Showing posts with label storage. Show all posts
Showing posts with label storage. Show all posts

Thursday, January 31, 2013

Cloud Security Concerns Are Dead...

Charles VI the Mad
Cloud Security Concerns Are Dead! Long Live Cloud Security Concerns!

By Randy Davis, VP Sales & Marketing Operations

Way back in 1422, seventy years before the discovery of America by Columbus, the French king, Charles VI, died. Upon his passing, the phrase Le Roi est mort, vive le Roi! was pronounced to indicate the immediate and unbroken transition of sovereignty from the dead king to the new king, Charles VII. The saying, "The King is dead, long live the king," was so powerful that it has been borrowed by other royalist nations to note the transfer of rule from a newly deceased monarch to the living one.

However, the saying did not assume that the manners, customs, priorities, principles or laws of rule would remain the same. The new monarch had, let us say, flexibility. Even so, the past is not easily resisted.

It's the idea of continuity that interests me as we transition from the perception that (at least for many IT practitioners) concerns over cloud security still reign supreme, to the idea that (for others) those concerns belong to the previous regime, and it's time to move on to less resolved matters such as how to make sense out of big data. The questions before us are these: are security concerns about cloud-based storage and computing providers alive and well, or should such concerns be relegated to the past so that we can devote our resources to truly unresolved problems?

I think the answer is Yes... and Yes.

Perception Vs. Reality

The fact is security is still the top concern preventing the adoption of public clouds. Of the 27% of respondents to the InformationWeek 2012 Cloud Security and Risk Survey that have no plans to use public cloud services, almost half (48%) cite security concerns.

In a recent Federal Computer Week cloud computing report sponsored by Brocade, the resistance to cloud computing was compared to that of opening a bank in the Wild West during the 1800's. In a time when people kept, protected and controlled their own money in their own "mattress safe," the idea of some newfangled bank providing those services seemed highly risky. Can the bank be trusted? How can I get to my money? What keeps someone from walking in and pretending he is me? What if the bank is robbed or fails? Over time, however, as people began to use banks to protect their money, banks proved trustworthy, and their use became ubiquitous.

Although the period of westward expansion in American history was a time of tension and uncertainty for frontier banks, most banks were more than capable of providing vaulted, secure financial services.

Still, many people were reluctant to give them their money, preferring to keep it under the mattress, and under their own control. The mattress model, however, proved to have the highest risk of all because of fire, flood, storm, accident, loss or theft.

For many IT managers and executives I think this illustrates where we are today as we transition from the on-premise, institutional, ad hoc "mattress" model of protecting information to the specialized cloud-based "bank" model. It is my conviction that, just as people have come to trust banks with their most valuable financial assets, they will inevitably come to trust specialized cloud-based providers with their most valuable information assets.

Actual Risk Vs. Perceived Risk

The dichotomy in opinion about security between those who use cloud storage and those who do not could not be better illustrated than by the following: when asked* if cloud storage improves data protection for disaster recovery, two-thirds of actual cloud storage users responded yes, while only one-quarter of those who do not use cloud storage responded the same way. Clearly the experience of actually using cloud storage services informs a different opinion of their efficacy.

For me, concerns about cloud security fall into two camps:
  1. Concerns that are legitimate and necessary and belong to any data protection scheme 
  2. Concerns that are dated, irrational or fail to recognize genuine progress or proven solutions 
That's not to say that all cloud providers are alike in scale and quality of service. Nor do they need to be. There is specialization in cloud storage services depending on need, use, and levels of security (within security I include transport, authentication, redundancy, ratings, facilities, segregation, certification, compliance, etc.).

I understand the "better safe than sorry" mentality that accompanies a move from a long-standing, well-proven solution to a solution that is being proven, and that mitigation of risk is a job-saving responsibility of IT practitioners. I also understand that, at some point, the risk is inverted. Holding on too long to technology or practices that have been superseded, irreversibly begins increasing the risk on the other side of the question. Who would now argue that a mattress is safer than a bank, or a filing cabinet is safer than an encrypted, replicated disk drive?

Warehouse Vs. Bank

Some cloud providers offer warehouse services that effectively provide a sheltered, even guarded, place to store things -- anything -- pictures, videos, music, documents and so on. A warehouse may have plenty of locked doors, a safe, a guard or two, and an alarm system, so to speak, but it's still a warehouse, and they'll let anyone store stuff there. You wouldn't want to store highly valuable or highly private information there, especially if you were legally liable for its security and privacy protection.

Other cloud providers offer an altogether different category of secure storage and management, more like a bank that provides reinforced steel doors, vaults, safety deposit boxes, government regulation and compliance procedures and facilities, certifications, financial services best practices, and so on, all specifically designed to provide the highest degree of protection of highly valuable assets.

There are some very good cloud "warehouse" providers (Dropbox, Box, Google Drive, SkyDrive, etc.), who provide an excellent, if limited, service.

There are other cloud "bank-vault" providers (such as eGistics) who have built their entire service model around securing, protecting, and replicating highly valuable, highly sensitive data.

Using eGistics as an example, because we provide cloud-based services for financial institutions and health care organizations, we are more akin to a vault within a bank rather than a safe within a warehouse. As a result, our concerns, responsibilities and capabilities are different and significantly more stringent, and our infrastructure more secure. Whereas a warehouse safe can provide a degree of safety and protection, it is still a safe within a warehouse, and not a vault within a bank. A safe within a warehouse does not come with the same protections, barriers, restrictions, alarms, monitors, authentications and governing agencies that a vault within a bank does.

My point in this article is that arguments suggesting that cloud technology and security are sub-par compared to on-premise solutions are getting a bit long in the tooth, and too often use the failures of warehouse-type cloud storage providers to argue against any cloud storage as a viable solution for financial, governmental, or health care information.

So, now I'm back to my point that the continuity of ideas and practices from one regime to another can be debilitating -- especially within the dynamic and evolving arena of technology and technological leadership.

I suggest that we are in a period of tension between the time that IT practitioners are unsure that cloud security has been sufficiently addressed, and the time they recognize that it has been. When cloud security is fully embraced, however, IT managers still need to appreciate the difference between a warehouse and a bank.

Let me know what you think about cloud security.



* "A Snapshot into Cloud Storage Adoption," TwinStrata white paper, updated January 2013

Thursday, June 9, 2011

Some Think Cloud Security Superior to In-house Data Centers


For some in-house data centers,
the data horse has already left the barn!
Randy Davis, VP eGistics

I just attended a panel discussion Webinar titled, "Ready for Cloud Storage? Key Considerations and Lessons Learned,"  hosted by SNIA, Cloud Storage Initiative.

The panel included Kipp Bertke, Manager of Infrastructure & Operations at Ohio Department of Developmental Disabilities; Ajay Chandramouly, Cloud & Data Center Industry Engagement Manager at Intel; and Nathan McBride, Executive Director of IT at AMAG Pharmaceuticals.

The discussion was meaty and substantial (you can find it here: http://www.brighttalk.com/webcast/679/27865), but the comments by McBride were downright breathtaking. I would say that he and I had been reading the same articles, but his comments were based on hard-earned experience rather than ivory-tower theorizing.

I was so impressed with his views that I am going to quote him as best I can, and quite extensively, in this blog entry.

The following comments from McBride are in response to my question, "Are cloud security concerns qualitatively different than those for on-premise solutions?" Although the question was misinterpreted to mean security differences between public and private clouds, rather than between cloud solutions and in-house (non-cloud) solutions, McBride's answer was spot on.
“Security is always a concern of mine. It brings me to questions I have to ask myself, and they are 'What is the best possible data center I could build? What’s the most amount of security I could put into it, and how much would that cost me?' I realized that the cloud storage vendors I selected had spent five times that much, or a hundred times that much, to build their data center. So there’s nothing I can do that would even come close to the security offered by my vendor for a low service cost.”
Then he addresses the trust issue head on. Can you trust cloud storage service providers?
"People say, 'Well, what about the people at the data center that is hosting your data? Do you trust them?' Well, I trust them just as much as I trust my own IT employees. The only way you can ever be secure is to remove people. Since I can’t remove people from the equation, I have to trust that at a certain level the companies I want to do business with want to keep doing business with their customers, so they’re going to employ best methods, best practices, and the best people to manage my data. And I don’t just trust that. I also verify through SAS70 certifications, on site audits, things like that. But I do feel comfortable and secure knowing that the companies we are doing business with have employed security practices that far exceed anything I could manage to put together."
McBride went on to discuss some of the data leaks common to in-house data centers, things like non-secured flash drives, data that is copied to dozens or hundreds of PC hard drives, data sent to casual, personally controlled file storage services such as Sky Drive and Google Docs, and so on. His point is that you have to consider the real risks, costs and vulnerabilities of in-house data center management, and realize that, for most companies, it's no Fort Knox for data. On the other hand some cloud storage service providers have gotten real close to Fort Knox-like security.

This Webinar is worth your listen.

Monday, May 30, 2011

Too Small to Succeed at Electronic Document Management

One Size Fits All?
Randy Davis, Vice President Sales and Marketing Operations

We've heard it ourselves in talking to prospects: "We're too small to benefit from an electronic document management (EDM) solution." Sometimes the prospect means "we don't process enough paper in a month," or "we don't have the technical staff to implement and support an EDM solution."

Whatever the reason, experience shows that "too small" may not be a good excuse to keep from making the move. The document management "suit" is not "one size fits all."

Consider this:

According to Ken Neal, a Certified Enterprise Content Management Practitioner and Director of Corporate Communications, for Océ Business Services, "In a recent industry survey, senior executives involved in document management indicated that document scanning has a high impact across the greatest range of business goals that include reducing costs, increasing competitive advantage, enhancing regulatory compliance, and improving customer service."

Benefits
In fact, scanning paper into a document management solution can provide even small companies with hard benefits (reduced paper storage and management costs, improved service, compliance and audit support, disaster recovery) and soft benefits (competitive advantage).

A compilation of studies* (including Gartner) put together by Formstack.com lists the following as making Cloud services, including document management, appealing to small business. Cloud services are mainly:
  1. Affordable
  2. Accessible
  3. Usable
* (Thanks to Rachel Delacour of Bime Analytics for pointing out this "Infographic")

Considerations
Here are some things to consider if you think your office is too small:
  1. Are you storing paper records on premise? If so, can you find needed records in seconds? Are documents safe from prying eyes or unauthorized removal? How will those records be quickly replaced if they are lost or destroyed?
  2. Are you paying to store documents? This includes preparation, the cost of storage, file folders/boxes, transportation, retrieval and duplication.
  3. Does your office look like it could qualify for "America's most cluttered office"? Running a business is hard enough. It's just easier to run a profitable business and service your customers if you can find important documents quickly. Besides that, staff and customers alike associate a messy office with sloth and inefficiency. There's just something about decent organization that makes people feel better about where they work or do business.
  4. Are you under legal or moral obligation to protect or retain records for years and prove that you are doing so?
Counting the Cost
I will be frank here. Scanning documents and storing them in an electronic document management solution is not without up-front and on-going effort and cost. It's not a magic bullet. You may have to buy one or more scanners. You may need to create a barcode-based document identification system to help automate filing (this is easier than you may think). You may need to create a different (and better) process to capture, route, authorize and store documents. You may need to train someone how to use a PC.

The question that only you can answer is, "Will my business and staff benefit from changing the way we do things now?"

Eyes Wide Open
If you think that is possible, taking advantage of an electronic document management solution can go easier if you go in with your eyes wide open and after doing some homework.

Dan Antion, vice president of information services for American Nuclear Insurers, shares "8 Secrets of an Effective Content or Records Management Implementation":
  1. You are not too small for Document Management.
  2. Document Management offers value beyond the obvious.
  3. Document Management is not a technology project.
  4. Management support is required.
  5. Document Management includes costs that are not obvious. [Scanners? Training?]
  6. Document Management technology doesn’t have to be expensive.
  7. Education is important and available.
  8. All vendors are not created equal.
(Dan's full discussion can be found at AIIM.org's Digital Landfill, dated June 23, 2009.)

Call to Action
If you are a small business, hopefully this has given you a few things to consider on your way to a more efficient office. Start today the first step of evaluating your document management processes. At worst, you may discover some ways to make your existing processes better. At best, you may find that electronic document management can help you run a better business and prepare for the growing demands of instantly accessible digital information.

Do you think a company can be too small to use EDM? Share your comments.

(If you find these discussions interesting, please take time to Follow this blog. Also, consider following us on Twitter: twitter.com/eGistics or tweet us @egistics. Thanks!)

Wednesday, February 9, 2011

Do You Discriminate?

by Randy Davis, VP Sales and Marketing Operations

Well, when it comes to electronic document storage management, you should. Discriminate, that is.

In the cloudy skies of storage management (hosted storage, in the now old vernacular. As a further aside, with a wink and nod to Yogi Berra, have you noted that concepts are getting old much younger now?). Anyway, in the cloudy skies of storage management you almost need a vendor traffic controller to work your way through the congestion. There are some excellent choices out there, depending on what one needs.

Ah, that's the crux of the matter. What does one need? A simple needs assessment may start with a need to store stuff: documents, photos, video, audio, databases, images, graphics and so on. There are plenty of solutions in the Cloud to do that.

But many of those solutions seemed aimed at individuals who need a place to collect stuff, and create some kind of organized, hierarchical schematic that will enable them to pigeon hole stuff with the hopes of finding it later via some search term. Even companies that claim to serve the business community seem designed to encourage the ad hoc storage approach.

The business use of document storage is much more stringent. (Let's see, you need to find the invoice that contains the payment amount for account 837394, paid between March 15 and June 30, 2006. Oh, and you need to see if any explanatory notes or correspondence or payments are attached to the invoice. Can you have all that to your boss in the next 60 seconds, please?)

So, a more thoughtful needs assessment should include a way to easily accommodate standard document data that can be indexed; the ability to associate, attach or link related documents and information together; and the ability to find just the information you need so that you can use it. By the way, one of the many benefits of such an approach is the ability to transfer document research responsibilities to others in a group, temporary employees, or new staff.

Why am I discussing this? Part of the reason is to remind you that we have provided the power of the structured document storage management approach to our enterprise customers for many years. Now we are in the process of providing the same capabilities to the Small to Medium-size Business market. In the next few weeks we'll be introducing you to our new flagship product, CloudDocs(TM).

To keep informed about our plans and upcoming launch, be sure to become a follower of this blog. Just use the Follow button in the right hand column.

Also, don't hesitate to add your experience, opinion or question by using the Comment space below.