Welcome!

Cloud Security Authors: Liz McMillan, Scott Millis, Elizabeth White, Kevin Jackson, Doron Kolton

Related Topics: Government Cloud, Microservices Expo, Containers Expo Blog, API Journal, Agile Computing, @CloudExpo, Cloud Security

Government Cloud: Blog Feed Post

Cloud Archiving and Compliance

Clients like governments and the finance industry have extensive requirements for archiving and e-discovery

Our Cloud Archiving and Compliance best practices will define a maturity model for this hugely important segment within the industry.

It will also produce a best practices white paper, tailored to meet the needs of the NIST Business Use Case that defines the specific requirements for this functionality,  the FAA E-Discovery scenario (11-page PDF).

It will also describe a response to the general best practices defined in the recent CIO.gov document: Best practices for ITaaS, which also describes eDiscovery requirements. Download the 44-page PDF here.

Cloud Archiving Managed Services
This is such a hugely important area for Cloud Providers to develop new services because of the double impact it represents.

First there is the simple facet of the business opportunity. Clients like governments and the finance industry have extensive requirements for archiving and e-discovery.

Secondly and the accelerating factor is that the biggest hold up to Cloud adoption is the lack of maturity in this area. Typically the fears all centre on issues like data residency, where is the data hosted, and what protections are in place to ensure this data is not tampered with and so on.

These are requirements that archiving solutions deal with straight off the bat.

The Gartner Magic Quadrant places vendors like HP (Autonomy), IBM and Symantec as the leaders in this space, but this is a focus on the overall broad category of enterprise archiving, meaning it includes traditional on-site systems too.

Where the real challenge and opportunity is presented is how these types of capabilities can be absorbed into Cloud hosting environments, challenges that are well described in this white paper from another of the vendors Proofpoint: Cloud Computing and eDiscovery.

They describe critical points like:

Cloud computing makes IT operations fast and nimble, but it doesn’t necessarily make ESI easier to discover or legal holds easier to enforce. On the contrary, cloud computing can make legal holds and ESI searches more complex, time-consuming, and difficult. The vast majority of cloud providers would be unable to satisfy the stringent security, privacy, and data access requirements of corporate counsel and other stakeholders responsible for managing legal risk exposure.

They are exactly right on this, which is a blunt explanation of why Cloud adoption is still very low despite the huge hype. There`s your answer.

Also Proofpoint describe the solution, and the associated opportunity for Cloud Providers:

Enterprise IT departments need guidance for deploying eDiscovery applications and for crafting Service Level Agreements (SLAs) with cloud service providers, so that new cloud computing initiatives don’t undermine the enterprise’s investments in eDiscovery.

If Cloud Providers do this they will not only open up a specific product segment, Cloud Archiving, but they will also alleviate Cloud adoption fears in general and open the floodgates for broader adoption of all Cloud apps.

This is why, in my opinion, Cloud Archiving is the single most important product area for Cloud Providers to invest in.

Cloud Archiving – Service specifications

For a taste of these market opportunities we can review a number of related industry initiatives.

Managing Government Records - President Obama recently declared the ‘Managing Government Records‘ initiative , to better use Cloud technologies to perform Information Management and achieve Open Government. Canada also recently announced a similar initiative, to build a ‘GC Docs’ portal that publishes all of their records.

The NIST Business Use Case details the required service specifications, begun with this high level introduction and overview:

“The Federal Aviation Administration (FAA) is examining how to implement cloud-based e-discovery and Freedom of Information Act (FOIA) processes for email. The system must be able to perform discovery in both its in-house email implementation (Lotus Notes) but also in cloud-based email systems. The system will also be used to manage content for compliance purposes, and will serve as an archive of FAA messaging content.

The long-run goal is to support four primary functions: e-discovery, electronic records management, FOIA, and privacy. These four processes have similar needs and capabilities, including searching business applications, document repositories, email (including calendar, contacts, tasks, etc.) and instant messages, and distributed storage (both internal and external) for electronically stored information (ESI) meeting defined criteria.

The focus of this business use case is the processes and systems required to respond to e-discovery and FOIA requests as they pertain to email message data and other supporting data such as calendar entries, tasks, attachments, etc. that are produced and processed by the FAA’s traditional and cloud email messaging systems.”

Our Cloud Archiving best practices program will detail how Cloud Providers can develop products in this area to meet these requirements and opportunities.

Read the original blog entry...

More Stories By Cloud Best Practices Network

The Cloud Best Practices Network is an expert community of leading Cloud pioneers. Follow our best practice blogs at http://CloudBestPractices.net

@ThingsExpo Stories
Internet-of-Things discussions can end up either going down the consumer gadget rabbit hole or focused on the sort of data logging that industrial manufacturers have been doing forever. However, in fact, companies today are already using IoT data both to optimize their operational technology and to improve the experience of customer interactions in novel ways. In his session at @ThingsExpo, Gordon Haff, Red Hat Technology Evangelist, will share examples from a wide range of industries – includin...
We're entering the post-smartphone era, where wearable gadgets from watches and fitness bands to glasses and health aids will power the next technological revolution. With mass adoption of wearable devices comes a new data ecosystem that must be protected. Wearables open new pathways that facilitate the tracking, sharing and storing of consumers’ personal health, location and daily activity data. Consumers have some idea of the data these devices capture, but most don’t realize how revealing and...
Unless your company can spend a lot of money on new technology, re-engineering your environment and hiring a comprehensive cybersecurity team, you will most likely move to the cloud or seek external service partnerships. In his session at 18th Cloud Expo, Darren Guccione, CEO of Keeper Security, revealed what you need to know when it comes to encryption in the cloud.
"We build IoT infrastructure products - when you have to integrate different devices, different systems and cloud you have to build an application to do that but we eliminate the need to build an application. Our products can integrate any device, any system, any cloud regardless of protocol," explained Peter Jung, Chief Product Officer at Pulzze Systems, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, discussed how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team at D...
Data is the fuel that drives the machine learning algorithmic engines and ultimately provides the business value. In his session at 20th Cloud Expo, Ed Featherston, director/senior enterprise architect at Collaborative Consulting, will discuss the key considerations around quality, volume, timeliness, and pedigree that must be dealt with in order to properly fuel that engine.
In addition to all the benefits, IoT is also bringing new kind of customer experience challenges - cars that unlock themselves, thermostats turning houses into saunas and baby video monitors broadcasting over the internet. This list can only increase because while IoT services should be intuitive and simple to use, the delivery ecosystem is a myriad of potential problems as IoT explodes complexity. So finding a performance issue is like finding the proverbial needle in the haystack.
According to Forrester Research, every business will become either a digital predator or digital prey by 2020. To avoid demise, organizations must rapidly create new sources of value in their end-to-end customer experiences. True digital predators also must break down information and process silos and extend digital transformation initiatives to empower employees with the digital resources needed to win, serve, and retain customers.
"Once customers get a year into their IoT deployments, they start to realize that they may have been shortsighted in the ways they built out their deployment and the key thing I see a lot of people looking at is - how can I take equipment data, pull it back in an IoT solution and show it in a dashboard," stated Dave McCarthy, Director of Products at Bsquare Corporation, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Fact is, enterprises have significant legacy voice infrastructure that’s costly to replace with pure IP solutions. How can we bring this analog infrastructure into our shiny new cloud applications? There are proven methods to bind both legacy voice applications and traditional PSTN audio into cloud-based applications and services at a carrier scale. Some of the most successful implementations leverage WebRTC, WebSockets, SIP and other open source technologies. In his session at @ThingsExpo, Da...
@GonzalezCarmen has been ranked the Number One Influencer and @ThingsExpo has been named the Number One Brand in the “M2M 2016: Top 100 Influencers and Brands” by Onalytica. Onalytica analyzed tweets over the last 6 months mentioning the keywords M2M OR “Machine to Machine.” They then identified the top 100 most influential brands and individuals leading the discussion on Twitter.
Today we can collect lots and lots of performance data. We build beautiful dashboards and even have fancy query languages to access and transform the data. Still performance data is a secret language only a couple of people understand. The more business becomes digital the more stakeholders are interested in this data including how it relates to business. Some of these people have never used a monitoring tool before. They have a question on their mind like “How is my application doing” but no id...
As data explodes in quantity, importance and from new sources, the need for managing and protecting data residing across physical, virtual, and cloud environments grow with it. Managing data includes protecting it, indexing and classifying it for true, long-term management, compliance and E-Discovery. Commvault can ensure this with a single pane of glass solution – whether in a private cloud, a Service Provider delivered public cloud or a hybrid cloud environment – across the heterogeneous enter...
"IoT is going to be a huge industry with a lot of value for end users, for industries, for consumers, for manufacturers. How can we use cloud to effectively manage IoT applications," stated Ian Khan, Innovation & Marketing Manager at Solgeniakhela, in this SYS-CON.tv interview at @ThingsExpo, held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA.
"We're a cybersecurity firm that specializes in engineering security solutions both at the software and hardware level. Security cannot be an after-the-fact afterthought, which is what it's become," stated Richard Blech, Chief Executive Officer at Secure Channels, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Information technology is an industry that has always experienced change, and the dramatic change sweeping across the industry today could not be truthfully described as the first time we've seen such widespread change impacting customer investments. However, the rate of the change, and the potential outcomes from today's digital transformation has the distinct potential to separate the industry into two camps: Organizations that see the change coming, embrace it, and successful leverage it; and...
Data is the fuel that drives the machine learning algorithmic engines and ultimately provides the business value. In his session at Cloud Expo, Ed Featherston, a director and senior enterprise architect at Collaborative Consulting, discussed the key considerations around quality, volume, timeliness, and pedigree that must be dealt with in order to properly fuel that engine.
We are always online. We access our data, our finances, work, and various services on the Internet. But we live in a congested world of information in which the roads were built two decades ago. The quest for better, faster Internet routing has been around for a decade, but nobody solved this problem. We’ve seen band-aid approaches like CDNs that attack a niche's slice of static content part of the Internet, but that’s it. It does not address the dynamic services-based Internet of today. It does...
Internet of @ThingsExpo, taking place June 6-8, 2017 at the Javits Center in New York City, New York, is co-located with the 20th International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. @ThingsExpo New York Call for Papers is now open.
What happens when the different parts of a vehicle become smarter than the vehicle itself? As we move toward the era of smart everything, hundreds of entities in a vehicle that communicate with each other, the vehicle and external systems create a need for identity orchestration so that all entities work as a conglomerate. Much like an orchestra without a conductor, without the ability to secure, control, and connect the link between a vehicle’s head unit, devices, and systems and to manage the ...