Jurisdiction in the Cloud: Clear Rules to Build Confidence in Cloud Computing. Steve Mutkoski Worldwide Policy Director Microsoft Corporation

Similar documents
UK Cloud Computing Interception - nothing new. Clive Gringras. Olswang LLP

Data Obesity: Ethics, Law or Regulation?

Hardware enhanced Security in Cloud Compu8ng. Cloud Compu8ng (Public IaaS)

Cloud Infrastructure Services Survey: Key UK Takeaways. Survey conducted by

CS 91: Cloud Systems & Datacenter Networks Failures & Replica=on

THE WINDOWS AZURE PROGRAMMING MODEL

Opportuni)es and Challenges of Textual Big Data for the Humani)es

WINDOWS AZURE EXECUTION MODELS

Data Management in the Cloud: Limitations and Opportunities. Annies Ductan

Main Research Gaps in Cyber Security

Cloud Compu)ng. Yeow Wei CHOONG Anne LAURENT

How To Protect Virtualized Data From Security Threats

Retaining globally distributed high availability Art van Scheppingen Head of Database Engineering

Licensing++ for Clouds. Mark Perry

FULLY INTEGRATED GOVERNANCE, RISK MANAGEMENT, COMPLIANCE AND AUDIT SOFTWARE

Everything You Need to Know about Cloud BI. Freek Kamst

Top Practices in Health IT Compliance. Data Breach & Leading Program Prac3ces

Kaseya Fundamentals Workshop DAY THREE. Developed by Kaseya University. Powered by IT Scholars

InterCloud Exchange: pia5aforme neutrali di comunicazione tra sistemi di Cloud Compu:ng. Cosimo Anglano Lorenzo Benussi Andrea Casalegno Andrea

CPNI VIEWPOINT 01/2010 CLOUD COMPUTING

ISO/IEC Safeguarding Personal Information in the Cloud. Whitepaper

B2B Offerings. Helping businesses op2mize. Infolob s amazing b2b offerings helps your company achieve maximum produc2vity

Cisco Intercloud Fabric for Business

WINDOWS AZURE NETWORKING

WINDOWS AZURE DATA MANAGEMENT

THE VIRTUALIZATION CHALLENGE

Prac+cali+es of CE technical file and quality system for medical so=ware

CS 91: Cloud Systems & Datacenter Networks Misc. Topics

Interna'onal Standards Ac'vi'es on Cloud Security EVA KUIPER, CISA CISSP HP ENTERPRISE SECURITY SERVICES

WHITE PAPER. Building Blocks of the Modern Data Center

WINDOWS AZURE DATA MANAGEMENT AND BUSINESS ANALYTICS

Contact Center Rou,ng Strategies for Improving Customer Experience

Qubera Solu+ons Access Governance a next genera0on approach to Iden0ty Management

Implications for Cloud Computing & Data Privacy

HI THIS IS URGENT PLZ FIX ASAP: Cri5cal Vulnerabili5es and Bug Bounty Programs

Cloud Platforms in the Enterprise

Compu4ng Privacy Requirements

Privacy in the Cloud A Microsoft Perspective

Taking E-Payment to the pan-european level

Networked Virtual Spaces and Clouds. Magda El Zarki UC Irvine

Software Engineering Suite. BSc/BSc(Hons) IT Management for Business BSc/BSc(Hons) Software Development for Business BSc/BSc(Hons) Computing

Clusters in the Cloud

Road Public Transport Informa5on Management Program BIG DATA. Market Consulta5on August 7, 2015

Building Secure Cloud Applications. On the Microsoft Windows Azure platform

Migra1ng to the Cloud

ECEC Europe s Cloud Future. Chambre du Commerce September. October. 14. Mai 2013, Konzerthaus. 1st 2014

The Real Score of Cloud

UNIFIED, END- TO- END EDISCOVERY

How To Create An E Signature System On Cloud On Windows Azure (Windows) And A Client (For A Large Logistics Organization)

Harbor law in the region have added to customer angst over data locality, so this is timely for NTT.

Microsoft Private Cloud Fast Track

Workforce Strategy Survey: Global Key Findings

Cloud Trends and Survey Results

Norwegian Data Inspectorate

Will The Document Survive?

WHITE PAPER. Data Center Fabrics. Why the Right Choice is so Important to Your Business

Building an Effec.ve Cloud Security Program

Data Center Evolu.on and the Cloud. Paul A. Strassmann George Mason University November 5, 2008, 7:20 to 10:00 PM

SDN Controller Requirement

/Endpoint Security and More Rondi Jamison

Webinar: Having the Best of Both World- Class Customer Experience and Comprehensive Iden=ty Security

Migrating to Hosted Telephony. Your ultimate guide to migrating from on premise to hosted telephony.

PRIVACY CHECKLIST FOR CLOUD SERVICE CONTRACTS

This white paper describes the three reasons why backup is a strategic element of your IT plan and why it is critical to your business that you plan

Legacy Archiving How many lights do you leave on? September 14 th, 2015

Workshop : Open and Big Data for Life Imaging

Project Por)olio Management

The benefits of migrating to Exchange 2010

Agenda. FY16 State Budget Advocacy 3/9/15. Housing Ac0on Illinois 2015 Advocacy Agenda Webinar March 9, :00 p.m. to 4:00 p.m.

I. Personal data and its use in the business to business environment.

Ch. 13 Cloud Services. Magda El Zarki Dept. of CS UC, Irvine

Unleashing the Potential of Cloud Computing in Europe - What is it and what does it mean for me?

benefit of virtualiza/on? Virtualiza/on An interpreter may not work! Requirements for Virtualiza/on 1/06/15 Which of the following is not a poten/al

Journey to the Private Cloud. Key Enabling Technologies

Challenges emerging from future cloud applica4on scenarios

Texas Digital Government Summit. Data Analysis Structured vs. Unstructured Data. Presented By: Dave Larson

Three Ways Enterprises are Protecting SQL Server in the Cloud

A Flexible and Comprehensive Approach to a Cloud Compliance Program

Program Model: Muskingum University offers a unique graduate program integra6ng BUSINESS and TECHNOLOGY to develop the 21 st century professional.

Energy Policy Breakfast The financing of new energy infrastructure in the EU: obstacles and solu9ons. Jérôme Guillet 23 March 2011

The Development of Cloud Interoperability

Ana Juan Ferrer Cloud Forward 2015, 07/10/2015

Cloud Computing. Chapter 1 Introducing Cloud Computing

Outlook. Corporate Research and Technologies, Munich, Germany. 20 th May 2010

CLINES Cluster- based Innova6on through Embedded Systems technology

Understanding NoSQL on Microsoft Azure

Distributed Systems Interconnec=ng Them Fundamentals of Distributed Systems Alvaro A A Fernandes School of Computer Science University of Manchester

CSER & emerge Consor.a EHR Working Group Collabora.on on Display and Storage of Gene.c Informa.on in Electronic Health Records

Drawing Lines in the Cloud: Jurisdictional Access to Data. Nancy Libin Mary Ellen Callahan

CUMULUX WHICH CLOUD PLATFORM IS RIGHT FOR YOU? COMPARING CLOUD PLATFORMS. Review Business and Technology Series

Data Center DC planning for the next 5 10 years. Copyright Experture and Robert Frances Group, all rights reserved

Adding value as a Cloud Broker. Nick Hyner Director Cloud Services EMEA Twitter Dell.com/Cloud

Today s Mobile Internet. Geoff Huston, APNIC Labs

There s a Future in it: How will EMS and Healthcare Reform Co-exist?

CS 5150 So(ware Engineering Legal Aspects of So(ware Development

Cloud computing with the Azure platform

Can Cloud Hos+ng Providers Really Replace. Your Cri(cal IT Infrastructure?

2 e 2 : A S t r o n g S t o r y i n D a t a c e n t e r T r a n s f o r m a t i o n a n d C l o u d

Answering the Requirements of Flash-Based SSDs in the Virtualized Data Center

Transcription:

Jurisdiction in the Cloud: Clear Rules to Build Confidence in Cloud Computing Steve Mutkoski Worldwide Policy Director Microsoft Corporation

Cloud Computing and Jurisdiction Why cloud ma,ers: Dis3nguishing business and technical aspects of cloud compu3ng Tradi3onal no3ons of jurisdic3on and some examples in the cloud context Solu3ons or ways forward?

Cloud Computing Creates Significant New Opportunities for Business & Government Cost Efficiency Agility Cloud Computing Innovation Economic Growth

Windows Azure: Distributed Computing and Data Storage Regardless of how it s stored in blobs, tables, or queues all data held in Windows Azure storage is replicated three 3mes. This replica3on allows fault tolerance, since losing a copy isn t fatal. On Windows Azure, an applica3on typically has mul3ple instances, each running a copy of all or part of the applica3on s code. Each of these instances runs in its own Windows virtual machine (VM). [A] developer creates applica3ons using Web roles and/or Worker roles, then tells Windows Azure how many instances of each role to run. Windows Azure silently creates a VM for each instance, then runs the applica3on in those VMs. Introducing the Windows Azure Pla6orm. David Chappell (2009)

Windows Azure Applica'ons and Data Connect Compute Storage Fabric Controller

Technical Consequences Data is likely at least three places at any given 3me May be sharded meaning it is further spread out May be moved to op3mize delivery 3me Instances may be spread across data centers Instances are killed and re- spawned at intervals May be moved to balance demand at rest vs. in transit

Legal Uncertainty Clouds Expansion and Adoption of Cloud Computing UK-based provider of email in the cloud 5 th fastest-growing company in Europe 1 impact Impact Higher operating costs Higher customer prices Investment diverted to non-european countries It s counter-productive that we do not have a Single Digital Market in place. Because of the added costs of operating multiple resources in multiple European countries, we have decided to look elsewhere for growth opportunities. Jus5n Pirie, Cloud Strategist, Mimecast 1 Deloi,e Technology Fast 500 EMEA 2010

Jurisdiction and the cloud Tradi3onal no3ons of jurisdic3on in personam and in rem jurisdic3on Par3es to cloud disputes Cloud infrastructure provider, Cloud service provider and Cloud user; Other third par3es, regulators How does the issue of jurisdic3on arise in the cloud? Contractual disputes Asser3on of IPR rights Regulatory ac3ons Law enforcement access

Regulatory enforcement: Data protection regulations Patchwork of regula3on in this area is a worldwide problem Need for EU harmoniza3on is the 3p of the iceberg Varia3on in categories of controls as well as specific requirements Some controls that predate modern systems and cloud compu3ng Jurisdic3on ma,ers Difference between having to comply with one, several or possibly many conflic3ng or vague sets of requirements A burden and risk that falls dispropor3onately on small and medium size cloud providers

Law Enforcement Access An ac3ve topic in recent weeks There are many layers of laws enabling law enforcement access to informa3on stored on service provider Is the US Patriot Act unique?

UK Cloud Computing Interception - nothing new Some UK cloud- compu3ng customers are concerned that they should not entrust US cloud- providers with their data for fear of US law enforcement intercep3on. If intercep3on is so much of a concern they should not only avoid US cloud providers but also should avoid using the UK s telephone, the Internet, and the postal system. The intercep3on of communica3ons, whether stored in the 21st Century cloud or sealed in 16th Century scrolls, and whether here in the UK or in the US, is nothing new. All communica3ons data, where jus3fied, may be intercepted by the State s watchful and propor3onal Clive eye. Gringras (2011), available at h,p://www.olswang.com/pdfs/ CloudCompu3ngIntercep3on_CQG.pdf

Law Enforcement and Cloud Computing Law enforcement agencies within the EU operate by virtue of the specific powers they are granted to gather informa3on and evidence and many EU Member States possess legisla3on which grants extensive and ooen intrusive inves3gatory powers to na3onal authori3es. In the end, law enforcement access to data is not a new issue nor an issue that is specific to cloud compu3ng. Tanguy Van Overstraeten (2011) available at h,p://www.linklaters.com/pdfs/mkt/london/law%20enforcement.pdf

In Defence of the Cloud What should we make of recent reports about the banning by the Dutch government of non EU- based cloud services and the launch by leading providers of EU- only clouds? Is this fierce European protec3onism or sensible data protec3on? If anything, these developments show a trend towards restric3ng cloud compu3ng services geographically, so that the fuzzy Internet cloud becomes a series of neatly divided gas bubbles. However, instead of a technological uproar against such an aberra3on, there seems to be a quiet acceptance based on legal constraints and half- baked security arguments. Is data protec3on being cited once again as the jus3fica3on for s3fling technological progress? That would not be surprising, but it is somewhat unfair and clearly unnecessary. Eduardo Ustaran (2011) available at h,p://www.scl.org/site.aspx?i=ed22541

Solutions- Toward a seamless and borderless cloud Greater bilateral and mul3lateral engagement by governments Some work already under way These agreements take 3me Harmonizing and unifying underlying substan3ve law E.g., data protec3on Would be a good first step

Questions?

Thank You