MODULE 2
Privacy: Responsibilities of privacy, Data life cycle ,Privacy risk management ,Legal and
Regulatory Implications of data security and [Link] and Compliance: Billing and cost
management,CSP life cycle, Governance, Risk, and Compliance (GRC), Common Industry/Regulatory
Requirements
Privacy
Privacy refers to the right of individuals or organizations to control access to their personal information, keeping
it confidential and protected from unauthorized use or disclosure.
Personal Identifiable Information (PII)PII refers to information that can be used to identify an individual.
Protecting PII is crucial to maintaining individual privacy and preventing identity theft, financial loss, or
reputational damage.
Who is Responsible for protecting PRIVACY
1. Individuals: Protect personal data by being cautious online, using strong passwords, and monitoring
accounts.
2. Organizations: Implement robust data protection policies, train employees, and ensure compliance
with regulations.
3. Cloud Service Providers (CSPs): Provide secure infrastructure, encrypt data, and data protection
regulations.
Responsibilities:
Organizations:
1. Data Protection Policies: Implement and enforce data protection policies.
2. Data Security Measures: Implement robust security measures to protect data.
3. Compliance: Ensure compliance with relevant regulations and laws.
4. Employee Training: Educate employees on data protection best practices.
Cloud Service Providers (CSPs):
1. Infrastructure Security: Ensure the security and integrity of their infrastructure.
2. Data Storage: Provide secure data storage and management.
3. Compliance: Comply with relevant regulations and industry standards.
4. Transparency: Provide transparency into their security practices.
Individuals:
1. Data Awareness: Understand how their data is being used and shared.
2. Password Management: Use strong, unique passwords and enable multi-factor authentication.
3. Data Sharing: Be cautious when sharing personal data online.
4. Monitoring: Monitor their accounts and report suspicious activity.
Shared Responsibilities:
1. Collaboration: Organizations, CSPs, and individuals must collaborate to protect privacy.
2. Communication: Clear communication about data practices and security measures.
3. Accountability: Hold each other accountable for protecting privacy.
Best Practices:
1. Implement robust security measures: Use encryption, firewalls, and access controls.
2. Conduct regular audits: Regularly audit systems and data for vulnerabilities.
3. Provide transparency: Be transparent about data practices and security measures.
4. Educate users: Educate users about data protection best practices.
Data Life Cycle
The components within each of these phases are:
Generation of the information
Generation, Ownership, and Governance
The data life cycle refers to the stages that data goes through from its creation to its eventual disposal.
Components:
1. Data Generation:
- Definition: Data generation refers to the process of creating or collecting data.
- Examples:
- Sensors collecting temperature data.
- Users filling out online forms.
- IoT devices generating data.
2. Data Ownership:
- Definition: Data ownership refers to the rights and responsibilities associated with data.
- Examples:
- Organizations owning customer data.
- Individuals owning their personal data.
- Governments owning public data.
3. Data Governance:
- Definition: Data governance refers to the policies, procedures, and controls that manage data throughout its
life cycle.
- Examples:
- Data protection policies.
- Data access controls.
- Data quality management.
Use
Internal vs. External Data and Third-Party Appropriateness and Discovery
The data life cycle involves managing data throughout its various stages, including creation, storage,
processing, and disposal. Two critical aspects of data management are:
1. Internal vs. External Data: Determining whether data is generated and stored within an organization
(internal) or obtained from outside sources (external).
2. Third-Party Appropriateness and Discovery: Ensuring that third-party vendors or partners handle data
responsibly and securely.
[Link]:
- Definition: Ensuring that third-party vendors or partners handle data responsibly and securely.
- Examples:
- Cloud storage providers.
- Data analytics vendors.
- Marketing agencies.
4. Discovery:
- Definition: Identifying and assessing the risks associated with sharing data with third-party vendors or
partners.
- Examples:
- Conducting risk assessments.
- Reviewing third-party security policies.
- Establishing data protection agreements.
Transformation
Derivation, Aggregation, and Integrity
Data transformation is a critical stage in the data life cycle that involves converting data from one format to
another, aggregating data from multiple sources, and ensuring data integrity.
Derivation:
- Definition: Data derivation involves creating new data from existing data through calculations,
transformations, or aggregations.
- Examples:
- Calculating customer lifetime value.
- Deriving average order value.
- Creating data summaries.
Aggregation:
- Definition: Data aggregation involves combining data from multiple sources into a single, unified view.
- Examples:
- Aggregating sales data from multiple regions.
- Combining customer data from multiple systems.
- Creating data warehouses.
Integrity:
- Definition: Data integrity refers to the accuracy, completeness, and consistency of data.
- Examples:
- Validating data against business rules.
- Checking for data inconsistencies.
- Ensuring data accuracy.
Storage
Access Control, Structured vs. Unstructured Data, Integrity, Availability, Confidentiality, and Encryption
Overview:
Data storage is a critical component of the data life cycle that involves storing and managing data in a secure
and efficient manner.
Access Control:
- Definition: Access control refers to the mechanisms and policies that regulate who can access data and what
actions they can perform.
- Examples:
- Role-based access control (RBAC).
- Attribute-based access control (ABAC).
- Mandatory access control (MAC).
Structured vs. Unstructured Data:
- Structured Data: Organized and formatted data that can be easily searched, such as databases.
- Unstructured Data: Unorganized and unformatted data, such as text documents, images, and videos.
Data Integrity:
- Definition: Data integrity refers to the accuracy, completeness, and consistency of data.
- Examples:
- Data validation.
- Data normalization.
- Data cleansing.
Data Availability:
- Definition: Data availability refers to the ability to access data when needed.
- Examples:
- Data backup and recovery.
- Redundancy and replication.
- Disaster recovery planning.
Data Confidentiality:
- Definition: Data confidentiality refers to protecting sensitive data from unauthorized access.
- Examples:
- Encryption.
- Access controls.
- Data masking.
Encryption:
- Definition: Encryption is the process of converting plaintext data into unreadable ciphertext to protect it from
unauthorized access.
- Examples:
- Symmetric encryption (e.g., AES).
- Asymmetric encryption (e.g., RSA).
- Hashing (e.g., SHA-256)
Archival
Legal, Compliance, and Operational Considerations
Overview:
Data archiving is the process of storing data for long-term preservation and potential future use.
Legal Considerations:
1. Regulatory Compliance: Ensure compliance with laws and regulations regarding data retention and
archiving.
2. Litigation Holds: Preserve data relevant to ongoing or anticipated litigation.
3. Data Protection: Ensure archived data is protected from unauthorized access.
Compliance Considerations:
1. Data Retention Policies: Establish policies for data retention and archiving.
2. Audit Trails: Maintain audit trails to track data access and modifications.
3. Compliance with Industry Standards: Ensure compliance with industry standards, such as HIPAA or GDPR.
Operational Considerations:
1. Data Storage: Ensure secure and reliable storage of archived data.
2. Data Management: Develop processes for managing archived data.
3. Data Retrieval: Ensure efficient retrieval of archived data.
Media Concerns:
1. Data Degradation: Ensure that archived data is not degraded over time.
2. Media Obsolescence: Ensure that archived data is not stored on obsolete media.
3. Data Migration: Migrate archived data to new storage media as needed.
Destruction
Secure and Complete
Overview:
Data destruction is the process of securely and permanently eliminating data that is no longer needed or is
deemed unnecessary.
Importance of Secure Data Destruction:
1. Protects Sensitive Information: Prevents unauthorized access to sensitive data.
2. Compliance: Ensures compliance with data protection regulations and laws.
3. Reduces Risk: Reduces the risk of data breaches and identity theft.
Methods of Data Destruction:
1. Physical Destruction: Physically destroying storage media, such as shredding or crushing hard drives.
2. Data Wiping: Using software to overwrite data multiple times, making it unrecoverable.
3. Degaussing: Demagnetizing magnetic storage media, such as tapes or hard drives.
Privacy Risk Management
Changes to Privacy Risk Management and Compliance in Cloud Computing
Cloud computing introduces new challenges to privacy risk management and compliance. Organizations must
ensure that their cloud computing environments comply with relevant privacy laws and regulations.
1. Data Collection Limitation Principle:
- Definition: Limiting the collection of personal data to only what is necessary.
- Example: A company collects only the necessary customer information, such as name and email address, for
marketing purposes.
2. Security Principle:
- Definition: Protecting personal data from unauthorized access, disclosure, or destruction.
- Example: Implementing encryption and access controls to protect customer data in a cloud-based customer
relationship management (CRM) system.
3. Retention and Destruction Principle:
- Definition: Retaining personal data only for as long as necessary and destroying it when no longer needed.
- Example: A company retains customer data for only 2 years after the customer relationship has ended and
then securely destroys it.
4. Transfer Principle:
- Definition: Ensuring that personal data is transferred securely and in accordance with relevant laws and
regulations.
- Example: Using secure protocols, such as HTTPS, to transfer customer data between cloud-based systems.
5. Accountability Principle:
- Definition: Ensuring that organizations are accountable for their handling of personal data.
- Example: Appointing a data protection officer (DPO) to oversee data protection practices and ensure
compliance with relevant laws and regulations.
Real-Time Examples:
1. Cloud Storage: A company uses cloud storage to store customer documents. To comply with data protection
regulations, the company implements access controls, encryption, and regular security audits.
2. Cloud-Based CRM: A company uses a cloud-based CRM system to manage customer interactions. To
comply with data protection regulations, the company ensures that customer data is encrypted, access is
restricted to authorized personnel, and data is retained only for as long as necessary.
Benefits:
1. Improved Compliance: Ensures compliance with relevant privacy laws and regulations.
2. Enhanced Trust: Builds trust with customers and stakeholders by demonstrating a commitment to data
protection.
3. Reduced Risk: Reduces the risk of data breaches and associated reputational damage.
Challenges:
1. Complexity: Cloud computing environments can be complex, making it challenging to ensure compliance
with relevant laws and regulations.
2. Data Sovereignty: Ensuring that data is stored and processed in accordance with relevant laws and
regulations can be challenging in cloud computing environments.
3. Vendor Management: Ensuring that cloud service providers comply with relevant laws and regulations can
be challenging.
AUDIT AND COMPLIANCE REFERS TO THE INTERNAL AND EXTERNAL PROCESSES
that an organization implements to:
• Identify the requirements with which it must abide—whether those requirements are
driven by business objectives, laws and regulations, customer contracts, internal corporate
policies and standards, or other factors.
• Put into practice policies, procedures, processes, and systems to satisfy such requirements
• Monitor or check whether such policies, procedures, and processes are consistently followed.
Audit and compliance functions have always played an important role in traditional
outsourcing relationships. However, these functions take on increased importance in the cloud
given the dynamic nature of software-as-a-service (SaaS), infrastructure-as-a-service (IaaS),
and platform-as-a-service (PaaS) environments. Cloud service providers (CSPs) are challenged
to establish, monitor, and demonstrate ongoing compliance with a set of controls that meets
their customer’s business and regulatory requirements.
Billing and cost management
Cloud billing is the procedure of producing and sending invoices for using cloud services to
customers. Most cloud provider carriers provide special billing reports, permitting groups to
apprehend their intake patterns. These reports provide data on the resources used, the time
period of utilization, and associated expenses. By comprehensively studying these
reports,companies can benefit from insights into their expenditure and make informed
decisions to optimize their utilization and reduce costs.
Key Benefits of Cloud Billing
• Cost Transparency: Cloud billing presents designated insights into your utilization,
enabling you to understand wherein your money is going. This transparency is critical
for budgeting and resource allocation.
• Cost Control: By intently monitoring your cloud utilization, you may discover unused
or underutilized resources. This information empowers you to lessen or decommission
such resources, leading to significant cost savings.
• Forecasting and Budgeting: Cloud billing data may be used to forecast future costs
correctly. With this information, companies can create realistic budgets and allocate
resources efficaciously.
• Resource Optimization: Cloud billing reports utilization styles. By understanding the
pattern, companies can optimize their resources, ensuring they pay only for what they
need.
• Cost Allocation: For large businesses, cloud billing permits costs to be allotted to
different departments. This granular perception ensures that each department is aware to
its cloud usage and may plan its budget correctly.
Key components of billing and cost management include usage metering, invoice generation,
payment management, budgeting and forecasting, cost analysis, and cost allocation and
tagging. These components work together to ensure accurate and efficient billing, as well as
effective cost control and optimization.
Here's a more detailed breakdown:
1. Usage Metering: This involves collecting and aggregating data on resource usage to
accurately track costs.
2. Invoice Generation: This step uses the usage data to create invoices based on the customer's
billing plan or pricing model.
3. Payment Management: This component handles payment processing, including receiving
funds, managing payment methods, and tracking payment history.
4. Budgeting and Forecasting: This involves setting spending limits, tracking actual costs
against budgets, and using historical data to forecast future spending.
5. Cost Analysis: This involves analyzing spending patterns to identify areas where costs can be
optimized, such as unused resources or inefficiencies in pricing models.
6. Cost Allocation and Tagging: This process helps allocate costs to specific departments,
projects, or users, providing better visibility into where costs are being incurred and who is
responsible for them.
7. Additional Considerations:
• Cost Trend Reporting:
Tracking cost trends over time to identify areas for improvement and optimize spending.
• Cost Control:
Implementing strategies to manage and reduce costs, such as resource optimization, right-
sizing, and using cost-effective pricing models.
• Cost Monitoring:
Using dashboards and reports to monitor spending and identify potential cost overruns or areas
of concern.
CSP life cycle approach
A cloud service provider (CSP) life cycle approach encompasses the stages from initial service request to
decommissioning, ensuring efficient resource management and optimal performance. This includes
provisioning, configuration, monitoring, maintenance, scaling, and eventually, the retirement or deletion of
services.
The CSP life cycle refers to the stages involved in designing, implementing, and managing cloud services.
Stage 1: Define Strategy
- Definition: Defining the CSP's overall strategy and goals.
- Activities:
- Identifying business objectives.
- Defining target market and customer segments.
- Developing a unique value proposition.
Stage 2: Define Requirements
- Definition: Defining the requirements for the cloud service.
- Activities:
- Gathering business and technical requirements.
- Defining functional and non-functional requirements.
- Identifying compliance and regulatory requirements.
Stage 3: Define Architecture
- Definition: Designing the architecture of the cloud service.
- Activities:
- Defining the technical architecture.
- Selecting cloud deployment models (public, private, hybrid).
- Designing scalability, security, and performance.
Stage 4: Define Policies
- Definition: Defining policies for the cloud service.
- Activities:
- Developing security policies.
- Defining data management policies.
- Establishing compliance policies.
Stage 5: Define Processes and Procedures
- Definition: Defining processes and procedures for the cloud service.
- Activities:
- Developing incident management processes.
- Defining change management procedures.
- Establishing problem management processes.
Stage 6: Ongoing Operation
- Definition: Managing the day-to-day operation of the cloud service.
- Activities:
- Monitoring service performance.
- Managing incidents and problems.
- Performing routine maintenance.
Stage 7: Ongoing Monitoring
- Definition: Continuously monitoring the cloud service.
- Activities:
- Monitoring performance and security.
- Analyzing logs and metrics.
- Identifying areas for improvement.
Stage 8: Continuous Improvement
- Definition: Continuously improving the cloud service.
- Activities:
- Identifying opportunities for improvement.
- Implementing changes and updates.
- Evaluating the effectiveness of improvements.
Governance, Risk, and Compliance (GRC)
CSPs are typically challenged to meet the requirements of a diverse client base. To build a
sustainable model, it is essential that the CSP establish a strong foundation of controls that can
be applied to all of its clients.
Risk Assessment and Management in Cloud Service Providers
Risk assessment and management are critical components of ensuring the security and reliability of cloud
services.
Risk Assessment:
- Definition: Identifying, assessing, and prioritizing potential risks to the cloud service.
- Activities:
- Identifying potential risks (e.g., data breaches, system failures).
- Assessing the likelihood and impact of each risk.
- Prioritizing risks based on likelihood and impact.
Key Controls:
- Definition: Implementing controls to mitigate identified risks.
- Examples:
- Access controls (e.g., authentication, authorization).
- Data encryption.
- Firewalls and intrusion detection systems.
Monitoring:
- Definition: Continuously monitoring the cloud service for potential security threats and risks.
- Activities:
- Monitoring system logs and metrics.
- Conducting regular security audits.
- Implementing incident response plans.
Reporting:
- Definition: Reporting on risk assessment and management activities to stakeholders.
- Activities:
- Providing regular risk assessment reports.
- Notifying stakeholders of potential security threats.
- Reporting on compliance with regulatory requirements
Continuous Improvement:
- Definition: Continuously improving risk assessment and management processes.
- Activities:
- Reviewing and updating risk assessment processes.
- Implementing new controls and technologies.
- Conducting regular training and awareness programs.
New IT Project and Systems:
- Definition: Assessing risks associated with new IT projects and systems.
- Activities:
- Conducting risk assessments for new projects and systems.
- Identifying potential security threats and risks.
- Implementing controls and mitigation strategies.
Implementing a GRC (Governance, Risk, and Compliance) Program
A GRC program is a framework that helps organizations manage governance, risk, and compliance in a holistic
and integrated way.
Governance Build-out:
- Definition: Establishing a governance framework that defines roles, responsibilities, and decision-making
processes.
- Activities:
- Defining governance structure and policies.
- Establishing clear roles and responsibilities.
- Developing decision-making processes.
Risk Management Build-out:
- Definition: Identifying, assessing, and mitigating risks that could impact the organization.
- Activities:
- Identifying potential risks.
- Assessing risk likelihood and impact.
- Developing risk mitigation strategies.
Compliance Build-out:
- Definition: Ensuring compliance with relevant laws, regulations, and industry standards.
- Activities:
- Identifying applicable laws and regulations.
- Developing compliance policies and procedures.
- Conducting regular compliance audits.
Continuous Improvement:
- Definition: Continuously monitoring and improving the GRC program.
- Activities:
- Monitoring program performance.
- Identifying areas for improvement.
- Implementing changes and updates.
Benefits:
1. Improved Governance: Enhances governance and decision-making processes.
2. Reduced Risk: Identifies and mitigates potential risks.
3. Increased Compliance: Ensures compliance with relevant laws and regulations.
Illustrative Control Objectives for Cloud Computing
Security policy
Information security policy
Provides management direction and support for information security in accordance with business requirements
and relevant laws and regulations
Organization of information security
Internal organization
Manages information security within the organization
External parties
Maintains the security of the organization’s information and information processing facilities that are accessed,
processed, communicated to, or managed by external partie
Asset management
Responsibility for assets :To achieve and maintain appropriate protection of organizational assets
Information classification: To ensure that information receives an appropriate level of protection.
Human resources security
Prior to employment
To ensure that employees, contractors, and third-party users understand their responsibilities and are suitable
for the roles they are considered for, and to reduce the risk of theft, fraud, or misuse of facilities
During employment
To ensure that all employees, contractors, and third-party users are aware of information security threats and
concerns and of their responsibilities and liabilities, and are equipped to support an organizational security
policy in the course of their normal work, and to
Reduce the risk of human error
Termination or change of employment To ensure that employees, contractors, and third-party users exit an
organization or change employment in an orderly manner.
Physical and environmental security
Secure areas
To prevent unauthorized physical access, damage, and interference to the organization’s premises and
information
Equipment security
To prevent loss, damage, theft, or compromise of assets and interruption to the
organization’s activities.
Communications and operations management
Operational procedures and [Link] ensure the correct and secure operation of information
processing facilities
Common Industry/Regulatory Requirements
(Sarbanes-Oxley, PCI DSS, HIPAA) and their applicability in a cloud computing environment.
Sarbanes-Oxley(SOX)
Protects investors: By improving corporate governance and financial transparency.
Enhances corporate accountability: By holding executives accountable for financial reporting
PCI DSS Payment Card Industry Data Security Standard)
PCI DSS is a security standard for organizations handling payment card information.
HIPAA (Health Insurance Portability and Accountability Act)
HIPAA is a US law protecting individuals' medical records and personal health information.
COBIT (Control Objectives for Information and Related Technology)
COBIT is a widely-used framework for IT governance and management that helps organizations align their IT
strategies with business objectives.