tgreene
Executive Editor

The legal implications of cloud security

Opinion
May 5, 20092 mins

* No easy answers to the legal implications of cloud security

The legal implications of cloud security are wide ranging and potentially daunting – and there are no easy answers.

For example, businesses that fall under Sarbanes-Oxley and use cloud services have to make sure their providers meet SOX regulations. Businesses can check out that their providers actually do meet the regulations and write it into contracts that they will meet them, but if they fail, the providers don’t answer to the regulators. The responsibility falls to the business that hired them.

This means that a business that has become responsible for data – such as personal credit card and Social Security numbers – retains responsibility for their confidentiality even if the numbers are relegated to a service provider’s cloud.

The situation can get even more complicated if there are regulations about where the data must be stored. A cloud provider could have its gear anywhere, and wherever that anywhere is, local laws will apply. This is relevant if data that must be kept confidential is stored in a country where the government has the legal right to examine whatever is on servers within its borders.

These are just a very few of the legal ramifications off cloud services. Some of these challenges may prove too complex to solve, so businesses may decide they have to use infrastructure under their own control to store data affected by these regulations. They will avoid putting this data in the cloud.

But cloud providers will eventually recognize this business that is being left on the table and make a play for it. Expect providers to develop cloud services specifically designed to meet specific regulations faced by businesses in various vertical markets such as healthcare and finance.