Cloud Service Contracts: An Issue of Trust



Similar documents
TERRITORY RECORDS OFFICE BUSINESS SYSTEMS AND DIGITAL RECORDKEEPING FUNCTIONALITY ASSESSMENT TOOL

Office 365 Data Processing Agreement with Model Clauses

<Choose> Addendum Windows Azure Data Processing Agreement Amendment ID M129

Annex 1. Contract Checklist for Cloud-Based Genomic Research Version 1.0, 21 July 2015

Retention & Disposition in the Cloud Do you really have control?

RECORD AND INFORMATION MANAGEMENT FRAMEWORK FOR ONTARIO SCHOOL BOARDS/AUTHORITIES

CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES:

Article 29 Working Party Issues Opinion on Cloud Computing

Record Retention and Digital Asset Management Tim Shinkle Perpetual Logic, LLC

Considerations for Outsourcing Records Storage to the Cloud

Enrollment for Education Solutions Addendum Microsoft Online Services Agreement Amendment 10 EES

Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Security Amendment Amendment ID MOS10

Interagency Science Working Group. National Archives and Records Administration

Management of Official Records in a Business System

Cloud Computing: Legal Risks and Best Practices

UNIVERSITY OF MANITOBA PROCEDURE

Protecting Official Records as Evidence in the Cloud Environment. Anne Thurston

HIPAA CRITICAL AREAS TECHNICAL SECURITY FOCUS FOR CLOUD DEPLOYMENT

White Paper on Financial Institution Vendor Management

This Amendment consists of two parts. This is part 1 of 2 and must be accompanied by and signed with part 2 of 2 (Annex 1) to be valid.

Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries

CCBE RESPONSE REGARDING THE EUROPEAN COMMISSION PUBLIC CONSULTATION ON CLOUD COMPUTING

ADRI. Advice on managing the recordkeeping risks associated with cloud computing. ADRI v1.0

Approved by: Vice President, Human Resources & Corporate Resources and Vice President, Treasury & Compliance Date: October 14, 2009

Information Management

Privacy and Cloud Computing for Australian Government Agencies

How To Manage Cloud Data Safely

SOUTHWEST VIRGINIA COMMUNITY COLLEGE RECORDS MANAGEMENT POLICY

HL7 EHR-S Records Management & Evidentiary Support Functional Profile

Digital Records Preservation Procedure No.: 6701 PR2

Rackspace Archiving Compliance Overview

Metadata, Electronic File Management and File Destruction

What We ll Cover. Defensible Disposal of Records and Information Litigation Holds Information Governance the future of records management programs

CORPORATE RECORD RETENTION IN AN ELECTRONIC AGE (Outline)

Recommendations for companies planning to use Cloud computing services

Privacy Level Agreement Outline for the Sale of Cloud Services in the European Union

Type of Personal Data We Collect and How We Use It

Data Processing Agreement for Oracle Cloud Services

The Use of Cloud Computing for the Storing and Accessing of Client Information: Some Practical and Ethical Considerations

Document Management in the FIPPA Era

Microsoft Online Services - Data Processing Agreement

Transition Guidelines: Managing legacy data and information. November 2013 v.1.0

Life Cycle of Records

Business Process Design As-Is and To-Be Checklists Introduction

Cloud Computing and Records Management

IT Forum UW-Madison Records Management Program. UW Archives and Records Management

Scotland s Commissioner for Children and Young People Records Management Policy

39C-1 Records Management Program 39C-3

Global Privacy and Data Security in the Cloud September 14, 2011 Miriam Wugmeister

Applicability: All Employees Effective Date: December 6, 2005; revised January 27, 2009 Source(s):

Corporate Records Management Policy

Astaro Services AG Rheinweg 7, CH-8200 Schaffhausen. Supplementary data protection agreement. to the license agreement for license ID: between

Management: A Guide For Harvard Administrators

Acquia Comments on EU Recommendations for Data Processing in the Cloud

Managing Contracts under the FOIP Act. A Guide for Government of Alberta Contract Managers and FOIP Coordinators

NSW Government. Cloud Services Policy and Guidelines

Union County. Electronic Records and Document Imaging Policy

ECSA EuroCloud Star Audit Data Privacy Audit Guide

BOARD POLICY POLICY TITLE. Records and Information Management 1.0 PURPOSE

Cloud Computing Contracts. October 11, 2012

Guideline 1. Cloud Computing Decision Making. Public Record Office Victoria Cloud Computing Policy. Version Number: 1.0. Issue Date: 26/06/2013

LEGAL ISSUES IN CLOUD COMPUTING

INFORMATION AND DOCUMENTATION RECORDS MANAGEMENT PART 1: GENERAL IRISH STANDARD I.S. ISO :2004. Price Code

HIPAA/HITECH Compliance Using VMware vcloud Air

CANADIAN PRIVACY AND DATA RESIDENCY REQUIREMENTS. White Paper

Polices and Procedures

Records and Information Management. General Manager Corporate Services

RECORDS MANAGEMENT LAWS

PARLIAMENTARY AND HEALTH SERVICE OMBUDSMAN. Records Management Policy. Version 4.0. Page 1 of 11 Policy PHSO Records Management Policy v4.

Quality Management. Retention of Project Documentation. Guidelines. Association of Professional Engineers and Geoscientists of British Columbia

Records Management Policy

Politique de sécurité de l information Information Security Policy

INFORMATION SECURITY GUIDE. Cloud Computing Outsourcing. Information Security Unit. Information Technology Services (ITS) July 2013

Presented by Vickie Swam, Director of University Compliance. Records Management is one of the functions supported by the University Compliance Office.

Guideline 2. Cloud Computing: Tools. Public Record Office Victoria Cloud Computing Policy. Version Number: 1.0. Issue Date: 26/06/2013

Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation

How To Ensure Health Information Is Protected

Guideline 2. Cloud Computing: Tools. Public Record Office Victoria Cloud Computing Policy. Version Number: 1.0. Issue Date: 26/06/2013

The supplier shall have appropriate policies and procedures in place to ensure compliance with

ACCESS, PRODUCTION AND RETENTION OF CITY RECORDS

September 15, 2014 MEMORANDUM FOR THE HEADS OF EXECUTIVE DEPARTMENTS AND AGENCIES AND INDEPENDENT AGENCIES

RECORDS MANAGEMENT POLICY

Data Management: Considerations for Integrating Compliance Requirements At Home and Abroad. Toronto, Ontario June 14, 2005

Information Sheet: Cloud Computing

DELAWARE PUBLIC ARCHIVES POLICY STATEMENT AND GUIDELINES MODEL GUIDELINES FOR ELECTRONIC RECORDS

Table of Contents. Chapter No. 1. Introduction Objective Use Compliance Definitions Roles and Responsibilities 2

How To Preserve Records In Mississippi

Cloud Computing: Privacy and Other Risks

Transcription:

Cloud Service Contracts: An Issue of Trust Marie Demoulin Assistant Professor Université de Montréal École de Bibliothéconomie et des Sciences de l Information (EBSI) itrust 2d International Symposium, Victoria, 16 th Oct. 2014

Workgroup members Researcher Marie Demoulin, Université de Montréal Graduate research assistants Jessica Bushey, UBC Robert McLelland, UBC

Research object Contract as a tool to build Trust in the Cloud

Research question How effective are cloud service contracts at addressing the needs of records managers and archivists?

Milestones itrust Project 10 : Contract terms with cloud service providers Cloud contracts vs RM s needs itrust Project 14 : Trust in Cloud Service Contracts Cloud contracts vs RM and archivists needs Standards and Legal framework Also linked to Project 6 : Retention and disposition in the cloud

Selected contracts Boilerplate contracts No room for negociation Take it or leave it Cloud Services relevant for RM and archivists No consumer contracts Contractual (binding) documents No marketing material Terms of Service (ToS) Service Level Agreement (SLA) Privacy Policy, Acceptable Use Policy, Security Terms Jurisdiction Canada US Europe

Selected standards ISO 15489:2001 Records management ISO 14721:2002 Preservation of records ISO 14721:2012 Open Archival Information System (OAIS) ARMA s Recordkeeping Principles (2013) Moreq 2009

Legal framework Canada US EU Transverse view on Freedom of information law (public bodies) «Patriot» laws Privacy law Evidence law (esp. Civil law) Ownership principles

Research Product Check-list for record managers and archivists to: Understand boilerplate cloud contracts verify if they meet their needs clarify recordkeeping needs to legal and IT departments communicate recordkeeping needs to cloud providers

Methodology Literature review and annotated bibliography Legal, archival and RM literature on cloud contracts Existing recommendations for private and public bodies Identify RM and archival needs & functions to be considered in the contract Clarify the legal framework linked to these needs Compare with a sample of cloud provider contracts Identify gaps Cloud contracts Reader s Check-list

Cloud contracts Reader s Check-list (Preliminary results) Data ownership Availability, retrieval and use Data retention and disposition Data storage and preservation Security, confidentiality and privacy Data location and cross-border data flows End of Service Contract termination

Gaps Data retention and disposition Data preservation Data location End of contract Not (fully) addressed in the majority of the contract terms

Data Ownership Who owns the data stored, transmitted of created in the cloud by the customer (i.e. you)? Does the service provider have the right to use them and, if so, to what extent? the associated metadata generated by the system/ provider? Do you have the right to access to them for recordkeeping or legal purposes during the contractual relationship? at the end of the contract?

Availability, retrieval and use Precise indicators and providing clear information about the availability of the service? Does the degree of availability of the data fit with your business needs? allow you to comply with the freedom of information legislation (if public body), the right of a person to access to her own personal data the right of authorities to legally access to your data for investigation, control or judicial purposes?

Data retention and disposition Are your data (and all their copies) destroyed In compliance with your data retention and disposition schedules Immediately and permanently According to a secure destruction policy? Associated metadata generated by the provider Need to be destroyed? Same time & same manner? Will the service provider proceed to such destruction? Audit trails? Attestation or report of deletion? (if requested)

Data storage and preservation Who is responsible for backups and for recovering the data? Are records migrated or emulated in a way that preserves their authenticity, reliability, integrity and usability? Audit trails? How will the service evolve? Will you be noticed of any evolution that could impede the authenticity of your data?

Security, Confidentiality & Privacy Does the system prevent unauthorized access, use, alteration or destruction of the data through technical, physical and organizational measures? Audit trails, metadata and/or access logs to demonstrate this? Will you be noticed in the case of security breach or system malfunction? Any subcontractor? Information about the identity of the subcontractor and its tasks? Confidentiality policy of the service provider, in regards to its employees, partners and subcontractors? Any special confidentiality or security policy for sensitive, confidential, personal or other special kinds of data? Is the service provider accredited and/or is he audited on a systematic, regular and independent basis by a third-party in order to demonstrate that he complies with his security, confidentiality and privacy policies? Is such a certification or audit process documented? Certifying or audit body and expiration date of the certification?

Data location & Cross-border data flows Where is the location of the data (and their copies)? Does it comply with the location requirements imposed by law? (if applicable) Will you be notified if the data location is moved outside your jurisdiction? Does the contract mention the possibility of disclosure orders by national or foreign security authorities? Will the provider inform you and ask for your consent prior to disclosure? (if allowed by law)

End of Service Contract termination Duration of the contract? Why and how can it be terminated? Any prior notification? At the end of the contract, whatever the reason Warranty that your data will be restored in a usable and interoperable format? Time, procedure and cost? Provider s assistance? Right to access to the associated metadata generated by the system? After restitution of data, immediate and permanent destruction?

Next steps Consolidation of the results From check-list to guidelines (vs. «model contract») Collaboration with itrust Project 6 Retention and disposition in the cloud (Pat Franks) Comments and suggestions are welcome: Marie.demoulin@umontreal.ca

Dissemination Canadian Journal of Information and Library Science Special Issue on Data, Records and Archives in the Cloud (June 2015) Paper submitted (October 2014)