SlideShare une entreprise Scribd logo
1  sur  20
Télécharger pour lire hors ligne
Data Residency:
Challenges and the Need for Standards
Webinar
May 11, 2017
1
Speakers
2
Tracie
Berardi
Sr. Marketing Manager, OMG
Moderator
Andrew
Watson
Technical Director, OMG
Claude
Baudoin
Principal, cébé IT & Knowledge Management
Energy Domain Consultant, OMG
Member of the CSCC Steering Committee
3
 One of the most successful forums for creating open
integration standards in the computer industry
• Middleware platforms (DDS, CORBA and related specs)
• Modeling platforms (UML, BPMN, SysML and related work)
• System Assurance (SACM, DAF for SSCD ...)
• Vertical domain specifications (Finance, Healthcare, C4I, ...)
 Member-controlled industrial consortium
• Both vendors and users
• Not-for-profit
 Adopted specifications are freely available to all
• Visit http://www.omg.org
 Path to adoption by ISO and other standards bodies
Introducing OMG
4
ACORD
Adaptive
Adelard LLP
Airbus Grp
Appian
AT&T
BAE Systems
Bizagi
Bloomberg
Boeing
CA
Camunda
Dell EMC
Eclipse Fndn.
EDM Council
FICO
Ford
FSTC/BITS
Fujitsu
Gen. Electric
Harris
HPe
Huawei
IBM
KDM Analytic
Lockheed
MEGA
Microsoft
Micro Focus
MID GmbH
MITRE
Mitsubishi
ModelFoundry
NASA
NARA
NIST
No Magic
Northrop
Oracle
OSD
PNA
PrismTech
PROSTEP AG
PTC
PwC
Rolls-Royce
RTI
SAP
Scheer E2E
Signavio
Simula Labs
Softeam
Software AG
Sparx
State St
Thales
Thematix
TIBCO
Toshiba
Trisotech
Twin Oaks
VDMbee
Visumpoint
W3C
(200+ more)
Worldwide Membership
Introducing the CSCC
5
THE Customer’s Voice for Cloud Standards!
650+ Organizations
participating
http://cloud-council.org
• Provide customer-led guidance to multiple
cloud standards-defining bodies
• Establishing criteria for open
standards based cloud computing
2017 Projects
 Data Residency discussion paper
 Security for Cloud Services Ref. Architecture
 Impact of Cloud Computing on Healthcare v2
 Hybrid Integration Reference Architecture
 API Management Reference Architecture
 Blockchain Reference Architecture
 Multi-cloud Management whitepaper
 And more!
2016 Deliverables
 Prac Guide to Hybrid Cloud Computing
 Public Cloud Service Agreements, V2
 Cloud Security Standards, V2
 IoT Ref. Architecture
 e-Commerce Ref. Architecture
 Impact of Cloud Computing on Healthcare, V2
 Enterprise Social Collaboration Ref. Architecture
2015 Deliverables
 Web App Hosting Ref. Architecture
 Mobile Ref. Architecture
 Big Data & Analytics Ref. Architecture
 Security for Cloud Computing, V2
 Practical Guide to Cloud SLAs, V2
 Practical Guide to PaaS
2013/2014 Deliverables
 Convergence of Social, Mobile, Cloud
 Analysis of Public Cloud SLAs
 Cloud Security Standards
 Migrating Apps to Public Cloud Services
 Social Business in the Cloud
 Deploying Big Data in the Cloud
 Practical Guide to Cloud Computing, V2
 Migrating Apps: Performance Rqmnts
 Cloud Interoperability/Portability
History of This Effort
 March 2015: initial request from an OMG member
 June 2015: first OMG Data Residency WG meeting (Berlin)
 Sep.-Dec. 2015: 2nd and 3rd meetings, prepared an RFI
 March-June 2016: 4th - 5th meetings, processed RFI results,
decide to create a discussion paper as first deliverable
 Sep.-Dec. 2016: 6th - 7th meetings, preliminary draft of
discussion paper, agreement to collaborate with CSCC and
issue two separate but almost identical papers
 Q1 ‘17: collect contributions, edit paper, go the OMG
approval process (8th meeting, Washington DC)
 April ‘17: create CSCC companion white paper, review
process, release
 May ‘17: press releases and this webinar
 June ‘17: working group meeting and tutorial in Brussels
6
The Two Papers
 Both about 35 pages
 CSCC paper omits the history of the OMG effort and the
discussion of OMG’s potential roadmap for standards
7
Data Residency Definition, Scope
 There are a number of definitions of data residency – as is usually the case
in a new domain
 We propose this definition:
Data residency is the set of issues and practices related to the
location of data and metadata, the movement of (meta)data
across geographies and jurisdictions, and the protection of
that (meta)data against unintended access and other location-
related risks
 Scope
• Not just about the protection of personally identifiable information (PII)
• Also concerns the right to move “sovereign” data, such as oil reserves
data; international licensing of genomics data; distribution of biometrics
data for security purposes; etc.
8
Risks Related to Data Residency
 Violating of a government law or regulation
 Unintended/unauthorized access by a foreign organization
 Demand by a foreign government’s authorities to access data
 Having to provide a foreign government with secret keys to inspect
encrypted data
 Violation of “domestic content” policies
 Increased cost of doing business in a given country
 Inability of a multinational organization to provide shared employee services,
such as payroll and benefits
 Losing business to a local competitor
 Inability to qualify for government or private contracts
 Multiplication of locally managed data centers with smaller and less
experienced security teams
 Diminished disaster recovery capabilities
 Delays in business transformation and technology modernization
 Consumer and citizen mistrust of technology, organizations, governments 9
Challenges: Example 1
 Migration to the cloud
• Am I allowed to put my data in the cloud if it is going to be
stored in another country, or if there is a possibility that
the cloud provider might move it to another country later
without my knowledge or consent?
• Regulations may be unclear
• Regulations may be used as a rationale to reject the
cloud… even when they do not really exist (Mexico
government example)
• Authorization may require high-level approval (Danish
bank example)
10
Challenges: Example 2
 Genomic data sets
• Can I license a data set from another country to perform
research on a larger sample?
• How do I prove to regulators that the data no longer
contains personally identifiable information (PII)?
11
Challenges: Example 3
 Processing data on petroleum reserves
• In countries with national companies,
subsurface data is often considered a
national asset
• Exploration is subcontracted to foreign
companies
Can it remotely control an automated drilling
operation from a monitoring center in another
country?
Can it move data to a foreign location in order to
do better analytics?
If it returns data interpreted in a center in another
country, does it have to pay duties on the added
value of those results?
12
Challenges: Example 4
 Law enforcement vs. personal communication
• A US citizen is suspected of criminal activity
• Some evidence may reside in their e-mail stored in the
cloud by a US provider
• However, the data is stored outside of the US, in a country
with strong data protection laws
• Which law prevails? Is the provider “damned if they do,
damned if they don’t” give the US government access to
the data?
13
Use Case Matrix
14
Laws and Regulations
 Multiple, inconsistent, overlapping, and still evolving laws and
regulations around the world
 Range from non-existent to severe
 Sometimes (but not always) apply to government data /
public records, not to private companies’ data
 The European Union’s General Data Protection Regulation
(GDPR) of 2016 is among the most comprehensive
 Multiple motivations behind the laws:
• Protecting the privacy of citizens
• Enabling police and tax authorities to inspect data
• Protectionism – force companies to create domestic facilities
• Monetize the flow of data
15
Some Country-Specific Cases
 See Appendix in the papers – but remember that the
situation keeps evolving
• Australia
• Canada
• China
• Denmark
• European Union
• France
• Germany
• India
• Indonesia
• Korea
• Malaysia
• Netherlands
• Nigeria
• Norway
• Russia
• Turkey
• Ukraine
• United States
• Venezuela
• Vietnam
16
Existing Relevant Standards
 There is currently no standard that deals specifically with data
residency
 Data residency is related to the security and privacy aspects of
• Several NIST publications (800-144, 500-299, 1500)
• Several ISO/IEC standards (27001, 27017, 27018)
• The work of the CSA’s International Standardization Council (ISC)
• Work being considered in ISO/IEC JTC 1/SC 38
• The “Voluntary Data Protection Code” of CISPE (Cloud Infrastructure
Service Providers in Europe)
 Some technical standards may prove useful
• Information Exchange Framework (IEF) – OMG
• Data Tagging and Labeling – OMG work in progress
• XACML – eXtensible Access Control Markup Language
• ORDL – Open Digital Rights Language
17
What is Needed
 Documentation and education
• These papers are a good start
 Cataloguing of laws and regulations
• See the Digital Trade Database from the European Centre for
International Political Economy (ECIPE)
 Formal description of laws and regulations
• Because natural language is ambiguous and does not lend itself to
automated policy enforcement
 Formal description of the content of data
• Extension of data tagging and labeling or IEF policy
 With both of the above, we might be able to better manage
residency
 Several difficult challenges
• Willingness to participate – requires recognizing there are issues
• Implementation may be difficult due to legacy systems
18
Summary and How to Participate
 Data residency is a serious challenge for suppliers as
well as users
• Can (and already does) hurt the ability to do business
 It may well get worse before it gets better
 Organizations need to learn about it and develop
business and technical approaches
 OMG is looking into what standards may help
• Metadata describing data location constraints?
• Formal description of data residency laws and regulations?
 Call to action
• Participate in OMG Data Residency Working Group
• and/or in the various Working Groups of the CSCC
19
Thanks – Q&A Time
More information at
www.omg.org/data-residency
and
www.cloud-council.org/resource-hub
20

Contenu connexe

Tendances

Storage virtualization
Storage virtualizationStorage virtualization
Storage virtualizationramya1591
 
Distributed database
Distributed databaseDistributed database
Distributed databasesanjay joshi
 
11. Storage and File Structure in DBMS
11. Storage and File Structure in DBMS11. Storage and File Structure in DBMS
11. Storage and File Structure in DBMSkoolkampus
 
AVATA Webinar: Upgrading ASCP - The New Face of ASCP is Here! www.avata.com
AVATA Webinar:  Upgrading ASCP - The New Face of ASCP is Here! www.avata.comAVATA Webinar:  Upgrading ASCP - The New Face of ASCP is Here! www.avata.com
AVATA Webinar: Upgrading ASCP - The New Face of ASCP is Here! www.avata.comAVATA
 
NetApp enterprise All Flash Storage
NetApp enterprise All Flash StorageNetApp enterprise All Flash Storage
NetApp enterprise All Flash StorageDavid Mallenco
 
Data Abstraction and Independance (1).pptx
Data Abstraction and Independance (1).pptxData Abstraction and Independance (1).pptx
Data Abstraction and Independance (1).pptxnehasahuji
 
Resilient file system
Resilient file systemResilient file system
Resilient file systemAyush Gupta
 
Emc data domain technical deep dive workshop
Emc data domain  technical deep dive workshopEmc data domain  technical deep dive workshop
Emc data domain technical deep dive workshopsolarisyougood
 
Chapter10 conceptual data modeling
Chapter10 conceptual data modelingChapter10 conceptual data modeling
Chapter10 conceptual data modelingDhani Ahmad
 
Components of ddbms
Components of ddbmsComponents of ddbms
Components of ddbmsPooja Dixit
 
Introduction to san ( storage area networks )
Introduction to san ( storage area networks )Introduction to san ( storage area networks )
Introduction to san ( storage area networks )sagaroceanic11
 
Fundamentals of Database Systems Questions and Answers
Fundamentals of Database Systems Questions and AnswersFundamentals of Database Systems Questions and Answers
Fundamentals of Database Systems Questions and AnswersAbdul Rahman Sherzad
 
z/VSE Connectors Introduction, Use Cases, and News
z/VSE Connectors Introduction, Use Cases, and Newsz/VSE Connectors Introduction, Use Cases, and News
z/VSE Connectors Introduction, Use Cases, and NewsIBM
 
3 Tier Architecture
3 Tier Architecture3 Tier Architecture
3 Tier Architectureguestd0cc01
 
HANA SPS07 Architecture & Landscape
HANA SPS07 Architecture & LandscapeHANA SPS07 Architecture & Landscape
HANA SPS07 Architecture & LandscapeSAP Technology
 
Advanced processor Principles
Advanced processor PrinciplesAdvanced processor Principles
Advanced processor PrinciplesVinit Raut
 
Function Oriented Design
Function Oriented DesignFunction Oriented Design
Function Oriented DesignSharath g
 
BCON22: oneAPI backend - Blender Cycles on Intel GPUs
BCON22: oneAPI backend - Blender Cycles on Intel GPUsBCON22: oneAPI backend - Blender Cycles on Intel GPUs
BCON22: oneAPI backend - Blender Cycles on Intel GPUsXavier Hallade
 

Tendances (20)

Storage virtualization
Storage virtualizationStorage virtualization
Storage virtualization
 
Distributed database
Distributed databaseDistributed database
Distributed database
 
11. Storage and File Structure in DBMS
11. Storage and File Structure in DBMS11. Storage and File Structure in DBMS
11. Storage and File Structure in DBMS
 
AVATA Webinar: Upgrading ASCP - The New Face of ASCP is Here! www.avata.com
AVATA Webinar:  Upgrading ASCP - The New Face of ASCP is Here! www.avata.comAVATA Webinar:  Upgrading ASCP - The New Face of ASCP is Here! www.avata.com
AVATA Webinar: Upgrading ASCP - The New Face of ASCP is Here! www.avata.com
 
NetApp enterprise All Flash Storage
NetApp enterprise All Flash StorageNetApp enterprise All Flash Storage
NetApp enterprise All Flash Storage
 
Data Abstraction and Independance (1).pptx
Data Abstraction and Independance (1).pptxData Abstraction and Independance (1).pptx
Data Abstraction and Independance (1).pptx
 
Resilient file system
Resilient file systemResilient file system
Resilient file system
 
Emc data domain technical deep dive workshop
Emc data domain  technical deep dive workshopEmc data domain  technical deep dive workshop
Emc data domain technical deep dive workshop
 
Chapter10 conceptual data modeling
Chapter10 conceptual data modelingChapter10 conceptual data modeling
Chapter10 conceptual data modeling
 
VMware
VMwareVMware
VMware
 
Components of ddbms
Components of ddbmsComponents of ddbms
Components of ddbms
 
Introduction to san ( storage area networks )
Introduction to san ( storage area networks )Introduction to san ( storage area networks )
Introduction to san ( storage area networks )
 
Fundamentals of Database Systems Questions and Answers
Fundamentals of Database Systems Questions and AnswersFundamentals of Database Systems Questions and Answers
Fundamentals of Database Systems Questions and Answers
 
z/VSE Connectors Introduction, Use Cases, and News
z/VSE Connectors Introduction, Use Cases, and Newsz/VSE Connectors Introduction, Use Cases, and News
z/VSE Connectors Introduction, Use Cases, and News
 
3 Tier Architecture
3 Tier Architecture3 Tier Architecture
3 Tier Architecture
 
HANA SPS07 Architecture & Landscape
HANA SPS07 Architecture & LandscapeHANA SPS07 Architecture & Landscape
HANA SPS07 Architecture & Landscape
 
NetAppOverview
NetAppOverviewNetAppOverview
NetAppOverview
 
Advanced processor Principles
Advanced processor PrinciplesAdvanced processor Principles
Advanced processor Principles
 
Function Oriented Design
Function Oriented DesignFunction Oriented Design
Function Oriented Design
 
BCON22: oneAPI backend - Blender Cycles on Intel GPUs
BCON22: oneAPI backend - Blender Cycles on Intel GPUsBCON22: oneAPI backend - Blender Cycles on Intel GPUs
BCON22: oneAPI backend - Blender Cycles on Intel GPUs
 

Similaire à Data Residency: Challenges and the Need for Standards

Clouds and Chains
Clouds and ChainsClouds and Chains
Clouds and ChainsTim Swanson
 
Data Portability: Law and Code
Data Portability: Law and CodeData Portability: Law and Code
Data Portability: Law and Codeaudriga.com
 
Privacy policy information in data value chains
Privacy policy information in data value chainsPrivacy policy information in data value chains
Privacy policy information in data value chainsBig Data Value Association
 
Safe Harbor Webinar
Safe Harbor WebinarSafe Harbor Webinar
Safe Harbor WebinarEthisphere
 
ISACA Houston - Practical data privacy and de-identification techniques
ISACA Houston  - Practical data privacy and de-identification techniquesISACA Houston  - Practical data privacy and de-identification techniques
ISACA Houston - Practical data privacy and de-identification techniquesUlf Mattsson
 
26 Nov 2013 - Law and Policy Meet the Cloud, by Bernie Trudel [IIC-TRPC Singa...
26 Nov 2013 - Law and Policy Meet the Cloud, by Bernie Trudel [IIC-TRPC Singa...26 Nov 2013 - Law and Policy Meet the Cloud, by Bernie Trudel [IIC-TRPC Singa...
26 Nov 2013 - Law and Policy Meet the Cloud, by Bernie Trudel [IIC-TRPC Singa...accacloud
 
A Successful Data Strategy for Insurers in Volatile Times (EMEA)
A Successful Data Strategy for Insurers in Volatile Times (EMEA)A Successful Data Strategy for Insurers in Volatile Times (EMEA)
A Successful Data Strategy for Insurers in Volatile Times (EMEA)Denodo
 
Deployment strategies of Open Data Node focused mainly on pilots (2015-May)
Deployment strategies of Open Data Node focused mainly on pilots (2015-May)Deployment strategies of Open Data Node focused mainly on pilots (2015-May)
Deployment strategies of Open Data Node focused mainly on pilots (2015-May)Comsode - FP7 project
 
GDPR and IoT: What do you need to know?
GDPR and IoT: What do you need to know?GDPR and IoT: What do you need to know?
GDPR and IoT: What do you need to know?MicheleNati
 
Session 2 ure_changingrules_final
Session 2 ure_changingrules_finalSession 2 ure_changingrules_final
Session 2 ure_changingrules_finalTRPC Pte Ltd
 
Why care about GDPR and avoid over $20 million fines, even outside EU ?
Why care about GDPR and avoid over $20 million fines, even outside EU ?Why care about GDPR and avoid over $20 million fines, even outside EU ?
Why care about GDPR and avoid over $20 million fines, even outside EU ?FactoVia
 
2015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 050520152015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 05052015Jan Dhont
 
Tim Willoughby - Presentation to Innovation Masters 2016
Tim Willoughby - Presentation to Innovation Masters 2016Tim Willoughby - Presentation to Innovation Masters 2016
Tim Willoughby - Presentation to Innovation Masters 2016Tim Willoughby
 
Personal Data Receipts - Michele Nati - Lead Technologist Privacy and Trust -...
Personal Data Receipts - Michele Nati - Lead Technologist Privacy and Trust -...Personal Data Receipts - Michele Nati - Lead Technologist Privacy and Trust -...
Personal Data Receipts - Michele Nati - Lead Technologist Privacy and Trust -...MicheleNati
 
Future of Data Strategy
Future of Data StrategyFuture of Data Strategy
Future of Data StrategyDenodo
 
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...Denodo
 

Similaire à Data Residency: Challenges and the Need for Standards (20)

Where's My Data? Managing the Data Residency Challenge
Where's My Data? Managing the Data Residency ChallengeWhere's My Data? Managing the Data Residency Challenge
Where's My Data? Managing the Data Residency Challenge
 
Clouds and Chains
Clouds and ChainsClouds and Chains
Clouds and Chains
 
Data Portability: Law and Code
Data Portability: Law and CodeData Portability: Law and Code
Data Portability: Law and Code
 
Privacy policy information in data value chains
Privacy policy information in data value chainsPrivacy policy information in data value chains
Privacy policy information in data value chains
 
Safe Harbor Webinar
Safe Harbor WebinarSafe Harbor Webinar
Safe Harbor Webinar
 
ISACA Houston - Practical data privacy and de-identification techniques
ISACA Houston  - Practical data privacy and de-identification techniquesISACA Houston  - Practical data privacy and de-identification techniques
ISACA Houston - Practical data privacy and de-identification techniques
 
Sible 09
Sible 09Sible 09
Sible 09
 
26 Nov 2013 - Law and Policy Meet the Cloud, by Bernie Trudel [IIC-TRPC Singa...
26 Nov 2013 - Law and Policy Meet the Cloud, by Bernie Trudel [IIC-TRPC Singa...26 Nov 2013 - Law and Policy Meet the Cloud, by Bernie Trudel [IIC-TRPC Singa...
26 Nov 2013 - Law and Policy Meet the Cloud, by Bernie Trudel [IIC-TRPC Singa...
 
A Successful Data Strategy for Insurers in Volatile Times (EMEA)
A Successful Data Strategy for Insurers in Volatile Times (EMEA)A Successful Data Strategy for Insurers in Volatile Times (EMEA)
A Successful Data Strategy for Insurers in Volatile Times (EMEA)
 
Deployment strategies of Open Data Node focused mainly on pilots (2015-May)
Deployment strategies of Open Data Node focused mainly on pilots (2015-May)Deployment strategies of Open Data Node focused mainly on pilots (2015-May)
Deployment strategies of Open Data Node focused mainly on pilots (2015-May)
 
GDPR and IoT: What do you need to know?
GDPR and IoT: What do you need to know?GDPR and IoT: What do you need to know?
GDPR and IoT: What do you need to know?
 
Session 2 ure_changingrules_final
Session 2 ure_changingrules_finalSession 2 ure_changingrules_final
Session 2 ure_changingrules_final
 
Why care about GDPR and avoid over $20 million fines, even outside EU ?
Why care about GDPR and avoid over $20 million fines, even outside EU ?Why care about GDPR and avoid over $20 million fines, even outside EU ?
Why care about GDPR and avoid over $20 million fines, even outside EU ?
 
2015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 050520152015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 05052015
 
Tim Willoughby - Presentation to Innovation Masters 2016
Tim Willoughby - Presentation to Innovation Masters 2016Tim Willoughby - Presentation to Innovation Masters 2016
Tim Willoughby - Presentation to Innovation Masters 2016
 
GDPR- The Buck Stops Here
GDPR-  The Buck Stops HereGDPR-  The Buck Stops Here
GDPR- The Buck Stops Here
 
Personal Data Receipts - Michele Nati - Lead Technologist Privacy and Trust -...
Personal Data Receipts - Michele Nati - Lead Technologist Privacy and Trust -...Personal Data Receipts - Michele Nati - Lead Technologist Privacy and Trust -...
Personal Data Receipts - Michele Nati - Lead Technologist Privacy and Trust -...
 
Future of Data Strategy
Future of Data StrategyFuture of Data Strategy
Future of Data Strategy
 
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
 
DPO Circle 2018
DPO Circle 2018 DPO Circle 2018
DPO Circle 2018
 

Plus de Cloud Standards Customer Council

Kubernetes and Container Technologies from Cloud Native Computing Foundation
Kubernetes and Container Technologies from Cloud Native Computing FoundationKubernetes and Container Technologies from Cloud Native Computing Foundation
Kubernetes and Container Technologies from Cloud Native Computing FoundationCloud Standards Customer Council
 
Interoperability and Portability for Cloud Computing: A Guide V2.0
Interoperability and Portability for Cloud Computing: A Guide V2.0Interoperability and Portability for Cloud Computing: A Guide V2.0
Interoperability and Portability for Cloud Computing: A Guide V2.0Cloud Standards Customer Council
 
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0Cloud Standards Customer Council
 
Cloud Customer Architecture for Big Data and Analytics V2.0
Cloud Customer Architecture for Big Data and Analytics V2.0Cloud Customer Architecture for Big Data and Analytics V2.0
Cloud Customer Architecture for Big Data and Analytics V2.0Cloud Standards Customer Council
 
Cloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Customer Architecture for Securing Workloads on Cloud ServicesCloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Customer Architecture for Securing Workloads on Cloud ServicesCloud Standards Customer Council
 
Cloud Customer Architecture for Enterprise Social Collaboration
Cloud Customer Architecture for Enterprise Social CollaborationCloud Customer Architecture for Enterprise Social Collaboration
Cloud Customer Architecture for Enterprise Social CollaborationCloud Standards Customer Council
 
Latest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and PrivacyLatest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and PrivacyCloud Standards Customer Council
 
Interoperability and Portability for Cloud Computing: A Guide
Interoperability and Portability for Cloud Computing: A GuideInteroperability and Portability for Cloud Computing: A Guide
Interoperability and Portability for Cloud Computing: A GuideCloud Standards Customer Council
 
Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Security Standards: What to Expect and What to Negotiate V2.0Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Security Standards: What to Expect and What to Negotiate V2.0Cloud Standards Customer Council
 

Plus de Cloud Standards Customer Council (20)

Kubernetes and Container Technologies from Cloud Native Computing Foundation
Kubernetes and Container Technologies from Cloud Native Computing FoundationKubernetes and Container Technologies from Cloud Native Computing Foundation
Kubernetes and Container Technologies from Cloud Native Computing Foundation
 
What's New in Cloud Foundry
What's New in Cloud FoundryWhat's New in Cloud Foundry
What's New in Cloud Foundry
 
Hyperledger: Market, Technology & Community Update
Hyperledger: Market, Technology & Community UpdateHyperledger: Market, Technology & Community Update
Hyperledger: Market, Technology & Community Update
 
Interoperability and Portability for Cloud Computing: A Guide V2.0
Interoperability and Portability for Cloud Computing: A Guide V2.0Interoperability and Portability for Cloud Computing: A Guide V2.0
Interoperability and Portability for Cloud Computing: A Guide V2.0
 
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
 
Hybrid Cloud Considerations for Big Data and Analytics
Hybrid Cloud Considerations for Big Data and AnalyticsHybrid Cloud Considerations for Big Data and Analytics
Hybrid Cloud Considerations for Big Data and Analytics
 
Cloud Customer Architecture for Big Data and Analytics V2.0
Cloud Customer Architecture for Big Data and Analytics V2.0Cloud Customer Architecture for Big Data and Analytics V2.0
Cloud Customer Architecture for Big Data and Analytics V2.0
 
Practical Guide to Cloud Management Platforms
Practical Guide to Cloud Management PlatformsPractical Guide to Cloud Management Platforms
Practical Guide to Cloud Management Platforms
 
Cloud Customer Architecture for Blockchain
Cloud Customer Architecture for BlockchainCloud Customer Architecture for Blockchain
Cloud Customer Architecture for Blockchain
 
Cloud Foundry Road Map in 2017
Cloud Foundry Road Map in 2017Cloud Foundry Road Map in 2017
Cloud Foundry Road Map in 2017
 
Hyperledger: Advancing Blockchain Technology for Business
Hyperledger: Advancing Blockchain Technology for BusinessHyperledger: Advancing Blockchain Technology for Business
Hyperledger: Advancing Blockchain Technology for Business
 
Cloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Customer Architecture for Securing Workloads on Cloud ServicesCloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Customer Architecture for Securing Workloads on Cloud Services
 
Impact of Cloud Computing on Healthcare v2.0
Impact of Cloud Computing on Healthcare v2.0Impact of Cloud Computing on Healthcare v2.0
Impact of Cloud Computing on Healthcare v2.0
 
Cloud Customer Architecture for API Management
Cloud Customer Architecture for API ManagementCloud Customer Architecture for API Management
Cloud Customer Architecture for API Management
 
Cloud Customer Architecture for Hybrid Integration
Cloud Customer Architecture for Hybrid IntegrationCloud Customer Architecture for Hybrid Integration
Cloud Customer Architecture for Hybrid Integration
 
Cloud Customer Architecture for Enterprise Social Collaboration
Cloud Customer Architecture for Enterprise Social CollaborationCloud Customer Architecture for Enterprise Social Collaboration
Cloud Customer Architecture for Enterprise Social Collaboration
 
Latest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and PrivacyLatest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and Privacy
 
Interoperability and Portability for Cloud Computing: A Guide
Interoperability and Portability for Cloud Computing: A GuideInteroperability and Portability for Cloud Computing: A Guide
Interoperability and Portability for Cloud Computing: A Guide
 
Cloud Customer Architecture for e-Commerce
Cloud Customer Architecture for e-CommerceCloud Customer Architecture for e-Commerce
Cloud Customer Architecture for e-Commerce
 
Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Security Standards: What to Expect and What to Negotiate V2.0Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Security Standards: What to Expect and What to Negotiate V2.0
 

Dernier

Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...harshavardhanraghave
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️Delhi Call girls
 
A Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxA Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxComplianceQuest1
 
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...panagenda
 
How To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsHow To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsAndolasoft Inc
 
Unlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language ModelsUnlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language Modelsaagamshah0812
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsAlberto González Trastoy
 
CALL ON ➥8923113531 🔝Call Girls Badshah Nagar Lucknow best Female service
CALL ON ➥8923113531 🔝Call Girls Badshah Nagar Lucknow best Female serviceCALL ON ➥8923113531 🔝Call Girls Badshah Nagar Lucknow best Female service
CALL ON ➥8923113531 🔝Call Girls Badshah Nagar Lucknow best Female serviceanilsa9823
 
5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdfWave PLM
 
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AISyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AIABDERRAOUF MEHENNI
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerThousandEyes
 
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...Health
 
TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providermohitmore19
 
Hand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptxHand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptxbodapatigopi8531
 
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...MyIntelliSource, Inc.
 
Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVshikhaohhpro
 
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...ICS
 
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...OnePlan Solutions
 

Dernier (20)

Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
 
A Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxA Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docx
 
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
 
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
 
How To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsHow To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.js
 
Unlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language ModelsUnlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language Models
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
 
CALL ON ➥8923113531 🔝Call Girls Badshah Nagar Lucknow best Female service
CALL ON ➥8923113531 🔝Call Girls Badshah Nagar Lucknow best Female serviceCALL ON ➥8923113531 🔝Call Girls Badshah Nagar Lucknow best Female service
CALL ON ➥8923113531 🔝Call Girls Badshah Nagar Lucknow best Female service
 
5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf
 
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AISyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
 
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
 
TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service provider
 
Hand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptxHand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptx
 
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
 
Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTV
 
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
 
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
 

Data Residency: Challenges and the Need for Standards

  • 1. Data Residency: Challenges and the Need for Standards Webinar May 11, 2017 1
  • 2. Speakers 2 Tracie Berardi Sr. Marketing Manager, OMG Moderator Andrew Watson Technical Director, OMG Claude Baudoin Principal, cébé IT & Knowledge Management Energy Domain Consultant, OMG Member of the CSCC Steering Committee
  • 3. 3  One of the most successful forums for creating open integration standards in the computer industry • Middleware platforms (DDS, CORBA and related specs) • Modeling platforms (UML, BPMN, SysML and related work) • System Assurance (SACM, DAF for SSCD ...) • Vertical domain specifications (Finance, Healthcare, C4I, ...)  Member-controlled industrial consortium • Both vendors and users • Not-for-profit  Adopted specifications are freely available to all • Visit http://www.omg.org  Path to adoption by ISO and other standards bodies Introducing OMG
  • 4. 4 ACORD Adaptive Adelard LLP Airbus Grp Appian AT&T BAE Systems Bizagi Bloomberg Boeing CA Camunda Dell EMC Eclipse Fndn. EDM Council FICO Ford FSTC/BITS Fujitsu Gen. Electric Harris HPe Huawei IBM KDM Analytic Lockheed MEGA Microsoft Micro Focus MID GmbH MITRE Mitsubishi ModelFoundry NASA NARA NIST No Magic Northrop Oracle OSD PNA PrismTech PROSTEP AG PTC PwC Rolls-Royce RTI SAP Scheer E2E Signavio Simula Labs Softeam Software AG Sparx State St Thales Thematix TIBCO Toshiba Trisotech Twin Oaks VDMbee Visumpoint W3C (200+ more) Worldwide Membership
  • 5. Introducing the CSCC 5 THE Customer’s Voice for Cloud Standards! 650+ Organizations participating http://cloud-council.org • Provide customer-led guidance to multiple cloud standards-defining bodies • Establishing criteria for open standards based cloud computing 2017 Projects  Data Residency discussion paper  Security for Cloud Services Ref. Architecture  Impact of Cloud Computing on Healthcare v2  Hybrid Integration Reference Architecture  API Management Reference Architecture  Blockchain Reference Architecture  Multi-cloud Management whitepaper  And more! 2016 Deliverables  Prac Guide to Hybrid Cloud Computing  Public Cloud Service Agreements, V2  Cloud Security Standards, V2  IoT Ref. Architecture  e-Commerce Ref. Architecture  Impact of Cloud Computing on Healthcare, V2  Enterprise Social Collaboration Ref. Architecture 2015 Deliverables  Web App Hosting Ref. Architecture  Mobile Ref. Architecture  Big Data & Analytics Ref. Architecture  Security for Cloud Computing, V2  Practical Guide to Cloud SLAs, V2  Practical Guide to PaaS 2013/2014 Deliverables  Convergence of Social, Mobile, Cloud  Analysis of Public Cloud SLAs  Cloud Security Standards  Migrating Apps to Public Cloud Services  Social Business in the Cloud  Deploying Big Data in the Cloud  Practical Guide to Cloud Computing, V2  Migrating Apps: Performance Rqmnts  Cloud Interoperability/Portability
  • 6. History of This Effort  March 2015: initial request from an OMG member  June 2015: first OMG Data Residency WG meeting (Berlin)  Sep.-Dec. 2015: 2nd and 3rd meetings, prepared an RFI  March-June 2016: 4th - 5th meetings, processed RFI results, decide to create a discussion paper as first deliverable  Sep.-Dec. 2016: 6th - 7th meetings, preliminary draft of discussion paper, agreement to collaborate with CSCC and issue two separate but almost identical papers  Q1 ‘17: collect contributions, edit paper, go the OMG approval process (8th meeting, Washington DC)  April ‘17: create CSCC companion white paper, review process, release  May ‘17: press releases and this webinar  June ‘17: working group meeting and tutorial in Brussels 6
  • 7. The Two Papers  Both about 35 pages  CSCC paper omits the history of the OMG effort and the discussion of OMG’s potential roadmap for standards 7
  • 8. Data Residency Definition, Scope  There are a number of definitions of data residency – as is usually the case in a new domain  We propose this definition: Data residency is the set of issues and practices related to the location of data and metadata, the movement of (meta)data across geographies and jurisdictions, and the protection of that (meta)data against unintended access and other location- related risks  Scope • Not just about the protection of personally identifiable information (PII) • Also concerns the right to move “sovereign” data, such as oil reserves data; international licensing of genomics data; distribution of biometrics data for security purposes; etc. 8
  • 9. Risks Related to Data Residency  Violating of a government law or regulation  Unintended/unauthorized access by a foreign organization  Demand by a foreign government’s authorities to access data  Having to provide a foreign government with secret keys to inspect encrypted data  Violation of “domestic content” policies  Increased cost of doing business in a given country  Inability of a multinational organization to provide shared employee services, such as payroll and benefits  Losing business to a local competitor  Inability to qualify for government or private contracts  Multiplication of locally managed data centers with smaller and less experienced security teams  Diminished disaster recovery capabilities  Delays in business transformation and technology modernization  Consumer and citizen mistrust of technology, organizations, governments 9
  • 10. Challenges: Example 1  Migration to the cloud • Am I allowed to put my data in the cloud if it is going to be stored in another country, or if there is a possibility that the cloud provider might move it to another country later without my knowledge or consent? • Regulations may be unclear • Regulations may be used as a rationale to reject the cloud… even when they do not really exist (Mexico government example) • Authorization may require high-level approval (Danish bank example) 10
  • 11. Challenges: Example 2  Genomic data sets • Can I license a data set from another country to perform research on a larger sample? • How do I prove to regulators that the data no longer contains personally identifiable information (PII)? 11
  • 12. Challenges: Example 3  Processing data on petroleum reserves • In countries with national companies, subsurface data is often considered a national asset • Exploration is subcontracted to foreign companies Can it remotely control an automated drilling operation from a monitoring center in another country? Can it move data to a foreign location in order to do better analytics? If it returns data interpreted in a center in another country, does it have to pay duties on the added value of those results? 12
  • 13. Challenges: Example 4  Law enforcement vs. personal communication • A US citizen is suspected of criminal activity • Some evidence may reside in their e-mail stored in the cloud by a US provider • However, the data is stored outside of the US, in a country with strong data protection laws • Which law prevails? Is the provider “damned if they do, damned if they don’t” give the US government access to the data? 13
  • 15. Laws and Regulations  Multiple, inconsistent, overlapping, and still evolving laws and regulations around the world  Range from non-existent to severe  Sometimes (but not always) apply to government data / public records, not to private companies’ data  The European Union’s General Data Protection Regulation (GDPR) of 2016 is among the most comprehensive  Multiple motivations behind the laws: • Protecting the privacy of citizens • Enabling police and tax authorities to inspect data • Protectionism – force companies to create domestic facilities • Monetize the flow of data 15
  • 16. Some Country-Specific Cases  See Appendix in the papers – but remember that the situation keeps evolving • Australia • Canada • China • Denmark • European Union • France • Germany • India • Indonesia • Korea • Malaysia • Netherlands • Nigeria • Norway • Russia • Turkey • Ukraine • United States • Venezuela • Vietnam 16
  • 17. Existing Relevant Standards  There is currently no standard that deals specifically with data residency  Data residency is related to the security and privacy aspects of • Several NIST publications (800-144, 500-299, 1500) • Several ISO/IEC standards (27001, 27017, 27018) • The work of the CSA’s International Standardization Council (ISC) • Work being considered in ISO/IEC JTC 1/SC 38 • The “Voluntary Data Protection Code” of CISPE (Cloud Infrastructure Service Providers in Europe)  Some technical standards may prove useful • Information Exchange Framework (IEF) – OMG • Data Tagging and Labeling – OMG work in progress • XACML – eXtensible Access Control Markup Language • ORDL – Open Digital Rights Language 17
  • 18. What is Needed  Documentation and education • These papers are a good start  Cataloguing of laws and regulations • See the Digital Trade Database from the European Centre for International Political Economy (ECIPE)  Formal description of laws and regulations • Because natural language is ambiguous and does not lend itself to automated policy enforcement  Formal description of the content of data • Extension of data tagging and labeling or IEF policy  With both of the above, we might be able to better manage residency  Several difficult challenges • Willingness to participate – requires recognizing there are issues • Implementation may be difficult due to legacy systems 18
  • 19. Summary and How to Participate  Data residency is a serious challenge for suppliers as well as users • Can (and already does) hurt the ability to do business  It may well get worse before it gets better  Organizations need to learn about it and develop business and technical approaches  OMG is looking into what standards may help • Metadata describing data location constraints? • Formal description of data residency laws and regulations?  Call to action • Participate in OMG Data Residency Working Group • and/or in the various Working Groups of the CSCC 19
  • 20. Thanks – Q&A Time More information at www.omg.org/data-residency and www.cloud-council.org/resource-hub 20