The vision of DNB on the supervision of cloud-computing



Similar documents
Case Study Cloud Computing

Cloud Computing Guide & Handbook. SAI USA Madhav Panwar

Managing Cloud Computing Risk

Developments in International IT-Supervision

Perspectives on Moving to the Cloud Paradigm and the Need for Standards. Peter Mell, Tim Grance NIST, Information Technology Laboratory

Why Private Cloud? Nenad BUNCIC VPSI 29-JUNE-2015 EPFL, SI-EXHEB

John Essner, CISO Office of Information Technology State of New Jersey

Cloud Computing; What is it, How long has it been here, and Where is it going?

What Factors Determine Cloud Computing Adoption by Colleges and Universities? Bill Klug Instructor, BCIT

Clinical Trials in the Cloud: A New Paradigm?

Cloud Computing and Records Management

IT Security Risk Management Model for Cloud Computing: A Need for a New Escalation Approach.

KERALA STATE IT MISSION ICT Campus, Vellayambalam, Trivandrum Phone: , , Fax:

JOB DESCRIPTION CONTRACTUAL POSITION

BUSINESS MANAGEMENT SUPPORT

Cloud Computing--Efficiency and Security

Securing and Auditing Cloud Computing. Jason Alexander Chief Information Security Officer

Cloud Computing Technology

CLOUD BASED SCADA. Removing Implementation and Deployment Barriers. Liam Kearns Open Systems International, Inc.

CSO Cloud Computing Study. January 2012

OFFICE OF AUDITS & ADVISORY SERVICES CLOUD COMPUTING AUDIT FINAL REPORT

Kent State University s Cloud Strategy

Federal Cloud Computing Initiative Overview

CLOUD COMPUTING GUIDELINES FOR LAWYERS

Upgrading a computer to Windows 10 with PetLinx

SFJCCAD2 Promote business continuity management

Cloud Security. Nantawan Wongkachonkitti Electronic Government Agency, Thailand Cloud Security Alliance, Thailand Chapter October 2014

Cloud Computing Thunder and Lightning on Your Horizon?

Shared Services Canada and Cloud Computing Architecture Framework Advisory Committee

Privacy and security in the cloud

A Secure System Development Framework for SaaS Applications in Cloud Computing

About iomart Group plc

Dynateam CRM Sync Migration made easy

Evolving Technology Issues: Cloud Computing

Cloud Computing: Contracting and Compliance Issues for In-House Counsel

Strategic approach to cloud computing deployment

SCADA Cloud Computing

ADRI. Advice on managing the recordkeeping risks associated with cloud computing. ADRI v1.0

Chapter3: Understanding Cloud Computing

Polish Financial Supervision Authority. Guidelines

Core Solutions of Microsoft Exchange Server 2013

Company Profile Outstanding data centres. Expertise you can trust. Europe s leading provider of premium carrier-neutral data centres.

Cloud Security checklist Are you really ready for Cloud

Security Issues in Cloud Computing

Security, Compliance & Risk Management for Cloud Relationships. Adnan Dakhwe, MS, CISA, CRISC, CRMA Safeway Inc. In-Depth Seminars D32

The Magical Cloud. Lennart Franked. Department for Information and Communicationsystems (ICS), Mid Sweden University, Sundsvall.

Validation of a Cloud-Based ERP system, in practice. Regulatory Affairs Conference Raleigh. 8Th September 2014

IS PRIVATE CLOUD A UNICORN?

What is Cloud Computing? First, a little history. Demystifying Cloud Computing. Mainframe Era ( ) Workstation Era ( ) Xerox Star 1981!

Application management services that power business transformation

NATO s Journey to the Cloud Vision and Progress

Evaluating the Cloud An Executive Perspective

The NIST Definition of Cloud Computing (Draft)

Information Blue Valley Schools FEBRUARY 2015

Cloud Computing: What needs to Be Validated and Qualified. Ivan Soto

iso20000templates.com

Cloud definitions you've been pretending to understand. Jack Daniel, Reluctant CISSP, MVP Community Development Manager, Astaro

Security in the Cloud: Visibility & Control of your Cloud Service Providers

The process of. The Software-as-a- Cloud-Based Software Model. Service Model

Seeing Though the Clouds

Cloud Computing. Introduction

ICT Strategy Consulting Services for Schools. Helping schools to establish a clear vision for ICT.

Security Techniques for Protecting Data in Cloud Computing one SHOULD know WHAT...

East African Information Conference th August, 2013, Kampala, Uganda. Security and Privacy: Can we trust the cloud?

The NREN s core activities are in providing network and associated services to its user community that usually comprises:

Bank of Israel. 1. Background. In recent years, cloud. environmentally. from. aspects in. these. 2. Applicability. Directive ). 3.

The reality of cloud. Go beyond the hype and make a better choice. t e sales@365itms.co.uk.

Quality Manual ISO 9001:2015 Quality Management System

(a) the kind of data and the harm that could result if any of those things should occur;

The HIPAA Security Rule: Cloudy Skies Ahead?

Managing Outsourcing Arrangements

Contracting for Cloud Computing

A COALFIRE PERSPECTIVE. Moving to the Cloud. NCHELP Spring Convention Panel May 2012

Core Solutions of Microsoft Exchange Server 2013 MOC 20341

Islamic Relief Worldwide ICT Desktop Support Technician

WWT View Point. Journey to the Private Cloud: Take the First Steps with FlexPod

CLOUD COMPUTING. A Primer

Cloud Computing Best Practices and Considerations for Project Managers Mike Lamoureux, PMP, MBA. Page 1

Cloud powered services composition using Public Cloud PaaS platform

END TO END DATA CENTRE SOLUTIONS COMPANY PROFILE

Transcription:

The vision of DNB on the supervision of cloud-computing CBCS: Information Technology Service Management Seminar Evert Koning, 18 November 2014

Financial industry in the Netherlands Institution type Number Banking 100 Insurance companies 300 Pension funds 350 Investment firms 350 Trust and payment firms 400 Total 1500 2

Strategy Supervision focusses on protection of interests of creditors/consumers stability and integrity of the financial system This means that Supervision must be kept posted and understand what institutions are doing and how they manage and control the risks Timely identify relevant developments & threats and advise on them 3

Strategy of ICT supervision ICT Focus Strategy with differentation An institution of some magnitude is not viable without ICT Supervision needs to make certain that the institutions recognise and adequately manage ICT-related risks 4

Mission statement of EC-ICT Was To offer the maximum added value for general Supervision specific as for the Central Bank as a whole by means of effective and efficient use of people and tools with the focus on the different expertises within the department. Is To achieve, through effective and efficient means, adequate control of IT risks by supervised institutions 5

Supervision cycle 6

Assessment of risks 7

Organisation EC-ICT 10 IT examiners No hierarchy 3 levels of experience Flexibility Account structure T5 and T4 8

Cloud computing Cloud computing qualifies as a form of outsourcing. So the same legal requirements apply: risk s need to be demonstrably known and mitigated Outsourcing to third parties may not obstruct supervision by DNB http://www.toezicht.dnb.nl/en/binaries/circulaire%2 0cloud%20computing_tcm51-224828.pdf 9

Legal Framework Outsourcing Specific rules for outsourcing (6 articles) Outsourcing is not allowed if it obstructs prudential supervision on the institution (art. 27) Outsourcing is not allowed if it harms the independent internal audit & compliance process (art. 28) The institution needs to have a sourcing strategy and detailed procedures in place to manage the outsourcing (art. 29) 10 10

Legal Framework Outsourcing Specific rules for outsourcing (6 articles) The institution needs to have sufficient procedures, knowledge & information to assess the outsourced processes (art. 30) a sufficient written outsource agreement is mandatory (art. 31) Above mentioned articles are not applicable if the processes are outsourced to a company in another country that is part of the group of the financial institution (art. 32) 11 11

Legal Framework Specific rules for risk management (4 articles) Policy regarding control of risks is documented in detailed procedures and measures to control risks (art. 23) Systematic and independent risks analysis (art. 23) Institution supervises compliance of procedures and measures as mentioned in art. 23 (art. 24) Internal developed models are assessed and validated (art. 25) The treasurer of the institution has procedures and measures in place to ensure the financial position (art. 26) 12 12

Definition cloud computing NIST definition of cloud computing (ref. SP800-145): Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model is composed of five essential characteristics, three service models, and four deployment models. 13

Attentionpoints cloud computing Where are my (back-up) data? Who can access my data? How do I know that performance is as contracted? Exit from cloud provider: is all data wiped? Right to audit also for subcontractor? 14

Cloud computing / International aspects International agreement on cloud computing Letters on cloud computing: APRA, MAS, DNB, US, Spain and Canada All countries have the same attitude w.r.t. cloud computing Some countries are more strict Bron: 15 http://www.toezicht.dnb.nl/binaries/cloud%20com puting_tcm50-224828.pdf

International agreement Common understanding ITSG Cloud computing qualifies as outsourcing Cloud computing is defined by NIST Right to audit of Supervisors is obliged in contracts Email is considered as part of critical business 16

Cloud computing & DNB Journey with Microsoft: circulaire cloud computing 6 December 2011 (English 10 January 2012*) Contact with financial institution about Microsoft cloud services. Contact with Microsoft Contact with Microsoft and financial institution Agreement with Microsoft NL -> involvement Microsoft EMEA and US Agreement with Microsoft US Implementing Microsoft office 365 Financial institution Visit Dublin datacentre Visit Microsoft Campus Redmond *http://www.toezicht.dnb.nl/en/binaries/circulaire%20cloud%20computing_tcm51-224828.pd 17

Agreement with Microsoft http://www.toezicht.dnb.nl/en/7/51-226970.jsp 18

DNB & Cloud computing Symposium Cloud Computing 2013 Regulator view Assurance Lessons learned by Service providers Lessons learned by Financial organisations Market perspective http://www.toezicht.dnb.nl/7/50-228265.jsp Risk analysis framework based on Enisa*: http://www.toezicht.dnb.nl/binaries/sjabloon%20cloud%20com puting%20%20risicoanalyse_tcm50-228202.pdf * http://www.enisa.europa.eu/activities/riskmanagement/files/deliverables/cloud-computing-risk-assessment 19

Cloud computing right to examine 20

Questions? Evert Koning Operational Risks & Data quality Telephone: Mobile: E-mail: : 21 +31 20 524 2428 +31 6 524 96 399 e.koning@dnb.nl