cloud computing panel - nycla

23
© 2010 Raj Goel [email protected] | 917.685.7731 1 Brainlink International, Inc. IT Management & Solutions Chief Technology Officer Brainlink International, Inc. Head In The Clouds? Implications of Head In The Clouds? Implications of Cloud Computing Public Forum Cloud Computing Public Forum Raj Goel, CISSP Raj Goel, CISSP

Upload: rajjgoelny

Post on 05-Dec-2014

969 views

Category:

Documents


0 download

DESCRIPTION

The New York County Lawyers’ Association’s Cyberspace Law Committeepresents a Public ForumHead in the Clouds? Head in the Clouds?Implications of Cloud Computing Implications of Cloud ComputingCloud computing, an Internet-based development and use of computer technology typically involving the provision of dynamically scalable resources, is fast becoming a part of our daily lives. Whether one is checking webmail, backing up data online or collaborating on documents, it is hard to ...

TRANSCRIPT

Page 1: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 1

Brainlink International, Inc.IT Management & Solutions

Chief Technology OfficerBrainlink International, Inc.

Head In The Clouds? Implications of Cloud Computing Head In The Clouds? Implications of Cloud Computing Public ForumPublic Forum

Raj Goel, CISSPRaj Goel, CISSP

Page 2: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 2

Brainlink International, Inc.IT Management & Solutions

First Cloud Application?First Cloud Application?

Voicemail

- Similarities to clouds today

- What have we learned from the history of Voicemail that might apply to clouds?

Page 3: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 3

Brainlink International, Inc.IT Management & Solutions

The “Voicemail Cloud” Killer AppThe “Voicemail Cloud” Killer App

Where is your voicemail stored?

Do you know? Do you care?

Tired: Voicemail as attachment

Wired: Voicemail as trans*!@&#!cription

Page 4: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 4

Brainlink International, Inc.IT Management & Solutions

Are you Googling Your Privacy Away?Are you Googling Your Privacy Away?

http://www.brainlink.com/news/138/24/Is-Your-Company-Googling-its-Security-and-Privacy-Away-Raj-Goel-investigates.html

https://www.box.net/shared/9gl5t6pi5p

Page 5: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 5

Brainlink International, Inc.IT Management & Solutions

Pre-cursor to the Internet CloudPre-cursor to the Internet Cloud

GeoCities

- Similarities

- Lessons learned

Page 6: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 6

Brainlink International, Inc.IT Management & Solutions

Could DiddyCould Diddy

Google

- Google Search

- Gmail

Page 7: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 7

Brainlink International, Inc.IT Management & Solutions

Modern CloudsModern Clouds

Amazon AWS, StrataScale, IBM, etc.

Saas?

RackSpace?

Joe’s Cloud-in-a-can?

Page 8: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 8

Brainlink International, Inc.IT Management & Solutions

Business Continuity ChallengesBusiness Continuity ChallengesClouds have better uptime than internal

servers

But…

Where’s your backup when the cloud runs dry?

Page 9: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 9

Brainlink International, Inc.IT Management & Solutions

Facebook your country's security away...Facebook your country's security away...

Farce of the Facebook spy: MI6 chief faces probe after wife exposes their life on Net

“ MI6 faced calls for an inquiry last night after an extraordinary lapse of judgment led to the new head of MI6's personal detailsbeing plastered over Facebook.

Millions of people could have gained access to compromising photographs of Sir John Sawers and his family on the social networking website. ...“

http://www.dailymail.co.uk/news/article-1197757/New-MI6-chief-faces-probe-wife-exposes-life-Facebook.html

Page 10: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 10

Brainlink International, Inc.IT Management & Solutions

Business Continuity ChallengesBusiness Continuity ChallengesMost clouds are digital roach motels.

- Migrating data – somewhat easy

- Migrating applications or functionality?

Page 11: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 11

Brainlink International, Inc.IT Management & Solutions

Regulatory and Liability ChallengesRegulatory and Liability ChallengesUse Gmail/YahooMail/etc. for email

- HIPAA, PCI, Red Flag violations?

- How do you subpeona gmail?

- Perform eDiscovery?

Page 12: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 12

Brainlink International, Inc.IT Management & Solutions

Regulatory and Liability ChallengesRegulatory and Liability ChallengesUse MS HealthVault, GoogleHealth

- HIPAA violations?

- How do you correct errors?

- Same process as Credit Bureaus (TRW, Equifax, etc)

See the Google Health Presentation at http://www.brainlink.com/raj_speaks.html

Page 13: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 13

Brainlink International, Inc.IT Management & Solutions

Regulatory and Liability ChallengesRegulatory and Liability ChallengesWho is responsible for security of data?

Freezing data or apps in case of litigation hold?

Chain Of Custody?

Page 14: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 14

Brainlink International, Inc.IT Management & Solutions

Crystal BallCrystal BallClouds are here to stay

Will take years to define what it really means

New name for old game – managed hosting, outsourced IT, etc.

Law is 10 years behind the technology

Page 15: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 15

Brainlink International, Inc.IT Management & Solutions

Next StepsNext StepsDetermine where the cloud makes sense in your

business.

- Don’t throw corporate jewels in the cloud (yet)

- Don’t ignore clouds – they add competitive value

- Ensure IT, Compliance and Business Continuity/Disaster Recovery are on the same page

Page 16: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 16

Brainlink International, Inc.IT Management & Solutions

Raj Goel, CISSP, is an Oracle and Solaris expert and he has over 20 years of experience in software development, systems, networks, communications and security for the financial, banking, insurance, health care and pharmaceutical industries. Raj is a regular speaker on HIPAA, Sarbanes-Oxley,PCI-DSS Credit Card Security, Information Security and other technology and business issues, addressing diverse audiences including technologists, policy-makers, front-line workers and corporate executives.

A nationally known expert, Raj has appeared in over 20 magazine and newspaper articles worldwide, including Entrepreneur Magazine, Business2.0 and InformationWeek, and on television including CNNfn and Geraldo At Large.

Raj has been published in Informatiion Security Magazine and Commercial Property News.

[email protected] 917-685-7731

www.brainlink.comwww.linkedin.com/in/rajgoel

Page 17: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 17

Brainlink International, Inc.IT Management & Solutions

Audience QuestionsAudience QuestionsWhat is Google Scanning?

Can they scan what’s in my GoogleDocs?

(This is what I think the questioner said. Audio pickup was muffled)

Page 18: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 18

Brainlink International, Inc.IT Management & Solutions

Audience QuestionsAudience QuestionsI heard Google’s head of privacy say that they

can’t tell where the information is stored. They say they can’t delete information.

Why can’t they do that? I think that’s a lie.

(This is what I think the questioner said. Audio pickup was muffled)

Page 19: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 19

Brainlink International, Inc.IT Management & Solutions

Audience QuestionsAudience QuestionsI heard they [Google] don’t delete data is so they

can analyze the logs.

(This is what I think the questioner said. Audio pickup was muffled)

Page 20: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 20

Brainlink International, Inc.IT Management & Solutions

Panel DiscussionPanel DiscussionProblems with data leakage;

How data collectors are selling data and metadata to law enforcement.

Page 21: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 21

Brainlink International, Inc.IT Management & Solutions

Audience SuggestionAudience SuggestionYou can protect yourself by encrypting data.

Response:

How metadata analysis defeats privacy settings and encryption.

Page 22: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 22

Brainlink International, Inc.IT Management & Solutions

Audience QuestionsAudience QuestionsWhat are the risks in Multi-tenancy

environments?

e.g. Websites on a shared server,

virtual servers on a shared server,

Servers in a colocation facility

(This is what I think the questioner said. Audio pickup was muffled)

Page 23: Cloud Computing Panel - NYCLA

© 2010 Raj Goel [email protected] | 917.685.7731 23

Brainlink International, Inc.IT Management & Solutions

Raj Goel, CISSP, is an Oracle and Solaris expert and he has over 20 years of experience in software development, systems, networks, communications and security for the financial, banking, insurance, health care and pharmaceutical industries. Raj is a regular speaker on HIPAA, Sarbanes-Oxley,PCI-DSS Credit Card Security, Information Security and other technology and business issues, addressing diverse audiences including technologists, policy-makers, front-line workers and corporate executives.

A nationally known expert, Raj has appeared in over 20 magazine and newspaper articles worldwide, including Entrepreneur Magazine, Business2.0 and InformationWeek, and on television including CNNfn and Geraldo At Large.

Raj has been published in Informatiion Security Magazine and Commercial Property News.

[email protected] 917-685-7731

www.brainlink.comwww.linkedin.com/in/rajgoel