Cloud Computing –  Benefits and Risks President, ISACA China Hong Kong Michael Yung
Evolution – Mainframe Computer Page  
Evolution – Mini Computer, PCs and Internet Page  
Evolution - Cloud Computing Page  
Next 25 Minutes Page     Pain Points Benefits Risks
Infrastructure Cost and Service Delivery  Page     Pain Points
Pain Points Page     Keep It Running vs. Implement New Things
Pain Points Page     We Are Too Slow
Pain Points Page     Right Sizing
Pain Points Page  
Cloud Computing Page     Benefits
Cloud Computing Market Page     Estimation by IBM, 2009 84% Saving on H/W, labour,  power
IT and Business Benefits Page     Highly abstracted H/W, S/W resources for pooling Near instant scalability, provisioning ‘ Service On demand’ A ‘Pay as you go’ billing system  1 2 3 4
Business Benefits Page     We are finally in sync with business
Cloud Computing Page     What Are  the Risks ?
Applicability for Cloud Computing Page     Source: Federal Reserve System, USA System Type Scalability Availability Security Cloud Type Information site Medium Medium Low Public /Hybrid External Collaboration  Medium Medium Medium Public /Hybrid Public research / survey Low Medium Medium Public /Hybrid Internal R&D Low Low Medium Public /Hybrid Disaster Recovery Medium Medium Medium Public /Hybrid Application Test and QA Low Medium Medium Private Application Development Low Medium Medium Private Production Applications High High Medium No Mission Critical Applications High High High No
Risks and Security Concerns Page     Vendor Lock In Poor SLA 3 rd  Party access to Data Poor DR Plan Few tools, procedures or standard formats available for data and service portability Service level affects confidentiality and availability The needs to protect the intellectual property, trade secrets; and complied to regulations and laws in different geographical regions Business continuity and disaster recovery plans must be well documented and tested Service and contractual risks
Risks and Security Concerns Page     Integration / Bandwidth Encryption and Key Mgnt Testing and Monitoring Resource Allocation How to integrate the in-house systems to the Cloud ? High speed bandwidth ready ?  Speedy encryption / decryption;  Key management Provider may not allow you to do thorough PEN test, audit; Are there good monitoring tools available ? Overbooking, underbooking;  Handling of DOS attack; Payment cap Technology risks
Cloud Computing Page     Addressing the Risks
Addressing the Risks Page     Service Level Agreement to address Handling, usage, storage, availability of data Business continuity and disaster recovery objectives Right to audit Reassess your IT Governance framework Meeting performance objectives Technology provisioning is aligned to business Risks are managed Inventory of Information Assets Classified, labeled
Assurance Considerations Page     Must demonstrate existence of effective and robust security controls Must prove that privacy controls are in place and able to prevent, detect and react to breaches Independent assurance from third-party audits and service auditor reports Ensure the compliance of various countries' laws, but at the same time able to access your own data when needed Transparency Certification Privacy Compliance
Take Away Messages Page     Many benefits - reduce costs, greater agility Need to assess business impact and risks Address the risk with legal, security and assurance professionals
Resources Page  
Questions ? Page     www.isaca.org www.isaca.org.hk [email_address] [email_address]
End of Presentation Page  

Cloud Computing - Benefits and Risks

  • 1.
    Cloud Computing – Benefits and Risks President, ISACA China Hong Kong Michael Yung
  • 2.
    Evolution – MainframeComputer Page 
  • 3.
    Evolution – MiniComputer, PCs and Internet Page 
  • 4.
    Evolution - CloudComputing Page 
  • 5.
    Next 25 MinutesPage  Pain Points Benefits Risks
  • 6.
    Infrastructure Cost andService Delivery Page  Pain Points
  • 7.
    Pain Points Page  Keep It Running vs. Implement New Things
  • 8.
    Pain Points Page  We Are Too Slow
  • 9.
    Pain Points Page  Right Sizing
  • 10.
  • 11.
    Cloud Computing Page  Benefits
  • 12.
    Cloud Computing MarketPage  Estimation by IBM, 2009 84% Saving on H/W, labour, power
  • 13.
    IT and BusinessBenefits Page  Highly abstracted H/W, S/W resources for pooling Near instant scalability, provisioning ‘ Service On demand’ A ‘Pay as you go’ billing system 1 2 3 4
  • 14.
    Business Benefits Page  We are finally in sync with business
  • 15.
    Cloud Computing Page  What Are the Risks ?
  • 16.
    Applicability for CloudComputing Page  Source: Federal Reserve System, USA System Type Scalability Availability Security Cloud Type Information site Medium Medium Low Public /Hybrid External Collaboration Medium Medium Medium Public /Hybrid Public research / survey Low Medium Medium Public /Hybrid Internal R&D Low Low Medium Public /Hybrid Disaster Recovery Medium Medium Medium Public /Hybrid Application Test and QA Low Medium Medium Private Application Development Low Medium Medium Private Production Applications High High Medium No Mission Critical Applications High High High No
  • 17.
    Risks and SecurityConcerns Page  Vendor Lock In Poor SLA 3 rd Party access to Data Poor DR Plan Few tools, procedures or standard formats available for data and service portability Service level affects confidentiality and availability The needs to protect the intellectual property, trade secrets; and complied to regulations and laws in different geographical regions Business continuity and disaster recovery plans must be well documented and tested Service and contractual risks
  • 18.
    Risks and SecurityConcerns Page  Integration / Bandwidth Encryption and Key Mgnt Testing and Monitoring Resource Allocation How to integrate the in-house systems to the Cloud ? High speed bandwidth ready ? Speedy encryption / decryption; Key management Provider may not allow you to do thorough PEN test, audit; Are there good monitoring tools available ? Overbooking, underbooking; Handling of DOS attack; Payment cap Technology risks
  • 19.
    Cloud Computing Page  Addressing the Risks
  • 20.
    Addressing the RisksPage  Service Level Agreement to address Handling, usage, storage, availability of data Business continuity and disaster recovery objectives Right to audit Reassess your IT Governance framework Meeting performance objectives Technology provisioning is aligned to business Risks are managed Inventory of Information Assets Classified, labeled
  • 21.
    Assurance Considerations Page  Must demonstrate existence of effective and robust security controls Must prove that privacy controls are in place and able to prevent, detect and react to breaches Independent assurance from third-party audits and service auditor reports Ensure the compliance of various countries' laws, but at the same time able to access your own data when needed Transparency Certification Privacy Compliance
  • 22.
    Take Away MessagesPage  Many benefits - reduce costs, greater agility Need to assess business impact and risks Address the risk with legal, security and assurance professionals
  • 23.
  • 24.
    Questions ? Page  www.isaca.org www.isaca.org.hk [email_address] [email_address]
  • 25.

Editor's Notes

  • #13 Hong Kong GDP is around 200 billion USD. In one case study moving from traditional data center to cloud infrastructure ( from US$3.9 million to US$0.6 million ).