[an error occurred while processing this directive]
Home > Data Center Management Tips > Data Center Operations and Design Tips > Cloud computing legal checklist
Data Center Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

DATA CENTER OPERATIONS AND DESIGN TIPS

Cloud computing legal checklist


Mark Weston, Contributor
11.26.2009
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Questions to ask and clarifications that should be requested before signing on the dotted line according to Mark Weston, Principal at UK law firm Matthew Arnold & Baldwin LLP

1. A customer should check its own (and the cloud provider's) processes on data handling, clarifying where the data is located and how it is managed. This should include an inspection of the processes involved if the cloud service provider loses customer data.

2. A customer should check the service provider's policies on data and data corruption, asking if data is backed up and whether it can easily be reconstituted from the backups.

3. A customer should clarify policies on identity management and access control. This should cover issues which boil down to who is authorised to do what and under what circumstances. This should cover who is authorised to have sight of the customer's data.

A customer should clarify whether the cloud service provider authorised itself to "see" the data and what controls exist to prevent data being copied or otherwise removed – and this encompasses removal by the cloud service provider and also removal by members of the customer organisation – is there a robust audit trail?

4. There should also be robust audit checking procedures for data co-location to ensure that a competitor of the customer cannot access the customer's information – even though both the customer and its competitor may be hosted on the same hardware. (It is worth noting here that most cloud services being offered today are on a "shared server" basis i.e. any given server is are shared between multiple organisations.

This is because the economies of scale allow for a cheaper service provision. Nevertheless, primarily due to security concerns, certain more security-conscious organisations are opting for non-shared cloud services which are offered with greater guarantees of security. IBM, for example, offers such a service.)

5. A customer should check compliance with regulatory requirements such as accounting and auditing standards, banking regulation, corporate governance, information provision requirements (such as Sarbanes-Oxley), data regulation etc. The policies of the cloud service provider (such as the data protection policy) should also be carefully scrutinised. There are already data checks on export of data to certain jurisdictions.

For example, European data protection law would prevent export of personal data to the USA. However, in reality most large organisations providing cloud services will be able to take advantage of one of the legal exceptions to that restriction.

6. A customer should check how easy it is to terminate and move to another cloud service provider – not contractually but practically!

Mark Weston is a Principal at Matthew Arnold & Baldwin LLP and a Contributor to SearchVirtualDataCentre.co.uk

Rate this Tip
To rate tips, you must be a member of SearchDataCenter.IN.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Data center operations and asset management,   Evaluating cloud computing technologies,   Data Center Operations and Design Tips,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Evaluating cloud computing technologies
Five open source tools for building and managing clouds
Private cloud architecture implementation tips
Cloud computing service aids Viva Infomedia's growing business needs
Cloud computing for enterprise apps: India Infoline's twin approach
Netmagic Cloud 2.0 : Pricing overview and more
AWS cloud computing early adopter: Hungama Digital Media's experience
Sify-HP cloud computing: Pricing details and more
Cloud computing adoption on the rise in India.Org, claims survey
Amazon EC2 pricing models for India: An overview
Cloud computing licensing: Buyer beware

Data Center Operations and Design Tips
Storage certification guide for networking pros
Hottest data center certifications of 2010
Why virtualization is harder for desktops than servers
Green Grid debuts four categories for measuring PUE
IT disaster recovery services and outsourcing guide for beginners
Determining the true value of a server operating system
Automation of data centers: 10 ways to start off your automation initiatives
Disaster preparedness and recovery for flood disasters: What DR planners need to know
Five open source tools for building and managing clouds
Six things a data center operations manager shouldn't do

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite Papers
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2009 - 2010, TechTarget | Read our Privacy Policy
  TechTarget