Welcome!

@CloudExpo Authors: Yeshim Deniz, Pat Romanski, Liz McMillan, Elizabeth White, Charles Araujo

Related Topics: @CloudExpo, Microservices Expo

@CloudExpo: Article

Four Steps to Compliance Management in the Public Cloud

Is it possible to ensure compliance when sending services to the cloud?

Feeling nervous about the cloud? Many CIOs understandably hesitate to send services requiring regulatory compliance to the public cloud. Though not outsourcing such services may seem like a good idea, this approach limits your flexibility in offering the best combination of services to meet business demands. As public cloud services continue to grow in both diversity and quality, IT and the business can't afford to bypass opportunities offered there and hope to remain competitive. The compliance issue must be addressed, but how? Is it possible to ensure compliance when sending services to the cloud?

Fortunately, the answer is "yes." By using a strategy based on Business Service Management (BSM), a comprehensive approach and unified platform for running IT, you can extend the BSM processes and solutions that you use to manage your internal infrastructure to the public cloud environment.

Step 1: Divide Services into Three Categories
You can choose from a variety of public cloud services. These include Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS), plus individual business services that you can integrate with your in-house systems to support compound business processes. For example, you could integrate an external credit card processing service with your internal order-entry system or integrate an external search engine with your internally managed Web site.

Start by dividing the services you have selected for public cloud sourcing into three major categories, according to their monitoring and management requirements:

1. Services Without Service Quality or Regulatory Compliance Commitments
You can offload these services to the public cloud with little or no risk to the organization. For example, you can take advantage of PaaS offerings to obtain computing platforms for your application developers. You can consume these services quickly and on a pay-as-you-go basis, avoiding capital expenditures.

2. Services with Service Level Agreements (SLAs)
These services require monitoring and management to ensure that they meet commitments. For example, if you offload your service desk processes, you still have to ensure that they meet the availability and performance requirements specified by SLAs.

You cannot typically monitor and manage public cloud resources to the same degree as private cloud resources. Scaling up or down is typically the responsibility of the service provider, not the consumer of the service. However, you can use BSM solutions to proactively monitor and manage the availability and performance of public cloud services. And you can do so in a unified way, with the same tools you use to manage your internally provided services.

3. Services that Require Regulatory Compliance
Your first thought may be to say "no" to outsourcing any services that are under regulatory compliance for fear of introducing the risk of noncompliance. However, as mentioned, this approach limits your flexibility in creating the optimum combination of internal and external services. To offload compliance-mandated services to public cloud providers, while also minimizing the risk of noncompliance, follow the rest of the tips outlined in this article.

Even if you choose to keep compliance-mandated services in house for now, keep in mind that cloud computing is evolving, and service providers are continually improving their ability to ensure and attest to regulatory compliance. Keep your options open for switching to external providers for these services in the future.

Step 2: Develop, Document, and Enforce Internal Compliance Policies
Take a look at all of the regulations that affect IT services in your industry, and then develop and document compliance policies for managing all internally generated services, both cloud and non-cloud. Some of these are government regulations, such as the Health Insurance Portability and Accountability Act (HIPAA), the Sarbanes-Oxley Act of 2002, and the Basel Accords. Others are industry standards, such as the Payment Card Industry Data Security Standard (PCI DSS).

These regulations specify various criteria with which IT organizations must comply. They also include safeguards. HIPAA, for example, covers three types of safeguards: administrative, physical, and technical.

  • Administrative safeguards deal with such areas as assigned security responsibility, information access management, and security incident procedures.
  • Physical safeguards include facility access controls and workstation security.
  • Technical safeguards include audit controls and person or entity authentication.

The regulation may also include implementation specifications. A HIPAA security rule, for example, outlines 18 standards for administrative, physical, and technical safeguards, plus 36 implementation specifications to protect the confidentiality, integrity, and availability of protected health information.

Establish policies that translate the relevant regulations and standards into processes and procedures to which your IT organization must adhere, and then publicize these policies and procedures to the internal IT organization. Here, an IT controlled management solution can help you author, publish, manage, and enforce the policies.

If your IT organization is like most, your internal IT infrastructure will be heterogeneous as you move incrementally from your current environment to the cloud environment. It might include dedicated physical systems, virtualized systems, and private cloud systems. The technology you deploy should enable you to manage the entire infrastructure in a unified manner with respect to compliance.

Here again, BSM can help. For example, data access solutions help you manage the identity and authorization of entities or people that access data that come under the purview of the policies. As another example, change management solutions ensure that all changes made to the IT infrastructure are made in compliance with the policies.

Step 3: Extend Your Internal Compliance Policies to the Cloud
Most public cloud service providers publish their compliance capabilities so customers can review them. For example, some cloud providers publish compliance with the Statement on Auditing Standards No. 70 (SAS 70), which defines the standards an auditor must employ to assess the internal controls of an outsource service provider, such as a hosted data center, insurance claim processor, or credit processing company. Outsourced providers of credit card services usually publish compliance with PCI DSS.

However, it's up to you, the customer, to reconcile the cloud provider's offerings with your own policies. While you can't directly monitor, manage, and control all aspects of the supplier's administrative, physical, and technical safeguards, you can translate your internal compliance policies into a form that is appropriate for the external providers, and then publish these transformed policies. You can leverage the same BSM solutions that you used to create and manage your internal policies to transform, publish, and manage the supplier policies.

This transformation can be a major effort and may involve manual processes. Some enterprises have pursued a path of partnering with their service provider, encouraging them to help complete a compliance checklist. While that effort isn't trivial, some service providers, eager to support a compliance-focused market, work collaboratively with customers.

In addition, you can request that external providers attest to their compliance with your published policies. This approach enables you to extend the rigor of your internal compliance and attestation processes to external service providers.

Step 4: Monitor and Manage Your Public Cloud Providers
In addition to monitoring and managing the services you send to the public cloud, be sure to monitor and manage your public cloud service providers with the same rigor that you apply to other vendors.

First, evaluate and select the highest-value vendors by enforcing best-practice vendor review and approval processes. After you select the vendors, track their performance against their commitments. For example, you can create a risk scorecard for each vendor that tracks its performance in meeting your compliance policies. Finally, you need to continually optimize and consolidate your vendor portfolio by using a fact-based, systematic program for strategic vendor management based on portfolio-level analysis and reporting.

Supplier management solutions enable you to manage the entire supplier lifecycle - from evaluation through termination. These solutions centralize vendor information and help you enforce critical processes, track financials, and track and measure performance against commitments.

Fear Not the Public Cloud
Cloud computing gives you the freedom and flexibility to choose the right mix of internally and externally provided services to best meet the needs of the business. Public cloud providers are continually improving their security and compliance capabilities, making it feasible to offload more services to the public cloud. If you keep your options open, you'll be able to take advantage of additional opportunities in the public cloud as they emerge.

Instead of avoiding the public cloud for services that come under regulatory control, you can use compliance management tools and the IT practices described here to maintain compliance in the cloud.

More Stories By Dan Trevino

Dan Trevino, senior product marketing manager for BMC Software, is an expert in regulatory controls and compliance. He is currently driving the IT Governance, Risk, and Compliance (IT GRC) offering at BMC. Trevino maintains a strong product specialization and has driven the design and creation of the BMC compliance and IT GRC offerings since he joined BMC in 2009. He was an enterprise architect for an IT governance and compliance consultancy and developed and managed the services program and solutions deliverables for its successful IT compliance consulting practice. Trevino has more than 25 years of IT experience with expertise in both process management and systems management.

More Stories By Lilac Schoenbeck

Lilac Schoenbeck is Director of Cloud Computing Marketing at BMC Software. She has more than 12 years of experience with product marketing, strategy, business development, and software engineering in the grid, virtualization, and cloud domains. Schoenbeck has worked for IBM, Fortisphere, Innosight, and the Globus Alliance, and she holds an MBA from MIT Sloan School of Management and a computer science degree from Pacific Lutheran University.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@CloudExpo Stories
Without a clear strategy for cost control and an architecture designed with cloud services in mind, costs and operational performance can quickly get out of control. To avoid multiple architectural redesigns requires extensive thought and planning. Boundary (now part of BMC) launched a new public-facing multi-tenant high resolution monitoring service on Amazon AWS two years ago, facing challenges and learning best practices in the early days of the new service.
Digital Transformation is much more than a buzzword. The radical shift to digital mechanisms for almost every process is evident across all industries and verticals. This is often especially true in financial services, where the legacy environment is many times unable to keep up with the rapidly shifting demands of the consumer. The constant pressure to provide complete, omnichannel delivery of customer-facing solutions to meet both regulatory and customer demands is putting enormous pressure on...
The best way to leverage your CloudEXPO | DXWorldEXPO presence as a sponsor and exhibitor is to plan your news announcements around our events. The press covering CloudEXPO | DXWorldEXPO will have access to these releases and will amplify your news announcements. More than two dozen Cloud companies either set deals at our shows or have announced their mergers and acquisitions at CloudEXPO. Product announcements during our show provide your company with the most reach through our targeted audienc...
With 10 simultaneous tracks, keynotes, general sessions and targeted breakout classes, @CloudEXPO and DXWorldEXPO are two of the most important technology events of the year. Since its launch over eight years ago, @CloudEXPO and DXWorldEXPO have presented a rock star faculty as well as showcased hundreds of sponsors and exhibitors!
DXWorldEXPO LLC announced today that All in Mobile, a mobile app development company from Poland, will exhibit at the 22nd International CloudEXPO | DXWorldEXPO. All In Mobile is a mobile app development company from Poland. Since 2014, they maintain passion for developing mobile applications for enterprises and startups worldwide.
Both SaaS vendors and SaaS buyers are going “all-in” to hyperscale IaaS platforms such as AWS, which is disrupting the SaaS value proposition. Why should the enterprise SaaS consumer pay for the SaaS service if their data is resident in adjacent AWS S3 buckets? If both SaaS sellers and buyers are using the same cloud tools, automation and pay-per-transaction model offered by IaaS platforms, then why not host the “shrink-wrapped” software in the customers’ cloud? Further, serverless computing, cl...
JETRO showcased Japan Digital Transformation Pavilion at SYS-CON's 21st International Cloud Expo® at the Santa Clara Convention Center in Santa Clara, CA. The Japan External Trade Organization (JETRO) is a non-profit organization that provides business support services to companies expanding to Japan. With the support of JETRO's dedicated staff, clients can incorporate their business; receive visa, immigration, and HR support; find dedicated office space; identify local government subsidies; get...
The current age of digital transformation means that IT organizations must adapt their toolset to cover all digital experiences, beyond just the end users’. Today’s businesses can no longer focus solely on the digital interactions they manage with employees or customers; they must now contend with non-traditional factors. Whether it's the power of brand to make or break a company, the need to monitor across all locations 24/7, or the ability to proactively resolve issues, companies must adapt to...
"We view the cloud not as a specific technology but as a way of doing business and that way of doing business is transforming the way software, infrastructure and services are being delivered to business," explained Matthew Rosen, CEO and Director at Fusion, in this SYS-CON.tv interview at 18th Cloud Expo (http://www.CloudComputingExpo.com), held June 7-9 at the Javits Center in New York City, NY.
DXWorldEXPO LLC announced today that the upcoming DXWorldEXPO | CloudEXPO New York event will feature 10 companies from Poland to participate at the "Poland Digital Transformation Pavilion" on November 12-13, 2018.
In his Opening Keynote at 21st Cloud Expo, John Considine, General Manager of IBM Cloud Infrastructure, led attendees through the exciting evolution of the cloud. He looked at this major disruption from the perspective of technology, business models, and what this means for enterprises of all sizes. John Considine is General Manager of Cloud Infrastructure Services at IBM. In that role he is responsible for leading IBM’s public cloud infrastructure including strategy, development, and offering m...
As data explodes in quantity, importance and from new sources, the need for managing and protecting data residing across physical, virtual, and cloud environments grow with it. Managing data includes protecting it, indexing and classifying it for true, long-term management, compliance and E-Discovery. Commvault can ensure this with a single pane of glass solution – whether in a private cloud, a Service Provider delivered public cloud or a hybrid cloud environment – across the heterogeneous enter...
We all know that end users experience the internet primarily with mobile devices. From an app development perspective, we know that successfully responding to the needs of mobile customers depends on rapid DevOps – failing fast, in short, until the right solution evolves in your customers' relationship to your business. Whether you’re decomposing an SOA monolith, or developing a new application cloud natively, it’s not a question of using microservices - not doing so will be a path to eventual ...
"DivvyCloud as a company set out to help customers automate solutions to the most common cloud problems," noted Jeremy Snyder, VP of Business Development at DivvyCloud, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
More and more brands have jumped on the IoT bandwagon. We have an excess of wearables – activity trackers, smartwatches, smart glasses and sneakers, and more that track seemingly endless datapoints. However, most consumers have no idea what “IoT” means. Creating more wearables that track data shouldn't be the aim of brands; delivering meaningful, tangible relevance to their users should be. We're in a period in which the IoT pendulum is still swinging. Initially, it swung toward "smart for smart...
DXWorldEXPO LLC announced today that ICC-USA, a computer systems integrator and server manufacturing company focused on developing products and product appliances, will exhibit at the 22nd International CloudEXPO | DXWorldEXPO. DXWordEXPO New York 2018, colocated with CloudEXPO New York 2018 will be held November 11-13, 2018, in New York City. ICC is a computer systems integrator and server manufacturing company focused on developing products and product appliances to meet a wide range of ...
We all know that end users experience the Internet primarily with mobile devices. From an app development perspective, we know that successfully responding to the needs of mobile customers depends on rapid DevOps – failing fast, in short, until the right solution evolves in your customers' relationship to your business. Whether you’re decomposing an SOA monolith, or developing a new application cloud natively, it’s not a question of using microservices – not doing so will be a path to eventual b...
Major trends and emerging technologies – from virtual reality and IoT, to Big Data and algorithms – are helping organizations innovate in the digital era. However, to create real business value, IT must think beyond the ‘what’ of digital transformation to the ‘how’ to harness emerging trends, innovation and disruption. Architecture is the key that underpins and ties all these efforts together. In the digital age, it’s important to invest in architecture, extend the enterprise footprint to the cl...
Sanjeev Sharma Joins November 11-13, 2018 @DevOpsSummit at @CloudEXPO New York Faculty. Sanjeev Sharma is an internationally known DevOps and Cloud Transformation thought leader, technology executive, and author. Sanjeev's industry experience includes tenures as CTO, Technical Sales leader, and Cloud Architect leader. As an IBM Distinguished Engineer, Sanjeev is recognized at the highest levels of IBM's core of technical leaders.
Coca-Cola’s Google powered digital signage system lays the groundwork for a more valuable connection between Coke and its customers. Digital signs pair software with high-resolution displays so that a message can be changed instantly based on what the operator wants to communicate or sell. In their Day 3 Keynote at 21st Cloud Expo, Greg Chambers, Global Group Director, Digital Innovation, Coca-Cola, and Vidya Nagarajan, a Senior Product Manager at Google, discussed how from store operations and ...
As Cybric's Chief Technology Officer, Mike D. Kail is responsible for the strategic vision and technical direction of the platform. Prior to founding Cybric, Mike was Yahoo's CIO and SVP of Infrastructure, where he led the IT and Data Center functions for the company. He has more than 24 years of IT Operations experience with a focus on highly-scalable architectures.