SlideShare une entreprise Scribd logo
1  sur  2
Télécharger pour lire hors ligne
Is your cloud GDPR compliant?
25th
May 2018, Friday is nothing less scary for many as Friday the 13th
. Well, at least for
those who are struggling to meet the compliance requirements of GDPR.
It was revealed in the RSA Conference 2018 that 97 percent of worldwide IT professionals are using
some type of cloud service. It further revealed that more than 80% organizations store sensitive data on
public cloud. Right from customer information, information about IPs, network pass cards, personal staff
data and more – all of it is available on the cloud. Organizations trust their cloud service providers and
are unlikely to decrease their cloud investment in the years to come. Malware and other security
concerns continue to mar the adoption of cloud but if a cloud service provider follows some of industry’s
best practices, it is unlikely that they will have a dire situation as far as cloud security is concerned.
https://cdn.pixabay.com/photo/2018/02/11/23/45/cloud-3147119_960_720.png
If cloud service providers follow DevOps and DevSecOps can help reduce the data breaches and improve
code quality. Automation is also known to reduce the exploits and vulnerabilities. With a single platform
to manage multiple cloud services can help reduce the complexity of managing security.
It looks like that just encryption and authentication are not enough to control data breaches. These are
just basic security practices that are inadequate to protect workloads. As we are already aware that EU
has taken a huge step to enforce data protection. The General Data Protection Agreement (GDPR) is
EU’s move in the direction. On 25th
May 2018, GDPR tenet will become effective and will give the right
to an individual to protect his/her data.
GDPR is expected to adversely affect public cloud service providers and teams dealing in enterprise
compliance in that region. Every business must meet a threshold requirement to be GDPR compliant. If
anyone breaches GDPR requirements, the fine is quite high (in Euros of course). There are many
companies that provide services across the globe and they must meet the requirements of GDPR as well.
For example, AWS and Google, major public cloud service providers, are taking some serious action to
meet the GDPR requirements. But unfortunately, the use of compliant cloud service will alone not
suffice.
The basic requirement of GDPR is for organizations that initiate the personal data collection or are cloud
environment operators should be able to provide proof that data is protected at all stages that is while it
is in transit or processed or stored.
Key steps to ensure GDPR compliance
• Perform a thorough data protection audit and ensure that the primary cloud provider using on-
premises or other applications are compliant to the need of GDPR
• You must own the encryption keys for data sets that your business owns. Even backup encryption
requires you to review the compliance report from your software vendor, if necessary
• Apply all possible encryption and authentication standards to all the personal data of users that you
might be dealing with. Most of the cloud service providers will provide you with the apt tools and
services that can help with this
• You must be careful about who can access the personal data. Limit the access of sensitive data and
create stricter norms for fewer eyes for the user data
• You can also deploy software that can help you to manage accessibility and detect any intruders to
the software. It is nearly impossible to stop all attacks but it can detect a few.
• Take help from specialized service providers who can help your business to comply with the GDPR
standards. It might cost you a fee but it might be better than paying a hefty non-compliance fee
GDPR is a commitment and meeting its requirements need all departments to be involved. As far as your
cloud hosting service provider is concerned, you must have a contract with them that defines all the
security standards and requirements clearly. If you wish to discuss more about GDPR or its impact, we
are waiting to hear from you.
To read it online, please click here: http://www.anythingcloud.com/blog/cloud-gdpr-compliant/

Contenu connexe

Tendances

Tendances (20)

MITRE ATT&CKcon 2.0: ATT&CK Updates - ICS; Otis Alexander, MITRE
MITRE ATT&CKcon 2.0: ATT&CK Updates - ICS; Otis Alexander, MITREMITRE ATT&CKcon 2.0: ATT&CK Updates - ICS; Otis Alexander, MITRE
MITRE ATT&CKcon 2.0: ATT&CK Updates - ICS; Otis Alexander, MITRE
 
Le soluzioni tecnologiche a supporto della normativa GDPR
Le soluzioni tecnologiche a supporto della normativa GDPRLe soluzioni tecnologiche a supporto della normativa GDPR
Le soluzioni tecnologiche a supporto della normativa GDPR
 
June 2016 Worldwide Netskope Cloud Report
June 2016 Worldwide Netskope Cloud Report June 2016 Worldwide Netskope Cloud Report
June 2016 Worldwide Netskope Cloud Report
 
Azure Privacy & GDPR @ Service Management World
Azure Privacy & GDPR @ Service Management WorldAzure Privacy & GDPR @ Service Management World
Azure Privacy & GDPR @ Service Management World
 
Data privacy and security in uae
Data privacy and security in uaeData privacy and security in uae
Data privacy and security in uae
 
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
 
Cisco Connect 2018 Singapore - Data center transformation a customer perspec...
Cisco Connect 2018 Singapore -  Data center transformation a customer perspec...Cisco Connect 2018 Singapore -  Data center transformation a customer perspec...
Cisco Connect 2018 Singapore - Data center transformation a customer perspec...
 
Nimbox presentation
Nimbox presentationNimbox presentation
Nimbox presentation
 
The EU General Protection Regulation and how Oracle can help
The EU General Protection Regulation and how Oracle can help The EU General Protection Regulation and how Oracle can help
The EU General Protection Regulation and how Oracle can help
 
Splunk: How Machine Data Supports GDPR Compliance
Splunk: How Machine Data Supports GDPR ComplianceSplunk: How Machine Data Supports GDPR Compliance
Splunk: How Machine Data Supports GDPR Compliance
 
Convince your board: How to prepare your business for List X
Convince your board: How to prepare your business for List XConvince your board: How to prepare your business for List X
Convince your board: How to prepare your business for List X
 
MITRE ATT&CKcon 2.0: ATT&CK Updates - Controls Mapping; Mike Long, MITRE
MITRE ATT&CKcon 2.0: ATT&CK Updates - Controls Mapping; Mike Long, MITREMITRE ATT&CKcon 2.0: ATT&CK Updates - Controls Mapping; Mike Long, MITRE
MITRE ATT&CKcon 2.0: ATT&CK Updates - Controls Mapping; Mike Long, MITRE
 
Cybersecurity 2020 the biggest threats to watch out for
Cybersecurity 2020 the biggest threats to watch out forCybersecurity 2020 the biggest threats to watch out for
Cybersecurity 2020 the biggest threats to watch out for
 
The 1% Who Can Take Down your Organization
The 1% Who Can Take Down your OrganizationThe 1% Who Can Take Down your Organization
The 1% Who Can Take Down your Organization
 
The Riskiest Industries in the Cloud
The Riskiest Industries in the CloudThe Riskiest Industries in the Cloud
The Riskiest Industries in the Cloud
 
GDPR in the Digital World
GDPR in the Digital WorldGDPR in the Digital World
GDPR in the Digital World
 
EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance
 
What the GDPR Means for your Cybersecurity Strategy [Webinar Slides]
What the GDPR Means for your Cybersecurity Strategy [Webinar Slides]What the GDPR Means for your Cybersecurity Strategy [Webinar Slides]
What the GDPR Means for your Cybersecurity Strategy [Webinar Slides]
 
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
 
Benchmarking Your GDPR Compliance: Will You Make the Grade? [TrustArc Webinar...
Benchmarking Your GDPR Compliance: Will You Make the Grade? [TrustArc Webinar...Benchmarking Your GDPR Compliance: Will You Make the Grade? [TrustArc Webinar...
Benchmarking Your GDPR Compliance: Will You Make the Grade? [TrustArc Webinar...
 

Similaire à Is your cloud GDPR compliant?

C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
guestd7fc9c
 
Understanding Minimizing And Mitigating Risk In Cloud Computing
Understanding Minimizing And Mitigating Risk In Cloud ComputingUnderstanding Minimizing And Mitigating Risk In Cloud Computing
Understanding Minimizing And Mitigating Risk In Cloud Computing
Janine Anthony Bowen, Esq.
 
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009 Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
EuroCloud
 

Similaire à Is your cloud GDPR compliant? (20)

Keep Calm and GDPR
Keep Calm and GDPRKeep Calm and GDPR
Keep Calm and GDPR
 
Top gdpr assessment tools
Top  gdpr assessment toolsTop  gdpr assessment tools
Top gdpr assessment tools
 
Symantec Webinar Part 2 of 6 GDPR Compliance
Symantec Webinar Part 2 of 6 GDPR ComplianceSymantec Webinar Part 2 of 6 GDPR Compliance
Symantec Webinar Part 2 of 6 GDPR Compliance
 
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
 
Understanding Minimizing And Mitigating Risk In Cloud Computing
Understanding Minimizing And Mitigating Risk In Cloud ComputingUnderstanding Minimizing And Mitigating Risk In Cloud Computing
Understanding Minimizing And Mitigating Risk In Cloud Computing
 
DevOps vs GDPR: How to Comply and Stay Agile
DevOps vs GDPR: How to Comply and Stay AgileDevOps vs GDPR: How to Comply and Stay Agile
DevOps vs GDPR: How to Comply and Stay Agile
 
Securing data in the cloud: A challenge for UK Law Firms
Securing data in the cloud: A challenge for UK Law FirmsSecuring data in the cloud: A challenge for UK Law Firms
Securing data in the cloud: A challenge for UK Law Firms
 
Five strategies for gdpr compliance
Five strategies for gdpr complianceFive strategies for gdpr compliance
Five strategies for gdpr compliance
 
Cutting To The Chase: Cloud From A Customers Perspective
Cutting To The Chase: Cloud From A Customers PerspectiveCutting To The Chase: Cloud From A Customers Perspective
Cutting To The Chase: Cloud From A Customers Perspective
 
4.5.cloud security
4.5.cloud security4.5.cloud security
4.5.cloud security
 
Cloud service providers in pune
Cloud service providers in puneCloud service providers in pune
Cloud service providers in pune
 
Cloud data security and GDPR compliance
Cloud data security and GDPR complianceCloud data security and GDPR compliance
Cloud data security and GDPR compliance
 
10 Good Reasons: NetApp for GDPR
10 Good Reasons: NetApp for GDPR10 Good Reasons: NetApp for GDPR
10 Good Reasons: NetApp for GDPR
 
Qubole GDPR Security and Compliance Whitepaper
Qubole GDPR Security and Compliance Whitepaper Qubole GDPR Security and Compliance Whitepaper
Qubole GDPR Security and Compliance Whitepaper
 
Regulatory and compliance forum cloud computing for law firms
Regulatory and compliance forum   cloud computing for law firmsRegulatory and compliance forum   cloud computing for law firms
Regulatory and compliance forum cloud computing for law firms
 
Cloud adoption in the EU - and analyst's perspective (revised)
Cloud adoption in the EU - and analyst's perspective (revised)Cloud adoption in the EU - and analyst's perspective (revised)
Cloud adoption in the EU - and analyst's perspective (revised)
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Compliance
 
Symantec Webinar Part 3 of 6 How to Tackle Data Protection Risk in Time for G...
Symantec Webinar Part 3 of 6 How to Tackle Data Protection Risk in Time for G...Symantec Webinar Part 3 of 6 How to Tackle Data Protection Risk in Time for G...
Symantec Webinar Part 3 of 6 How to Tackle Data Protection Risk in Time for G...
 
What is cloud computing report
What is cloud computing reportWhat is cloud computing report
What is cloud computing report
 
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009 Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
 

Dernier

CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
giselly40
 

Dernier (20)

Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdf
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 

Is your cloud GDPR compliant?

  • 1. Is your cloud GDPR compliant? 25th May 2018, Friday is nothing less scary for many as Friday the 13th . Well, at least for those who are struggling to meet the compliance requirements of GDPR. It was revealed in the RSA Conference 2018 that 97 percent of worldwide IT professionals are using some type of cloud service. It further revealed that more than 80% organizations store sensitive data on public cloud. Right from customer information, information about IPs, network pass cards, personal staff data and more – all of it is available on the cloud. Organizations trust their cloud service providers and are unlikely to decrease their cloud investment in the years to come. Malware and other security concerns continue to mar the adoption of cloud but if a cloud service provider follows some of industry’s best practices, it is unlikely that they will have a dire situation as far as cloud security is concerned. https://cdn.pixabay.com/photo/2018/02/11/23/45/cloud-3147119_960_720.png If cloud service providers follow DevOps and DevSecOps can help reduce the data breaches and improve code quality. Automation is also known to reduce the exploits and vulnerabilities. With a single platform to manage multiple cloud services can help reduce the complexity of managing security. It looks like that just encryption and authentication are not enough to control data breaches. These are just basic security practices that are inadequate to protect workloads. As we are already aware that EU has taken a huge step to enforce data protection. The General Data Protection Agreement (GDPR) is EU’s move in the direction. On 25th May 2018, GDPR tenet will become effective and will give the right to an individual to protect his/her data.
  • 2. GDPR is expected to adversely affect public cloud service providers and teams dealing in enterprise compliance in that region. Every business must meet a threshold requirement to be GDPR compliant. If anyone breaches GDPR requirements, the fine is quite high (in Euros of course). There are many companies that provide services across the globe and they must meet the requirements of GDPR as well. For example, AWS and Google, major public cloud service providers, are taking some serious action to meet the GDPR requirements. But unfortunately, the use of compliant cloud service will alone not suffice. The basic requirement of GDPR is for organizations that initiate the personal data collection or are cloud environment operators should be able to provide proof that data is protected at all stages that is while it is in transit or processed or stored. Key steps to ensure GDPR compliance • Perform a thorough data protection audit and ensure that the primary cloud provider using on- premises or other applications are compliant to the need of GDPR • You must own the encryption keys for data sets that your business owns. Even backup encryption requires you to review the compliance report from your software vendor, if necessary • Apply all possible encryption and authentication standards to all the personal data of users that you might be dealing with. Most of the cloud service providers will provide you with the apt tools and services that can help with this • You must be careful about who can access the personal data. Limit the access of sensitive data and create stricter norms for fewer eyes for the user data • You can also deploy software that can help you to manage accessibility and detect any intruders to the software. It is nearly impossible to stop all attacks but it can detect a few. • Take help from specialized service providers who can help your business to comply with the GDPR standards. It might cost you a fee but it might be better than paying a hefty non-compliance fee GDPR is a commitment and meeting its requirements need all departments to be involved. As far as your cloud hosting service provider is concerned, you must have a contract with them that defines all the security standards and requirements clearly. If you wish to discuss more about GDPR or its impact, we are waiting to hear from you. To read it online, please click here: http://www.anythingcloud.com/blog/cloud-gdpr-compliant/