tgreene
Executive Editor

Classify data first

Opinion
May 11, 20092 mins

A big decision about cloud services is determining what not to commit to the cloud, so businesses should set about prioritizing their assets now.

The benefits of cloud computing – lower capital cost, greater flexibility of computing power, more efficient use of resources, etc. – are many and compelling. It seems likely that businesses will find at least some use for cloud services, but not without careful consideration especially from the security point of view.

It makes sense to decide at the outset that some corporate resources just won’t be fast-tracked into the cloud. Theoretically, cloud services can be made safe enough to handle any data. But the work it would take to assure that the most sensitive resources are safe clearly outweighs the value that would be derived by using cloud services.

The transition from a corporate-owned data center to a service-provider, cloud-based data center (or a hybrid corporate/public cloud) calls for classifying data as a first step. For some businesses, this will be a daunting task because it hasn’t been attempted before. Data was all stored in the data center with a monolithic security policy.

Sorting it out requires a business unit task force that knows the value of the data as intellectual property that needs to be protected. It needs an IT task force that knows the network requirements to meet whatever internal, governmental and industry security standards that apply. It also needs legal advice about what laws come into play regarding how and where data is stored. The goal of all groups is to divide data into classifications.

All these task forces then need to meet together to perform a risk analysis of each class of data, weighing the benefits of storing and using data in a particular environment vs. the threat of it being tampered with or lost.

This data analysis has benefits beyond making decisions about using cloud services. It can rationalize data use, data storage and data retention/destruction policies that should have been done but had gone ignored.