SlideShare a Scribd company logo
HIPAA and PCI Compliance in the Cloud 8th International Cloud Expo June 8th, 2011
Agenda Introductions About CCS What is PCI What is HIPAA Why are PCI and HIPAA Important to cloud providers? Technology and Best Practices Other Compliance Key Questions for Providers Questions
Introductions Jeff Uphues Stacy Griggs VP of Sales & Marketing  Cbeyond Cloud Services Senior Director of Customer Experience Cbeyond Cloud Services
About Cbeyond Cloud Services 3000+ Cloud Customers 58,000 Total Customers $450M Publically Traded NASD:CBEY 11 Years Old Public Cloud + Managed Dedicated Servers  = Hybrid 2009 Microsoft Worldwide Hosting Partner of the Year 2010 Microsoft Hyper-V Cloud Provider of the Year Focus on SMB’s with complex technology needs
What is PCI Set of regulations that businesses must follow to accept credit cards – mandated by merchant processors. Applies to merchants that take payments on-line or in person. Non-compliance generally results in litigation, reputational damage and loss of ability to take credit cards. 2 Levels Audited by a QSA SAQ 4 Types of SAD A-D Basically 36 pages of detailed security information Topical for smaller merchants <1M annual transactions Must not store credit card data.
What is HIPAA Set of regulations enacted by congress for the secure handling of patient health information. Applies to medical offices, hospitals, research labs, pharmaceutical companies, drug stores and any other company that handles patient information. Civil and criminal penalties for non-compliance. Requires technical and physical safeguards to protect patient data. Documented policies and annual risk assessments About to become bigger with new proposed rule - would give people the right to get a report on who has electronically accessed their protected health information May 31, 2011 - http://www.hhs.gov/news/press/2011pres/05/20110531c.html
Why PCI and HIPAA are important for the cloud US Economy $14.7 T GDP in 2010 - Wikipedia Healthcare = 16% of GDP - Wikipedia Visa / Amex + MC = $410B in Q1/10 – NY Times May,2011 Annualized Credit Card Spending  = 11% of GDP Collectively > ¼ of the economy Both spending categories are growing at >2X the pace of the general economy. Rapidly moving to the cloud If you aren’t providing PCI and HIPAA compliant service you are leaving ¼ of the economy to your competitors.
Technology Requirements and Best Practices Security! Firewalls Application Isolation (one primary function /server) WAF Log Management IPS Physical Building controls and logs CCTV and history Process, Policy and Review HIPAA – Business Associate Agreement Path to compliance - PCI SAQ or SAQ + QSA AOC - ROC
Other - less common areas of compliance Federal Information Security Act (FISMA) – Federal Government and Vendors Sarbanes-Oxley (SOX) – Public companies and their vendors Information Technology Infrastructure Library (ITIL) – Companies with advanced IT process especially European International Organization for Standards (ISO 9001) – Worldwide European Safe Harbor – Data protection standards for EU countries
Key Questions for Cloud Providers Show me your SAS70 Type II (SSAE16) How will you design a complaint infrastructure? What is the client responsible for and what is the vendor responsible for? Show me your privacy policy What's your SLA? How do you maintain a secure environment?
Contact Information Jeff Uphues Jeff.uphues@cbeyond.net 678-516-4751 Stacy Griggs Stacy.griggs@cbeyond.net 502-213-7738
Cloud Expo   pci-hipaa deck 053111

More Related Content

What's hot

DWS16 - Connected things forum - David Vasquez, Verizon Enterprise Solutions
DWS16 - Connected things forum - David Vasquez, Verizon Enterprise SolutionsDWS16 - Connected things forum - David Vasquez, Verizon Enterprise Solutions
DWS16 - Connected things forum - David Vasquez, Verizon Enterprise Solutions
IDATE DigiWorld
 
Internet of Things (IotT) Legal Issues Privacy and Cybersecurity
Internet of Things (IotT) Legal Issues Privacy and Cybersecurity Internet of Things (IotT) Legal Issues Privacy and Cybersecurity
Internet of Things (IotT) Legal Issues Privacy and Cybersecurity
Darek Czuchaj
 
DWS16 - Connected things forum - Luc Julia, Samsung Electronics
DWS16 - Connected things forum - Luc Julia, Samsung ElectronicsDWS16 - Connected things forum - Luc Julia, Samsung Electronics
DWS16 - Connected things forum - Luc Julia, Samsung Electronics
IDATE DigiWorld
 
What will the financial advice process look like in 2025?
What will the financial advice process look like in 2025?What will the financial advice process look like in 2025?
What will the financial advice process look like in 2025?
IRESS
 
Trends in legal tech 2018
Trends in legal tech 2018Trends in legal tech 2018
Trends in legal tech 2018
Dan Storbaek
 
How AI, Automation, and RegTech are Impacting Compliance Careers
How AI, Automation, and RegTech are Impacting Compliance CareersHow AI, Automation, and RegTech are Impacting Compliance Careers
How AI, Automation, and RegTech are Impacting Compliance Careers
TransparINT, LLC
 
Brokers overview
Brokers overviewBrokers overview
Brokers overview
Khurram Malik
 
Market into context - Three pillars for building a Smart Data Ecosystem: Trus...
Market into context - Three pillars for building a Smart Data Ecosystem: Trus...Market into context - Three pillars for building a Smart Data Ecosystem: Trus...
Market into context - Three pillars for building a Smart Data Ecosystem: Trus...
Big Data Value Association
 
Blockchain: a major disruptor in 3 industries
Blockchain: a major disruptor in 3 industriesBlockchain: a major disruptor in 3 industries
Blockchain: a major disruptor in 3 industries
Wendy Leung
 
Australia's RegTech Opportunities (in a digital-first world)
Australia's RegTech Opportunities (in a digital-first world)Australia's RegTech Opportunities (in a digital-first world)
Australia's RegTech Opportunities (in a digital-first world)
Guido Governatori
 
Three pillars for building a Smart Data Ecosystem: Trust, Security and Privacy
Three pillars for building a Smart Data Ecosystem: Trust, Security and PrivacyThree pillars for building a Smart Data Ecosystem: Trust, Security and Privacy
Three pillars for building a Smart Data Ecosystem: Trust, Security and Privacy
Big Data Value Association
 
Internet of Things (IoT) Strategic Patent Development Best Practice
Internet of Things (IoT) Strategic Patent Development Best PracticeInternet of Things (IoT) Strategic Patent Development Best Practice
Internet of Things (IoT) Strategic Patent Development Best Practice
Alex G. Lee, Ph.D. Esq. CLP
 
Bhadale group of companies law-justice industry products catalogue
Bhadale group of companies law-justice industry products catalogueBhadale group of companies law-justice industry products catalogue
Bhadale group of companies law-justice industry products catalogue
Vijayananda Mohire
 
Connected Identity: Benefits, Risks & Challenges
Connected Identity: Benefits, Risks & ChallengesConnected Identity: Benefits, Risks & Challenges
Connected Identity: Benefits, Risks & Challenges
WSO2
 
Drones and logistics - What legal issues and how to handle them
Drones and logistics - What legal issues and how to handle themDrones and logistics - What legal issues and how to handle them
Drones and logistics - What legal issues and how to handle them
Giulio Coraggio
 
What changes with the EU Data Protection Regulation for Gambling Companies
What changes with the EU Data Protection Regulation for Gambling CompaniesWhat changes with the EU Data Protection Regulation for Gambling Companies
What changes with the EU Data Protection Regulation for Gambling Companies
Giulio Coraggio
 
Presentation: Impact of IoT in Enterprise Architecture
Presentation: Impact of IoT in Enterprise ArchitecturePresentation: Impact of IoT in Enterprise Architecture
Presentation: Impact of IoT in Enterprise Architecture
Francisco Maroto
 
APIdays Paris 2019 - How API Empower the Open Banking Strategy? Credit as a S...
APIdays Paris 2019 - How API Empower the Open Banking Strategy? Credit as a S...APIdays Paris 2019 - How API Empower the Open Banking Strategy? Credit as a S...
APIdays Paris 2019 - How API Empower the Open Banking Strategy? Credit as a S...
apidays
 
Internet of Things Investment Report - February 2017
Internet of Things Investment Report - February 2017Internet of Things Investment Report - February 2017
Internet of Things Investment Report - February 2017
Harbor Research
 
Ahead of the Curve: Digital Reinvention in Electronics with Intelligent IoT
Ahead of the Curve: Digital Reinvention in Electronics with Intelligent IoTAhead of the Curve: Digital Reinvention in Electronics with Intelligent IoT
Ahead of the Curve: Digital Reinvention in Electronics with Intelligent IoT
Christophe Begue
 

What's hot (20)

DWS16 - Connected things forum - David Vasquez, Verizon Enterprise Solutions
DWS16 - Connected things forum - David Vasquez, Verizon Enterprise SolutionsDWS16 - Connected things forum - David Vasquez, Verizon Enterprise Solutions
DWS16 - Connected things forum - David Vasquez, Verizon Enterprise Solutions
 
Internet of Things (IotT) Legal Issues Privacy and Cybersecurity
Internet of Things (IotT) Legal Issues Privacy and Cybersecurity Internet of Things (IotT) Legal Issues Privacy and Cybersecurity
Internet of Things (IotT) Legal Issues Privacy and Cybersecurity
 
DWS16 - Connected things forum - Luc Julia, Samsung Electronics
DWS16 - Connected things forum - Luc Julia, Samsung ElectronicsDWS16 - Connected things forum - Luc Julia, Samsung Electronics
DWS16 - Connected things forum - Luc Julia, Samsung Electronics
 
What will the financial advice process look like in 2025?
What will the financial advice process look like in 2025?What will the financial advice process look like in 2025?
What will the financial advice process look like in 2025?
 
Trends in legal tech 2018
Trends in legal tech 2018Trends in legal tech 2018
Trends in legal tech 2018
 
How AI, Automation, and RegTech are Impacting Compliance Careers
How AI, Automation, and RegTech are Impacting Compliance CareersHow AI, Automation, and RegTech are Impacting Compliance Careers
How AI, Automation, and RegTech are Impacting Compliance Careers
 
Brokers overview
Brokers overviewBrokers overview
Brokers overview
 
Market into context - Three pillars for building a Smart Data Ecosystem: Trus...
Market into context - Three pillars for building a Smart Data Ecosystem: Trus...Market into context - Three pillars for building a Smart Data Ecosystem: Trus...
Market into context - Three pillars for building a Smart Data Ecosystem: Trus...
 
Blockchain: a major disruptor in 3 industries
Blockchain: a major disruptor in 3 industriesBlockchain: a major disruptor in 3 industries
Blockchain: a major disruptor in 3 industries
 
Australia's RegTech Opportunities (in a digital-first world)
Australia's RegTech Opportunities (in a digital-first world)Australia's RegTech Opportunities (in a digital-first world)
Australia's RegTech Opportunities (in a digital-first world)
 
Three pillars for building a Smart Data Ecosystem: Trust, Security and Privacy
Three pillars for building a Smart Data Ecosystem: Trust, Security and PrivacyThree pillars for building a Smart Data Ecosystem: Trust, Security and Privacy
Three pillars for building a Smart Data Ecosystem: Trust, Security and Privacy
 
Internet of Things (IoT) Strategic Patent Development Best Practice
Internet of Things (IoT) Strategic Patent Development Best PracticeInternet of Things (IoT) Strategic Patent Development Best Practice
Internet of Things (IoT) Strategic Patent Development Best Practice
 
Bhadale group of companies law-justice industry products catalogue
Bhadale group of companies law-justice industry products catalogueBhadale group of companies law-justice industry products catalogue
Bhadale group of companies law-justice industry products catalogue
 
Connected Identity: Benefits, Risks & Challenges
Connected Identity: Benefits, Risks & ChallengesConnected Identity: Benefits, Risks & Challenges
Connected Identity: Benefits, Risks & Challenges
 
Drones and logistics - What legal issues and how to handle them
Drones and logistics - What legal issues and how to handle themDrones and logistics - What legal issues and how to handle them
Drones and logistics - What legal issues and how to handle them
 
What changes with the EU Data Protection Regulation for Gambling Companies
What changes with the EU Data Protection Regulation for Gambling CompaniesWhat changes with the EU Data Protection Regulation for Gambling Companies
What changes with the EU Data Protection Regulation for Gambling Companies
 
Presentation: Impact of IoT in Enterprise Architecture
Presentation: Impact of IoT in Enterprise ArchitecturePresentation: Impact of IoT in Enterprise Architecture
Presentation: Impact of IoT in Enterprise Architecture
 
APIdays Paris 2019 - How API Empower the Open Banking Strategy? Credit as a S...
APIdays Paris 2019 - How API Empower the Open Banking Strategy? Credit as a S...APIdays Paris 2019 - How API Empower the Open Banking Strategy? Credit as a S...
APIdays Paris 2019 - How API Empower the Open Banking Strategy? Credit as a S...
 
Internet of Things Investment Report - February 2017
Internet of Things Investment Report - February 2017Internet of Things Investment Report - February 2017
Internet of Things Investment Report - February 2017
 
Ahead of the Curve: Digital Reinvention in Electronics with Intelligent IoT
Ahead of the Curve: Digital Reinvention in Electronics with Intelligent IoTAhead of the Curve: Digital Reinvention in Electronics with Intelligent IoT
Ahead of the Curve: Digital Reinvention in Electronics with Intelligent IoT
 

Viewers also liked

Afcom air control solution presentation
Afcom air control solution presentation Afcom air control solution presentation
Afcom air control solution presentation
stacygriggs
 
Web 2.0 and pedagogy overview, Wesleyan 2006
Web 2.0 and pedagogy overview, Wesleyan 2006Web 2.0 and pedagogy overview, Wesleyan 2006
Web 2.0 and pedagogy overview, Wesleyan 2006
Bryan Alexander
 
Do you know about cat 8 cable
Do you know about cat 8 cableDo you know about cat 8 cable
Do you know about cat 8 cable
Angelina Li
 
Summary
SummarySummary
Summary
emahacct
 
What's Your LMSs Status? Online Learning Conference 2013 (#olc13) session 504v2
What's Your LMSs Status? Online Learning Conference 2013 (#olc13) session 504v2What's Your LMSs Status? Online Learning Conference 2013 (#olc13) session 504v2
What's Your LMSs Status? Online Learning Conference 2013 (#olc13) session 504v2
Brandon Williams
 
Saradr kumar resume
Saradr kumar resumeSaradr kumar resume
Saradr kumar resume
sardar solanki
 
Goldsmiths social media short course 7th - 8th November 2015
Goldsmiths social media short course 7th - 8th November 2015Goldsmiths social media short course 7th - 8th November 2015
Goldsmiths social media short course 7th - 8th November 2015
Adah Parris
 
Instalação e configuração do windows server 2012
Instalação e configuração do windows server 2012Instalação e configuração do windows server 2012
Instalação e configuração do windows server 2012
simoesflavio
 
RMA Essay
RMA EssayRMA Essay
RMA Essay
Sam Cooper
 
Nanotechnology by Ajay Bolloju
Nanotechnology by Ajay BollojuNanotechnology by Ajay Bolloju
Nanotechnology by Ajay Bolloju
Ajay Bolloju
 
Hanks joshua 4.4
Hanks joshua 4.4Hanks joshua 4.4
Hanks joshua 4.4
Joshua Hanks
 
Adult rhinosinusitis-defined 1997-otolaryngology---head-and-neck-surgery
Adult rhinosinusitis-defined 1997-otolaryngology---head-and-neck-surgeryAdult rhinosinusitis-defined 1997-otolaryngology---head-and-neck-surgery
Adult rhinosinusitis-defined 1997-otolaryngology---head-and-neck-surgery
Joel Mathew
 
Drug discovery process style 3 powerpoint presentation templates
Drug discovery process style 3 powerpoint presentation templatesDrug discovery process style 3 powerpoint presentation templates
Drug discovery process style 3 powerpoint presentation templates
SlideTeam.net
 
Web 2.0 intro
Web 2.0 introWeb 2.0 intro
Web 2.0 intro
Bryan Alexander
 
Commercial telematics global market outlook (2015-2022)
Commercial telematics   global market outlook (2015-2022)Commercial telematics   global market outlook (2015-2022)
Commercial telematics global market outlook (2015-2022)
Swaraj Nanda
 
BGP Security (Mum presentation 2016)
BGP Security (Mum presentation 2016) BGP Security (Mum presentation 2016)
BGP Security (Mum presentation 2016)
Rofiq Fauzi
 
Energy Industry Trends by Jonathan Tan, GZZ Cleantech Consulting
Energy Industry Trends  by Jonathan Tan, GZZ Cleantech ConsultingEnergy Industry Trends  by Jonathan Tan, GZZ Cleantech Consulting
Energy Industry Trends by Jonathan Tan, GZZ Cleantech Consulting
Jonathan L. Tan, M.B.A.
 
The Chemistry of Monoclonal Antibodies
The Chemistry of Monoclonal AntibodiesThe Chemistry of Monoclonal Antibodies
The Chemistry of Monoclonal Antibodies
Pharmaxo
 

Viewers also liked (18)

Afcom air control solution presentation
Afcom air control solution presentation Afcom air control solution presentation
Afcom air control solution presentation
 
Web 2.0 and pedagogy overview, Wesleyan 2006
Web 2.0 and pedagogy overview, Wesleyan 2006Web 2.0 and pedagogy overview, Wesleyan 2006
Web 2.0 and pedagogy overview, Wesleyan 2006
 
Do you know about cat 8 cable
Do you know about cat 8 cableDo you know about cat 8 cable
Do you know about cat 8 cable
 
Summary
SummarySummary
Summary
 
What's Your LMSs Status? Online Learning Conference 2013 (#olc13) session 504v2
What's Your LMSs Status? Online Learning Conference 2013 (#olc13) session 504v2What's Your LMSs Status? Online Learning Conference 2013 (#olc13) session 504v2
What's Your LMSs Status? Online Learning Conference 2013 (#olc13) session 504v2
 
Saradr kumar resume
Saradr kumar resumeSaradr kumar resume
Saradr kumar resume
 
Goldsmiths social media short course 7th - 8th November 2015
Goldsmiths social media short course 7th - 8th November 2015Goldsmiths social media short course 7th - 8th November 2015
Goldsmiths social media short course 7th - 8th November 2015
 
Instalação e configuração do windows server 2012
Instalação e configuração do windows server 2012Instalação e configuração do windows server 2012
Instalação e configuração do windows server 2012
 
RMA Essay
RMA EssayRMA Essay
RMA Essay
 
Nanotechnology by Ajay Bolloju
Nanotechnology by Ajay BollojuNanotechnology by Ajay Bolloju
Nanotechnology by Ajay Bolloju
 
Hanks joshua 4.4
Hanks joshua 4.4Hanks joshua 4.4
Hanks joshua 4.4
 
Adult rhinosinusitis-defined 1997-otolaryngology---head-and-neck-surgery
Adult rhinosinusitis-defined 1997-otolaryngology---head-and-neck-surgeryAdult rhinosinusitis-defined 1997-otolaryngology---head-and-neck-surgery
Adult rhinosinusitis-defined 1997-otolaryngology---head-and-neck-surgery
 
Drug discovery process style 3 powerpoint presentation templates
Drug discovery process style 3 powerpoint presentation templatesDrug discovery process style 3 powerpoint presentation templates
Drug discovery process style 3 powerpoint presentation templates
 
Web 2.0 intro
Web 2.0 introWeb 2.0 intro
Web 2.0 intro
 
Commercial telematics global market outlook (2015-2022)
Commercial telematics   global market outlook (2015-2022)Commercial telematics   global market outlook (2015-2022)
Commercial telematics global market outlook (2015-2022)
 
BGP Security (Mum presentation 2016)
BGP Security (Mum presentation 2016) BGP Security (Mum presentation 2016)
BGP Security (Mum presentation 2016)
 
Energy Industry Trends by Jonathan Tan, GZZ Cleantech Consulting
Energy Industry Trends  by Jonathan Tan, GZZ Cleantech ConsultingEnergy Industry Trends  by Jonathan Tan, GZZ Cleantech Consulting
Energy Industry Trends by Jonathan Tan, GZZ Cleantech Consulting
 
The Chemistry of Monoclonal Antibodies
The Chemistry of Monoclonal AntibodiesThe Chemistry of Monoclonal Antibodies
The Chemistry of Monoclonal Antibodies
 

Similar to Cloud Expo pci-hipaa deck 053111

Arrowinsight Quarterly: IT Trends
Arrowinsight Quarterly: IT TrendsArrowinsight Quarterly: IT Trends
Arrowinsight Quarterly: IT Trends
Eliot Arnold
 
NIIT and Denodo: Business Continuity Planning in the times of the Covid-19 Pa...
NIIT and Denodo: Business Continuity Planning in the times of the Covid-19 Pa...NIIT and Denodo: Business Continuity Planning in the times of the Covid-19 Pa...
NIIT and Denodo: Business Continuity Planning in the times of the Covid-19 Pa...
Denodo
 
apidays New York 2022 - Discussing the significance of API standardization, D...
apidays New York 2022 - Discussing the significance of API standardization, D...apidays New York 2022 - Discussing the significance of API standardization, D...
apidays New York 2022 - Discussing the significance of API standardization, D...
apidays
 
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDXapidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX
apidays
 
Evolving Technology Trends Is your bank ready for tomorrow?
Evolving Technology Trends Is your bank ready for tomorrow?Evolving Technology Trends Is your bank ready for tomorrow?
Evolving Technology Trends Is your bank ready for tomorrow?
aakash malhotra
 
Industry and Regulatory Insights Using Applied Science
Industry and Regulatory Insights Using Applied ScienceIndustry and Regulatory Insights Using Applied Science
Industry and Regulatory Insights Using Applied Science
Sven Von Dem Knesebeck
 
Reviving exports
Reviving exportsReviving exports
Reviving exports
MahmudulHasanNayeem
 
The programmable RegTech Eco System by Liv Apneseth Watson
The programmable RegTech Eco System by Liv Apneseth WatsonThe programmable RegTech Eco System by Liv Apneseth Watson
The programmable RegTech Eco System by Liv Apneseth Watson
Workiva
 
Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...
Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...
Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...
Burton Lee
 
Rebooting IT Infrastructure for the Digital Age
Rebooting IT Infrastructure for the Digital AgeRebooting IT Infrastructure for the Digital Age
Rebooting IT Infrastructure for the Digital Age
Capgemini
 
The Great Data Migration, Dealing With Cybersecurity and Privacy in Legacy Da...
The Great Data Migration, Dealing With Cybersecurity and Privacy in Legacy Da...The Great Data Migration, Dealing With Cybersecurity and Privacy in Legacy Da...
The Great Data Migration, Dealing With Cybersecurity and Privacy in Legacy Da...
Executive Leaders Network
 
LogSentinel Next-Gen SIEM
LogSentinel Next-Gen SIEMLogSentinel Next-Gen SIEM
LogSentinel Next-Gen SIEM
Denitsa Dimova
 
Goodenough 110424192114-phpapp02
Goodenough 110424192114-phpapp02Goodenough 110424192114-phpapp02
Goodenough 110424192114-phpapp02
Gerson Orlando Jr
 
ANZ SMS Synopsis
ANZ SMS SynopsisANZ SMS Synopsis
ANZ SMS Synopsis
patrikbzz
 
Solving Real Business Problems with Big Data: Measuring Customer Loyalty in t...
Solving Real Business Problems with Big Data: Measuring Customer Loyalty in t...Solving Real Business Problems with Big Data: Measuring Customer Loyalty in t...
Solving Real Business Problems with Big Data: Measuring Customer Loyalty in t...
Tanya Cashorali
 
delphix-ebook-using-data-effectively-compliance-banking-1
delphix-ebook-using-data-effectively-compliance-banking-1delphix-ebook-using-data-effectively-compliance-banking-1
delphix-ebook-using-data-effectively-compliance-banking-1
Jes Breslaw
 
Is ITIL relevant for the New Style of IT Tony Price SITS15 V1
Is ITIL relevant for the New Style of IT Tony Price SITS15 V1Is ITIL relevant for the New Style of IT Tony Price SITS15 V1
Is ITIL relevant for the New Style of IT Tony Price SITS15 V1
Tony Price
 
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc
 
5 Ways to Boost Regulatory Compliance
5 Ways to Boost Regulatory Compliance5 Ways to Boost Regulatory Compliance
5 Ways to Boost Regulatory Compliance
Flatirons Solutions®
 
Disruptive Technologies in Commodity Trading Markets
Disruptive Technologies in Commodity Trading MarketsDisruptive Technologies in Commodity Trading Markets
Disruptive Technologies in Commodity Trading Markets
CTRM Center
 

Similar to Cloud Expo pci-hipaa deck 053111 (20)

Arrowinsight Quarterly: IT Trends
Arrowinsight Quarterly: IT TrendsArrowinsight Quarterly: IT Trends
Arrowinsight Quarterly: IT Trends
 
NIIT and Denodo: Business Continuity Planning in the times of the Covid-19 Pa...
NIIT and Denodo: Business Continuity Planning in the times of the Covid-19 Pa...NIIT and Denodo: Business Continuity Planning in the times of the Covid-19 Pa...
NIIT and Denodo: Business Continuity Planning in the times of the Covid-19 Pa...
 
apidays New York 2022 - Discussing the significance of API standardization, D...
apidays New York 2022 - Discussing the significance of API standardization, D...apidays New York 2022 - Discussing the significance of API standardization, D...
apidays New York 2022 - Discussing the significance of API standardization, D...
 
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDXapidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX
 
Evolving Technology Trends Is your bank ready for tomorrow?
Evolving Technology Trends Is your bank ready for tomorrow?Evolving Technology Trends Is your bank ready for tomorrow?
Evolving Technology Trends Is your bank ready for tomorrow?
 
Industry and Regulatory Insights Using Applied Science
Industry and Regulatory Insights Using Applied ScienceIndustry and Regulatory Insights Using Applied Science
Industry and Regulatory Insights Using Applied Science
 
Reviving exports
Reviving exportsReviving exports
Reviving exports
 
The programmable RegTech Eco System by Liv Apneseth Watson
The programmable RegTech Eco System by Liv Apneseth WatsonThe programmable RegTech Eco System by Liv Apneseth Watson
The programmable RegTech Eco System by Liv Apneseth Watson
 
Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...
Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...
Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...
 
Rebooting IT Infrastructure for the Digital Age
Rebooting IT Infrastructure for the Digital AgeRebooting IT Infrastructure for the Digital Age
Rebooting IT Infrastructure for the Digital Age
 
The Great Data Migration, Dealing With Cybersecurity and Privacy in Legacy Da...
The Great Data Migration, Dealing With Cybersecurity and Privacy in Legacy Da...The Great Data Migration, Dealing With Cybersecurity and Privacy in Legacy Da...
The Great Data Migration, Dealing With Cybersecurity and Privacy in Legacy Da...
 
LogSentinel Next-Gen SIEM
LogSentinel Next-Gen SIEMLogSentinel Next-Gen SIEM
LogSentinel Next-Gen SIEM
 
Goodenough 110424192114-phpapp02
Goodenough 110424192114-phpapp02Goodenough 110424192114-phpapp02
Goodenough 110424192114-phpapp02
 
ANZ SMS Synopsis
ANZ SMS SynopsisANZ SMS Synopsis
ANZ SMS Synopsis
 
Solving Real Business Problems with Big Data: Measuring Customer Loyalty in t...
Solving Real Business Problems with Big Data: Measuring Customer Loyalty in t...Solving Real Business Problems with Big Data: Measuring Customer Loyalty in t...
Solving Real Business Problems with Big Data: Measuring Customer Loyalty in t...
 
delphix-ebook-using-data-effectively-compliance-banking-1
delphix-ebook-using-data-effectively-compliance-banking-1delphix-ebook-using-data-effectively-compliance-banking-1
delphix-ebook-using-data-effectively-compliance-banking-1
 
Is ITIL relevant for the New Style of IT Tony Price SITS15 V1
Is ITIL relevant for the New Style of IT Tony Price SITS15 V1Is ITIL relevant for the New Style of IT Tony Price SITS15 V1
Is ITIL relevant for the New Style of IT Tony Price SITS15 V1
 
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
 
5 Ways to Boost Regulatory Compliance
5 Ways to Boost Regulatory Compliance5 Ways to Boost Regulatory Compliance
5 Ways to Boost Regulatory Compliance
 
Disruptive Technologies in Commodity Trading Markets
Disruptive Technologies in Commodity Trading MarketsDisruptive Technologies in Commodity Trading Markets
Disruptive Technologies in Commodity Trading Markets
 

Cloud Expo pci-hipaa deck 053111

  • 1. HIPAA and PCI Compliance in the Cloud 8th International Cloud Expo June 8th, 2011
  • 2. Agenda Introductions About CCS What is PCI What is HIPAA Why are PCI and HIPAA Important to cloud providers? Technology and Best Practices Other Compliance Key Questions for Providers Questions
  • 3. Introductions Jeff Uphues Stacy Griggs VP of Sales & Marketing Cbeyond Cloud Services Senior Director of Customer Experience Cbeyond Cloud Services
  • 4. About Cbeyond Cloud Services 3000+ Cloud Customers 58,000 Total Customers $450M Publically Traded NASD:CBEY 11 Years Old Public Cloud + Managed Dedicated Servers = Hybrid 2009 Microsoft Worldwide Hosting Partner of the Year 2010 Microsoft Hyper-V Cloud Provider of the Year Focus on SMB’s with complex technology needs
  • 5. What is PCI Set of regulations that businesses must follow to accept credit cards – mandated by merchant processors. Applies to merchants that take payments on-line or in person. Non-compliance generally results in litigation, reputational damage and loss of ability to take credit cards. 2 Levels Audited by a QSA SAQ 4 Types of SAD A-D Basically 36 pages of detailed security information Topical for smaller merchants <1M annual transactions Must not store credit card data.
  • 6. What is HIPAA Set of regulations enacted by congress for the secure handling of patient health information. Applies to medical offices, hospitals, research labs, pharmaceutical companies, drug stores and any other company that handles patient information. Civil and criminal penalties for non-compliance. Requires technical and physical safeguards to protect patient data. Documented policies and annual risk assessments About to become bigger with new proposed rule - would give people the right to get a report on who has electronically accessed their protected health information May 31, 2011 - http://www.hhs.gov/news/press/2011pres/05/20110531c.html
  • 7. Why PCI and HIPAA are important for the cloud US Economy $14.7 T GDP in 2010 - Wikipedia Healthcare = 16% of GDP - Wikipedia Visa / Amex + MC = $410B in Q1/10 – NY Times May,2011 Annualized Credit Card Spending = 11% of GDP Collectively > ¼ of the economy Both spending categories are growing at >2X the pace of the general economy. Rapidly moving to the cloud If you aren’t providing PCI and HIPAA compliant service you are leaving ¼ of the economy to your competitors.
  • 8. Technology Requirements and Best Practices Security! Firewalls Application Isolation (one primary function /server) WAF Log Management IPS Physical Building controls and logs CCTV and history Process, Policy and Review HIPAA – Business Associate Agreement Path to compliance - PCI SAQ or SAQ + QSA AOC - ROC
  • 9. Other - less common areas of compliance Federal Information Security Act (FISMA) – Federal Government and Vendors Sarbanes-Oxley (SOX) – Public companies and their vendors Information Technology Infrastructure Library (ITIL) – Companies with advanced IT process especially European International Organization for Standards (ISO 9001) – Worldwide European Safe Harbor – Data protection standards for EU countries
  • 10. Key Questions for Cloud Providers Show me your SAS70 Type II (SSAE16) How will you design a complaint infrastructure? What is the client responsible for and what is the vendor responsible for? Show me your privacy policy What's your SLA? How do you maintain a secure environment?
  • 11. Contact Information Jeff Uphues Jeff.uphues@cbeyond.net 678-516-4751 Stacy Griggs Stacy.griggs@cbeyond.net 502-213-7738

Editor's Notes

  1. Jeff
  2. Jeff and STacy
  3. Jeff
  4. StacyQSA - Qualified System AuditorSAQ – Self Assessment QuestionnaireSAQ A, D most common for online merchants.Storage = QSA
  5. Jeff
  6. Stacy
  7. StacyWAF – Web Application FirewallIPS – Intrusion Protection System (or IDS)AOC – Attestation of ComplianceROC – Report on Compliance
  8. StacyOver 1M companies ISO certified but it uncommon for companies to expect this from their cloud vendor.
  9. I know the description had 5 questions, but we are giving you 20% more for free…SOC 1/2/3 Type 1 and 2Infrastructure - Public / Private, VPN Privacy policy should be in the contractSecure environment – IPS, VPN, Firewalls, VLAN’s, physical securityAWS / Azure Example on SLA
  10. Q&amp;A