Microsoft appreciates the opportunity to respond to the Cloud Computing Consumer Protocol: ACS Discussion Paper July 2013 (the protocol).

Size: px
Start display at page:

Download "Microsoft appreciates the opportunity to respond to the Cloud Computing Consumer Protocol: ACS Discussion Paper July 2013 (the protocol)."

Transcription

1 Microsoft Submission to ACS Cloud Protocol Discussion Paper General Comments Microsoft appreciates the opportunity to respond to the Cloud Computing Consumer Protocol: ACS Discussion Paper July 2013 (the protocol). We acknowledge the considerable efforts of the contributors and team at the Australian Computer Society (ACS) in drafting the discussion paper and in endeavouring to deliver on the recommendation of the Australian Government s National Cloud Computing Strategy. In addition to some general comments, we have provided responses to each of the relevant questions (those related to providers as opposed to users) asked within the Discussion Paper. It is critical that the objective and proposed uses of the protocol are well defined. In addition, the protocol should clearly state what it is not proposed to be used for. The aim should be to achieve a simple set of common disclosures that improve the ability for consumers, businesses and other organisations to make an informed choice about Cloud services. Microsoft believes the protocol should not aim to become de facto regulation by prescribing standards or answers; or become a mandatory requirement for procurement. Business Readiness Firstly, Microsoft would question whether businesses are truly reticent to integrate the cloud into their businesses and operations. 1 We are seeing strong global appetite and take up from organisations of all sizes as they come to understand the options and business models related to Cloud computing. In the consumer market, Cloud computing adoption is widespread and growing rapidly. On this point, it is our opinion that it is too early to take the view that there has been a market failure requiring significant intervention. We also feel that current legislative protections like Competition and Consumer laws and the Privacy Act provide adequate protection for cloud consumers. Relevance of Government Guidelines Guidelines developed for internal Government use include standards, recommendations, and positions that may not be appropriate for small and medium business. For example, the DSD Cloud Considerations paper, developed by an organisation with a primary focus on protecting national security secrets, is not relevant for a broader national audience and includes statements like: DSD recommends against outsourcing information technology services and functions outside of Australia, unless agencies are dealing with data that is all publicly available. DSD strongly encourages agencies to choose either a locally-owned vendor or a foreign-owned 1 ACS Cloud Protocol Discussion Paper July 2013, page 2 Microsoft Pty Ltd, Page 1

2 vendor that is located in Australia and stores, processes and manages sensitive data only within Australian borders 2 The Attorney General s Department Policy for the Storage and Processing of Information in Outsourced or Offshore ICT Arrangements goes even further. This new policy introduced arbitrary requirements whereby any government agency wishing to utilise the benefits of public cloud requires (a) a formal and explicit risk assessment, (b) an audit against the mandatory requirements of the Protective Service Policy Framework, (c) the formal approval of the Agency Head, and (d) the formal approval of both the Minister and the Attorney General. 3 Far from being useful guidance to encourage small and medium business to leverage the economic and security benefits of cloud computing, this guidance is more likely to be a much greater inhibiter of progress. We also feel that the ACS should avoid trying to build requirements into any proposed code that aims to address the National Cloud Computing Strategy objective of: Responsiveness to market and technology developments 4. This is a highly subjective statement that is at the core of innovation and competition within the cloud services market. It would be nearly impossible to develop language that would enable industry compliance and meet this objective. Transparency and Trust We do, however, strongly support transparency, particularly with relation to customer data. Cloud providers should contractually commit that at all times, customers own their own data, and retain all rights, title and interest in the data stored with the provider. Customers should be able to download a copy of all of their data at any time and for any reason, without any assistance from the Cloud provider. Customers should have full control and access to their data and be able to remove or delete it as they deem necessary throughout the duration of the service. In addition, customers have the option of purchasing services from a variety of IT organisations to assist them in migrating their data. In line with this commitment on transparency and privacy, we have developed online Trust Centres that provide additional information for our Cloud services including: Office 365, Dynamics CRM Online, and Windows Azure. Guiding Principles There are some guiding principles for any Protocols developed with regards to cloud: Transparency is key: Any voluntary code should seek to encourage transparency and disclosure as the basis of an improved trust relationship with customers. 2 DSD Cloud Computing Security Considerations, page 1 3 Australian Government Policy and Risk management guidelines for the storage and processing of Australian Government information in outsourced or offshore ICT arrangements, page 7 4 ACS Cloud Protocol Discussion Paper July 2013, page 6 Microsoft Pty Ltd, Page 2

3 Avoid a prescriptive one size fits all approach: Microsoft alone operates more than 100 Cloud services, many of which have different business models (e.g., free, subscription based, or ad-funded), platforms, and audiences (e.g., consumer, commercial, Government, or a combination of these). Prescriptive and coverall reporting/disclosure requirements may not be relevant across all of these services. Don t try to create new standards: Cloud computing services are global services. Incompatible regulatory or standards regimes impose barriers to market entry and additional costs, not just for global organisations in providing services to Australians, but also for Australian cloud providers trying to access international markets. Encouraging and supporting the adoption of global standards and best practice creates a level playing field for all providers. Question 1. Do you believe a voluntary protocol in which cloud suppliers provide undertakings and information about their services would improve confidence in the market and increase the adoption and take-up of cloud computing services? As stated, we feel that it is too early to establish that there is a lack of confidence in the market. We have witnessed strong global adoption of our cloud services. For example 250 million people use our cloud storage service Skydrive, there are 400 million Outlook.com accounts, 7 million people use our corporate social media platform Yammer and use of our cloud-based productivity suite Office365 is growing rapidly. Question 2 b). If you are a provider of cloud services, is the description above of cloud services and the outline of its benefits accurate and comprehensive for prospective users who may know little of the details of cloud computing? Microsoft is broadly comfortable with the definition and benefits outlined within the Discussion Paper. However, any Protocol should avoid making sweeping statements with regards to cost savings or pricing, as this will vary dramatically across the market and also needs to consider an organisation s particular circumstances. In a competitive market, it is ultimately incumbent on the cloud service providers to adequately describe the service and demonstrate the benefit, including financial benefits of a service; and on customers to conduct their own financial due diligence. Question 4. Are there other disclosures from cloud vendors that have not been outlined in this section? What are they? The aim should be to achieve a simple set of common disclosures that improve the ability for consumers, businesses and other organisations to make an informed choice about cloud services. Microsoft Pty Ltd, Page 3

4 Any code should avoid prescribing the format or content of the answers. For example, when customers are asking about security, they typically want to know what security practices and standards are in place for data that is at rest or in transit, and how their data might be used and disclosed while it is in the provider s care. For most customers, critical questions include: Where are security practices and standards for the service documented by the provider? Where does the provider document its protocol for handling law enforcement enquiries relating to customer data associated with the service? Does the provider use customer data associated with the service for any purpose other than providing the service to the customer? If so, where does the provider document its other uses of the customer data? In addition to those disclosures outlined within the Discussion Paper, data mining should be disclosed, such as whether the provider will mine a user s data for the purpose of serving advertising or another commercial reason. Other potential questions to use as the basis of disclosures include: What is the service? Where are the features of the service documented? How can documents and data be worked on when there is no internet connection and synchronised when the internet connection is restored? Where is the fee for the service documented? How much notice do I get about fee increases? Do I need anything else to make it work the way I need it to? How much does the service cost to set up? What is the on-going service fee, and how long do I have to commit to? How well does the service respect and protect my data? Will the integrity and content of documents and other data be preserved? Could the provider use my data (beyond providing me the service I m paying for)? Could the provider use my data to build advertising profiles on my staff or clients? Could my staff and clients easily keep their work and personal identities separate? Is the service certified to ISO27001? Is there a response to the Cloud Security Alliance s standard questions for the service? What are the data protection and data recovery practices for the service? What is the policy for dealing with law enforcement requests relating to the service? What level of support is available for the service? How extensive is the professional support network I can turn to in Australia? What standard of reliability does the provider promise for the service? How am I compensated if reliability standards are not met? Are any parts of the service not covered by the reliability standard? Is audited financial information about the provider publicly available (e.g., is the provider is a listed company)? Is the provider financially sound? How does the provider make most of its money? Microsoft Pty Ltd, Page 4

5 Is it practical for me to leave the service? Will I have time to retrieve my data? Can I get my data out in a format that is easy to transfer to another service? Question 6. If you are a provider of cloud services and products, what is the current state of market confidence in cloud computing, and are there any outstanding transparency issues that concern users? If so, what is the best method of addressing these concerns? According to IDC, Public IT cloud services spending will reach $98 billion in 2016, with a compound annual growth rate (CAGR ) five (5) times the growth of the IT industry overall. 5 These strong growth rates for Cloud demonstrate improved market confidence in Cloud services. As adoption increases and businesses become more familiar with Cloud services, we also feel that user confidence is growing, Providing open and transparent information about Cloud services is the best way to address any potential concerns. In line with this our online Trust Centres provide additional information for users of our Cloud services aimed at building trust and improving transparency. Again, it s important for consumers of Cloud services to do their own risk analysis, based on best practice checklists and other relevant information made available by Cloud providers and the industry, and then to be free to make their own choice. Any proposed protocol should aim to support this informed choice. Question 7. If a voluntary protocol is introduced, do you have any comments on potential compliance costs, jurisdictional complexities and the interaction between the Protocol and other cloud standards currently being developed globally? We strongly support the ACS view that: any cloud protocol for Australia must avoid further regulatory complexity, jurisdictional variation, anti-competitive outcomes and overly prescriptive disclosure requirements. In general, due to the need to scale and to keep the prices as low and competitive as possible, whilst Cloud computing services are configurable, they are not customisable. The service is the same for every customer and so customers need to do their own due diligence to determine whether any given service is suitable for their specific needs. For example, vendors have their own security standards and protocols, usually based on recognized world standards like ISO and so they are not in a position to agree to comply with a customer s specific security policy, or some other self-regulatory scheme or protocol, to the extent they differ from the worldwide standard followed by the vendor. As with any technology, innovation generally precedes standardisation. Cloud computing is in no way different. Many Cloud providers have achieved certification with the internationally 5 IDC Worldwide and Regional Public IT Cloud Services Forecast Microsoft Pty Ltd, Page 5

6 recognized ISO Already international standards such as ISO are in draft that embody the consensus acceptance of global practices in standards. We do not support any attempt to provide an exhaustive or recommended list of standards. Industry standards are continually evolving and a list would quickly be outdated. To the extent that any voluntary/self-regulatory scheme purports to require Cloud vendors to change the service or the policies that govern it (ie. security and privacy), then the majority of Cloud vendors will not be in a position to sign up to it. This may then have the adverse effect of limiting competition and preventing market entry, to the extent that customers or consumers see a vendor s compliance with such regulatory regime as a mandatory pre-condition of any purchase and so avoid vendors who are not able to join. The impact of an additional protocol may adversely impact both the cloud provider and the cloud consumer, as the consumer needs to factor the protocol into their procurement decisions, supplier engagement and onward supply chain processes. This is especially true in the very common scenario of application service providers who assemble and develop their offering on top of the offerings of global Cloud providers. Microsoft has thousands of local cloud partners who build solutions in this way who would feel any additional compliance burden. Care would need to be taken with the proposed voluntary protocol to ensure that it does not add to the existing compliance burden that already exists both for cloud providers and cloud consumers. Question 8. Using the New Zealand Code as an example, are there changes or improvements that could be made which would improve the efficacy of that process in an Australian context? Are there other issues not addressed in the New Zealand Code that need to be considered? Microsoft has provided extensive comment on the development of the New Zealand CloudCode. We would very much appreciate the opportunity to discuss our experiences and challenges in the development and implementation of the New Zealand CloudCode in greater detail with the ACS. Microsoft Pty Ltd, Page 6

ACS CLOUD COMPUTING CONSUMER PROTOCOL. Response from AIIA

ACS CLOUD COMPUTING CONSUMER PROTOCOL. Response from AIIA ACS CLOUD COMPUTING CONSUMER PROTOCOL Response from AIIA AUGUST 2013 INTRODUCTION The Australian Information Industry Association (AIIA) is the peak national body representing multinational and domestic

More information

AARNet submission to the Australian Computer Society Cloud Protocol Discussion Paper. James Sankar, Alex Reid August 2013

AARNet submission to the Australian Computer Society Cloud Protocol Discussion Paper. James Sankar, Alex Reid August 2013 AARNet submission to the Australian Computer Society Cloud Protocol Discussion Paper James Sankar, Alex Reid August 2013 AARNet, Australia's Academic and Research Network (AARNet) is the not- for- profit

More information

COMMUNICATIONS ALLIANCE LTD

COMMUNICATIONS ALLIANCE LTD COMMUNICATIONS ALLIANCE LTD Communications Alliance Response to ACS Discussion Paper on a Potential Cloud Computing Consumer Protocol - 1 - TABLE OF CONTENTS INTRODUCTION 2 SECTION 1 OVERVIEW OF RESPONSE

More information

Cloud Computing Consumer Protocol. ACS Cloud Discussion Paper July 2013

Cloud Computing Consumer Protocol. ACS Cloud Discussion Paper July 2013 Cloud Computing Consumer Protocol ACS Cloud Discussion Paper July 2013 ACS Cloud Protocol Discussion Paper July 2013 2 CONTENTS SECTION PAGE 1. Introduction and Purpose 3 2. Structure and Timelines 3 3.

More information

Microsoft Pty Ltd. Australian Financial System Inquiry: Response to request for further submissions

Microsoft Pty Ltd. Australian Financial System Inquiry: Response to request for further submissions Microsoft Pty Ltd Australian Financial System Inquiry: Response to request for further submissions August 2014 1 Response in relation to Chapter 9 of the Interim Report Microsoft is pleased to respond

More information

Privacy and Cloud Computing for Australian Government Agencies

Privacy and Cloud Computing for Australian Government Agencies Privacy and Cloud Computing for Australian Government Agencies Better Practice Guide February 2013 Version 1.1 Introduction Despite common perceptions, cloud computing has the potential to enhance privacy

More information

AUSTRALIAN INDUSTRY GROUP SUBMISSION to. Australian Computer Society. Discussion paper on the Cloud Computing Consumer Protocol

AUSTRALIAN INDUSTRY GROUP SUBMISSION to. Australian Computer Society. Discussion paper on the Cloud Computing Consumer Protocol AUSTRALIAN INDUSTRY GROUP SUBMISSION to Australian Computer Society Discussion paper on the Cloud Computing Consumer Protocol 6 September 2013 EXECUTIVE SUMMARY The Australian Industry Group (Ai Group)

More information

Cloud Computing Strategy. an addendum to the. Queensland Government. ICT Strategy 2013 17. Queensland Government

Cloud Computing Strategy. an addendum to the. Queensland Government. ICT Strategy 2013 17. Queensland Government Department of Science, Information Technology, Innovation and the Arts Queensland Government Cloud Computing Strategy an addendum to the Queensland Government ICT Strategy 2013 17 Supporting Queensland

More information

New Zealand Cloud Computing Code of Practice

New Zealand Cloud Computing Code of Practice New Zealand Cloud Computing Code of Practice Draft Code Consultation Document March 2012 v1.3 Contents Introduction... 3 Consultation Process... 3 Areas of Consultation.... 4 1. Approach of The Code...

More information

Security in the Cloud: Visibility & Control of your Cloud Service Providers

Security in the Cloud: Visibility & Control of your Cloud Service Providers Whitepaper: Security in the Cloud Security in the Cloud: Visibility & Control of your Cloud Service Providers Date: 11 Apr 2012 Doc Ref: SOS-WP-CSP-0412A Author: Pierre Tagle Ph.D., Prashant Haldankar,

More information

Information Sheet: Cloud Computing

Information Sheet: Cloud Computing info sheet 03.11 Information Sheet: Cloud Computing Info Sheet 03.11 May 2011 This Information Sheet gives a brief overview of how the Information Privacy Act 2000 (Vic) applies to cloud computing technologies.

More information

NSW Government. Cloud Services Policy and Guidelines

NSW Government. Cloud Services Policy and Guidelines NSW Government Cloud Services Policy and Guidelines August 2013 1 CONTENTS 1. Introduction 2 1.1 Policy statement 3 1.2 Purpose 3 1.3 Scope 3 1.4 Responsibility 3 2. Cloud services for NSW Government 4

More information

Cloud Computing in the Victorian Public Sector

Cloud Computing in the Victorian Public Sector Cloud Computing in the Victorian Public Sector AIIA response July 2015 39 Torrens St Braddon ACT 2612 Australia T 61 2 6281 9400 E info@aiia.com.au W www.aiia.comau Page 1 of 9 17 July 2015 Contents 1.

More information

Guideline 1. Cloud Computing Decision Making. Public Record Office Victoria Cloud Computing Policy. Version Number: 1.0. Issue Date: 26/06/2013

Guideline 1. Cloud Computing Decision Making. Public Record Office Victoria Cloud Computing Policy. Version Number: 1.0. Issue Date: 26/06/2013 Public Record Office Victoria Cloud Computing Policy Guideline 1 Cloud Computing Decision Making Version Number: 1.0 Issue Date: 26/06/2013 Expiry Date: 26/06/2018 State of Victoria 2013 Version 1.0 Table

More information

005ASubmission to the Serious Data Breach Notification Consultation

005ASubmission to the Serious Data Breach Notification Consultation 005ASubmission to the Serious Data Breach Notification Consultation (Consultation closes 4 March 2016 please send electronic submissions to privacy.consultation@ag.gov.au) Your details Name/organisation

More information

Draft Australian Privacy Principles (APP) Guidelines first tranche

Draft Australian Privacy Principles (APP) Guidelines first tranche The Association of Superannuation Funds of Australia Limited ABN 29 002 786 290 ASFA Secretariat PO Box 1485, Sydney NSW 2001 p: 02 9264 9300 (1800 812 798 outside Sydney) f: 1300 926 484 w: www.superannuation.asn.au

More information

RE: ITI Comments on Korea s Proposed Bill for the Development of Cloud Computing and Protection of Users

RE: ITI Comments on Korea s Proposed Bill for the Development of Cloud Computing and Protection of Users August 19, 2012 Korean Communications Commission Via e-mail to: ycs@kcc.go.kr RE: ITI Comments on Korea s Proposed Bill for the Development of Cloud Computing and Protection of Users Dear Director Yang:

More information

RE: ITI s Comments on Korea s Revised Proposed Bill for the Development of Cloud Computing and Protection of Users

RE: ITI s Comments on Korea s Revised Proposed Bill for the Development of Cloud Computing and Protection of Users July 3, 2013 Jung-tae Kim Director Smart Network & Communications Policy Division Ministry of Science, ICT, and Future Planning (MSIP) Via e-mail to: kchu@msip.go.kr RE: ITI s Comments on Korea s Revised

More information

COMMONWEALTH GOVERNMENT RESPONSE TO THE PRODUCTIVITY COMMISSION INQUIRY: THE MARKET FOR RETAIL TENANCY LEASES IN AUSTRALIA

COMMONWEALTH GOVERNMENT RESPONSE TO THE PRODUCTIVITY COMMISSION INQUIRY: THE MARKET FOR RETAIL TENANCY LEASES IN AUSTRALIA COMMONWEALTH GOVERNMENT RESPONSE TO THE PRODUCTIVITY COMMISSION INQUIRY: THE MARKET FOR RETAIL TENANCY LEASES IN AUSTRALIA August 2008 SUMMARY 1. The former Treasurer asked the Productivity Commission

More information

Email Protective Marking Standard Implementation Guide for the Australian Government

Email Protective Marking Standard Implementation Guide for the Australian Government Email Protective Marking Standard Implementation Guide for the Australian Government May 2012 (V2012.1) Page 1 of 14 Disclaimer The Department of Finance and Deregulation (Finance) has prepared this document

More information

CPNI VIEWPOINT 01/2010 CLOUD COMPUTING

CPNI VIEWPOINT 01/2010 CLOUD COMPUTING CPNI VIEWPOINT 01/2010 CLOUD COMPUTING MARCH 2010 Acknowledgements This viewpoint is based upon a research document compiled on behalf of CPNI by Deloitte. The findings presented here have been subjected

More information

Cloud Computing Consumer Protocol

Cloud Computing Consumer Protocol Cloud Computing Consumer Protocol Submission by the Australian Communications Consumer Action Network to the Australian Computer Society 16 August 2013 Australian Communications Consumer Action Network

More information

Australia s unique approach to trans-border privacy and cloud computing

Australia s unique approach to trans-border privacy and cloud computing Australia s unique approach to trans-border privacy and cloud computing Peter Leonard Partner, Gilbert + Tobin Lawyers and Director, iappanz In Australia, as in many jurisdictions, there have been questions

More information

DISCLOSURE STATEMENT PREPARED BY

DISCLOSURE STATEMENT PREPARED BY DISCLOSURE STATEMENT PREPARED BY - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

More information

Procurement Policy Note Use of Cyber Essentials Scheme certification

Procurement Policy Note Use of Cyber Essentials Scheme certification Procurement Policy Note Use of Cyber Essentials Scheme certification Action Note 09/14 25 September 2014 Issue 1. Government is taking steps to further reduce the levels of cyber security risk in its supply

More information

(a) the kind of data and the harm that could result if any of those things should occur;

(a) the kind of data and the harm that could result if any of those things should occur; Cloud Computing This information leaflet aims to advise organisations on the factors they should take into account in considering engaging cloud computing. It explains the relevance of the Personal Data

More information

Personal data and cloud computing, the cloud now has a standard. by Luca Bolognini

Personal data and cloud computing, the cloud now has a standard. by Luca Bolognini Personal data and cloud computing, the cloud now has a standard by Luca Bolognini Lawyer, President of the Italian Institute for Privacy and Data Valorization, founding partner ICT Legal Consulting Last

More information

COMPLIANCE FRAMEWORK AND REPORTING GUIDELINES

COMPLIANCE FRAMEWORK AND REPORTING GUIDELINES COMPLIANCE FRAMEWORK AND REPORTING GUIDELINES DRAFT FOR CONSULTATION June 2015 38 Cavenagh Street DARWIN NT 0800 Postal Address GPO Box 915 DARWIN NT 0801 Email: utilities.commission@nt.gov.au Website:

More information

NATIONAL INSURANCE BROKERS ASSOCIATION OF AUSTRALIA (NIBA) Submission to WorkCover Western Australia. Legislative Review 2013

NATIONAL INSURANCE BROKERS ASSOCIATION OF AUSTRALIA (NIBA) Submission to WorkCover Western Australia. Legislative Review 2013 NATIONAL INSURANCE BROKERS ASSOCIATION OF AUSTRALIA (NIBA) ABOUT NIBA Submission to WorkCover Western Australia Legislative Review 2013 February 2014 NIBA is the peak body of the insurance broking profession

More information

Office of Regulation Review (ORR) Submission regarding the Attorney General s Discussion Paper on Privacy protection in the private sector

Office of Regulation Review (ORR) Submission regarding the Attorney General s Discussion Paper on Privacy protection in the private sector Office of Regulation Review (ORR) Submission regarding the Attorney General s Discussion Paper on Privacy protection in the private sector The Office of Regulation Review (ORR) located within the Industry

More information

Pooled Registered Pension Plans in Ontario - What the Canadian Banks Have to Offer

Pooled Registered Pension Plans in Ontario - What the Canadian Banks Have to Offer Framework for Pooled Registered Pension Plans CBA Submission to the Ontario Ministry of Finance January 23, 2014 EXPERTISE CANADA BANKS ON LA RÉFÉRENCE BANCAIRE AU CANADA Framework for Pooled Registered

More information

XIT CLOUD SOLUTIONS LIMITED

XIT CLOUD SOLUTIONS LIMITED DISCLOSURE STATEMENT PREPARED BY - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

More information

CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES:

CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES: CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES: Privacy Responsibilities and Considerations Cloud computing is the delivery of computing services over the Internet, and it offers many potential

More information

Disclosure Requirements of CloudCode Software

Disclosure Requirements of CloudCode Software DISCLOSURE STATEMENT PREPARED BY - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

More information

Cloud Computing and Records Management

Cloud Computing and Records Management GPO Box 2343 Adelaide SA 5001 Tel (+61 8) 8204 8773 Fax (+61 8) 8204 8777 DX:336 srsarecordsmanagement@sa.gov.au www.archives.sa.gov.au Cloud Computing and Records Management June 2015 Version 1 Version

More information

Australian Government Information Security Manual CONTROLS

Australian Government Information Security Manual CONTROLS 2015 Australian Government Information Security Manual CONTROLS 2015 Australian Government Information Security Manual CONTROLS Commonwealth of Australia 2015 All material presented in this publication

More information

BRITISH COUNCIL DATA PROTECTION CODE FOR PARTNERS AND SUPPLIERS

BRITISH COUNCIL DATA PROTECTION CODE FOR PARTNERS AND SUPPLIERS BRITISH COUNCIL DATA PROTECTION CODE FOR PARTNERS AND SUPPLIERS Mat Wright www.britishcouncil.org CONTENTS Purpose of the code 1 Scope of the code 1 The British Council s data protection commitment and

More information

Protective security governance guidelines

Protective security governance guidelines Protective security governance guidelines Security of outsourced services and functions Approved 13 September 2011 Version 1.0 Commonwealth of Australia 2011 All material presented in this publication

More information

International money transfers public interest determination applications. Consultation paper

International money transfers public interest determination applications. Consultation paper International money transfers public interest determination applications Consultation paper Closing date for comment 4 August 2014 Purpose of consultation paper The Office of the Australian Information

More information

APES GN 30 Outsourced Services

APES GN 30 Outsourced Services APES GN 30 Outsourced Services Prepared and issued by Accounting Professional & Ethical Standards Board Limited ISSUED: March 2013 Copyright 2013 Accounting Professional & Ethical Standards Board Limited

More information

Mitigating and managing cyber risk: ten issues to consider

Mitigating and managing cyber risk: ten issues to consider Mitigating and managing cyber risk: ten issues to consider The board of directors is responsible for managing and mitigating risk exposure. A recent study conducted by the Ponemon Institute 1 revealed

More information

Cloud Software Services for Schools

Cloud Software Services for Schools Cloud Software Services for Schools Supplier self-certification statements with service and support commitments Supplier name Address Contact name Contact email Contact telephone Parent Teacher Online

More information

ITCRA Response. Request for Submissions on the Draft Version of the APP Guideline Chapters A to D and 1 to 5 covering APPs 1 to 5

ITCRA Response. Request for Submissions on the Draft Version of the APP Guideline Chapters A to D and 1 to 5 covering APPs 1 to 5 ITCRA Response Request for Submissions on the Draft Version of the APP Guideline Chapters A to D and 1 to 5 covering APPs 1 to 5 To: The Office of the Australian Information Commission Submitted: 20th

More information

Cloud Computing in a Government Context

Cloud Computing in a Government Context Cloud Computing in a Government Context Introduction There has been a lot of hype around cloud computing to the point where, according to Gartner, 1 it has become 'deafening'. However, it is important

More information

OVERVIEW. stakeholder engagement mechanisms and WP29 consultation mechanisms respectively.

OVERVIEW. stakeholder engagement mechanisms and WP29 consultation mechanisms respectively. Joint work between experts from the Article 29 Working Party and from APEC Economies, on a referential for requirements for Binding Corporate Rules submitted to national Data Protection Authorities in

More information

Accounting for Goodwill

Accounting for Goodwill Australian Accounting Standard AAS 18 June 1996 Accounting for Goodwill Prepared by the Public Sector Accounting Standards Board of the Australian Accounting Research Foundation and by the Australian Accounting

More information

The NREN s core activities are in providing network and associated services to its user community that usually comprises:

The NREN s core activities are in providing network and associated services to its user community that usually comprises: 3 NREN and its Users The NREN s core activities are in providing network and associated services to its user community that usually comprises: Higher education institutions and possibly other levels of

More information

Document and Records Management Systems

Document and Records Management Systems GPO Box 2343 Adelaide SA 5001 Tel (08) 8204 8773 Fax (08) 8204 8777 DX:467 srsarecordsmanagement@sa.gov.au www.archives.sa. gov.au Document and Records Management Systems August 2009 Version 2.1 Table

More information

ROYAL AUSTRALASIAN COLLEGE OF SURGEONS

ROYAL AUSTRALASIAN COLLEGE OF SURGEONS 1. SCOPE This policy details the College s privacy policy and related information handling practices and gives guidelines for access to any personal information retained by the College. This includes personal

More information

Cloud Software Services for Schools

Cloud Software Services for Schools Cloud Software Services for Schools Supplier self-certification statements with service and support commitments Please insert supplier details below Supplier name Address Isuz Ltd. trading as Schoolcomms

More information

Cloud Computing Security Considerations

Cloud Computing Security Considerations Cloud Computing Security Considerations Roger Halbheer, Chief Security Advisor, Public Sector, EMEA Doug Cavit, Principal Security Strategist Lead, Trustworthy Computing, USA January 2010 1 Introduction

More information

Cloud Software Services for Schools

Cloud Software Services for Schools Cloud Software Services for Schools Supplier self-certification statements with service and support commitments Please insert supplier details below Supplier name Address Contact name Contact email Contact

More information

Annex 1. Contract Checklist for Cloud-Based Genomic Research Version 1.0, 21 July 2015

Annex 1. Contract Checklist for Cloud-Based Genomic Research Version 1.0, 21 July 2015 Annex 1. Contract Checklist for Cloud-Based Genomic Research Version 1.0, 21 July 2015 The following comprises a checklist of areas that genomic research organizations or consortia (collectively referred

More information

Cloud Computing. Introduction

Cloud Computing. Introduction Cloud Computing Introduction This information leaflet aims to advise organisations which are considering engaging cloud computing on the factors they should consider. It explains the relationship between

More information

Microsoft Office 365 for Education. Professional services for schools that are looking to adopt Microsoft Office 365.

Microsoft Office 365 for Education. Professional services for schools that are looking to adopt Microsoft Office 365. Microsoft Office 365 for Education. Professional services for schools that are looking to adopt Microsoft Office 365. What is Microsoft Office 365 for Education? Microsoft Office 365 for Education is a

More information

Align Technology. Data Protection Binding Corporate Rules Processor Policy. 2014 Align Technology, Inc. All rights reserved.

Align Technology. Data Protection Binding Corporate Rules Processor Policy. 2014 Align Technology, Inc. All rights reserved. Align Technology Data Protection Binding Corporate Rules Processor Policy Confidential Contents INTRODUCTION TO THIS POLICY 3 PART I: BACKGROUND AND ACTIONS 4 PART II: PROCESSOR OBLIGATIONS 6 PART III:

More information

ADRI. Advice on managing the recordkeeping risks associated with cloud computing. ADRI-2010-1-v1.0

ADRI. Advice on managing the recordkeeping risks associated with cloud computing. ADRI-2010-1-v1.0 ADRI Advice on managing the recordkeeping risks associated with cloud computing ADRI-2010-1-v1.0 Version 1.0 29 July 2010 Advice on managing the recordkeeping risks associated with cloud computing 2 Copyright

More information

Privacy in the Cloud A Microsoft Perspective

Privacy in the Cloud A Microsoft Perspective A Microsoft Perspective November 2010 The information contained in this document represents the current view of Microsoft Corp. on the issues discussed as of the date of publication. Because Microsoft

More information

NATIONAL PARTNERSHIP AGREEMENT ON E-HEALTH

NATIONAL PARTNERSHIP AGREEMENT ON E-HEALTH NATIONAL PARTNERSHIP AGREEMENT ON E-HEALTH Council of Australian Governments An agreement between the Commonwealth of Australia and the States and Territories, being: The State of New South Wales The State

More information

Quick guide: Using the Cloud to support your business

Quick guide: Using the Cloud to support your business Quick guide: Using the Cloud to support your business This Quick Guide is one of a series of information products targeted at small to medium sized enterprises (SMEs). It is designed to help businesses

More information

Data Protection Act 1998. Guidance on the use of cloud computing

Data Protection Act 1998. Guidance on the use of cloud computing Data Protection Act 1998 Guidance on the use of cloud computing Contents Overview... 2 Introduction... 2 What is cloud computing?... 3 Definitions... 3 Deployment models... 4 Service models... 5 Layered

More information

Records Disposal Schedule Anti-Discrimination Services Northern Territory Anti-Discrimination Commission

Records Disposal Schedule Anti-Discrimination Services Northern Territory Anti-Discrimination Commission Records disposal schedule Records Disposal Schedule Anti-Discrimination Services Northern Territory Anti-Discrimination Commission Disposal Schedule No. 2015/12 August 2015 NT Archives Service For information

More information

NSW Government. Cloud Services Policy and Guidelines

NSW Government. Cloud Services Policy and Guidelines NSW Government Cloud Services Policy and Guidelines August 2013 CONTENTS 1. Introduction 2 1.1 Policy statement 3 1.2 Purpose 3 1.3 Scope 3 1.4 Responsibility 3 2. Cloud services for NSW Government 4 2.1

More information

CYBERSECURITY IN FINANCIAL SERVICES POINT OF VIEW CHALLENGE 1 REGULATORY COMPLIANCE ACROSS GEOGRAPHIES

CYBERSECURITY IN FINANCIAL SERVICES POINT OF VIEW CHALLENGE 1 REGULATORY COMPLIANCE ACROSS GEOGRAPHIES POINT OF VIEW CYBERSECURITY IN FINANCIAL SERVICES Financial services institutions are globally challenged to keep pace with changing and covert cybersecurity threats while relying on traditional response

More information

APES GN 30 Outsourced Services

APES GN 30 Outsourced Services APES GN 30 Outsourced Services Prepared and issued by Accounting Professional & Ethical Standards Board Limited ISSUED: [DATE] Copyright 2012 Accounting Professional & Ethical Standards Board Limited (

More information

AN INSIDE VIEW FROM THE EU EXPERT GROUP ON CLOUD COMPUTING

AN INSIDE VIEW FROM THE EU EXPERT GROUP ON CLOUD COMPUTING AN INSIDE VIEW FROM THE EU EXPERT GROUP ON CLOUD COMPUTING 1. Overview and Background On 27 September 2012, the European Commission adopted a strategy for "Unleashing the potential of cloud computing in

More information

Cloud-Based ICT Services Checklist

Cloud-Based ICT Services Checklist Cloud-Based ICT Services Checklist Guideline A non-exhaustive list of considerations to be made when evaluating, purchasing, implementing and managing cloud-based ICT services. Keywords: Cloud-based ICT

More information

Cloud Procurement Discussion Paper. For Comment

Cloud Procurement Discussion Paper. For Comment Cloud Procurement Discussion Paper For Comment AUGUST 2014 Acronyms Acronym AGIMO ASD DCaaS MUL IaaS NIST PaaS RFT SaaS SCS Definition Australian Government Information Management Office Australian Signals

More information

NATIONAL INSURANCE BROKERS ASSOCIATION OF AUSTRALIA (NIBA) SUBMISSION TO THE ECONOMIC REGULATION AUTHORITY

NATIONAL INSURANCE BROKERS ASSOCIATION OF AUSTRALIA (NIBA) SUBMISSION TO THE ECONOMIC REGULATION AUTHORITY NATIONAL INSURANCE BROKERS ASSOCIATION OF AUSTRALIA (NIBA) SUBMISSION TO THE ECONOMIC REGULATION AUTHORITY INQUIRY INTO WESTERN AUSTRALIA S HOME INDEMNITY INSURANCE ARRANGEMENTS ABOUT NIBA 16 August 2012

More information

2010THE LEGISLATIVE ASSEMBLY FOR THEAUSTRALIAN CAPITAL TERRITORY. WORKPLACE PRIVACY BILL 2010EXPLANATORY STATEMENT Circulated by Amanda Bresnan MLA

2010THE LEGISLATIVE ASSEMBLY FOR THEAUSTRALIAN CAPITAL TERRITORY. WORKPLACE PRIVACY BILL 2010EXPLANATORY STATEMENT Circulated by Amanda Bresnan MLA 2010THE LEGISLATIVE ASSEMBLY FOR THEAUSTRALIAN CAPITAL TERRITORY WORKPLACE PRIVACY BILL 2010EXPLANATORY STATEMENT Circulated by Amanda Bresnan MLA OVERVIEW The objects of this Bill are to ensure that employers

More information

REPORT 59 Equity release products

REPORT 59 Equity release products REPORT 59 Equity release products November 2005 Executive summary In the last year Australia has seen the rapid development of a range of equity release products, where consumers can obtain current financial

More information

NSW Government. Data Centre & Cloud Readiness Assessment Services Standard. v1.0. June 2015

NSW Government. Data Centre & Cloud Readiness Assessment Services Standard. v1.0. June 2015 NSW Government Data Centre & Cloud Readiness Assessment Services Standard v1.0 June 2015 ICT Services Office of Finance & Services McKell Building 2-24 Rawson Place SYDNEY NSW 2000 standards@finance.nsw.gov.au

More information

Financial Adviser Regulations: Discretionary Investment Management Services and Custody

Financial Adviser Regulations: Discretionary Investment Management Services and Custody Financial Adviser Regulations: Discretionary Investment Management Services and Custody Submission by Forsyth Barr General or introductory comments We agree with aligning the requirements for AFAs providing

More information

Professional Trainers, Licensing Assessment and Consultancy Services Professional Indemnity and Public Liability Insurance Proposal Form

Professional Trainers, Licensing Assessment and Consultancy Services Professional Indemnity and Public Liability Insurance Proposal Form Tranznet Association Inc Arranges the insurance IMPORTANT INFORMATION Professional Trainers, Licensing Assessment and Consultancy Services Professional Indemnity and Public Liability Insurance Proposal

More information

Whitepaper. Implications of Federal Privacy Reforms for Federal Government Agencies. Date Released: 1 August 2013

Whitepaper. Implications of Federal Privacy Reforms for Federal Government Agencies. Date Released: 1 August 2013 Whitepaper Implications of Federal Privacy Reforms for Federal Government Agencies Date Released: 1 August 2013 Authors: Amanda Biggs and Helaine Leggat Disclaimer This White Paper is published for general

More information

Catalyst Consulting & Events (CCE) takes seriously its commitment to preserve the privacy of the personal information that we collect.

Catalyst Consulting & Events (CCE) takes seriously its commitment to preserve the privacy of the personal information that we collect. PRIVACY POLICY 1. Introduction Catalyst Consulting & Events (CCE) takes seriously its commitment to preserve the privacy of the personal information that we collect. We will only collect information that

More information

AISA Position Statement: Mandatory Data Breach Notification in Australia

AISA Position Statement: Mandatory Data Breach Notification in Australia AISA Position Statement: Mandatory Data Breach Notification in Australia Overview Although AISA members are broadly in support of mandatory data breach notification in Australia they have a number of concerns

More information

DIGITALEUROPE and European Services Forum (ESF) response to the Draft Supervision Rules on Insurance Institutions Adopting Digitalised Operations

DIGITALEUROPE and European Services Forum (ESF) response to the Draft Supervision Rules on Insurance Institutions Adopting Digitalised Operations DIGITALEUROPE and European Services Forum (ESF) response to the Draft Supervision Rules on Insurance Institutions Adopting Digitalised Operations Brussels, October 2015 INTRODUCTION On behalf of the European

More information

Submission on Insolvency Practitioner Regulation To the Competition, Trade & Investment Branch, Ministry of Economic Development.

Submission on Insolvency Practitioner Regulation To the Competition, Trade & Investment Branch, Ministry of Economic Development. Submission on Insolvency Practitioner Regulation To the Competition, Trade & Investment Branch, Ministry of Economic Development Prepared by Grant Thornton Submission on Insolvency Practitioner Regulation

More information

Life Insurance Product Advice - A Guide for the Appointed Actuary

Life Insurance Product Advice - A Guide for the Appointed Actuary LIFE INSURANCE AND WEALTH MANAGEMENT PRACTICE COMMITTEE Information Note: Product Advice regarding Policies and Reinsurance to a Life Insurer or Friendly Society under LPS 320 Contents A. Status of Information

More information

Using AWS in the context of Australian Privacy Considerations October 2015

Using AWS in the context of Australian Privacy Considerations October 2015 Using AWS in the context of Australian Privacy Considerations October 2015 (Please consult https://aws.amazon.com/compliance/aws-whitepapers/for the latest version of this paper) Page 1 of 13 Overview

More information

UNCLASSIFIED UNCONTROLLED-IF-PRINTED. Public. 2:51 Outsourced Offshore and Cloud Based Computing Arrangements

UNCLASSIFIED UNCONTROLLED-IF-PRINTED. Public. 2:51 Outsourced Offshore and Cloud Based Computing Arrangements Defence Security Manual DSM Part 2:51 Outsourced Offshore and Cloud Based Computing Arrangements Version 1 ation date July 2105 Amendment list 23 Optimised for Screen; Print; Screen Reader Releasable to

More information

Residential Tenancies and Rooming Accommodation Amendment Bill 2011

Residential Tenancies and Rooming Accommodation Amendment Bill 2011 Residential Tenancies and Rooming Accommodation Amendment Bill 2011 Explanatory Notes Title of the Bill Residential Tenancies and Rooming Accommodation Amendment Bill 2011 (the Bill) Objectives of the

More information

SERVICES OVERVIEW. Integrating Risk, Technology, People and Process for a sustainable Future CONTACT US. About Us. Our Business Philosophy

SERVICES OVERVIEW. Integrating Risk, Technology, People and Process for a sustainable Future CONTACT US. About Us. Our Business Philosophy About Us Vestinex Pty Ltd is a boutique professional business services provider based in Sydney, Australia. We offer a range of services across two broad categories of Ethics and Investigations and Information

More information

Contracting with a Cloud Service Provider DATA PROTECTION WORKSHOP NJERI OLWENY, MICROSOFT

Contracting with a Cloud Service Provider DATA PROTECTION WORKSHOP NJERI OLWENY, MICROSOFT Contracting with a Cloud Service Provider DATA PROTECTION WORKSHOP NJERI OLWENY, MICROSOFT Overview Cloud computing offers great opportunities for organizations, including schools, hospitals and businesses

More information

Cloud (educational apps) software services and the Data Protection Act

Cloud (educational apps) software services and the Data Protection Act Cloud (educational apps) software services and the Data Protection Act Departmental advice for local authorities, school leaders, school staff and governing bodies October 2014 Contents 1. Summary 3 About

More information

Deloitte Access Economics Pty Ltd ACN149 633 116 Grosvenor Place Level 9, 225 George Street PO Box N250 Sydney, NSW 2000 Competition Policy Review Secretariat The Treasury Langton Crescent PARKES ACT 2600

More information

Buchanan Law Communications Update

Buchanan Law Communications Update Buchanan Law Communications Update Planning for the regulatory future This edition of the is all about change: or more accurately, preparing for change. Australia s regulatory bodies have been busy addressing

More information

Policy Statement. Employee privacy, data protection and human resources. Prepared by the Commission on E-Business, IT and Telecoms. I.

Policy Statement. Employee privacy, data protection and human resources. Prepared by the Commission on E-Business, IT and Telecoms. I. International Chamber of Commerce The world business organization Policy Statement Employee privacy, data protection and human resources Prepared by the Commission on E-Business, IT and Telecoms I. Introduction

More information

HKCS RESPONSE COMMONLY ACCEPTED AUDIT OR ASSESSMENT MECHANISM TO CERTIFY INFORMATION SECURITY STANDARDS

HKCS RESPONSE COMMONLY ACCEPTED AUDIT OR ASSESSMENT MECHANISM TO CERTIFY INFORMATION SECURITY STANDARDS Hong Kong Computer Society Room 1915, 19/F, China Merchants Tower, Shun Tak Centre, 168 Connaught Road Central, Hong Kong Tel: 2834 2228 Fax: 2834 3003 URL: http://www.hkcs.org.hk Email: hkcs@hkcs.org.hk

More information

Cloud Security checklist Are you really ready for Cloud

Cloud Security checklist Are you really ready for Cloud checklist Are you really ready for Cloud Introduction Once you have assessed the benefits of migrating a business system or its function to the Cloud (See our White Book of Cloud Adoption), the next step

More information

Cloud Computing Consumer Protocol

Cloud Computing Consumer Protocol 78 Sidaway St Chapman ACT 2611 AUSTRALIA Tel: +61 2 6288 6916 Roger.Clarke@xamax.com.au.. http://www.xamax.com.au/ 12 August 2013 Mr A. Redman Head of Policy and External Affairs Australian Computer Society

More information

The HR Skinny: Effectively managing international employee data flows

The HR Skinny: Effectively managing international employee data flows The HR Skinny: Effectively managing international employee data flows Topics we will cover today Laws affecting HR data flows HR international data protection challenges and strategic solutions Case study

More information

/ WHITEPAPER / THE EVOLUTION OF CLOUD ADOPTION IN AUSTRALIA. By Melbourne IT Enterprise Services

/ WHITEPAPER / THE EVOLUTION OF CLOUD ADOPTION IN AUSTRALIA. By Melbourne IT Enterprise Services / WHITEPAPER / THE EVOLUTION OF CLOUD ADOPTION IN AUSTRALIA By Melbourne IT Enterprise Services THE EVOLUTION OF CLOUD According to the United States Department of Commerce Computer Security Division i,

More information

APES 205 CONFORMITY WITH ACCOUNTING STANDARDS

APES 205 CONFORMITY WITH ACCOUNTING STANDARDS APES 205 CONFORMITY WITH ACCOUNTING STANDARDS (Issued December 2007) CONTENTS Section Scope and application...1 Definitions...2 Fundamental responsibilities of Members...3 - Public interest - Professional

More information

CLOUD COMPUTING GUIDELINES FOR LAWYERS

CLOUD COMPUTING GUIDELINES FOR LAWYERS INTRODUCTION Legal practices are increasingly using cloud storage and software systems as an alternative to in-house data storage and IT programmes. The cloud has a number of advantages particularly flexibility

More information

www.corrs.com.au OFFSHORING Data the new privacy laws

www.corrs.com.au OFFSHORING Data the new privacy laws www.corrs.com.au OFFSHORING Data the new privacy laws OFFSHORING DATA THE NEW PRIVACY LAWS Transfer of data by Australian organisations to other jurisdictions is increasingly common. This is a result of

More information