Accountability Model for Cloud Governance

Similar documents
The problem of cloud data governance

FSPFCC04(SQA Unit Code-F88P 04) Ensure you comply with regulations in your financial services environment

Accountability in Cloud Computing An Introduction to the Issues, Approaches, and Tools

(a) the kind of data and the harm that could result if any of those things should occur;

The Legal Pitfalls of Failing to Develop Secure Cloud Services

Article 29 Working Party Issues Opinion on Cloud Computing

Cloud Computing: Legal Risks and Best Practices

The New Zealand Human Services Quality Framework - ISO9002:2008 to 2012

Business Associate Agreement

PCL2\ \1 CYBER RISKS: RISK MANAGEMENT STRATEGIES

Ethical Trading Initiative Management Benchmarks

Job Description. Radiography Services Manager

A Flexible and Comprehensive Approach to a Cloud Compliance Program

Information Security Management System for Microsoft s Cloud Infrastructure

The Use of Cloud Computing for the Storing and Accessing of Client Information: Some Practical and Ethical Considerations

Overview TECHIS Carry out risk assessment and management activities

Data Integrity & Technical Ethics

LEEDS BECKETT UNIVERSITY. Information Security Policy. 1.0 Introduction

FSPAMFPI06 Complete reports for mortgage and/or financial planning clients

Memorandum of Understanding between the Office of the Independent Adjudicator (OIA) and the General Medical Council (GMC)

Consultative report. Committee on Payment and Settlement Systems. Board of the International Organization of Securities Commissions

REGULATIONS OF THE COMPLIANCE UNIT OF IBERDROLA GENERACIÓN ESPAÑA, S.A.U. 16/12/14

The CIPM certification is comprised of two domains: Privacy Program Governance (I) and Privacy Program Operational Life Cycle (II).

Cloud Computing. Introduction

Personal data and cloud computing, the cloud now has a standard. by Luca Bolognini

Model Based Engineering and Its Integration with Safety Assurance Cases for Medical Device Software

BUSINESS ASSOCIATE AGREEMENT

Requirements Evolution of an Avionics Safety-Critical Industrial Case Study Predictive Changes Risk/Cost Analyses

Information Security Management System (ISMS) Policy

BUSINESS ASSOCIATE AGREEMENT

Information Security Governance:

Application of King III Corporate Governance Principles

BUSINESS ASSOCIATE AGREEMENT

Board of Directors Meeting 12/04/2010. Operational Risk Management Charter

Professional Solutions Insurance Company. Business Associate Agreement re HIPAA Rules

Cloud Computing Security Considerations

Helping to protect your business and your customers in the event of a data breach

Privacy and Electronic Communications Regulations

NORTHERN IRELAND FIRE & RESCUE SERVICE JOB DESCRIPTION

Application of King III Corporate Governance Principles

Acquia Comments on EU Recommendations for Data Processing in the Cloud

Information Security Policy. Document ID: 3809 Version: 1.0 Owner: Chief Security Officer, Security Services

I S O I E C I N F O R M A T I O N S E C U R I T Y A U D I T T O O L

REGULATIONS FOR THE SECURITY OF INTERNET BANKING

CFABAI132 Inform and facilitate organisational decision-making

The PNC Financial Services Group, Inc. Business Continuity Program

National Cyber Security Policy -2013

Part E: Contract management

CPNI VIEWPOINT 01/2010 CLOUD COMPUTING

WHITEPAPER Complying with HIPAA LogRhythm and HIPAA Compliance

MANAGEMENT STANDARD CLOSURE PLANNING

Enabling the re-use of research data: organising stakeholders and infrastructure in the Netherlands

Best Practices at Research Level

How To Assess A Critical Service Provider


Cloud security architecture

Practical and ethical considerations on the use of cloud computing in accounting

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) BUSINESS ASSOCIATE AGREEMENT

D:C-3.1 Requirements for cloud interoperability

Information Security and Governance in ERP Implementation (JD Edwards)

REGULATIONS FOR COMPLIANCE OFFICERS

IT Professional Standards. Information Security Discipline. Sub-discipline 605 Information Security Testing and Information Assurance Methodologies

CCSAPAB2 Develop and agree objectives for archaeological projects

This form may not be modified without prior approval from the Department of Justice.

Procurement Capability Standards

COMPLIANCE FRAMEWORK AND REPORTING GUIDELINES

Accountability: Data Governance for the Evolving Digital Marketplace 1

HIPAA BUSINESS ASSOCIATE ADDENDUM (Privacy & Security) I. Definitions

Compliance Policy ALCO recommended standard

Role of contracts in Cloud Computing an Overview. Kevin McGillivray Doctoral Candidate (NRCCL)

By Emily Hay and Jan Dhont, Data Privacy Department, Lorenz Brussels.

Privacy in the Cloud A Microsoft Perspective

CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES:

BUSINESS ASSOCIATE AGREEMENT BETWEEN AND COMMISSION ON ACCREDITATION, AMERICAN PSYCHOLOGICAL ASSOCIATION

Privacy by Design The 7 Foundational Principles Implementation and Mapping of Fair Information Practices

All about Threat Central

Business Associate Agreement (BAA) Guidance

Transcription:

Accountability Model for Cloud Governance Massimo Felici, Hewlett-Packard Laboratories CSP Forum 2014, Athens, 21-22 May 2014

Overview Problem of Data Governance Data Governance in the Cloud Accountability Definitions Conceptual Definition of Accountability Definition of Accountability for Data Stewardship in the Cloud Accountability Model Accountability Attributes, Practices and Mechanisms Accountability Governance Accountability Framework Accountability Context Accountability Governance

Problem of Data Governance Different regulatory regimes Complex governance environment Lack of trust in the cloud Transfer of data into the cloud Lack of governance and transparency

Conceptual Definition of Accountability Defining Accountability Applicable across different domains and capturing a shared multidisciplinary understanding within the project Concerned about governance Conceptual Definition of Accountability Accountability consists of defining governance to comply in a responsible manner with internal and external criteria, ensuring implementation of appropriate actions, explaining and justifying those actions and remedying any failure to act properly. Responsibly and proactively (explaining, justifying, remedying) delivery of actions Compliance with respect to internal and external criteria defined by stakeholders

Defining Accountability Contextualising accountability for data governance in cloud ecosystems personal and/or confidential data Definition of Accountability for Data Stewardship in the Cloud Accountability for an organisation consists of accepting responsibility for the stewardship of personal and/or confidential data with which it is entrusted in a cloud environment, for processing, storing, sharing, deleting and otherwise using the data according to contractual and legal requirements from the time it is collected until when the data are destroyed (including onward transfer to and from third parties). It involves committing to legal and ethical obligations, policies, procedures and mechanisms, explaining and demonstrating ethical implementation to internal and external stakeholders and remedying any failure to act properly. Deploying different mechanisms Ethical aspects of accountability

From accountability to being accountable Accountability Model Operationalise the accountability definitions Capture different abstraction levels of accountability Identify attributes contributing towards accountability Characterise accountable organisations Identify elements of accountability practices Enable accountability practices

Accountability Model Accountability Definitions Observability Verifiability Attributability Transparency Responsibility Liability Remediability Defining governance Ensuring governance Demonstrating governance Holding to account Different mechanisms supporting accountability

Accountability Framework Preventive investigating and mitigating risk in order to form policies and determine appropriate mechanisms to put in place; putting in place appropriate policies, procedures and technical mechanisms) Detective monitoring and identifying policy violation; putting in place detection and traceability measures Corrective managing incidents and providing notifications and redress Supporting accountability at different stages Supporting cloud actors Co-designing: Responsible and ethical corporate governance, Innovative regulatory frameworks, and Supporting technologies

Accountability Context Obligations, responsibilities and liabilities of actors Regulatory Regimes Trustworthy Account Clarification of Requirements Accountability Transparency Stakeholders Requirements Cloud Ecosystems Help with meeting Obligations

Accountability Governance Claims Emerging Trustworthiness Deciding to Trust Questioning Evidence Supported by arguments Providing Evidence

Accountability Highlights Addressing data governance in the cloud Accountability Definitions Accountability Model Accountability Framework Accountability Governance

Thank You.