SlideShare a Scribd company logo
1 of 10
Download to read offline
Compliance policies and procedures followed in data centers
Along with the growth of information technology the amount of data accumulated is
also rapidly grown. The biggest threat that existing on these days is to make sure
these data are secure. In order to make sure the high availability of data without
cyber any attack or loosing chances it’s necessary to take necessary steps in every
possible ways.
Compliance typically involves adherence to standards set by government regulatory
agencies. There are a significant number of regulations in effect worldwide related to
protecting private and sensitive data. For many businesses, regulatory compliance is
a topic that simply cannot be ignored. Handling confidential customer data in all its
varied forms has become a routine, even essential, task in almost every industry, and
companies that ignore the legal obligations they have to keep that data secure do so
at significant peril. In 2018, for instance, the health insurance giant Anthem Inc.
was fined a record $16 million by the US government for failing to comply fully with
HIPAA standards in the wake of the data breach that occurred in December 2014-
January 2015.
Have you ever thought where does all these data are existing? Simply we may say on
internet or in any applications that you are using. Let’s take the example of
Facebook, we are all having a Facebook account and many things related to us is
available(photos, videos, personal information etc)on Facebook. You can see all
these data from anywhere in the part of world just with an internet connection.
There is a massive IT infrastructure is available in background to support your
activity. Where does these IT infrastructures existing? The answer is nothing but on
data centers. The biggest security threat that can affect your data is nothing but the
insecurities in a location where it resides. Now you can imaging the necessity of
complying with policies, procedures and standards in a data center.
For a data center, providing compliance assurances is a matter of transparency and
security. By providing infrastructure that meets compliance standards for data
security, a facility can help their customers to better mitigate business risks and
enhance reporting procedures. The best facilities build their infrastructure from the
ground up with compliance in mind rather than viewing it as a “bolt-on” service to be
incorporated after the fact. Some are focused on protection of specific industry
information, where others are more concerned with proper disclosure of data loss
incidents and general privacy attributes. Most of today’s standards and compliance
regulations are concerned largely with the protection of private data at rest, during
transactions, and while it traverses network connections.
The compliance rules and regulations within a data center environment can be based
on two things which are,
• Data related
• Non-Data related
What does it mean is Remember these two terms where we will segregate different
compliance standards based on this two types.
There are three things which are said to be the pillars of compliance and namely
• Codes & Regulations - These are usually enforced by national law and
compliance is mandatory.
• National/International standards – This is an agreed set of minimum
requirements, conformance with which ensures quality and operational
performance.
• Industry guidelines and best practices – Commonly published by
manufactures to describe installation procedures for equipment. Have also
been published to describe process in the absence of an appropriate standard.
Let’s have a deep look into each of these pillars.
Codes & Regulations
Codes and regulations are usually enforced by national law and compliance is
mandatory. We know that the laws has to be obeyed by every citizens without any
exceptions. Depending on the region where data centers resides there will be
regulations law by government entities which is mandatory to be followed. Laws are
usually created to protect,
• The safety and health of people
• The rights and freedoms of individuals
• National infrastructure
• National security
• Personal data
And many more things. Some of the codes and regulations within the data centre
you are governed by is as below,
If anybody would like to know more about above codes and standard, do let me
know and I can catchup more details for you.
National/International standards
What is a standard? A standard is a published document that contains a technical
specification or other precise criteria designed to be used consistently as a rule,
guideline or definition. In simple standards are designed for voluntary use and do not
impose any regulations. However, laws and regulations may refer to certain
standards and make compliance with them compulsory.
So in a data center we would have international standards, national standards and
regional standards. But as you know adoption of all standards is not compulsory
unless they are mandated in contract. Let me give you an example, when you are a
data center co-location provider and one of the health customer want to lease the
space. It is a standard that the data center should follow the Health Insurance
Portability and Accountability Act (HIPAA) when they want to lease the space for this
health related customer. As you can see this is just a standard and it’s not necessary
for data center to operate. They can still lease their co-location space to customers
of other industry without any issues. But following HIPPA standard will become part
of a regulation law when you want to host the data of this health industry based
customer.
Always remember that your regional and national standards are having higher
priority than international standards. Because the regional standards will be defined
by understanding local conditions whereas international standards are general.
Some of the major international initiatives for standardizations are ISO(International
organization for standardization), BSI(British standards), CENELEC (French: Comité
Européen de Normalisation Électrotechnique; English: European Committee for
Electrotechnical Standardization), ANSI(American National Standards Institute) and
TIA(Telecommunications Industries Association).Some of the data center specific
standardization by these bodies are as below,
• BS EN 50600 – Information Technology- Data center facilities and
infrastructure.
• BS EN 50173-5 - Information Technology-Generic cabling systems
• BSEN 50174-2 - Information Technology-cabling installation
• TIA 942- Telecommunications Infrastructure Standard for Data centers
• ISO/IEC 24764 – Information Technology-Generic cabling systems for data
centers.
• ANSI/BICSI 002 – Data center design and implementation best practices.
• ANSI/ASHRE standard 90.4-2016 standard for data centers.
Industry guidelines and best practices
There are many organizations that contribute to the data center industry through
the publication of industry best practices and codes of conduct. They do provide the
certifications also based on their criteria which is considered as a standard measures
to prove the operation, design and facilities capabilities.
Some of the bodies who provides the guidelines for data centers are as following,
- Uptime institute – Provides guidelines for improving the performance ,
efficiency and reliability through innovation, collaboration and independent
certification.
- European Commission – In 2007 EU has developed a code of conduct in
response to the increasing energy consumption in data centers and need to
reduce the related environmental, economic and energy supply security
impacts.
- US Department of energy – They have partnered with industry to create the
data center energy practitioner program. It is reinforced proven best practices
as well as introduce new tools and techniques in key areas such as IT
department, air management, cooling systems and electrical systems.
- The Green Grid – The green grid association is a non-profit, open industry
consortium of information and communications technology(ICT) industry end
users, policy makers, technology providers, facility architects and utility
companies that works to improve IT and data center resource efficiency
around the world.
- BREEAM – It’s an international scheme that provides independent third party
certification of the assessment for sustainability performance of individual
buildings, communities and infrastructure projects.
- U.S Green building council – They have developed the national certification
for leadership in energy and environmental design(LEED) to encourage the
construction of energy and resource efficient buildings that are healthy to live
in.
As a summary of this article we have discussed the necessity of compliance at data
centers and various ways that data is protected through data center facilities.
Have a comment or points to be reviewed? Knowledge is power let’s grow
together. Feel free to comment.
Compliance policies and procedures followed in data centers

More Related Content

What's hot

Logicalis Data Center Solutions
Logicalis Data Center SolutionsLogicalis Data Center Solutions
Logicalis Data Center SolutionsLogicalisUS
 
Data center architure ppts
Data center architure pptsData center architure ppts
Data center architure pptsRajuPrasad33
 
InfoRelay National Data Centers Overview
InfoRelay National Data Centers OverviewInfoRelay National Data Centers Overview
InfoRelay National Data Centers OverviewJonathan Maxim
 
Transceiver – How They Help Support Big Data in Data Centers?
 Transceiver – How They Help Support Big Data in Data Centers? Transceiver – How They Help Support Big Data in Data Centers?
Transceiver – How They Help Support Big Data in Data Centers?Fern Xu
 
Efficient multicast delivery for data redundancy minimization over wireless d...
Efficient multicast delivery for data redundancy minimization over wireless d...Efficient multicast delivery for data redundancy minimization over wireless d...
Efficient multicast delivery for data redundancy minimization over wireless d...redpel dot com
 
Do you know virtual data center
Do you know virtual data centerDo you know virtual data center
Do you know virtual data centerMonica Geller
 
Do Carrier Neutral Data Centers Really Reduce Costs? (SlideShare)
Do Carrier Neutral Data Centers Really Reduce Costs? (SlideShare)Do Carrier Neutral Data Centers Really Reduce Costs? (SlideShare)
Do Carrier Neutral Data Centers Really Reduce Costs? (SlideShare)SP Home Run Inc.
 
Improving Datacenter Performance through Capacity Planning – Netmagic
Improving Datacenter Performance through Capacity Planning – NetmagicImproving Datacenter Performance through Capacity Planning – Netmagic
Improving Datacenter Performance through Capacity Planning – NetmagicNetmagic Solutions Pvt. Ltd.
 
Data Centers: The Pillars of Digital Economy
Data Centers: The Pillars of Digital EconomyData Centers: The Pillars of Digital Economy
Data Centers: The Pillars of Digital EconomyHTS Hosting
 
How e fpga future proofs data centers
How e fpga future proofs data centersHow e fpga future proofs data centers
How e fpga future proofs data centersdonnabrown085
 
Data center virtualization
Data center virtualizationData center virtualization
Data center virtualizationmazin Salih
 
Traditioanal vs-cloud based Data Centers
Traditioanal vs-cloud based Data CentersTraditioanal vs-cloud based Data Centers
Traditioanal vs-cloud based Data CentersShreya Srivastava
 
Data centers
Data centersData centers
Data centerstejaswi25
 
KVH Data Center Solutions
KVH Data Center SolutionsKVH Data Center Solutions
KVH Data Center SolutionsKVH Co. Ltd.
 
Are New Orleans Data Centers Making Green Strategies a Priority? (SlideShare)
Are New Orleans Data Centers Making Green Strategies a Priority? (SlideShare)Are New Orleans Data Centers Making Green Strategies a Priority? (SlideShare)
Are New Orleans Data Centers Making Green Strategies a Priority? (SlideShare)SP Home Run Inc.
 
Changing Landscape of Data Centers
Changing Landscape of Data CentersChanging Landscape of Data Centers
Changing Landscape of Data CentersSuhas Kelkar
 

What's hot (20)

Data Center Automation - Cisco ASAP Data Center
Data Center Automation - Cisco ASAP Data CenterData Center Automation - Cisco ASAP Data Center
Data Center Automation - Cisco ASAP Data Center
 
Logicalis Data Center Solutions
Logicalis Data Center SolutionsLogicalis Data Center Solutions
Logicalis Data Center Solutions
 
Data center architure ppts
Data center architure pptsData center architure ppts
Data center architure ppts
 
InfoRelay National Data Centers Overview
InfoRelay National Data Centers OverviewInfoRelay National Data Centers Overview
InfoRelay National Data Centers Overview
 
Transceiver – How They Help Support Big Data in Data Centers?
 Transceiver – How They Help Support Big Data in Data Centers? Transceiver – How They Help Support Big Data in Data Centers?
Transceiver – How They Help Support Big Data in Data Centers?
 
Efficient multicast delivery for data redundancy minimization over wireless d...
Efficient multicast delivery for data redundancy minimization over wireless d...Efficient multicast delivery for data redundancy minimization over wireless d...
Efficient multicast delivery for data redundancy minimization over wireless d...
 
Do you know virtual data center
Do you know virtual data centerDo you know virtual data center
Do you know virtual data center
 
Cisco data center
Cisco data centerCisco data center
Cisco data center
 
Do Carrier Neutral Data Centers Really Reduce Costs? (SlideShare)
Do Carrier Neutral Data Centers Really Reduce Costs? (SlideShare)Do Carrier Neutral Data Centers Really Reduce Costs? (SlideShare)
Do Carrier Neutral Data Centers Really Reduce Costs? (SlideShare)
 
Power saving in data centers
Power saving in data centersPower saving in data centers
Power saving in data centers
 
Data centers
Data centersData centers
Data centers
 
Improving Datacenter Performance through Capacity Planning – Netmagic
Improving Datacenter Performance through Capacity Planning – NetmagicImproving Datacenter Performance through Capacity Planning – Netmagic
Improving Datacenter Performance through Capacity Planning – Netmagic
 
Data Centers: The Pillars of Digital Economy
Data Centers: The Pillars of Digital EconomyData Centers: The Pillars of Digital Economy
Data Centers: The Pillars of Digital Economy
 
How e fpga future proofs data centers
How e fpga future proofs data centersHow e fpga future proofs data centers
How e fpga future proofs data centers
 
Data center virtualization
Data center virtualizationData center virtualization
Data center virtualization
 
Traditioanal vs-cloud based Data Centers
Traditioanal vs-cloud based Data CentersTraditioanal vs-cloud based Data Centers
Traditioanal vs-cloud based Data Centers
 
Data centers
Data centersData centers
Data centers
 
KVH Data Center Solutions
KVH Data Center SolutionsKVH Data Center Solutions
KVH Data Center Solutions
 
Are New Orleans Data Centers Making Green Strategies a Priority? (SlideShare)
Are New Orleans Data Centers Making Green Strategies a Priority? (SlideShare)Are New Orleans Data Centers Making Green Strategies a Priority? (SlideShare)
Are New Orleans Data Centers Making Green Strategies a Priority? (SlideShare)
 
Changing Landscape of Data Centers
Changing Landscape of Data CentersChanging Landscape of Data Centers
Changing Landscape of Data Centers
 

Similar to Compliance policies and procedures followed in data centers

Institute for the entrepreneur v1r3
Institute for the entrepreneur v1r3Institute for the entrepreneur v1r3
Institute for the entrepreneur v1r3Dawn Simpson
 
Michael Josephs
Michael JosephsMichael Josephs
Michael JosephsdaveGBE
 
Complying with Cybersecurity Regulations for IBM i Servers and Data
Complying with Cybersecurity Regulations for IBM i Servers and DataComplying with Cybersecurity Regulations for IBM i Servers and Data
Complying with Cybersecurity Regulations for IBM i Servers and DataPrecisely
 
Automatski - The Internet of Things - Security Standards
Automatski - The Internet of Things - Security StandardsAutomatski - The Internet of Things - Security Standards
Automatski - The Internet of Things - Security Standardsautomatskicorporation
 
Cyber Critical Infrastructure Framework Panel
Cyber Critical Infrastructure Framework PanelCyber Critical Infrastructure Framework Panel
Cyber Critical Infrastructure Framework PanelPaul Di Gangi
 
Cybersecurity solution-guide
Cybersecurity solution-guideCybersecurity solution-guide
Cybersecurity solution-guideAdilsonSuende
 
Data Privacy and Security in UAE.pptx
Data Privacy and Security in UAE.pptxData Privacy and Security in UAE.pptx
Data Privacy and Security in UAE.pptxAdarsh748147
 
Data privacy and security in uae
Data privacy and security in uaeData privacy and security in uae
Data privacy and security in uaeRishalHalid1
 
An Overview of the Major Compliance Requirements
An Overview of the Major Compliance RequirementsAn Overview of the Major Compliance Requirements
An Overview of the Major Compliance RequirementsDoubleHorn
 
Overcome regulatory data retention challenges
Overcome regulatory data retention challengesOvercome regulatory data retention challenges
Overcome regulatory data retention challengesBryant Bell
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceObservePoint
 
A practical data privacy and security approach to ffiec, gdpr and ccpa
A practical data privacy and security approach to ffiec, gdpr and ccpaA practical data privacy and security approach to ffiec, gdpr and ccpa
A practical data privacy and security approach to ffiec, gdpr and ccpaUlf Mattsson
 
William A. Tanenbaum Association of Benefit Administrators April 2015
William A. Tanenbaum  Association of Benefit Administrators April 2015William A. Tanenbaum  Association of Benefit Administrators April 2015
William A. Tanenbaum Association of Benefit Administrators April 2015William Tanenbaum
 
Big data analytics for life insurers
Big data analytics for life insurersBig data analytics for life insurers
Big data analytics for life insurersdipak sahoo
 
Big_data_analytics_for_life_insurers_published
Big_data_analytics_for_life_insurers_publishedBig_data_analytics_for_life_insurers_published
Big_data_analytics_for_life_insurers_publishedShradha Verma
 
Facility Environmental Audit Guidelines
Facility Environmental Audit GuidelinesFacility Environmental Audit Guidelines
Facility Environmental Audit Guidelinesamburyj3c9
 

Similar to Compliance policies and procedures followed in data centers (20)

Institute for the entrepreneur v1r3
Institute for the entrepreneur v1r3Institute for the entrepreneur v1r3
Institute for the entrepreneur v1r3
 
Michael Josephs
Michael JosephsMichael Josephs
Michael Josephs
 
Is it time for an IT Assessment?
Is it time for an IT Assessment?Is it time for an IT Assessment?
Is it time for an IT Assessment?
 
Complying with Cybersecurity Regulations for IBM i Servers and Data
Complying with Cybersecurity Regulations for IBM i Servers and DataComplying with Cybersecurity Regulations for IBM i Servers and Data
Complying with Cybersecurity Regulations for IBM i Servers and Data
 
Code of practice_for_consumer_io_t_security_october_2018
Code of practice_for_consumer_io_t_security_october_2018Code of practice_for_consumer_io_t_security_october_2018
Code of practice_for_consumer_io_t_security_october_2018
 
Automatski - The Internet of Things - Security Standards
Automatski - The Internet of Things - Security StandardsAutomatski - The Internet of Things - Security Standards
Automatski - The Internet of Things - Security Standards
 
Cyber Critical Infrastructure Framework Panel
Cyber Critical Infrastructure Framework PanelCyber Critical Infrastructure Framework Panel
Cyber Critical Infrastructure Framework Panel
 
Cybersecurity solution-guide
Cybersecurity solution-guideCybersecurity solution-guide
Cybersecurity solution-guide
 
Data Privacy and Security in UAE.pptx
Data Privacy and Security in UAE.pptxData Privacy and Security in UAE.pptx
Data Privacy and Security in UAE.pptx
 
Data privacy and security in uae
Data privacy and security in uaeData privacy and security in uae
Data privacy and security in uae
 
An Overview of the Major Compliance Requirements
An Overview of the Major Compliance RequirementsAn Overview of the Major Compliance Requirements
An Overview of the Major Compliance Requirements
 
Overcome regulatory data retention challenges
Overcome regulatory data retention challengesOvercome regulatory data retention challenges
Overcome regulatory data retention challenges
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
 
A practical data privacy and security approach to ffiec, gdpr and ccpa
A practical data privacy and security approach to ffiec, gdpr and ccpaA practical data privacy and security approach to ffiec, gdpr and ccpa
A practical data privacy and security approach to ffiec, gdpr and ccpa
 
PACE-IT: Security Policies and Other Documents
PACE-IT: Security Policies and Other DocumentsPACE-IT: Security Policies and Other Documents
PACE-IT: Security Policies and Other Documents
 
William A. Tanenbaum Association of Benefit Administrators April 2015
William A. Tanenbaum  Association of Benefit Administrators April 2015William A. Tanenbaum  Association of Benefit Administrators April 2015
William A. Tanenbaum Association of Benefit Administrators April 2015
 
Big data analytics for life insurers
Big data analytics for life insurersBig data analytics for life insurers
Big data analytics for life insurers
 
Big_data_analytics_for_life_insurers_published
Big_data_analytics_for_life_insurers_publishedBig_data_analytics_for_life_insurers_published
Big_data_analytics_for_life_insurers_published
 
Facility Environmental Audit Guidelines
Facility Environmental Audit GuidelinesFacility Environmental Audit Guidelines
Facility Environmental Audit Guidelines
 
Ai in compliance
Ai in compliance Ai in compliance
Ai in compliance
 

More from Livin Jose

Data center cooling infrastructure slide
Data center cooling infrastructure slideData center cooling infrastructure slide
Data center cooling infrastructure slideLivin Jose
 
Data center power infrastructure
Data center power infrastructureData center power infrastructure
Data center power infrastructureLivin Jose
 
What are cloud service models
What are cloud service modelsWhat are cloud service models
What are cloud service modelsLivin Jose
 
What are the types of cloud computing
What are the types of cloud computingWhat are the types of cloud computing
What are the types of cloud computingLivin Jose
 
Data center power availability provisioning
Data center power availability provisioningData center power availability provisioning
Data center power availability provisioningLivin Jose
 
What are the risks that may affect the availability of a data center
What are the risks that may affect the availability of a data centerWhat are the risks that may affect the availability of a data center
What are the risks that may affect the availability of a data centerLivin Jose
 
What is data center availability modes slide
What is data center availability modes slideWhat is data center availability modes slide
What is data center availability modes slideLivin Jose
 
What is a data center
What is a data centerWhat is a data center
What is a data centerLivin Jose
 
What are the types of data centers
What are the types of data centersWhat are the types of data centers
What are the types of data centersLivin Jose
 

More from Livin Jose (9)

Data center cooling infrastructure slide
Data center cooling infrastructure slideData center cooling infrastructure slide
Data center cooling infrastructure slide
 
Data center power infrastructure
Data center power infrastructureData center power infrastructure
Data center power infrastructure
 
What are cloud service models
What are cloud service modelsWhat are cloud service models
What are cloud service models
 
What are the types of cloud computing
What are the types of cloud computingWhat are the types of cloud computing
What are the types of cloud computing
 
Data center power availability provisioning
Data center power availability provisioningData center power availability provisioning
Data center power availability provisioning
 
What are the risks that may affect the availability of a data center
What are the risks that may affect the availability of a data centerWhat are the risks that may affect the availability of a data center
What are the risks that may affect the availability of a data center
 
What is data center availability modes slide
What is data center availability modes slideWhat is data center availability modes slide
What is data center availability modes slide
 
What is a data center
What is a data centerWhat is a data center
What is a data center
 
What are the types of data centers
What are the types of data centersWhat are the types of data centers
What are the types of data centers
 

Recently uploaded

APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDGMarianaLemus7
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraDeakin University
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 

Recently uploaded (20)

APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDG
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning era
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 

Compliance policies and procedures followed in data centers

  • 1. Compliance policies and procedures followed in data centers Along with the growth of information technology the amount of data accumulated is also rapidly grown. The biggest threat that existing on these days is to make sure these data are secure. In order to make sure the high availability of data without cyber any attack or loosing chances it’s necessary to take necessary steps in every possible ways. Compliance typically involves adherence to standards set by government regulatory agencies. There are a significant number of regulations in effect worldwide related to protecting private and sensitive data. For many businesses, regulatory compliance is a topic that simply cannot be ignored. Handling confidential customer data in all its varied forms has become a routine, even essential, task in almost every industry, and companies that ignore the legal obligations they have to keep that data secure do so at significant peril. In 2018, for instance, the health insurance giant Anthem Inc. was fined a record $16 million by the US government for failing to comply fully with HIPAA standards in the wake of the data breach that occurred in December 2014- January 2015. Have you ever thought where does all these data are existing? Simply we may say on internet or in any applications that you are using. Let’s take the example of Facebook, we are all having a Facebook account and many things related to us is
  • 2. available(photos, videos, personal information etc)on Facebook. You can see all these data from anywhere in the part of world just with an internet connection. There is a massive IT infrastructure is available in background to support your activity. Where does these IT infrastructures existing? The answer is nothing but on data centers. The biggest security threat that can affect your data is nothing but the insecurities in a location where it resides. Now you can imaging the necessity of complying with policies, procedures and standards in a data center. For a data center, providing compliance assurances is a matter of transparency and security. By providing infrastructure that meets compliance standards for data security, a facility can help their customers to better mitigate business risks and enhance reporting procedures. The best facilities build their infrastructure from the ground up with compliance in mind rather than viewing it as a “bolt-on” service to be incorporated after the fact. Some are focused on protection of specific industry information, where others are more concerned with proper disclosure of data loss incidents and general privacy attributes. Most of today’s standards and compliance regulations are concerned largely with the protection of private data at rest, during transactions, and while it traverses network connections. The compliance rules and regulations within a data center environment can be based on two things which are, • Data related • Non-Data related What does it mean is Remember these two terms where we will segregate different compliance standards based on this two types. There are three things which are said to be the pillars of compliance and namely • Codes & Regulations - These are usually enforced by national law and compliance is mandatory.
  • 3. • National/International standards – This is an agreed set of minimum requirements, conformance with which ensures quality and operational performance. • Industry guidelines and best practices – Commonly published by manufactures to describe installation procedures for equipment. Have also been published to describe process in the absence of an appropriate standard. Let’s have a deep look into each of these pillars.
  • 4. Codes & Regulations Codes and regulations are usually enforced by national law and compliance is mandatory. We know that the laws has to be obeyed by every citizens without any exceptions. Depending on the region where data centers resides there will be regulations law by government entities which is mandatory to be followed. Laws are usually created to protect, • The safety and health of people • The rights and freedoms of individuals • National infrastructure • National security • Personal data And many more things. Some of the codes and regulations within the data centre you are governed by is as below, If anybody would like to know more about above codes and standard, do let me know and I can catchup more details for you.
  • 5. National/International standards What is a standard? A standard is a published document that contains a technical specification or other precise criteria designed to be used consistently as a rule, guideline or definition. In simple standards are designed for voluntary use and do not impose any regulations. However, laws and regulations may refer to certain standards and make compliance with them compulsory. So in a data center we would have international standards, national standards and regional standards. But as you know adoption of all standards is not compulsory unless they are mandated in contract. Let me give you an example, when you are a data center co-location provider and one of the health customer want to lease the space. It is a standard that the data center should follow the Health Insurance Portability and Accountability Act (HIPAA) when they want to lease the space for this health related customer. As you can see this is just a standard and it’s not necessary for data center to operate. They can still lease their co-location space to customers of other industry without any issues. But following HIPPA standard will become part of a regulation law when you want to host the data of this health industry based customer. Always remember that your regional and national standards are having higher priority than international standards. Because the regional standards will be defined by understanding local conditions whereas international standards are general. Some of the major international initiatives for standardizations are ISO(International organization for standardization), BSI(British standards), CENELEC (French: Comité Européen de Normalisation Électrotechnique; English: European Committee for Electrotechnical Standardization), ANSI(American National Standards Institute) and TIA(Telecommunications Industries Association).Some of the data center specific standardization by these bodies are as below, • BS EN 50600 – Information Technology- Data center facilities and infrastructure.
  • 6. • BS EN 50173-5 - Information Technology-Generic cabling systems • BSEN 50174-2 - Information Technology-cabling installation • TIA 942- Telecommunications Infrastructure Standard for Data centers • ISO/IEC 24764 – Information Technology-Generic cabling systems for data centers. • ANSI/BICSI 002 – Data center design and implementation best practices. • ANSI/ASHRE standard 90.4-2016 standard for data centers. Industry guidelines and best practices There are many organizations that contribute to the data center industry through the publication of industry best practices and codes of conduct. They do provide the certifications also based on their criteria which is considered as a standard measures to prove the operation, design and facilities capabilities.
  • 7. Some of the bodies who provides the guidelines for data centers are as following, - Uptime institute – Provides guidelines for improving the performance , efficiency and reliability through innovation, collaboration and independent certification. - European Commission – In 2007 EU has developed a code of conduct in response to the increasing energy consumption in data centers and need to reduce the related environmental, economic and energy supply security impacts. - US Department of energy – They have partnered with industry to create the data center energy practitioner program. It is reinforced proven best practices as well as introduce new tools and techniques in key areas such as IT department, air management, cooling systems and electrical systems. - The Green Grid – The green grid association is a non-profit, open industry consortium of information and communications technology(ICT) industry end users, policy makers, technology providers, facility architects and utility companies that works to improve IT and data center resource efficiency around the world.
  • 8. - BREEAM – It’s an international scheme that provides independent third party certification of the assessment for sustainability performance of individual buildings, communities and infrastructure projects. - U.S Green building council – They have developed the national certification for leadership in energy and environmental design(LEED) to encourage the construction of energy and resource efficient buildings that are healthy to live in. As a summary of this article we have discussed the necessity of compliance at data centers and various ways that data is protected through data center facilities.
  • 9. Have a comment or points to be reviewed? Knowledge is power let’s grow together. Feel free to comment.