2. Cloud Computing
•Emerging opportunity in IT- Service delivery
•Helps firms reduce costs
• Compelling Scale
Public • Cost reduction
• Costly
Private • Greater adoption
One has to be living under a rock to not have heard of Cloud Computing
3. Issues in Cloud Computing
•Control
Availability
Integrity
Confidentiality
•Visibility
Compliance
Governance
Risk Management
Lack of Visibility = Lack of Security
4. Cloud- Financial Services
•Need for Cost Reduction - Recession
Firms need to reduce costs to make
•Tremendous focus on Data Security
Tougher regulatory norms
Compliance- SOX, PCI etc
Anti-Money Laundering
Fraud Prevention
•Slowest adoption compared to other industries
A “not good” Data Security would have Financial and Reputational Loss
5. Fundamentally Difficult Issue
•Cloud is controlled by CSP (Cloud Service Provider) –External
Vendors
High Dependency on Financial Health of CSP
Site inspection and audit very difficult
Constant connectivity required
Loss of data due to improper back-up
High Difficulty in migrating to another CSP
•Access to Data is difficult given the network of databases
Especially for public clouds
CSP’s and Enterprises are still figuring out a way to solve the above
problems
6. Understanding the Issue
•High Vulnerability
Cost of Entry is Low
Little or no due- diligence
•CIO’s of Banks/ Insurance firms need to ask:
• Who can see my clients’ data?
• What regulatory and compliance audits has the firm completed?
• If the firm doesn’t keep data in its own systems, how can we ensure it is safe?
• What safeguards are in place to ensure data is never viewed by someone who
shouldn’t see it?
• If the system is compromised, what’s the emergency action plan, and how will that
be communicated to our clients?
Not Understanding the issue can have dire consequences