Preventing a Leaky Cloud?

Opinion
Dec 17, 20092 mins

New laws may mean keeping PII out of the cloud

The US House of Representatives recently passed the Data Accountability and Trust Act (DATA). DATA may become the first national breach disclosure law. For organizations that put personally identifiable information (PII) in the cloud, one law clarifies breach definition and disclosure requirements. Still, the goal is to prevent a breach in the first place—a very difficult if not impossible task leading many organizations to keep PII out of the cloud.

The challenge is, the cloud customer assumes full leak liability but has only partial control over data leak prevention (DLP). Ideally, cloud DLP includes a mix of controls from customer and CSP: Encryption, logging and analysis, identity management (AAA), file integrity monitoring, anti-X, patch management and, well, DLP technology. Unfortunately, CSPs don’t disclose their security control specifics; often pointing to a SAS-70 audit instead. Pointing is insufficient. A SAS-70 audit doesn’t define security controls; it defines an audit of the security controls (objectives and activities) and procedures an organization sets for itself. The good news is the audit report describes the CSP security controls and their testing and evaluation. Of course the CSP must be willing to share the report with non-customers; their only obligation is to share with customers.

The bottom line is without knowledge of CSP security controls the only choice is keep PII out of the cloud. Incidentally, this is the message from some CSPs, particularly when the PII involves credit card holder data or the data is Protected Health Information (PHI)—topics for later posts.