SlideShare a Scribd company logo
1 of 9
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Auditing Issues for Cloud-based
Business Services
Jonathan Sinclair
SAP Research Belfast
UK
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Agenda
• Fundamentals of Cloud, Compliance and Auditing
• Cloud Compliance Challenges
• Use Case: Future Healthcare and CRM
• Compliance Auditing
• Conclusions
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Fundamentals
Compliance
Compliance is defined as
being in accordance with
relevant governmental orindustrial laws, regulationsand standards through
governance processes.
Business Web
A business model and
technical framework that
represents a marketplace
allowing providers and
consumers to negotiate the
usage of products.
Clouds are a large pool of
easily usable and accessible
virtualized resources that
can be dynamically
reconfigured to adjust to a
variable load.
Cloud Computing
Auditing
The process of collecting and
evaluating evidence to
determine whether a
computer system (information
system) safeguards assets,
maintains data integrity,
achieves organizational goals
effectively and consumes
resources efficiently.
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Motivation, Problem Area
“An undefined problem has an infinite number of solutions”
Robert A. Humphrey
Customer Data
Legislation
Government
Auditor
Compliance CheckCompliance Report
Regulation
Regulator
creates creates
Businesses
have to
comply with
store and are
responsible for
use IT to improve
operations
IT Department
have to
comply with
Governance
Compliance
Customer Data
Legislation
Government
Auditor
Compliance CheckCompliance Report
Regulation
Regulator
creates creates
Businesses
have to
comply with
store and are
responsible for
use IT to improve
operations
IT Department
have to
comply with
Governance
Compliance
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Research Objectives
• The locality of data is of key importance to adhere to legislation
– Cross-jurisdictional conflictions
– Performance and Availability
– Disaster Recovery and Backup
• Multi-tenancy and data accessibility
– Company Multi-tenancy
– Systems Multi-tenancy
• Data Retention
– Retaining data in the Cloud
– Retaining data from the Cloud
“The greatest challenge to any thinker is stating the problem in a way that will allow a solution.”
Bertrand Russell
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
CloudCloud
AuditorAuditor
Research Approach, Methodology
“Most human beings have an almost infinite capacity for taking things for granted”
Aldous Huxley
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Major Outcomes/Results
“A complex system that works is invariably found to have evolved from a simple system that works”
John Gaule
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Conclusion and Outlook
• Ensure the security of consumer’s data
• Maintain compliance with data security / privacy laws
• Assure that service providers, integrators or composers cannot
• access data within a consumer’s service
• transfer data from a consumer’s service
“A conclusion is the place where you got tired of thinking”
Harold Fricklestein
Session 2b, 26th
October 2011 eChallenges e-2011 Copyright 2011 SAP Research
Thank You!
Jonathan Sinclair
Research Associate
SAP Research Belfast
SAP [UK] Ltd
The Concourse, Queen‘s Road
Queen‘s Island, Titanic Quarter
Belfast BT3 9DT
T +44 (0)28 9078 5749
E jonathan.sinclair@sap.com
Blogger:
cloudauditing.blogspot.com
LinkedIn:
jonathangsinclair
Twitter:
jonnygsinclair
Slideshare:
jonathansinclair86

More Related Content

What's hot

SFScon 21 - Nicola Altamura - Implementation of IOTA solutions on embedded de...
SFScon 21 - Nicola Altamura - Implementation of IOTA solutions on embedded de...SFScon 21 - Nicola Altamura - Implementation of IOTA solutions on embedded de...
SFScon 21 - Nicola Altamura - Implementation of IOTA solutions on embedded de...
South Tyrol Free Software Conference
 
Benefits of cloud computing
Benefits of cloud computingBenefits of cloud computing
Benefits of cloud computing
Rishabh Dogra
 
The potential of the cloud
The potential of the cloudThe potential of the cloud
The potential of the cloud
Jisc
 
Asset Intelligence
Asset IntelligenceAsset Intelligence
Asset Intelligence
Juliann2012
 

What's hot (20)

TheValueChain Beyond Simple 10-05-16 - Internet of Things
TheValueChain Beyond Simple 10-05-16 - Internet of ThingsTheValueChain Beyond Simple 10-05-16 - Internet of Things
TheValueChain Beyond Simple 10-05-16 - Internet of Things
 
Characterizing Incidents in Cloud-based IoT Data Analytics
Characterizing Incidents in Cloud-based IoT Data AnalyticsCharacterizing Incidents in Cloud-based IoT Data Analytics
Characterizing Incidents in Cloud-based IoT Data Analytics
 
SFScon 21 - Nicola Altamura - Implementation of IOTA solutions on embedded de...
SFScon 21 - Nicola Altamura - Implementation of IOTA solutions on embedded de...SFScon 21 - Nicola Altamura - Implementation of IOTA solutions on embedded de...
SFScon 21 - Nicola Altamura - Implementation of IOTA solutions on embedded de...
 
Energy efficient fault-tolerant data storage & processing in mobile cloud
Energy efficient fault-tolerant data storage & processing in mobile cloudEnergy efficient fault-tolerant data storage & processing in mobile cloud
Energy efficient fault-tolerant data storage & processing in mobile cloud
 
Tim scottkoenverheyenpresentation
Tim scottkoenverheyenpresentationTim scottkoenverheyenpresentation
Tim scottkoenverheyenpresentation
 
Benefits of cloud computing
Benefits of cloud computingBenefits of cloud computing
Benefits of cloud computing
 
Energy efficient fault-tolerant data storage and processing in mobile cloud
Energy efficient fault-tolerant data storage and processing in mobile cloudEnergy efficient fault-tolerant data storage and processing in mobile cloud
Energy efficient fault-tolerant data storage and processing in mobile cloud
 
Cloud Computing Introduction
Cloud Computing IntroductionCloud Computing Introduction
Cloud Computing Introduction
 
The potential of the cloud
The potential of the cloudThe potential of the cloud
The potential of the cloud
 
Adoptive Gateways for dIverse MuLtiple Environments
Adoptive Gateways for dIverse MuLtiple EnvironmentsAdoptive Gateways for dIverse MuLtiple Environments
Adoptive Gateways for dIverse MuLtiple Environments
 
How to Architect Smarter Systems for Healthcare
How to Architect Smarter Systems for HealthcareHow to Architect Smarter Systems for Healthcare
How to Architect Smarter Systems for Healthcare
 
SMART Seminar Series: "From cloud-sourced flood mapping to connected communit...
SMART Seminar Series: "From cloud-sourced flood mapping to connected communit...SMART Seminar Series: "From cloud-sourced flood mapping to connected communit...
SMART Seminar Series: "From cloud-sourced flood mapping to connected communit...
 
Data Science for Effective Network Operations
Data Science for Effective Network OperationsData Science for Effective Network Operations
Data Science for Effective Network Operations
 
Engineering and OW2 Big Data Initiative: an open approach to the data-driven ...
Engineering and OW2 Big Data Initiative: an open approach to the data-driven ...Engineering and OW2 Big Data Initiative: an open approach to the data-driven ...
Engineering and OW2 Big Data Initiative: an open approach to the data-driven ...
 
Cloud computing and managed services (Sumit Dutta, CSSWA)
Cloud computing and managed services (Sumit Dutta, CSSWA)Cloud computing and managed services (Sumit Dutta, CSSWA)
Cloud computing and managed services (Sumit Dutta, CSSWA)
 
Asset Intelligence
Asset IntelligenceAsset Intelligence
Asset Intelligence
 
Open Source at GLA - a road less travelled
Open Source at GLA - a road less travelledOpen Source at GLA - a road less travelled
Open Source at GLA - a road less travelled
 
2014.11 meetup presentation v1
2014.11 meetup presentation v12014.11 meetup presentation v1
2014.11 meetup presentation v1
 
NordForsk Open Access Reykjavik 14-15/8-2014:NeIC
NordForsk Open Access Reykjavik 14-15/8-2014:NeICNordForsk Open Access Reykjavik 14-15/8-2014:NeIC
NordForsk Open Access Reykjavik 14-15/8-2014:NeIC
 
Improving Innovation Through Open Data - Construction Excellence Annual Confe...
Improving Innovation Through Open Data - Construction Excellence Annual Confe...Improving Innovation Through Open Data - Construction Excellence Annual Confe...
Improving Innovation Through Open Data - Construction Excellence Annual Confe...
 

Viewers also liked

Infographic RBD Nordic-Baltic - 2016 Final
Infographic RBD Nordic-Baltic - 2016 FinalInfographic RBD Nordic-Baltic - 2016 Final
Infographic RBD Nordic-Baltic - 2016 Final
Yvette Entius
 
Presentation Kenzen Paleo Bar™ Slide Show 4-16-16
Presentation Kenzen Paleo Bar™ Slide Show 4-16-16Presentation Kenzen Paleo Bar™ Slide Show 4-16-16
Presentation Kenzen Paleo Bar™ Slide Show 4-16-16
Pamela Hoffner Schuler
 
Natives_guide_2017.compressed
Natives_guide_2017.compressedNatives_guide_2017.compressed
Natives_guide_2017.compressed
Stephan Morse
 
stroud-david-resume (1) (1) (1)
stroud-david-resume (1) (1) (1)stroud-david-resume (1) (1) (1)
stroud-david-resume (1) (1) (1)
David Stroud
 

Viewers also liked (14)

Infographic RBD Nordic-Baltic - 2016 Final
Infographic RBD Nordic-Baltic - 2016 FinalInfographic RBD Nordic-Baltic - 2016 Final
Infographic RBD Nordic-Baltic - 2016 Final
 
Presentation Kenzen Paleo Bar™ Slide Show 4-16-16
Presentation Kenzen Paleo Bar™ Slide Show 4-16-16Presentation Kenzen Paleo Bar™ Slide Show 4-16-16
Presentation Kenzen Paleo Bar™ Slide Show 4-16-16
 
Natives_guide_2017.compressed
Natives_guide_2017.compressedNatives_guide_2017.compressed
Natives_guide_2017.compressed
 
Bursting The Filter Bubble
Bursting The Filter BubbleBursting The Filter Bubble
Bursting The Filter Bubble
 
What are the Key Customer Experience Mistakes that Brands Make?
What are the Key Customer Experience Mistakes that Brands Make?What are the Key Customer Experience Mistakes that Brands Make?
What are the Key Customer Experience Mistakes that Brands Make?
 
MikeGTaylor
MikeGTaylorMikeGTaylor
MikeGTaylor
 
Paola medina
Paola medinaPaola medina
Paola medina
 
Fcb
FcbFcb
Fcb
 
stroud-david-resume (1) (1) (1)
stroud-david-resume (1) (1) (1)stroud-david-resume (1) (1) (1)
stroud-david-resume (1) (1) (1)
 
Λεωφορείο-Μέσο συγκοινωνίας
Λεωφορείο-Μέσο συγκοινωνίαςΛεωφορείο-Μέσο συγκοινωνίας
Λεωφορείο-Μέσο συγκοινωνίας
 
Bonitasoft BPMN Presentation
Bonitasoft BPMN PresentationBonitasoft BPMN Presentation
Bonitasoft BPMN Presentation
 
Informal email 3º
Informal email 3ºInformal email 3º
Informal email 3º
 
Presentation by Chris Uttley, Stroud RSuds Project Officer - Delivery of Natu...
Presentation by Chris Uttley, Stroud RSuds Project Officer - Delivery of Natu...Presentation by Chris Uttley, Stroud RSuds Project Officer - Delivery of Natu...
Presentation by Chris Uttley, Stroud RSuds Project Officer - Delivery of Natu...
 
Production schedule
Production scheduleProduction schedule
Production schedule
 

Similar to eChallenges_e2011_JS

Cloud Compliance Auditing - Closer 2011
Cloud Compliance Auditing - Closer 2011Cloud Compliance Auditing - Closer 2011
Cloud Compliance Auditing - Closer 2011
Jonathan Sinclair
 
Multi-faceted Classification of Big Data Use Cases and Proposed Architecture ...
Multi-faceted Classification of Big Data Use Cases and Proposed Architecture ...Multi-faceted Classification of Big Data Use Cases and Proposed Architecture ...
Multi-faceted Classification of Big Data Use Cases and Proposed Architecture ...
Geoffrey Fox
 
Paper Final Taube Bienert GridInterop 2012
Paper Final Taube Bienert GridInterop 2012Paper Final Taube Bienert GridInterop 2012
Paper Final Taube Bienert GridInterop 2012
Bert Taube
 
OCSL-Nabarro-LLP-Cast-Study-Web-
OCSL-Nabarro-LLP-Cast-Study-Web-OCSL-Nabarro-LLP-Cast-Study-Web-
OCSL-Nabarro-LLP-Cast-Study-Web-
Charlotte Sanders
 

Similar to eChallenges_e2011_JS (20)

Cloud Compliance Auditing - Closer 2011
Cloud Compliance Auditing - Closer 2011Cloud Compliance Auditing - Closer 2011
Cloud Compliance Auditing - Closer 2011
 
Cloud Computing and the Changing IT Model
Cloud Computing and the Changing IT ModelCloud Computing and the Changing IT Model
Cloud Computing and the Changing IT Model
 
Advancing Cloud Initiatives and Removing Barriers to Adoption
Advancing Cloud Initiatives and Removing Barriers to AdoptionAdvancing Cloud Initiatives and Removing Barriers to Adoption
Advancing Cloud Initiatives and Removing Barriers to Adoption
 
ADV Slides: The Evolution of the Data Platform and What It Means to Enterpris...
ADV Slides: The Evolution of the Data Platform and What It Means to Enterpris...ADV Slides: The Evolution of the Data Platform and What It Means to Enterpris...
ADV Slides: The Evolution of the Data Platform and What It Means to Enterpris...
 
Bridging the Last Mile: Getting Data to the People Who Need It
Bridging the Last Mile: Getting Data to the People Who Need ItBridging the Last Mile: Getting Data to the People Who Need It
Bridging the Last Mile: Getting Data to the People Who Need It
 
Scality medical imaging storage
Scality medical imaging storageScality medical imaging storage
Scality medical imaging storage
 
Multi-faceted Classification of Big Data Use Cases and Proposed Architecture ...
Multi-faceted Classification of Big Data Use Cases and Proposed Architecture ...Multi-faceted Classification of Big Data Use Cases and Proposed Architecture ...
Multi-faceted Classification of Big Data Use Cases and Proposed Architecture ...
 
A Logical Architecture is Always a Flexible Architecture (ASEAN)
A Logical Architecture is Always a Flexible Architecture (ASEAN)A Logical Architecture is Always a Flexible Architecture (ASEAN)
A Logical Architecture is Always a Flexible Architecture (ASEAN)
 
Big Data Fabric: A Necessity For Any Successful Big Data Initiative
Big Data Fabric: A Necessity For Any Successful Big Data InitiativeBig Data Fabric: A Necessity For Any Successful Big Data Initiative
Big Data Fabric: A Necessity For Any Successful Big Data Initiative
 
Cloud Presentation and OpenStack case studies -- Harvard University
Cloud Presentation and OpenStack case studies -- Harvard UniversityCloud Presentation and OpenStack case studies -- Harvard University
Cloud Presentation and OpenStack case studies -- Harvard University
 
A Survey on A Secure Anti-Collusion Data Sharing Scheme for Dynamic Groups in...
A Survey on A Secure Anti-Collusion Data Sharing Scheme for Dynamic Groups in...A Survey on A Secure Anti-Collusion Data Sharing Scheme for Dynamic Groups in...
A Survey on A Secure Anti-Collusion Data Sharing Scheme for Dynamic Groups in...
 
Paper Final Taube Bienert GridInterop 2012
Paper Final Taube Bienert GridInterop 2012Paper Final Taube Bienert GridInterop 2012
Paper Final Taube Bienert GridInterop 2012
 
Agile Big Data Analytics Development: An Architecture-Centric Approach
Agile Big Data Analytics Development: An Architecture-Centric ApproachAgile Big Data Analytics Development: An Architecture-Centric Approach
Agile Big Data Analytics Development: An Architecture-Centric Approach
 
Building a Logical Data Fabric using Data Virtualization (ASEAN)
Building a Logical Data Fabric using Data Virtualization (ASEAN)Building a Logical Data Fabric using Data Virtualization (ASEAN)
Building a Logical Data Fabric using Data Virtualization (ASEAN)
 
OCSL-Nabarro-LLP-Cast-Study-Web-
OCSL-Nabarro-LLP-Cast-Study-Web-OCSL-Nabarro-LLP-Cast-Study-Web-
OCSL-Nabarro-LLP-Cast-Study-Web-
 
Intel and Cloudera: Accelerating Enterprise Big Data Success
Intel and Cloudera: Accelerating Enterprise Big Data SuccessIntel and Cloudera: Accelerating Enterprise Big Data Success
Intel and Cloudera: Accelerating Enterprise Big Data Success
 
Internet of Things and Multi-model Data Infrastructure
Internet of Things and Multi-model Data InfrastructureInternet of Things and Multi-model Data Infrastructure
Internet of Things and Multi-model Data Infrastructure
 
Qubole on AWS - White paper
Qubole on AWS - White paper Qubole on AWS - White paper
Qubole on AWS - White paper
 
On the Application of AI for Failure Management: Problems, Solutions and Algo...
On the Application of AI for Failure Management: Problems, Solutions and Algo...On the Application of AI for Failure Management: Problems, Solutions and Algo...
On the Application of AI for Failure Management: Problems, Solutions and Algo...
 
Privacy preserving public auditing for secured cloud storage
Privacy preserving public auditing for secured cloud storagePrivacy preserving public auditing for secured cloud storage
Privacy preserving public auditing for secured cloud storage
 

eChallenges_e2011_JS

  • 1. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Auditing Issues for Cloud-based Business Services Jonathan Sinclair SAP Research Belfast UK
  • 2. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Agenda • Fundamentals of Cloud, Compliance and Auditing • Cloud Compliance Challenges • Use Case: Future Healthcare and CRM • Compliance Auditing • Conclusions
  • 3. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Fundamentals Compliance Compliance is defined as being in accordance with relevant governmental orindustrial laws, regulationsand standards through governance processes. Business Web A business model and technical framework that represents a marketplace allowing providers and consumers to negotiate the usage of products. Clouds are a large pool of easily usable and accessible virtualized resources that can be dynamically reconfigured to adjust to a variable load. Cloud Computing Auditing The process of collecting and evaluating evidence to determine whether a computer system (information system) safeguards assets, maintains data integrity, achieves organizational goals effectively and consumes resources efficiently.
  • 4. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Motivation, Problem Area “An undefined problem has an infinite number of solutions” Robert A. Humphrey Customer Data Legislation Government Auditor Compliance CheckCompliance Report Regulation Regulator creates creates Businesses have to comply with store and are responsible for use IT to improve operations IT Department have to comply with Governance Compliance Customer Data Legislation Government Auditor Compliance CheckCompliance Report Regulation Regulator creates creates Businesses have to comply with store and are responsible for use IT to improve operations IT Department have to comply with Governance Compliance
  • 5. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Research Objectives • The locality of data is of key importance to adhere to legislation – Cross-jurisdictional conflictions – Performance and Availability – Disaster Recovery and Backup • Multi-tenancy and data accessibility – Company Multi-tenancy – Systems Multi-tenancy • Data Retention – Retaining data in the Cloud – Retaining data from the Cloud “The greatest challenge to any thinker is stating the problem in a way that will allow a solution.” Bertrand Russell
  • 6. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research CloudCloud AuditorAuditor Research Approach, Methodology “Most human beings have an almost infinite capacity for taking things for granted” Aldous Huxley
  • 7. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Major Outcomes/Results “A complex system that works is invariably found to have evolved from a simple system that works” John Gaule
  • 8. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Conclusion and Outlook • Ensure the security of consumer’s data • Maintain compliance with data security / privacy laws • Assure that service providers, integrators or composers cannot • access data within a consumer’s service • transfer data from a consumer’s service “A conclusion is the place where you got tired of thinking” Harold Fricklestein
  • 9. Session 2b, 26th October 2011 eChallenges e-2011 Copyright 2011 SAP Research Thank You! Jonathan Sinclair Research Associate SAP Research Belfast SAP [UK] Ltd The Concourse, Queen‘s Road Queen‘s Island, Titanic Quarter Belfast BT3 9DT T +44 (0)28 9078 5749 E jonathan.sinclair@sap.com Blogger: cloudauditing.blogspot.com LinkedIn: jonathangsinclair Twitter: jonnygsinclair Slideshare: jonathansinclair86