Showing posts with label Cloud. Show all posts
Showing posts with label Cloud. Show all posts

Wednesday, February 20, 2013

Cloud Sprawl in Financial Institutions

Leaking Data to the Cloud

Bob Lund, chairman and CEO

According to Computer Business Review, Cloud Sprawl is defined as the uncontrolled use of public cloud services in an organization with little or no input from management or IT.  It is especially problematic in the financial industry where rapidly growing amounts and variety of data have surpassed the IT department’s ability to provide adequate data management solutions.

Here’s a common scenario: one bank department uses Amazon Cloud Drive while another uses SkyDrive, and other employees use Apple iCloud or DropBox for collaboration.  None of the solutions are compliant with banking regulation, nor under the supervision of the IT group.

The growth of Cloud Sprawl is being driven by complex and lengthy IT provisioning processes, an unmet need for flexible, available document management solutions, the low price point of public cloud services and applications (easy to charge to a p-card), and the familiarity of employees with public cloud services.

The key concern for financial institutions is that uncontrolled public cloud deployment models are leading to security and compliance risks.

Some of the specific problems that Cloud Sprawl poses for financial institutions include:
  • Data resident in accounts that don’t meet the bank’s security or compliance standards
  • Unauthorized access to regulated data, including customer data
  • Employees forgetting to delete data in cloud accounts that they set up
  • Potential of data loss if the owner of a cloud account leaves the bank
  • No corporate ability to audit usage and content of disparate cloud accounts and resulting inability to identify data risk and compliance problems
Not surprisingly, 67 percent of IT executives at companies with over 1,000 employees are worried about Cloud Sprawl, according to a 2012 study by Vanson Bourne.  Fifty-four percent of these IT executives admit they are unsure how many cloud services their employees use.  Worse, 20 percent of IT executives say it is “impossible” to manage disparate cloud services, finds Kelton Research.

eGistics provides applications for financial services that help control Cloud Sprawl, and delivers them on a highly secure, highly scalable cloud platform that offers:
  • Tight user security 
  • Activity audit reporting
  • Data management procedures focused on banking compliance
  • Centralized administrative control over secured data and its access
  • Standardized workflows and processes 
The eGistics Cloud Sprawl solution builds on our:
  • Fourteen-year track record in delivering cloud solutions
  • Footprint in the largest financial institutions
  • World-class infrastructure designed for data security and 7/24/365 access
  • PCI certification and compliance with HIPAA, SSAE 16, SOC 1 & 2, and FFIEC
Feedback
If you are in a financial institution, and are seeing the effects of cloud sprawl, share your ideas and experiences!

Thursday, January 31, 2013

Cloud Security Concerns Are Dead...

Charles VI the Mad
Cloud Security Concerns Are Dead! Long Live Cloud Security Concerns!

By Randy Davis, VP Sales & Marketing Operations

Way back in 1422, seventy years before the discovery of America by Columbus, the French king, Charles VI, died. Upon his passing, the phrase Le Roi est mort, vive le Roi! was pronounced to indicate the immediate and unbroken transition of sovereignty from the dead king to the new king, Charles VII. The saying, "The King is dead, long live the king," was so powerful that it has been borrowed by other royalist nations to note the transfer of rule from a newly deceased monarch to the living one.

However, the saying did not assume that the manners, customs, priorities, principles or laws of rule would remain the same. The new monarch had, let us say, flexibility. Even so, the past is not easily resisted.

It's the idea of continuity that interests me as we transition from the perception that (at least for many IT practitioners) concerns over cloud security still reign supreme, to the idea that (for others) those concerns belong to the previous regime, and it's time to move on to less resolved matters such as how to make sense out of big data. The questions before us are these: are security concerns about cloud-based storage and computing providers alive and well, or should such concerns be relegated to the past so that we can devote our resources to truly unresolved problems?

I think the answer is Yes... and Yes.

Perception Vs. Reality

The fact is security is still the top concern preventing the adoption of public clouds. Of the 27% of respondents to the InformationWeek 2012 Cloud Security and Risk Survey that have no plans to use public cloud services, almost half (48%) cite security concerns.

In a recent Federal Computer Week cloud computing report sponsored by Brocade, the resistance to cloud computing was compared to that of opening a bank in the Wild West during the 1800's. In a time when people kept, protected and controlled their own money in their own "mattress safe," the idea of some newfangled bank providing those services seemed highly risky. Can the bank be trusted? How can I get to my money? What keeps someone from walking in and pretending he is me? What if the bank is robbed or fails? Over time, however, as people began to use banks to protect their money, banks proved trustworthy, and their use became ubiquitous.

Although the period of westward expansion in American history was a time of tension and uncertainty for frontier banks, most banks were more than capable of providing vaulted, secure financial services.

Still, many people were reluctant to give them their money, preferring to keep it under the mattress, and under their own control. The mattress model, however, proved to have the highest risk of all because of fire, flood, storm, accident, loss or theft.

For many IT managers and executives I think this illustrates where we are today as we transition from the on-premise, institutional, ad hoc "mattress" model of protecting information to the specialized cloud-based "bank" model. It is my conviction that, just as people have come to trust banks with their most valuable financial assets, they will inevitably come to trust specialized cloud-based providers with their most valuable information assets.

Actual Risk Vs. Perceived Risk

The dichotomy in opinion about security between those who use cloud storage and those who do not could not be better illustrated than by the following: when asked* if cloud storage improves data protection for disaster recovery, two-thirds of actual cloud storage users responded yes, while only one-quarter of those who do not use cloud storage responded the same way. Clearly the experience of actually using cloud storage services informs a different opinion of their efficacy.

For me, concerns about cloud security fall into two camps:
  1. Concerns that are legitimate and necessary and belong to any data protection scheme 
  2. Concerns that are dated, irrational or fail to recognize genuine progress or proven solutions 
That's not to say that all cloud providers are alike in scale and quality of service. Nor do they need to be. There is specialization in cloud storage services depending on need, use, and levels of security (within security I include transport, authentication, redundancy, ratings, facilities, segregation, certification, compliance, etc.).

I understand the "better safe than sorry" mentality that accompanies a move from a long-standing, well-proven solution to a solution that is being proven, and that mitigation of risk is a job-saving responsibility of IT practitioners. I also understand that, at some point, the risk is inverted. Holding on too long to technology or practices that have been superseded, irreversibly begins increasing the risk on the other side of the question. Who would now argue that a mattress is safer than a bank, or a filing cabinet is safer than an encrypted, replicated disk drive?

Warehouse Vs. Bank

Some cloud providers offer warehouse services that effectively provide a sheltered, even guarded, place to store things -- anything -- pictures, videos, music, documents and so on. A warehouse may have plenty of locked doors, a safe, a guard or two, and an alarm system, so to speak, but it's still a warehouse, and they'll let anyone store stuff there. You wouldn't want to store highly valuable or highly private information there, especially if you were legally liable for its security and privacy protection.

Other cloud providers offer an altogether different category of secure storage and management, more like a bank that provides reinforced steel doors, vaults, safety deposit boxes, government regulation and compliance procedures and facilities, certifications, financial services best practices, and so on, all specifically designed to provide the highest degree of protection of highly valuable assets.

There are some very good cloud "warehouse" providers (Dropbox, Box, Google Drive, SkyDrive, etc.), who provide an excellent, if limited, service.

There are other cloud "bank-vault" providers (such as eGistics) who have built their entire service model around securing, protecting, and replicating highly valuable, highly sensitive data.

Using eGistics as an example, because we provide cloud-based services for financial institutions and health care organizations, we are more akin to a vault within a bank rather than a safe within a warehouse. As a result, our concerns, responsibilities and capabilities are different and significantly more stringent, and our infrastructure more secure. Whereas a warehouse safe can provide a degree of safety and protection, it is still a safe within a warehouse, and not a vault within a bank. A safe within a warehouse does not come with the same protections, barriers, restrictions, alarms, monitors, authentications and governing agencies that a vault within a bank does.

My point in this article is that arguments suggesting that cloud technology and security are sub-par compared to on-premise solutions are getting a bit long in the tooth, and too often use the failures of warehouse-type cloud storage providers to argue against any cloud storage as a viable solution for financial, governmental, or health care information.

So, now I'm back to my point that the continuity of ideas and practices from one regime to another can be debilitating -- especially within the dynamic and evolving arena of technology and technological leadership.

I suggest that we are in a period of tension between the time that IT practitioners are unsure that cloud security has been sufficiently addressed, and the time they recognize that it has been. When cloud security is fully embraced, however, IT managers still need to appreciate the difference between a warehouse and a bank.

Let me know what you think about cloud security.



* "A Snapshot into Cloud Storage Adoption," TwinStrata white paper, updated January 2013

Thursday, June 9, 2011

Some Think Cloud Security Superior to In-house Data Centers


For some in-house data centers,
the data horse has already left the barn!
Randy Davis, VP eGistics

I just attended a panel discussion Webinar titled, "Ready for Cloud Storage? Key Considerations and Lessons Learned,"  hosted by SNIA, Cloud Storage Initiative.

The panel included Kipp Bertke, Manager of Infrastructure & Operations at Ohio Department of Developmental Disabilities; Ajay Chandramouly, Cloud & Data Center Industry Engagement Manager at Intel; and Nathan McBride, Executive Director of IT at AMAG Pharmaceuticals.

The discussion was meaty and substantial (you can find it here: http://www.brighttalk.com/webcast/679/27865), but the comments by McBride were downright breathtaking. I would say that he and I had been reading the same articles, but his comments were based on hard-earned experience rather than ivory-tower theorizing.

I was so impressed with his views that I am going to quote him as best I can, and quite extensively, in this blog entry.

The following comments from McBride are in response to my question, "Are cloud security concerns qualitatively different than those for on-premise solutions?" Although the question was misinterpreted to mean security differences between public and private clouds, rather than between cloud solutions and in-house (non-cloud) solutions, McBride's answer was spot on.
“Security is always a concern of mine. It brings me to questions I have to ask myself, and they are 'What is the best possible data center I could build? What’s the most amount of security I could put into it, and how much would that cost me?' I realized that the cloud storage vendors I selected had spent five times that much, or a hundred times that much, to build their data center. So there’s nothing I can do that would even come close to the security offered by my vendor for a low service cost.”
Then he addresses the trust issue head on. Can you trust cloud storage service providers?
"People say, 'Well, what about the people at the data center that is hosting your data? Do you trust them?' Well, I trust them just as much as I trust my own IT employees. The only way you can ever be secure is to remove people. Since I can’t remove people from the equation, I have to trust that at a certain level the companies I want to do business with want to keep doing business with their customers, so they’re going to employ best methods, best practices, and the best people to manage my data. And I don’t just trust that. I also verify through SAS70 certifications, on site audits, things like that. But I do feel comfortable and secure knowing that the companies we are doing business with have employed security practices that far exceed anything I could manage to put together."
McBride went on to discuss some of the data leaks common to in-house data centers, things like non-secured flash drives, data that is copied to dozens or hundreds of PC hard drives, data sent to casual, personally controlled file storage services such as Sky Drive and Google Docs, and so on. His point is that you have to consider the real risks, costs and vulnerabilities of in-house data center management, and realize that, for most companies, it's no Fort Knox for data. On the other hand some cloud storage service providers have gotten real close to Fort Knox-like security.

This Webinar is worth your listen.

Thursday, June 2, 2011

90% of Businesses Think They Are Inefficient. So What?


Randy Davis, Vice President Sales and Marketing Operations

A competitor recently came out with a "press release" based on a survey of 5,500 company records managers that claimed "Ninety Percent of Businesses Believe They Are Inefficient."

I'd like to know who the 10% of businesses that believe they are efficient are.

This is a bit like saying, "90% of all people think they don't exercise enough." OK, now what? According to the survey results, most of the companies already have in place "formal programs for how their companies should manage information," which, I suppose, includes eliminating obstacles, removing paper, idling back the copier, etc.

This news release seems a bit like motherhood and apple pie.

I would imagine that most people would settle for bringing more efficiency to a single, departmental process rather than to an entire company.

How about this for capturing and eliminating paper, automatically organizing it, and then quickly finding it:
  • Use bar codes to identify form document types and identify account holders. You can inexpensively create label sheets of bar codes, or forms that automatically print with bar codes, that contain simple information such as:

    • Account ID
    • Document Type
One of our customers uses this simple technique to seamlessly and automatically process documents during the scanning process. 
  • Scan documents using a system that can automatically ID the documents, separate them, index and organize them, route them to the required work queue, and securely store them.

  • Shred any documents that do not need to be physically stored by law, regulation, or company policy

  • Use a cloud service provider to eliminate capital and reduce the need for IT maintenance.
If you have any other practical advice on how to bring efficiency to a business process burdened with paper, let us hear from you.

    Thursday, May 26, 2011

    Fog Reigns in The Cloud

    Randy Davis, VP Sales and Marketing Operations

    Look at these search results headlines from a simple Google search: "What is The Cloud?"

    August 19, 2008: "Can We Please Define Cloud Computing?"
    February 27, 2009: "So what is the Cloud, exactly? Experts want to know"
    July 24, 2009: "Twenty-One Experts Define Cloud Computing"
    July 15, 2010: "Clarifying the SaaS vs. Cloud Integration Confusion"
    July 27, 2010: "CompTIA Launches Effort to Define the Cloud"
    August 4, 2010: "Cloud Customer Confusion Continues"
    December 6, 2010: "Confusion in the Cloud"
    March 28, 2011: "Confusion in the Cloud"
    April 14, 2011: "Experts cut through the cloud computing confusion"
    May 5, 2011: "Cloud Computing Confusion: Is It the Name?"

    Should it really take over four years to define something that virtually everybody uses by now?

    I've been following the Cloud discussion on LinkedIn, and have been shocked at the disparity between opinions in answer to the question: what is Cloud Computing? In fact, I would say the discussion is an old fashioned argument amongst denominational practitioners! Fundamentalists, liberals and middle-of-the-roaders are all having their say.

    I'm not technically challenged, and can participate in complex discussions about technology without (usually) embarrassing myself. But I can't find one, decent definition of The Cloud that I can sink my teeth into. Defining The Cloud seems frustratingly elusive. When you have to resort to PC Magazine or Wikipedia to define an industry or technical term, because the industry or technocrats cannot articulate an agreed definition themselves, you know things are in a mess.

    I've come to the conclusion that the definition of Cloud Computing is about to be yanked away from the experts and placed firmly in the hands of the users, who don't care a hoot about layers of protocols, servers, virtualization, infrastructures, nodes, networks or nothin'. They just use it and think of it as "the Internet."

    In fact, PC Magazine, speaking to everyday users, says flatly, "The Cloud is the Internet."

    Wikipedia, speaking to everyday users, says the Cloud "refers to the on-demand provision of...data, software... via a computer network rather than from a local computer." Ok, that works, sort of, but it still doesn't satisfy.

    So my question is, "Is a definition of The Cloud necessary?" If it is, necessary to whom?

    I contend that, for all intents and purposes, The Cloud is the old "computer network" (represented in diagrams as a cloud), that became the old "Web" (represented in diagrams as a cloud) that became the new "Cloud" (represented in diagrams as a cloud). We've seen this all before when it was more controlled, and thus defined, by big hardware, software and network providers. But now, when almost anybody can play, and "the definition" of The Cloud is re-defined almost daily, it's become a bit like herding cats back into the corral.

    If you object that one has to understand the Cloud's technological and organizational complexity in order to safely participate in it, I say "bunk." Eventually one has to trust the chosen provider of services. You have to do what you've always had to do with any provider that provides important services to you, and to whom you entrust sensitive information (banks, brokers, doctors): you have to satisfy yourself that they will protect what you entrust to them, and then you have to trust them, and then you have to watch them very carefully.

    If you think something that goes into The Cloud goes into the great unknown, I think you are wrong. I think you can know where stuff is, and what is being done and used to protect it, because I think you can get to know a provider of cloud services. I think you can know whether something is being stored at Rackspace or at AT&T. I think you can know whether a data center is Tier 4 or Tier 1. I think you can know whether data is being encrypted or not. I think you can know whether your data is safely being replicated and geographically separated or not. I think you can know whether a provider is PCI certified or SAS70 compliant or not. For corporations dealing with cloud service providers, these are important and critical things to know. It is important to realize that these things can be known -- even if you are dealing with a cloud service provider.

    It is my conviction that, for most people, The Cloud is an experience rather than a thing. It is an adjective rather than a noun. It doesn't have to be defined because it has become undefinable. It's like trying to capture fog in a net.

    If The Cloud is an experience, an adjective, then it should be known by its attributes, by what it does or provides. For most people, it reduces or eliminates the need for hardware and software and additional IT resources. Or it provides a way to get access to some really powerful, really cool features by renting instead of buying. (Given this, I find it surprising that SMBs are some of the most reluctant users of cloud services.) Or it provides a way to almost instantly grow or shrink one's use (and cost) of computer systems and everything it takes to support them. Or it provides a way to take advantage of a security infrastructure that they could never afford in a million years.

    So where does this leave me in my search for a definition of The Cloud. I still don't have one. But it feels a lot like the Internet, or something close to it.

    What do you think?

    Wednesday, May 18, 2011

    Losing Electronic Documents? You’ve Got to Be Kidding!


    By Nathan Khani, CloudDocs Solution Specialist

    A report in USA Today (May 18, 2011) included this shocking finding: “The average worker wastes 2.5 hours per week looking for documents missing in poorly organized electronic files.” Wait a minute. I thought that electronic filing systems were supposed to solve the problem of losing files. Now we learn that even a small office of, say, five people wastes more than a day and a half of productivity each week looking for electronically filed documents. What gives?

    Here’s my thought. Electronic filing systems do not inherently solve the problem of finding files if they allow for disorganized filing methods. Worse, some document management systems actually encourage poor document filing practices. Wasted time is either a direct result of the disorganized use of electronic filing, or of electronic filing systems that are prone to disorganization.

    What do I mean by disorganized electronic filing? This. If you use an electronic filing system much the same way you use a paper filing system, you will experience the same challenges in finding documents. Filing systems based on Folders, file names, keywords, and text searches are simply not optimized for finding documents quickly. Such systems rely too much on ad hoc naming conventions, free-form keywords, and knowledge of filing method best practices.

    When it comes to storing and finding documents, too much flexibility and freedom can lead directly to disorganization. File management systems also depend too much on where a document is stored rather than on characteristics that make a document findable. Look. We’re not talking about storing your photos, videos, favorite recipes, old high school English papers, or music. We’re talking about documents you use to run your business. The fact is that good electronic document management requires good old fashioned standards, a bit of departmental discipline, and a document management solution that encourages and supports both.

    That’s why it’s important for an organization to used electronic business document management solutions that are designed to relieve you of the burden of organizing documents by folder and file name. Such solutions are often called “structured” document management solutions, and they utilize index data to find stored documents in a way that is predictable and fast. In a structured document management system you can literally scan or upload a document, index it (manually or automatically), and forget about it until it’s time to find it or use it as part of a business process or workflow. Then, by using one or more configurable, standardized index fields, you can almost instantly find the document or documents you need. Such systems reduce the complexity of filing and (almost) guarantee that you can find the documents you need when you need them.

    We would love to hear any tips or advice you may have regarding organizing your electronic files. Please share your thoughts below!

    Tuesday, May 17, 2011

    Security in the Cloud: Don't Let It Stop You

    by Randy Davis, Vice President, eGistics

    The primary reason companies cite for not taking advantage of Cloud services is concern about security. So it comes as a bit of a surprise when security analysts say, "Don't let security concerns stop you from migrating appropriate pieces of your IT operations to cloud-based services," as they did in a recent InformationWeek Analytics report of Cloud Security (5 April 2011). Of course this advice comes with fair warning about doing your homework, and hinges on the word "appropriate."

    The authors of the report point out that better security is not a reason to move to the Cloud, but undue concerns about security is not a reason (in many cases) not to, either. Still, in a recent survey, 53% of 208 respondents not planning to move to the Cloud cite security as a primary reason for not doing so. The InformationWeek Analytics report suggests that their concerns may be misplaced, and based on old data.

    The fact is, remote hosted services have been around for years, hosting billions of items of data for highly security-sensitive companies (like financial services companies processing check and credit card transactions) and doing so in a proven, secure environment. If financial processors trust your transactional payment data to the cloud, why wouldn't you trust, say, your business forms to the cloud?

    Some Cloud providers can provide better security than you can, believe it or not. They've already addressed, through extensive cost, time and effort, the requirements of the Payment Card Industry, or SAS70, or HIPAA.

    So the report concludes, it's not a matter of whether the Cloud is secure, it's a matter of (as in any business environment) whether your chosen partner has adequately addressed your specific security concerns. You may be pleasantly surprised to learn that they have.

    Let us know if you agree, or whether you have security concerns that cannot be addressed by Cloud service providers.

    Wednesday, February 9, 2011

    Do You Discriminate?

    by Randy Davis, VP Sales and Marketing Operations

    Well, when it comes to electronic document storage management, you should. Discriminate, that is.

    In the cloudy skies of storage management (hosted storage, in the now old vernacular. As a further aside, with a wink and nod to Yogi Berra, have you noted that concepts are getting old much younger now?). Anyway, in the cloudy skies of storage management you almost need a vendor traffic controller to work your way through the congestion. There are some excellent choices out there, depending on what one needs.

    Ah, that's the crux of the matter. What does one need? A simple needs assessment may start with a need to store stuff: documents, photos, video, audio, databases, images, graphics and so on. There are plenty of solutions in the Cloud to do that.

    But many of those solutions seemed aimed at individuals who need a place to collect stuff, and create some kind of organized, hierarchical schematic that will enable them to pigeon hole stuff with the hopes of finding it later via some search term. Even companies that claim to serve the business community seem designed to encourage the ad hoc storage approach.

    The business use of document storage is much more stringent. (Let's see, you need to find the invoice that contains the payment amount for account 837394, paid between March 15 and June 30, 2006. Oh, and you need to see if any explanatory notes or correspondence or payments are attached to the invoice. Can you have all that to your boss in the next 60 seconds, please?)

    So, a more thoughtful needs assessment should include a way to easily accommodate standard document data that can be indexed; the ability to associate, attach or link related documents and information together; and the ability to find just the information you need so that you can use it. By the way, one of the many benefits of such an approach is the ability to transfer document research responsibilities to others in a group, temporary employees, or new staff.

    Why am I discussing this? Part of the reason is to remind you that we have provided the power of the structured document storage management approach to our enterprise customers for many years. Now we are in the process of providing the same capabilities to the Small to Medium-size Business market. In the next few weeks we'll be introducing you to our new flagship product, CloudDocs(TM).

    To keep informed about our plans and upcoming launch, be sure to become a follower of this blog. Just use the Follow button in the right hand column.

    Also, don't hesitate to add your experience, opinion or question by using the Comment space below.