined in this section? What are they? Disclosures are an important indicator of the ability of the Cloud Service Provider to meet their Service Level obligations. Whilst consumers and relevant authorities need to be informed, it remains unclear how prospective customers can make an informed choice without relying on the media and online discussion forums for publicly available data. Should a provider consistently fail in meeting their obligations (in ways such as listed below), should Australia consider a level of national accreditation? The performance of network, compute, storage components against Service Level Guarantees should be disclosed. Statistics should be provided on the mean time to repair for both scheduled and unscheduled outages. Any breaches or loss of any customer data should be revealed (in case the mandatory legislation is not in place by March 2014). Question 5. Can you outline any experiences you have had with cloud computing which illustrate issues such as data security, data location, privacy or vendor lock- in? Whilst we are unable to provide hands on experiences, we can share how AARNet has attempted to address the issue of data location to deliver a shared storage service. AARNet provides a Cloud- based file transfer service (called CloudStor ) and a Cloud storage service (called CloudStor+ ) that offer uniquely high speed data throughput rates of an order of magnitude greater than available elsewhere. AARNet is able to support these speeds due to the operating infrastructure being hosted directly onto the AARNet4 network at various locations in Australia to which AARNet s Research and Education customers directly connect. The service supports direct high- speed network access data replication. The cost to develop the storage infrastructure and application was considerably lower than if customers had built their own. Furthermore, The Government- funded Research Data Storage Infrastructure (RDSI, which is a national storage array, is likely to be integrated with the CloudStor+ application further leveraging ICT investments for the Australian Research community. Australian located Cloud Service Providers are likely to offer greater network access and cloud service performance levels than overseas counterparts should customers, staff and suppliers be based here. For globally located businesses, the global Cloud Service Provider footprint offers new operating models that are worth exploring. Question 6. If you are a provider of cloud services and products, what is the current state of market confidence in cloud computing, and are there any outstanding transparency issues that concern users? If so, what is the best method of addressing these concerns? AARNet believes that enterprises may move to cloud computing without a comprehensive assessment of the end- to- end costs and benefits for the short, medium and long term. Cloud computing can indeed offer cost effective solutions for operating online services, without the need to manage in- house legacy equipment and services. Cloud computing can enable the re- deployment of staff from back- room tasks to customer focused high touch support and development. However, the costs of end- to- end network access and systems integration and growth in use of services, the degree of dependency on third parties, the effort required to manage third parties, contracts, data ownership and data migration need to be taken into account. We propose two ways to address these issues: (a) establish a best practice cookbook for enterprises, and (b) establish independent and regular audits of cloud service operation and customer services along with service rankings, so that enterprises can decide whether to adopt, continue with or migrate to a Cloud provider. Establishing and maintaining these rankings could require significant effort, and some providers may choose not to participate; those that do may benefit and the market should grow based on quality, flexibility and not just price. Page 4 of 5

5 Question 7. If a voluntary protocol is introduced, do you have any comments on potential compliance costs, jurisdictional complexities and the interaction between the Protocol and other cloud standards currently being developed globally? Compliance costs may be difficult to ascertain, however a community informed living cookbook document of best practice would be a cost effective first step. Reliance on community input may require diligence to ensure feedback is not tainted with a bias. Enterprises or Regulators may want to consider automating the remote monitoring of cloud services for real time and historical trend analysis of cloud service performance. Should a regulator or independent organisation choose to provide this monitoring service, it may be possible to cover costs by offering a snapshot overview to the public, followed by a more detailed paid report for interested enterprises. Question 8. Using the New Zealand Code as an example, are there changes or improvements that could be made which would improve the efficacy of that process in an Australian context? Are there other issues not addressed in the New Zealand Code that need to be considered? The New Zealand CloudCode presents an excellent template for Cloud Service Providers to self- certify their services within an industry brand. What may be lacking is the ability to address compliance outside New Zealand or third party service reviews/audits, monitoring, ranking as a regular activity. AARNet recommends that as cloud computing is so dynamic, that regular monitoring is undertaken to ensure competition and growth does not erode the quality of the services being delivered. About AARNet Pty Ltd AARNet is Australia's Academic and Research Network (AARNet) is the not- for- profit company that operates Australia's National Research and Education Network (NREN). Our shareholders are 38 Australian universities and the Commonwealth Scientific and Industrial Research Organisation (CSIRO). We provide high capacity, leading edge internet and other advanced communications services to the nation's universities, health and other research organisations, schools, vocational training providers and cultural institutions. AARNet serves over one million end users who access the network and services for teaching, learning and research. For more than 20 years, we have shared and exchanged expertise with our customers in many ways, supporting collaboration and innovation in research and education. We have also been effective in making representations to government on policy, legislation, strategy and programs to improve the telecommunications facilities and services available not only to the education and research sector, but to all Australians. Our Board of Directors is responsible for the overall direction of AARNet and for providing benefits to the shareholders as required under the AARNet Constitution. The AARNet Advisory Committee (AAC) provides technical and policy advice to the Chief Executive Officer (CEO). Our team is a small effective group of highly motivated, dedicated and expert staff. AARNet's CEO, together with the Senior Management Team has transformed the strategy of the organisation, enabling one of the largest operational footprints of any national research and education network in the world. Page 5 of 5

Microsoft appreciates the opportunity to respond to the Cloud Computing Consumer Protocol: ACS Discussion Paper July 2013 (the protocol).

Microsoft appreciates the opportunity to respond to the Cloud Computing Consumer Protocol: ACS Discussion Paper July 2013 (the protocol). Microsoft Submission to ACS Cloud Protocol Discussion Paper General Comments Microsoft appreciates the opportunity to respond to the Cloud Computing Consumer Protocol: ACS Discussion Paper July 2013 (the

More information

COMMUNICATIONS ALLIANCE LTD

COMMUNICATIONS ALLIANCE LTD COMMUNICATIONS ALLIANCE LTD Communications Alliance Response to ACS Discussion Paper on a Potential Cloud Computing Consumer Protocol - 1 - TABLE OF CONTENTS INTRODUCTION 2 SECTION 1 OVERVIEW OF RESPONSE

More information

ACS CLOUD COMPUTING CONSUMER PROTOCOL. Response from AIIA

ACS CLOUD COMPUTING CONSUMER PROTOCOL. Response from AIIA ACS CLOUD COMPUTING CONSUMER PROTOCOL Response from AIIA AUGUST 2013 INTRODUCTION The Australian Information Industry Association (AIIA) is the peak national body representing multinational and domestic

More information

Cloud Computing Consumer Protocol. ACS Cloud Discussion Paper July 2013

Cloud Computing Consumer Protocol. ACS Cloud Discussion Paper July 2013 Cloud Computing Consumer Protocol ACS Cloud Discussion Paper July 2013 ACS Cloud Protocol Discussion Paper July 2013 2 CONTENTS SECTION PAGE 1. Introduction and Purpose 3 2. Structure and Timelines 3 3.

More information

Quick guide: Using the Cloud to support your business

Quick guide: Using the Cloud to support your business Quick guide: Using the Cloud to support your business This Quick Guide is one of a series of information products targeted at small to medium sized enterprises (SMEs). It is designed to help businesses

More information

DISCLOSURE STATEMENT PREPARED BY

DISCLOSURE STATEMENT PREPARED BY DISCLOSURE STATEMENT PREPARED BY - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

More information

Cloud Computing Consumer Protocol

Cloud Computing Consumer Protocol Cloud Computing Consumer Protocol Submission by the Australian Communications Consumer Action Network to the Australian Computer Society 16 August 2013 Australian Communications Consumer Action Network

More information

Disclosure Requirements of CloudCode Software

Disclosure Requirements of CloudCode Software DISCLOSURE STATEMENT PREPARED BY - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

More information

XIT CLOUD SOLUTIONS LIMITED

XIT CLOUD SOLUTIONS LIMITED DISCLOSURE STATEMENT PREPARED BY - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

More information

AUSTRALIAN INDUSTRY GROUP SUBMISSION to. Australian Computer Society. Discussion paper on the Cloud Computing Consumer Protocol

AUSTRALIAN INDUSTRY GROUP SUBMISSION to. Australian Computer Society. Discussion paper on the Cloud Computing Consumer Protocol AUSTRALIAN INDUSTRY GROUP SUBMISSION to Australian Computer Society Discussion paper on the Cloud Computing Consumer Protocol 6 September 2013 EXECUTIVE SUMMARY The Australian Industry Group (Ai Group)

More information

Implementing Disaster Recovery? At What Cost?

Implementing Disaster Recovery? At What Cost? Implementing Disaster Recovery? At What Cost? Whitepaper Viktor Babkov Technical Director Business Continuity Copyright Business Continuity May 2010 In today s environment, minimizing IT downtime has become

More information

The trusted technology partner in the Public Sector

The trusted technology partner in the Public Sector The trusted technology partner in the Public Sector www.exponential-e.com/public-sector About Exponential-e Market Leaders in Technical Innovation GovConnect: The Exponential-e public sector service portfolio

More information

Escrow is dead? WHITE PAPER

Escrow is dead? WHITE PAPER Escrow is dead? WHITE PAPER June 2012 Table of Contents Executive summary........3 The growth of the Cloud and SaaS.4 Why are businesses migrating to the Cloud?.4 Why are businesses using SaaS technology?...6

More information

SaaS or On-Premise? How to Select the Right Paths for Your Enterprise. David Linthicum

SaaS or On-Premise? How to Select the Right Paths for Your Enterprise. David Linthicum SaaS or On-Premise? How to Select the Right Paths for Your Enterprise David Linthicum SaaS or On-Premise? How to Select the Right Paths for Your Enterprise 2 Executive Summary The growth of Software- as-

More information

ITCRA Response. Request for Submissions on the Draft Version of the APP Guideline Chapters A to D and 1 to 5 covering APPs 1 to 5

ITCRA Response. Request for Submissions on the Draft Version of the APP Guideline Chapters A to D and 1 to 5 covering APPs 1 to 5 ITCRA Response Request for Submissions on the Draft Version of the APP Guideline Chapters A to D and 1 to 5 covering APPs 1 to 5 To: The Office of the Australian Information Commission Submitted: 20th

More information

Security in the Cloud: Visibility & Control of your Cloud Service Providers

Security in the Cloud: Visibility & Control of your Cloud Service Providers Whitepaper: Security in the Cloud Security in the Cloud: Visibility & Control of your Cloud Service Providers Date: 11 Apr 2012 Doc Ref: SOS-WP-CSP-0412A Author: Pierre Tagle Ph.D., Prashant Haldankar,

More information

Smarter Data Centre Outsourcing Considerations for CFOs

Smarter Data Centre Outsourcing Considerations for CFOs Smarter Data Centre Outsourcing Considerations for CFOs This paper originated with a question Australian business has increasingly been asking: Is it more cost effective to outsource data centre infrastructure,

More information

The NREN s core activities are in providing network and associated services to its user community that usually comprises:

The NREN s core activities are in providing network and associated services to its user community that usually comprises: 3 NREN and its Users The NREN s core activities are in providing network and associated services to its user community that usually comprises: Higher education institutions and possibly other levels of

More information

On Premise or Hosted?

On Premise or Hosted? On Premise or Hosted? Introduction At the highest level the difference is clear on premise means that the software resides within your data centre(s), whilst hosted means that it is located external to

More information

Some Responses by W J Caelli, AO to: Cloud Computing Consumer Protocol : ACS Cloud Discussion Paper, July 2013. Part 1.

Some Responses by W J Caelli, AO to: Cloud Computing Consumer Protocol : ACS Cloud Discussion Paper, July 2013. Part 1. 21 Castle Hill Drive South, Gaven. Qld. 4211. Australia. Phone: +61 7 5502 2978 Mobile/Cell: +61 414 987 952 Email: w.caelli@iisec.com.au 2 September 2013 Some Responses by W J Caelli, AO to: Cloud Computing

More information

CONTROL. FLEXIBILITY. PERFORMANCE.

CONTROL. FLEXIBILITY. PERFORMANCE. CONTROL. FLEXIBILITY. PERFORMANCE. WHY MACQUARIE TELECOM FOR HOSTING. 2014 MACQUARIE TELECOM PTY LTD 01 WHY MACQUARIE TELECOM FOR HOSTING. CONTROL. FLEXIBILITY. PERFORMANCE. At Macquarie Telecom, we deliver

More information

Cloud Computing and Records Management

Cloud Computing and Records Management GPO Box 2343 Adelaide SA 5001 Tel (+61 8) 8204 8773 Fax (+61 8) 8204 8777 DX:336 srsarecordsmanagement@sa.gov.au www.archives.sa.gov.au Cloud Computing and Records Management June 2015 Version 1 Version

More information

WhitePaper. Private Cloud Computing Essentials

WhitePaper. Private Cloud Computing Essentials Private Cloud Computing Essentials The 2X Private Cloud Computing Essentials This white paper contains a brief guide to Private Cloud Computing. Contents Introduction.... 3 About Private Cloud Computing....

More information

Interoute Virtual Data Centre. Hands on cloud control.

Interoute Virtual Data Centre. Hands on cloud control. Interoute Virtual Data Centre. Hands on cloud control. Scale your computing resource on demand Choose where in Europe you want your data Europe s most trusted and secure network www.interoute.com/vdc Interoute

More information

NSW Government. Cloud Services Policy and Guidelines

NSW Government. Cloud Services Policy and Guidelines NSW Government Cloud Services Policy and Guidelines August 2013 1 CONTENTS 1. Introduction 2 1.1 Policy statement 3 1.2 Purpose 3 1.3 Scope 3 1.4 Responsibility 3 2. Cloud services for NSW Government 4

More information

White paper: Unlocking the potential of load testing to maximise ROI and reduce risk.

White paper: Unlocking the potential of load testing to maximise ROI and reduce risk. White paper: Unlocking the potential of load testing to maximise ROI and reduce risk. Executive Summary Load testing can be used in a range of business scenarios to deliver numerous benefits. At its core,

More information

Big Data Analytics Service Definition G-Cloud 7

Big Data Analytics Service Definition G-Cloud 7 Big Data Analytics Service Definition G-Cloud 7 Big Data Analytics Service Service Overview ThinkingSafe s Big Data Analytics Service allows information to be collected from multiple locations, consolidated

More information

Hitachi Cloud Service for Content Archiving. Delivered by Hitachi Data Systems

Hitachi Cloud Service for Content Archiving. Delivered by Hitachi Data Systems SOLUTION PROFILE Hitachi Cloud Service for Content Archiving, Delivered by Hitachi Data Systems Improve Efficiencies in Archiving of File and Content in the Enterprise Bridging enterprise IT infrastructure

More information

Cloud Computing Backgrounder

Cloud Computing Backgrounder Cloud Computing Backgrounder No surprise: information technology (IT) is huge. Huge costs, huge number of buzz words, huge amount of jargon, and a huge competitive advantage for those who can effectively

More information

Data Protection Act 1998. Guidance on the use of cloud computing

Data Protection Act 1998. Guidance on the use of cloud computing Data Protection Act 1998 Guidance on the use of cloud computing Contents Overview... 2 Introduction... 2 What is cloud computing?... 3 Definitions... 3 Deployment models... 4 Service models... 5 Layered

More information

Joint ICT Service ICT Strategy 2014-17

Joint ICT Service ICT Strategy 2014-17 Document History Document Location This document is only valid on the day it was printed. The source of the document will be found in (see footer) Revision History Date of this revision: 19 th May 2014

More information

Front Desk Software. for Psychologists in Private Practice

Front Desk Software. for Psychologists in Private Practice Front Desk Software for sychologists in rivate ractice Front Desk Software for sychologists in rivate ractice Contents urpose of this guide...3 rocess of developing this guide...3 Key questions to consider

More information

Privacy and Cloud Computing for Australian Government Agencies

Privacy and Cloud Computing for Australian Government Agencies Privacy and Cloud Computing for Australian Government Agencies Better Practice Guide February 2013 Version 1.1 Introduction Despite common perceptions, cloud computing has the potential to enhance privacy

More information

An Overview of ISO/IEC 27000 family of Information Security Management System Standards

An Overview of ISO/IEC 27000 family of Information Security Management System Standards What is ISO/IEC 27001? The ISO/IEC 27001 standard, published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), is known as Information

More information

Managing business risk

Managing business risk Managing business risk What senior managers need to know about business continuity bell.ca/businesscontinuity Information and Communications Technology (ICT) has become more vital than ever to the success

More information

SERVICES OVERVIEW. Integrating Risk, Technology, People and Process for a sustainable Future CONTACT US. About Us. Our Business Philosophy

SERVICES OVERVIEW. Integrating Risk, Technology, People and Process for a sustainable Future CONTACT US. About Us. Our Business Philosophy About Us Vestinex Pty Ltd is a boutique professional business services provider based in Sydney, Australia. We offer a range of services across two broad categories of Ethics and Investigations and Information

More information

How to Build a NOC & Help Desk Without Going Broke!

How to Build a NOC & Help Desk Without Going Broke! How to Build a NOC & Help Desk Without Going Broke! By Charles Weaver, CEO of MSPAlliance Sponsored by Summary & Objectives For companies getting into cloud or managed services, one inescapable obstacle

More information

INFRASTRUCTURE AS A SERVICE BUYER S CHECKLIST

INFRASTRUCTURE AS A SERVICE BUYER S CHECKLIST INFRASTRUCTURE AS A SERVICE BUYER S CHECKLIST 2 CONTENTS SERVICE LEVELS 3 SERVICE AND SUPPORT 4 CERTIFICATIONS 4 MANAGED HOSTING 7 BILLING 8 SERVICE MANAGEMENT 8 TECHNOLOGY 9 GLOBAL, REGIONAL, LOCAL 10

More information

Cloud Computing in a Government Context

Cloud Computing in a Government Context Cloud Computing in a Government Context Introduction There has been a lot of hype around cloud computing to the point where, according to Gartner, 1 it has become 'deafening'. However, it is important

More information

What You Need to Know About Cloud Backup: Your Guide to Cost, Security, and Flexibility

What You Need to Know About Cloud Backup: Your Guide to Cost, Security, and Flexibility Your Guide to Cost, Security, and Flexibility What You Need to Know About Cloud Backup: Your Guide to Cost, Security, and Flexibility 10 common questions answered Over the last decade, cloud backup, recovery

More information

Best Practice Implementation is Changing ERP. CPiO White Paper. T 0844 880 6140 E marketing@cpio.co.uk. CPiO. Part of the Waterdale Group of Companies

Best Practice Implementation is Changing ERP. CPiO White Paper. T 0844 880 6140 E marketing@cpio.co.uk. CPiO. Part of the Waterdale Group of Companies White Paper Best Practice Implementation is Changing ERP Part of the Waterdale Group of Companies Part of the Waterdale Group of Companies 1 I White Paper I Best Practice Implementation is Changing ERP

More information

Assessment of Software for Government

Assessment of Software for Government Version 1.0, April 2012 Aim 1. This document presents an assessment model for selecting software, including open source software, for use across Government, and the wider UK public sector. 2. It is presented

More information

Bruce Allison. Steve Moran

Bruce Allison. Steve Moran Bruce Allison Steve Moran ASK A QUESTION POST A COMMENT SUBMIT TECHNICAL QUERIES SHARE YOUR TIPS PROVIDE FEEDBACK DIAL IN AND LISTEN VIA YOUR TELEPHONE! 1800 896 323 81178679# Virtual Desktops A simple,

More information

Chiropractic Boards response 15 December 2008

Chiropractic Boards response 15 December 2008 NATIONAL REGISTRATION AND ACCREDITATION SCHEME FOR THE HEALTH PROFESSIONS Chiropractic Boards response 15 December 2008 CONSULTATION PAPER Proposed arrangements for accreditation Issued by the Practitioner

More information

Whitepaper: Defining the challenges to FOOD AND BEVERAGE

Whitepaper: Defining the challenges to FOOD AND BEVERAGE Defining the challenges to FOOD AND BEVERAGE businesses Overview Despite the continuing global financial crisis, the Australian food and beverages market managed a reasonable year-on-year increase during

More information

SECURE CLOUD SOLUTIONS FOR YOUR BUSINESS.

SECURE CLOUD SOLUTIONS FOR YOUR BUSINESS. SECURE CLOUD SOLUTIONS FOR YOUR BUSINESS. 2015 Learning Possibilities Ltd, 506 Centennial Park, Centennial Avenue, Elstree, Herts, WD6 3FG Email: info@cloudpossibilities.com Telephone: +44 (0) 20 8236

More information

Risk Management Policy and Framework

Risk Management Policy and Framework Risk Management Policy and Framework December 2014 phone 1300 360 605 08 89589500 email info@centraldesert.nt.gov.au location 1Bagot Street Alice Springs NT 0870 post PO Box 2257 Alice Springs NT 0871

More information

Quick Guide: Meeting ISO 55001 Requirements for Asset Management

Quick Guide: Meeting ISO 55001 Requirements for Asset Management Supplement to the IIMM 2011 Quick Guide: Meeting ISO 55001 Requirements for Asset Management Using the International Infrastructure Management Manual (IIMM) ISO 55001: What is required IIMM: How to get

More information

Pragmatic cloud computing Six keys to successfully using the cloud

Pragmatic cloud computing Six keys to successfully using the cloud Pragmatic cloud computing Six keys to successfully using the cloud It is imperative to develop a clear cloud strategy that is based on facts, that articulates the benefits and risks and that is holistic

More information

Driving Excellence in Implementation and Beyond The Underlying Quality Principles

Driving Excellence in Implementation and Beyond The Underlying Quality Principles SAP Thought Leadership Paper SAP Active Quality Management Driving Excellence in Implementation and Beyond The Underlying Quality Principles 2014 SAP AG or an SAP affiliate company. All rights reserved.

More information

Our School Backup A trusted, safe and secure remote backup solution for the UK education sector.

Our School Backup A trusted, safe and secure remote backup solution for the UK education sector. Our School Backup A trusted, safe and secure remote backup solution for the UK education sector. A trusted, safe and secure remote data backup solution for schools. Our ICT presents Our School Backup,

More information

The Panoptix Building Efficiency Solution: Ensuring a Secure Delivery of Building Efficiency

The Panoptix Building Efficiency Solution: Ensuring a Secure Delivery of Building Efficiency logo The Panoptix Building Efficiency Solution: Ensuring a Secure Delivery of Building Efficiency Understanding the Multiple Levels of Security Built Into the Panoptix Solution Published: October 2011

More information

How not to lose your head in the Cloud: AGIMO guidelines released

How not to lose your head in the Cloud: AGIMO guidelines released How not to lose your head in the Cloud: AGIMO guidelines released 07 December 2011 In brief The Australian Government Information Management Office has released a helpful guide on navigating cloud computing

More information

BMC Control-M Workload Automation

BMC Control-M Workload Automation solution overview BMC Control-M Workload Automation Accelerating Delivery of Digital Services with Workload Management Table of Contents 1 SUMMARY 2 FASTER AND CHEAPER DYNAMIC WORKLOAD MANAGEMENT Minimize

More information

White Paper: SLASH YOUR SME 1 COMPLIANCE COSTS

White Paper: SLASH YOUR SME 1 COMPLIANCE COSTS White Paper: SLASH YOUR SME 1 COMPLIANCE COSTS Most small business owners are attempting to juggle hundreds of activities at once just to run their business day to day. Every day there seems to be more

More information

CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES:

CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES: CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES: Privacy Responsibilities and Considerations Cloud computing is the delivery of computing services over the Internet, and it offers many potential

More information

G Cloud Service Description Premier SIP Trunk Software as a Service October 2015

G Cloud Service Description Premier SIP Trunk Software as a Service October 2015 G Cloud Service Description Premier SIP Trunk Software as a Service October 2015 Premier Choice Telecom has been a trusted provider of communications solutions for businesses for over 15 years. Our clients

More information

Cloud Computing: Legal Risks and Best Practices

Cloud Computing: Legal Risks and Best Practices Cloud Computing: Legal Risks and Best Practices A Bennett Jones Presentation Toronto, Ontario Lisa Abe-Oldenburg, Partner Bennett Jones LLP November 7, 2012 Introduction Security and Data Privacy Recent

More information

Licence Fee means the fees calculated as set out on the Website or such other fee as is agreed between You and the Supplier from time to time.

Licence Fee means the fees calculated as set out on the Website or such other fee as is agreed between You and the Supplier from time to time. BY CLICKING ON I AGREE BELOW, OR BY DOWNLOADING, INSTALLING OR MAKING ANY USE OF THE SYSTEM DESCRIBED BELOW, YOU AGREE TO THE FOLLOWING TERMS OF THIS AGREEMENT BETWEEN YOU AND {Reseller Business Name}

More information

5 Essential Benefits of Hybrid Cloud Backup

5 Essential Benefits of Hybrid Cloud Backup 5 Essential Benefits of Hybrid Cloud Backup QBR is a backup, disaster recovery (BDR), and business continuity solution targeted to the small to medium business (SMB) market. QBR solutions are designed

More information

Nine Steps to Smart Security for Small Businesses

Nine Steps to Smart Security for Small Businesses Nine Steps to Smart Security for Small Businesses by David Lacey Co-Founder, Jericho Forum Courtesy of TABLE OF CONTENTS INTRODUCTION... 1 WHY SHOULD I BOTHER?... 1 AREN T FIREWALLS AND ANTI-VIRUS ENOUGH?...

More information

Electronic Trading Information Template

Electronic Trading Information Template Electronic Trading Information Template Preface This Electronic Trading Information Template (the "Template") has been created through the collaborative efforts of the professional associations listed

More information

The Future of Small Town Computing: A Cloud or a Digital Divide?

The Future of Small Town Computing: A Cloud or a Digital Divide? The Future of Small Town Computing: A Cloud or a Digital Divide? David Davies, DLS Director of Information Technology Municipal computing in New England is different than in most of the country. Elsewhere,

More information

Royal Australian College of General Practitioners

Royal Australian College of General Practitioners Royal Australian College of General Practitioners Response to CoAG s National Registration and Accreditation Scheme: proposed arrangements 19 December 2008 1. INTRODUCTION The Royal Australian College

More information

What is Cloud-Based Security? Cloud-based Security = Security Management + Cloud Computing.

What is Cloud-Based Security? Cloud-based Security = Security Management + Cloud Computing. What is Cloud-Based Security? Cloud-based Security = Security Management + Cloud Computing. What is Cloud-Based Security? Cloud computing is: IT services via the internet from an external service provider

More information

NSW Government. Data Centre & Cloud Readiness Assessment Services Standard. v1.0. June 2015

NSW Government. Data Centre & Cloud Readiness Assessment Services Standard. v1.0. June 2015 NSW Government Data Centre & Cloud Readiness Assessment Services Standard v1.0 June 2015 ICT Services Office of Finance & Services McKell Building 2-24 Rawson Place SYDNEY NSW 2000 standards@finance.nsw.gov.au

More information

Cloud Procurement Discussion Paper. For Comment

Cloud Procurement Discussion Paper. For Comment Cloud Procurement Discussion Paper For Comment AUGUST 2014 Acronyms Acronym AGIMO ASD DCaaS MUL IaaS NIST PaaS RFT SaaS SCS Definition Australian Government Information Management Office Australian Signals

More information

Cloud Computing and Security Risk Analysis Qing Liu Technology Architect STREAM Technology Lab Qing.Liu@chi.frb.org

Cloud Computing and Security Risk Analysis Qing Liu Technology Architect STREAM Technology Lab Qing.Liu@chi.frb.org Cloud Computing and Security Risk Analysis Qing Liu Technology Architect STREAM Technology Lab Qing.Liu@chi.frb.org 1 Disclaimers This presentation provides education on Cloud Computing and its security

More information

Insights: Data Protection and the Cloud North America

Insights: Data Protection and the Cloud North America Insights: Data Protection and the Cloud North America Survey Report May 2012 Table of Contents Executive Summary Page 3 Key Findings Page 4 Investment in data protection & DR operations Page 4 Data and

More information

UNCLASSIFIED UNCONTROLLED-IF-PRINTED. Public. 2:51 Outsourced Offshore and Cloud Based Computing Arrangements

UNCLASSIFIED UNCONTROLLED-IF-PRINTED. Public. 2:51 Outsourced Offshore and Cloud Based Computing Arrangements Defence Security Manual DSM Part 2:51 Outsourced Offshore and Cloud Based Computing Arrangements Version 1 ation date July 2105 Amendment list 23 Optimised for Screen; Print; Screen Reader Releasable to

More information

Business Continuity Business Impact Analysis arrangements

Business Continuity Business Impact Analysis arrangements Aberdeen City Council Internal Audit Report 2012/2013 for Aberdeen City Council May 2013 Business Continuity Business Impact Analysis arrangements Final Report Contents Section Page 1. Executive Summary

More information

AVLOR SERVER CLOUD RECOVERY

AVLOR SERVER CLOUD RECOVERY AVLOR SERVER CLOUD RECOVERY WHITE PAPER 1 Table of Contents Abstract... 2 1. Introduction... 3 2. Server Cloud Recovery... 3 3. Amazon AWS Cloud... 4 a. What it is... 4 b. Why Use AWS?... 5 4. Difficulties

More information

<risk> Enterprise Risk Management

<risk> Enterprise Risk Management Global Resources... Local Knowledge is vital in supporting business continuity across diverse and challenging environments and operating models. By consolidating risk management activities into a single,

More information

SOFTWARE LICENSING AWARENESS IN DYNAMIC ENVIRONMENTS

SOFTWARE LICENSING AWARENESS IN DYNAMIC ENVIRONMENTS SOFTWARE LICENSING AWARENESS IN DYNAMIC ENVIRONMENTS 3 CLOUD TECHNOLOGIES AND EMPLOYEE COLLABORATION MAY SATISFY BUSINESS FLEXIBILITY, DYNAMISM AND INSTANT DEMAND BUT THE LICENSING IMPACT AND FINANCIAL

More information

A. Reference information. A0. G-Cloud Programme unique ID number for the service and version number of this scoping template

A. Reference information. A0. G-Cloud Programme unique ID number for the service and version number of this scoping template G-Cloud Service Pan Government Security Accreditation Scope This form is intended for Suppliers of services on the G-Cloud to complete. Upon receipt, the G-Cloud Programme will check Section A, Reference

More information

Things You Need to Know About Cloud Backup

Things You Need to Know About Cloud Backup Things You Need to Know About Cloud Backup Over the last decade, cloud backup, recovery and restore (BURR) options have emerged as a secure, cost-effective and reliable method of safeguarding the increasing

More information

<cloud> Secure Hosting Services

<cloud> Secure Hosting Services Global Resources... Local Knowledge Figtree offers the functionality of Figtree Systems Software without the upfront infrastructure investment. It is the preferred deployment solution for organisations

More information

CLOUD COMPUTING GUIDELINES FOR LAWYERS

CLOUD COMPUTING GUIDELINES FOR LAWYERS INTRODUCTION Legal practices are increasingly using cloud storage and software systems as an alternative to in-house data storage and IT programmes. The cloud has a number of advantages particularly flexibility

More information

Newcastle University Information Security Procedures Version 3

Newcastle University Information Security Procedures Version 3 Newcastle University Information Security Procedures Version 3 A Information Security Procedures 2 B Business Continuity 3 C Compliance 4 D Outsourcing and Third Party Access 5 E Personnel 6 F Operations

More information

Business Continuity Plan Toolkit

Business Continuity Plan Toolkit Business Continuity Plan Toolkit March 2015 1 Contents The Template instructions for use... 2 Introduction... 3 What is the purpose of this toolkit?... 3 Why do you need a Business Continuity Plan?...

More information

USER EXPERIENCE MONITORING Service Definition

USER EXPERIENCE MONITORING Service Definition About Littlefish Established in Nottingham in 2003, Littlefish (UK) Ltd has an innovative, stable and successful history in Managed IT Services and has grown continuously over the last ten years. Through

More information

ADRI. Advice on managing the recordkeeping risks associated with cloud computing. ADRI-2010-1-v1.0

ADRI. Advice on managing the recordkeeping risks associated with cloud computing. ADRI-2010-1-v1.0 ADRI Advice on managing the recordkeeping risks associated with cloud computing ADRI-2010-1-v1.0 Version 1.0 29 July 2010 Advice on managing the recordkeeping risks associated with cloud computing 2 Copyright

More information

Document Version. January 2013

Document Version. January 2013 Service and Technical Description Vendor Access Network Providers (VAN) January 2013 Contents Vendor Access Network Providers (VAN)... 1 Contents... 2 Document Version... 3 1. Introduction... 4 1.1. Purpose

More information

Selecting a Content Management System

Selecting a Content Management System 9 9 SELECTING A CONTENT MANAGEMENT SYSTEM Selecting a Content Management System Better Practice Checklist Practical guides for effective use of new technologies in Government www.agimo.gov.au/checklists

More information

March 2008 Grant Halverson CEO, GFG Group. Regional Processing Models

March 2008 Grant Halverson CEO, GFG Group. Regional Processing Models March 2008 Grant Halverson CEO, GFG Group Regional Processing Models The search for successful regional and global IT processing models has been a major focus of the last fifteen years across banks, insurance

More information

mybpos are a leading provider of business support services based in the UK

mybpos are a leading provider of business support services based in the UK mybpos are a leading provider of business support services based in the UK 1 Introduction to mybpos 2 Services 3 Workforce Management 4 Payroll 5 Contractor Pool 6 Relocation 7 Contractors 8 IT Support

More information

HOW MUCH MONEY HAVE YOU WASTED ON G-CLOUD?

HOW MUCH MONEY HAVE YOU WASTED ON G-CLOUD? Winning on G-Cloud & The Digital Marketplace 6 TIPS FROM SUCCESSFUL SUPPLIERS HOW MUCH MONEY HAVE YOU WASTED ON G-CLOUD? As of 2 February, there were a total of 1,852 suppliers registered on the G-Cloud

More information

Microsoft SQL Server 2008 R2 Enterprise Edition and Microsoft SharePoint Server 2010

Microsoft SQL Server 2008 R2 Enterprise Edition and Microsoft SharePoint Server 2010 Microsoft SQL Server 2008 R2 Enterprise Edition and Microsoft SharePoint Server 2010 Better Together Writer: Bill Baer, Technical Product Manager, SharePoint Product Group Technical Reviewers: Steve Peschka,

More information

Intel Enhanced Data Security Assessment Form

Intel Enhanced Data Security Assessment Form Intel Enhanced Data Security Assessment Form Supplier Name: Address: Respondent Name & Role: Signature of responsible party: Role: By placing my name in the box above I am acknowledging that I am authorized

More information

24/7 Monitoring Pro-Active Support High Availability Hardware & Software Helpdesk. itg CloudBase

24/7 Monitoring Pro-Active Support High Availability Hardware & Software Helpdesk. itg CloudBase 24/7 Monitoring Pro-Active Support High Availability Hardware & Software Helpdesk Onsite Support itg CloudBase Pro-Active managed it support services for one single cost per month covers all aspects of

More information

Standard Terms & Conditions for ecommerce, Website Design and Development and IT Services.

Standard Terms & Conditions for ecommerce, Website Design and Development and IT Services. Standard Terms & Conditions for ecommerce, Website Design and Development and IT Services. 2009 2010 Terms Cluster A redundant array of computer systems working together to provide one or more services

More information

How much do you pay for your PKI solution?

How much do you pay for your PKI solution? Information Paper Understand the total cost of your PKI How much do you pay for your PKI? A closer look into the real costs associated with building and running your own Public Key Infrastructure and 3SKey.

More information

AVANTGARD Hosting and Managed Services

AVANTGARD Hosting and Managed Services AVANTGARD Hosting and Managed Services AVANTGARD HOSTING AND MANAGED SERVICES SunGard meets its customers diverse set of requirements by not only bringing to market scalable, flexible, and industry leading

More information

You do the deals. We ll do the rest.

You do the deals. We ll do the rest. You do the deals. We ll do the rest. Mortgage software solutions for originators, aggregators, brokers and financial services providers. PO R Symmetry is a brand of Stargate Group. For over thirty years,

More information

Financial Planner Remuneration Policy October 2009

Financial Planner Remuneration Policy October 2009 Background In 2008, the FPA formed a remuneration policy committee to review our current remuneration policy, which included our Principles to Manage Conflicts of Interest, and develop a uniform set of

More information

Cloud Storage and Backup

Cloud Storage and Backup Cloud Storage and Backup Cloud Storage and Backup Cloud Storage and Backup services from iomartcloud have been designed to deliver the performance, capacity, security and flexibility needed to address

More information

What you need to know about cloud backup: your guide to cost, security, and flexibility. 8 common questions answered

What you need to know about cloud backup: your guide to cost, security, and flexibility. 8 common questions answered What you need to know about cloud backup: your guide to cost, security, and flexibility. 8 common questions answered Over the last decade, cloud backup, recovery and restore (BURR) options have emerged

More information

Business Process Approval Workflow Manager. Services Definition Document

Business Process Approval Workflow Manager. Services Definition Document Business Process Approval Workflow Manager Services Definition Document Introducing CoreStream CoreStream is a UK based provider of technology solutions focused on helping organisations manage risk, satisfy

More information