SlideShare a Scribd company logo
1 of 8
Download to read offline
Unintended Regulatory
Consequences And The
       Cloud
              Kirk Wylie
        kirk@kirkwylie.com
    http://kirkwylie.blogspot.com

          3 February, 2009
         Powered By Cloud
Nobody Says You Can’t
Use Cloud Computing
• Regulators don’t talk about the Cloud
• Regulators about what you must do
 • You must protect client data
 • You must protect against fraud
 • You must complete computations in time
Auditors Interprets
         Rules
• Auditors (internal and external) ensure
  compliance with regulations
• They follow best practice guides
• Violating guides requires strong IT
  leadership
  • You can do it, but your CIO better have a
    lot of political capital built up!
Best Practice Guides
 Don’t Understand
 Cloud Computing
Example: Client Data
• Applies to client or counterparty data
• Could use S3 to store and EC2 to process
• Best Practice is that your data never leave
  your premise
  • And you audit all access internally
  • And your data centre is completely
    secure
• What about extrusion?
Example: Risk Runs

• BASEL limits set by overnight risk runs
• Risk runs must complete by a given time, or
  you can’t trade
• What if it turns out Amazon IS finite?
• What if the market explodes at once?
Example: Fraud

• Must prevent nefarious teams from
  injecting P&L related code
• Must audit all injection vectors
• How can you do that in the cloud?
Conclusion
• Regulations don’t directly limit Cloud use
 • FSA doesn’t understand Virtualization
• Interpretation of regulations implicitly
  restrict cloud use
• Until compliance and audit teams
  understand new best practices, adoption
  will be limited

More Related Content

Viewers also liked

Rechtssicheres E-Mail-Marketing 2013
Rechtssicheres E-Mail-Marketing 2013Rechtssicheres E-Mail-Marketing 2013
Rechtssicheres E-Mail-Marketing 2013Connected-Blog
 
idOnDemand | Article | Looking For An ID Solution? Get It From idOnDemand!
idOnDemand | Article | Looking For An ID Solution? Get It From idOnDemand!idOnDemand | Article | Looking For An ID Solution? Get It From idOnDemand!
idOnDemand | Article | Looking For An ID Solution? Get It From idOnDemand!Identive
 
NFC Forum Compliance Program Overview
NFC Forum Compliance Program OverviewNFC Forum Compliance Program Overview
NFC Forum Compliance Program OverviewNFC Forum
 
How Social Data boosts Conversion
How Social Data boosts ConversionHow Social Data boosts Conversion
How Social Data boosts ConversionDatentreiber
 
An algorithm for decomposition coordination of large scale convex programmimg...
An algorithm for decomposition coordination of large scale convex programmimg...An algorithm for decomposition coordination of large scale convex programmimg...
An algorithm for decomposition coordination of large scale convex programmimg...Dr Talaat Refaat
 
How to build and manage a superior customer experience leading to a better bo...
How to build and manage a superior customer experience leading to a better bo...How to build and manage a superior customer experience leading to a better bo...
How to build and manage a superior customer experience leading to a better bo...Christoph Spengler
 
Identive | Press Release | Identive Group Announces Preliminary First Quarter...
Identive | Press Release | Identive Group Announces Preliminary First Quarter...Identive | Press Release | Identive Group Announces Preliminary First Quarter...
Identive | Press Release | Identive Group Announces Preliminary First Quarter...Identive
 
Kompetenz-Häppchen Nr. 03 zu Effizienz in der HR von Thomas Eggert
Kompetenz-Häppchen Nr. 03 zu Effizienz in der HR von Thomas Eggert Kompetenz-Häppchen Nr. 03 zu Effizienz in der HR von Thomas Eggert
Kompetenz-Häppchen Nr. 03 zu Effizienz in der HR von Thomas Eggert Competence Books
 
Appetizer Corporate Design
Appetizer Corporate DesignAppetizer Corporate Design
Appetizer Corporate DesignHauke Sann
 
Mobile Convention Amsterdam 2015 - MEF/ Wirecard - Jack Harris
Mobile Convention Amsterdam 2015 - MEF/ Wirecard - Jack HarrisMobile Convention Amsterdam 2015 - MEF/ Wirecard - Jack Harris
Mobile Convention Amsterdam 2015 - MEF/ Wirecard - Jack HarrisMobile Convention Amsterdam 2015
 
250 Diapositivas
250 Diapositivas250 Diapositivas
250 DiapositivasMartii15
 
Technische Innovationen vs. Erfüllung erforderter IT-Sicherheit?
Technische Innovationen vs. Erfüllung erforderter IT-Sicherheit?Technische Innovationen vs. Erfüllung erforderter IT-Sicherheit?
Technische Innovationen vs. Erfüllung erforderter IT-Sicherheit?Torben Haagh
 

Viewers also liked (14)

Online Reputation
Online ReputationOnline Reputation
Online Reputation
 
Rechtssicheres E-Mail-Marketing 2013
Rechtssicheres E-Mail-Marketing 2013Rechtssicheres E-Mail-Marketing 2013
Rechtssicheres E-Mail-Marketing 2013
 
idOnDemand | Article | Looking For An ID Solution? Get It From idOnDemand!
idOnDemand | Article | Looking For An ID Solution? Get It From idOnDemand!idOnDemand | Article | Looking For An ID Solution? Get It From idOnDemand!
idOnDemand | Article | Looking For An ID Solution? Get It From idOnDemand!
 
NFC Forum Compliance Program Overview
NFC Forum Compliance Program OverviewNFC Forum Compliance Program Overview
NFC Forum Compliance Program Overview
 
How Social Data boosts Conversion
How Social Data boosts ConversionHow Social Data boosts Conversion
How Social Data boosts Conversion
 
An algorithm for decomposition coordination of large scale convex programmimg...
An algorithm for decomposition coordination of large scale convex programmimg...An algorithm for decomposition coordination of large scale convex programmimg...
An algorithm for decomposition coordination of large scale convex programmimg...
 
How to build and manage a superior customer experience leading to a better bo...
How to build and manage a superior customer experience leading to a better bo...How to build and manage a superior customer experience leading to a better bo...
How to build and manage a superior customer experience leading to a better bo...
 
Identive | Press Release | Identive Group Announces Preliminary First Quarter...
Identive | Press Release | Identive Group Announces Preliminary First Quarter...Identive | Press Release | Identive Group Announces Preliminary First Quarter...
Identive | Press Release | Identive Group Announces Preliminary First Quarter...
 
Kompetenz-Häppchen Nr. 03 zu Effizienz in der HR von Thomas Eggert
Kompetenz-Häppchen Nr. 03 zu Effizienz in der HR von Thomas Eggert Kompetenz-Häppchen Nr. 03 zu Effizienz in der HR von Thomas Eggert
Kompetenz-Häppchen Nr. 03 zu Effizienz in der HR von Thomas Eggert
 
Appetizer Corporate Design
Appetizer Corporate DesignAppetizer Corporate Design
Appetizer Corporate Design
 
Studienergebnisse vertriebsklima-Index
Studienergebnisse vertriebsklima-IndexStudienergebnisse vertriebsklima-Index
Studienergebnisse vertriebsklima-Index
 
Mobile Convention Amsterdam 2015 - MEF/ Wirecard - Jack Harris
Mobile Convention Amsterdam 2015 - MEF/ Wirecard - Jack HarrisMobile Convention Amsterdam 2015 - MEF/ Wirecard - Jack Harris
Mobile Convention Amsterdam 2015 - MEF/ Wirecard - Jack Harris
 
250 Diapositivas
250 Diapositivas250 Diapositivas
250 Diapositivas
 
Technische Innovationen vs. Erfüllung erforderter IT-Sicherheit?
Technische Innovationen vs. Erfüllung erforderter IT-Sicherheit?Technische Innovationen vs. Erfüllung erforderter IT-Sicherheit?
Technische Innovationen vs. Erfüllung erforderter IT-Sicherheit?
 

Recently uploaded

EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 

Recently uploaded (20)

EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 

Powered By Cloud 2009-02-03

  • 1. Unintended Regulatory Consequences And The Cloud Kirk Wylie kirk@kirkwylie.com http://kirkwylie.blogspot.com 3 February, 2009 Powered By Cloud
  • 2. Nobody Says You Can’t Use Cloud Computing • Regulators don’t talk about the Cloud • Regulators about what you must do • You must protect client data • You must protect against fraud • You must complete computations in time
  • 3. Auditors Interprets Rules • Auditors (internal and external) ensure compliance with regulations • They follow best practice guides • Violating guides requires strong IT leadership • You can do it, but your CIO better have a lot of political capital built up!
  • 4. Best Practice Guides Don’t Understand Cloud Computing
  • 5. Example: Client Data • Applies to client or counterparty data • Could use S3 to store and EC2 to process • Best Practice is that your data never leave your premise • And you audit all access internally • And your data centre is completely secure • What about extrusion?
  • 6. Example: Risk Runs • BASEL limits set by overnight risk runs • Risk runs must complete by a given time, or you can’t trade • What if it turns out Amazon IS finite? • What if the market explodes at once?
  • 7. Example: Fraud • Must prevent nefarious teams from injecting P&L related code • Must audit all injection vectors • How can you do that in the cloud?
  • 8. Conclusion • Regulations don’t directly limit Cloud use • FSA doesn’t understand Virtualization • Interpretation of regulations implicitly restrict cloud use • Until compliance and audit teams understand new best practices, adoption will be limited