Cloud Computing. by Civic Consulting (research conducted October 2011 January 2012)

Similar documents
Cloud Computing and Security Risk Analysis Qing Liu Technology Architect STREAM Technology Lab

Perspectives on Cloud Computing and Standards. Peter Mell, Tim Grance NIST, Information Technology Laboratory

CSO Cloud Computing Study. January 2012

Privacy and security in the cloud

Perspectives on Moving to the Cloud Paradigm and the Need for Standards. Peter Mell, Tim Grance NIST, Information Technology Laboratory

Unleashing the Potential of Cloud Computing in Europe - What is it and what does it mean for me?

Topics. Images courtesy of Majd F. Sakr or from Wikipedia unless otherwise noted.

Why Private Cloud? Nenad BUNCIC VPSI 29-JUNE-2015 EPFL, SI-EXHEB

The Keys to the Cloud: The Essentials of Cloud Contracting

Drawing Lines in the Cloud: Jurisdictional Access to Data. Nancy Libin Mary Ellen Callahan

U.S. HOUSE OF REPRESENTATIVES SUBCOMMITTEE ON TECHNOLOGY AND INNOVATION COMMITTEE ON SCIENCE, SPACE, AND TECHNOLOGY HEARING CHARTER

A Flexible and Comprehensive Approach to a Cloud Compliance Program

Cloud Computing Masterclass

Cloud Computing in a Government Context

THE CLOUD: OPPORTUNITIES AND ISSUES

Strategic approach to cloud computing deployment

NATO s Journey to the Cloud Vision and Progress

CLOUD COMPUTING. A Primer

Security Issues in Cloud Computing

CLOUD BASED SCADA. Removing Implementation and Deployment Barriers. Liam Kearns Open Systems International, Inc.

Cloud Strategies for Public Sector in Central and Eastern Europe

Information Technology: This Year s Hot Issue - Cloud Computing

Cloud Computing and Government Services August 2013 Serdar Yümlü SAMPAŞ Information & Communication Systems

Cloud Security. Peter Jopling IBM UK Ltd Software Group Hursley Labs. peterjopling IBM Corporation

Guideline 1. Cloud Computing Decision Making. Public Record Office Victoria Cloud Computing Policy. Version Number: 1.0. Issue Date: 26/06/2013

Cloud Computing Best Practices. Creating Effective Cloud Computing Contracts for the Federal Government: Best Practices for Acquiring IT as a Service

BEUC s contribution on Cloud Computing for the Public Hearing in the ITRE Committee, European Parliament, 29 May 2013

Procurement Innovation for Cloud Services in Europe

CPNI VIEWPOINT 01/2010 CLOUD COMPUTING

INTRODUCTION TO CLOUD COMPUTING CEN483 PARALLEL AND DISTRIBUTED SYSTEMS

Summary of responses to the public consultation on Cloud computing run by CNIL from October to December 2011 and analysis by CNIL

OFFICE OF AUDITS & ADVISORY SERVICES CLOUD COMPUTING AUDIT FINAL REPORT

Resolution on Consumer Protection in Cloud Computing

Berlin, 15 th November Mark Dunne SaaSAssurance

(a) the kind of data and the harm that could result if any of those things should occur;

SECURITY & DATA PROTECTION ON THE CLOUD. Evènement parallèle organisé par l ANSI 16 novembre 2015 Hammamet, Tunisie

An SME perspective on Cloud Computing November 09. Survey

Implications for Cloud Computing & Data Privacy

Leading by Example - Government Cloud Services from the UK, Germany and Japan

ITL BULLETIN FOR JUNE 2012 CLOUD COMPUTING: A REVIEW OF FEATURES, BENEFITS, AND RISKS, AND RECOMMENDATIONS FOR SECURE, EFFICIENT IMPLEMENTATIONS

Cloud Based E-Government: Benefits and Challenges

Legal aspects of cloud computing

Cloud SingularLogic:

Cloud Computing; What is it, How long has it been here, and Where is it going?

Myths of Cloud Computing Business Models, Security Issues and Insights from Empirical Surveys

Deutsche Börse Cloud Exchange AG First vendor-neutral platform for IaaS cloud computing products. October 2013

(DRAFT)( 2 ) MOTION FOR A RESOLUTION

DIGITAL 21 STRATEGY ADVISORY COMMITTEE. Adoption of Cloud Computing Model in Government

CHAPTER 8 CLOUD COMPUTING

The problem of cloud data governance

Essential Characteristics of Cloud Computing: On-Demand Self-Service Rapid Elasticity Location Independence Resource Pooling Measured Service

Delivering Government Services through the Cloud. Ian Osborne, Intellect Director Cloud & Government IT ICT KTN

AskAvanade: Answering the Burning Questions around Cloud Computing

Seeing Though the Clouds

Clo l ud d C ompu p tin i g

New Zealand Cloud Computing Code of Practice

Recordkeeping and Archiving in the Cloud. Is There a Silver Lining?

Key Considerations of Regulatory Compliance in the Public Cloud

ADOPTING CLOUD COMPUTING AS AN ICT DEPLOYMENT STRATEGY FOR DELIVERING SERVICES IN THE GOVERNMENT

Cloud Security Introduction and Overview

Planning in Transport and Logistics Future Internet Solutions for Improved Integration and Collaboration

CCBE RESPONSE REGARDING THE EUROPEAN COMMISSION PUBLIC CONSULTATION ON CLOUD COMPUTING

Information Security: Cloud Computing

White Paper on CLOUD COMPUTING

Securing and Auditing Cloud Computing. Jason Alexander Chief Information Security Officer

Cloud for Europe lessons learned

In-House Counsel Day Priorities for 2012

Cloud Computing and Records Management

Cloud Computing: The atmospheric jeopardy. Unique Approach Unique Solutions. Salmon Ltd 2014 Commercial in Confidence Page 1 of 5

E-PROCUREMENT REDUCES OPPORTUNITIES FOR CORRUPTION and BRIBERY

Purpose. Service Model SaaS (Applications) PaaS (APIs) IaaS (Virtualization) Use Case 1: Public Use Case 2: Use Case 3: Public.

Cloud Computing. Introduction

Cloud for Europe trusted Cloud Services for the European market for public administrations

IS PRIVATE CLOUD A UNICORN?

Cloud computing and personal data protection. Gwendal LE GRAND Director of technology and innovation CNIL

The demand of Cloud Computing in Europe: drivers, barriers, market estimates

AN INSIDE VIEW FROM THE EU EXPERT GROUP ON CLOUD COMPUTING

Cloud computing: the state of the art and challenges. Jānis Kampars Riga Technical University

Service-Oriented Cloud Automation. White Paper

Cloud Computing Guide & Handbook. SAI USA Madhav Panwar

Cloud Based Computing: Are we Ready?

Office of the Government Chief Information Officer The Government of the Hong Kong Special Administrative Region

CLOUD IN HEALTHCARE EXECUTIVE SUMMARY 1/21/15

Contracting for Cloud Computing

On Premise Vs Cloud: Selection Approach & Implementation Strategies

PROGRAMME OVERVIEW: G-CLOUD APPLICATIONS STORE FOR GOVERNMENT DATA CENTRE CONSOLIDATION

Fujitsu Dynamic Cloud Bridging today and tomorrow

The Cloud Computing Revolution: Beyond the Hype

Privacy for Healthcare Data in the Cloud - Challenges and Best Practices

How to ensure control and security when moving to SaaS/cloud applications

Cloud Computing: Contracting and Compliance Issues for In-House Counsel

CLOUD COMPUTING, TRADE SECRET / KNOW-HOW & EUROPEAN LEGAL FRAMEWORK

CLOUDCATALYST. Cloud Trends and Critical Success Factors for European SMEs

The NREN cloud strategy should be aligned with the European and national policies, but also with the strategies of the member institutions.

Cloud Competency Programme Workshop [1] Secure cloud services in a regulated environment

Cloud 28+ Cloud of Clouds- Made in Europe, secured locally

Challenges in Delivering Large-scale Services over Cloud Environments

CHAPTER 1 INTRODUCTION

EXIN Cloud Computing Foundation

Transcription:

Cloud Computing by (research conducted October 2011 January 2012) for the European Parliament, DG Internal Policies of the Union, Directorate A (Economic and Scientific Policy); presentation for the EP Committee for Internal Market and Consumers

Purpose and methodology TOR: broad overview of cloud computing, and how it relates to EU consumer protection and digital market goals Benefits and risks and possible actions thereof Work between October 2011 and March 2012 Literature review Structured interviews (18) Small scale survey of provider terms and conditions transparency

What is cloud computing? Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction (US NIST) Cloud computing is when you use services, or storage, not at your own computer but somewhere else in the Internet, which is not in one data centre but is spread all over the Internet. As a user you don t know where your data is or where the services are which you are using. (Consumer organisation) 2

Economic impact North American providers make up 56% of market, against 25% in Western Europe. Gap to narrow to 50% against 29% by 2014 Potential economic impact: Fewer data centres for large organisations Cost savings and increased competitiveness of IT services available to public and private organisations Information more accessible/interactive for consumers with resulting cost savings

Example IBM data centre rationalisation and US Federal Government expansion Source: Renda, S., US Cloud First Policy Insights, EC-ETSI Standards in the Cloud Workshop, 2011. 5

Types and location of cloud Different types of cloud: public, private, hybrid, and community clouds Different types of service: Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS) Can be located anywhere in the world, and in several places at once, with significant policy implications 6

Examples of cloud use Consumers: webmail, payment intermediaries, photo/video sharing, storage, music streaming, etc. Business: document handling, customer relationship management, project collaboration, computation Public authorities: internal as for business; and development of e-government services 7

Potential benefits - consumers Services free (monetize personal data) Access from anywhere Lower computer costs Better access to and sharing of information Automatic maintenance and updating Potentially better security 8

Potential benefits - businesses Same as consumers, but also Avoiding capital expenditure for IT Scaling IT resources Better project collaboration and project management Design of custom applications by SMEs. 9

Potential benefits - governments Same as businesses, but also Better government services for citizens, thanks to Competition between suppliers Ability to rapidly trial new systems Lower barriers to entry for SMEs 10

Example of cost savings: UK G-Cloud Projected UK central government savings when shifting to cloud technologies Cloud strategy elements Savings by year in millions of GBP 2011-12 2012-13 2013-14 2014-15 G-Cloud & Application Store - 20 40 120 Data Centre Consolidation - 20 60 80 Source: HM Government, Government Cloud Strategy, 2011, p. 16 11

Main risks and policy challenges Barriers to take-up, and to single market : Data security Privacy and data protection Market fragmentation (jurisdictions) Problems with contracts Provider lock-in (no interoperability, no standards) 12

Data security Security risks relate to: Loss of confidentiality and integrity of data Loss of IT control Data interception Provider massive failure Risk-based approaches to address vulnerabilities: Different levels of security Private or community clouds Audit and certification system of cloud services 13

Privacy & data protection Cloud specific issues include: Role of the cloud provider (controller or processor?) Applicability of EU laws International data transfers Law enforcement access to personal data Providers have different thresholds of disclosure (contracts) Seen as both a risk and an opportunity (for EU clouds) 14

Market fragmentation (jurisdiction) Balkanisation of the cloud Complexities of many jurisdictions and many applicable laws the legal regime was unclear according to our public questionnaire in 90% of cases. Basically all people say it is an issue.all groups say they don t know what to apply Gaps in relevant laws when applied to the cloud

Problems with contracts Lack of transparency in contracts and information: Few data integrity guarantees Disclaimers of liability No standards regarding data control and security Rigid contracts Need for key terms and standard contracts Website check of 15 public cloud services showed lack of information on security, location of data, and privacy unclear. Need for standardised presentation of information 16

Future trends Same cloud services, but more Some services to go to public cloud for potential cost savings But others to remain in a private environment, as small scale solutions can still be more efficient than large scale ones 17

Future hurdles to overcome Adequate competition between providers (interoperability and standards, vertical integration, public procurement) Coordination of cloud computing initiatives Broadband connectivity Access to redress Environmental impacts 18

Conclusions and recommendations Main concerns and risks related to cloud computing are legislative framework-related, contracts/terms and conditions-related, or standards-related. To attend to these, EU policymakers should: 1. Address legislation-related gaps 2. Improve terms and conditions for all users 3. Address stakeholder security concerns 4. Encourage the public sector cloud 5. Promote further research and development in cloud computing 19