Cloud Computing Meets Washington: Lots of Data Security and Privacy Questions

There's a great deal of uncertainty how data security and privacy laws and regulations apply in a cloud computing environment. That's not good news for policymakers or users.

By Bernard Golden
Thu, March 26, 2009

CIO — Last week I was invited to participate in a cloud computing panel at the Newseum, located smack dab between the U.S. Capitol Building and the White House. The Washington D.C. event marked the release of a new report, Envisioning the Cloud: The Next Computing Paradigm. I appeared with the two report authors, Jeffrey Rayport and Andrew Heyward. Rayport is a former Harvard Business School Professor who currently chairs Marketspace LLC, which provides digital strategy consulting services and is part of the high-end strategy consulting firm, The Monitor Group. (Rayport also coined the term "viral marketing.") Heyward, the former head of CBS News, serves as a senior advisor to Marketspace. My role was to provide commentary on their presentation of the report's findings.

The overall findings of the report echo its title. The authors conclude that cloud computing offers immense potential and predict that it will shake up many established markets—technology (obviously), but also content.

Something the report highlights is a potential tension between government policy and market competition. Essentially, the authors identify a number of key areas in which the cloud is rapidly evolving or requires sustaining capability: Cybercrime enforcement, universal connectivity, privacy, interoperability, etc. They range them on a continuum between government responsibility and market appropriateness (i.e., that the area is one in which the market, rather than the government, is the best place for the issue to be worked out). The report is an excellent overview of the domain and well-worth reading. Its elegantly crafted prose also recommends it as a senior management briefing tool.

Something that fascinated me was the attitude and receptiveness of the audience. Attendees were a mix: White House, Congressional, and Agency technology policy folks; social media consultants, a few technology development types, and a goodly representation of media. One thing was clear: even if policy folks are not especially tech-savvy, they're all aware of the concept of cloud computing and recognize that it has real promise.

After presenting the slides, during which I made some observations about cloud issues and opportunities, the floor was opened for questions. I would say that half of the questions revolved around data security and privacy. Many in the audience were familiar with current government laws and regulations relating to these issues, but have not yet begun to consider how cloud computing will impact them (Heyward commented that today's laws are based on a mid-80s computing environment).

What many in the audience were not familiar with, however, is the pace of cloud adoption. I pointed out that these issues relating to data are not prospective, they're in the here-and-now. Most troubling for cloud users are two things:

There is a great deal of uncertainty in how the circa-80s laws and regulations apply in a cloud computing environment. Consequently, it is difficult for individual companies to determine exactly what their responsibilities are with respect to data being placed in cloud environments. This has the inevitable effect of restricting cloud adoption, as many companies will choose to take a wait-and-see attitude, preferring to avoid taking steps that they may later find out are inappropriate, or, worse, put them into non-compliance with penalty-laden laws and regulations.

Clarifying and making laws and regulations more appropriate for cloud computing environments is not something within the purview of individual companies. That is to say, these restrictions cannot be changed by any one organization. Most other aspects of cloud computing can be addressed by individual organizations and settled according to their own preferences. So, for example, on the question of whether cloud computing make financial sense, a company can look at its own applications and operations, assess the costs of migrating one or more applications to external cloud environments, and decide whether it makes sense—for them. Their decision can be entirely separate from other companies, which can make their own evaluations, based on their circumstances. But the legal strictures that define what data requirements obtain within cloud environments—those lie beyond the capacity of any individual actor to address.

For this reason, I suggested that, despite the obvious wisdom of government staying out of trying to define cloud winners, operating conditions (e.g., SLA requirements), etc., there is a real need for the government to get involved in cloud computing around the issues of data security and privacy. Only with cloud-appropriate laws and regulations that make clear what individual company's rights and responsibilities are, the adoption of cloud computing will be impaired. As I noted, this issue is especially relevant because cloud computing is being embraced very rapidly. I included a chart in a recent posting that showed cloud computing job postings as being nearly vertical, indicating enormous growth in implementation. I met with a venture capitalist yesterday and he echoed this, saying that all of their portfolio companies are leveraging Amazon EC2 to reduce capital expenditure in the startup phase. So this issue is a right-now one.

It's probably even more relevant given that the government itself is moving toward making data more accessible. The same day that the cloud computing event was held also featured an open government conference with participation from the new Federal CIO, Vivek Kundra. His mantra is making data more available to allow citizens more visibility into their public servants' activities. So the Federal government itself will be confronting these issues of data security and privacy in the coming months. You can read more about both the open government event as well as the cloud computing event here.

I predict that data privacy and security will prove to be the thorniest issue regarding cloud computing going forward and that the government will recognize that it needs to move quickly to clarify and support this technology trend.

This ESG Lab Review documents hands-on testing of Simpana 9 software from CommVault, specifically its "OnePass" data change gathering and retention mechanisms as well as its integration with HP X9000 (IBRIX) scale-out NAS.
In this paper, Forrester Consulting examines the total economic impact and potential return on investment (ROI) realized by three Enterprise organizations as they virtualized mission-critical Oracle databases on the VMware vSphere platform. The purpose of this study is to provide readers with a framework to evaluate the potential financial impact of VMware vSphere on their organizations.
Even though virtualization has brought positive change to enterprise IT over the last decade, some skepticism remains about how valuable virtualization can be in the way companies deliver and run business applications. Uncover the truth about how you can run your business critical applications with confi dence without sacrifi cing
availability or service quality-and at lower costs.
This IDG whitepaper highlights key findings based on the Quickpoll Survey conducted with more than 300 Enterprise and Commercial IT decision makers worldwide about the state of their virtualization of business critical applications. This paper answers such questions as: What drivers are pushing companies to extend virtualization beyond servers? and What value are they realizing? Central to the paper are key results that expose risks of the past (fears of limited ISV support, performance impact) no longer are a factor for companies moving to 80+% virtualized.
The Kelley School of Business at Indiana University deployed VMware Infrastructure which decreases costs, streamlines server deployment, and reduces energy consumption.
New study quantifies how VMware improved TCO and ROI for three companies' IT landscapes.
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Virtualizing business-critical applications is an essential step in your journey to the cloud. Microsoft SQL Server, Exchange and SharePoint, and Oracle applications, are often the backbone of business IT. The benefits of virtualizing these applications extend far beyond mere consolidation. Understanding how VMware improves quality of service and agility while reducing costs will help you make the case for taking virtualization to the next level in your company.
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere® 5, VMware is helping customers accelerate the deployment of business-critical applications, including Exchange, SQL, SAP and Oracle.
Want to say goodbye to missed SLAs? VMware can help you virtualize mission-critical applications such as Oracle, MS Exchange and SharePoint to achieve dramatic improvements in uptime, performance and responsiveness. In this webcast, we'll discuss the key benefits of virtualizing your agency's most critical applications and Oracle databases as a necessary first step in fulfilling OMB's mandate to move IT services to the cloud. With VMware, you'll be on the way to quick, effective and full compliance.
Federal IT managers are on the forefront of realizing the benefits that a secure, easy-to-manage virtual desktop environment can provide. The key is how to deliver the end-user experience that is comparable to a physical desktop. This webcast will show how the recently released VMware View 5 environment is being used to deploy virtual desktops to provide mission-critical solutions around Disaster Recover/COOP, telework and secure mobile applications to federal organizations. View this webcast and learn how new features and benefits of the VMware View 5 environment meet the needs of Federal customers
This video webcast is designed to help those with little to no virtualization experience understand why virtualization and VMware are so important to driving down both capital and operational costs. The session will start with the introduction of the key concepts and technologies of virtualization, introduce the vSphere Hypervisor, and build up to an overview of VMware vSphere® 5, the world's most robust and complete virtualization platform. This session will also discuss new solutions such as the vSphere Storage Appliance and VMware GO that are making it easier than ever before to get started with virtualization.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Sponsored Links
Resource Center