Compliance Complexity and the Almighty Audit

By Nicole Hemsoth

June 12, 2010

There are a host of issues that often get wrapped into cloud security discussions ranging from network and data security to the protection of private health and financial information, but for many, security means more than just knowing data is security, it means being able to prove it. In great detail, no less.

Growing regulation governing mounting data complicates efforts for technology to keep pace with the law, which for some industries, barriers to migration for private clouds alone can create enormous challenges. What this all boils down to is compliance and what that can be pared down to, at least on the individual enterprise level, is the notion of the much-dreaded audit.

Audits are not a particular concern for all HPC applications in the cloud, certainly, but for sectors like financial services, this concern is enough to dissuade broad adoption of any cloud model — no matter how tenuous it might be at first. Furthermore, since regulation is swift and revisions are frequent, organizations are understandably concerned about how new regulation might influence their current IT environment.

Grounded Concerns Versus Lofty IT Goals

LogLogic, a San Jose, Calif.-based company offering security and log management services, recently released a report that suggested enterprises are focused on security and compliance over new technology investments. More specifically, LogLogic discussed how financial services firms in particular are still hesitant to adopt cloud — no matter what model or approach. According to their survey, “more than 75 percent of respondents are concerned about increasing government regulation” since, shall we say “enhancement” of existing regulatory measures further complicates IT at every level for those who are under the most compliance-related scrutiny.

Although the report did not go into deep specific differences between private and public clouds, it does highlight some of the critical barriers to wider cloud adoption in industries with intense regulation considerations underpinning nearly every single element of IT. The report was based on surveys with members of some of the largest international banking giants as well as numerous investment and insurance firms. It found, not surprisingly, that security was one of the biggest concerns but wrapped up in that overarching (and valid) concern are the more specific matters of transparency.

Compliance and Security Concern Trump Cloud Investments

The financial services sector is one of the most compelling to watch because they have historically been routine early adopters of technological innovation. Throw in a network, however, and the situation changes dramatically, especially with the increasingly stringent regulations that apply to specific HPC applications in the cloud that deal with personal financial and health information, for example. However, with penalities that are stiff enough to bury companies that are not compliant, the obvious driver here is keeping pace with regulation, certainly not investing in “new” technologies and ways of handling IT that might throw them into ruin.

I talked with LogLogic’s Bill Roth and Lex Van Den Berghe about some of the more specific concerns and trends that reflect the hesitancy of the financial services sector and the word that kept cropping up was “audit.” In addition to more generalized issues about data security as a whole, concerns about audits cannot be underestimated.

As Bill Roth of LogLogic noted, “In terms of the level of security required for those in the financial services industry since they’re so heavily regulated, cloud-based providers and HPC in the cloud in general still does not have the security regimes needed to satisfy a lot of regulators.” This statement is not based exclusively on the findings of this one report; the company has carried out similar studies with similar conclusions in the life sciences as well with focus on HIPPA compliance with similar conclusions.

It All Comes Down to the Audit

While LogLogic has a direct stake in helping firms overcome auditing angst, the points Roth and Van Den Berghe makes are difficult to take issue with. When asked about what the primary concern was for those they spoke with during their study, there was no question that fear of the almighty audit and its associated fines was enough to make any enterprise think twice about sending their business into a network.

As Bill Roth notes, “At the fundamental business level it is all about audits; the survey calls out that the two most important regulatory regimes people are concerned about are Sarbanes-Oxley and PCIS for credit card processing. SOX is governmental, PCIS is industry-based — people’s biggest concern is not being audited, not getting fined.

An example of the biggest requirements (two biggest) are section 404 of SOX as well as PCI rule 10. If you go to the site, the list of regulations looks scary but it’s not that much (changing default passwords on firewall) but as rule 10 states — you have to log everything; among other things, you are required to log all state changes to your firewalls so when you have an audit, there is a clear audit trail of what went on in the case of a breach.”

Are New Regulations Taking the Cloud into Account?

There is a new version of PCI specific 1.3 is coming out for final draft June 30 that has been modified to address the cloud specifically and to tighten areas of concern about wireless networking, tokenization and cloud as an overarching concept. Tokenization, which refers to personal information being stored as a token rather than a directly-accessible tide of information, is an important issue in current debates about cloud and compliance since it means that privileged data can be stored in a more secure offsite location. Elements of that are taken into consideration to allay concerns about where data is being stored, which helps appease auditors and lawyers.

Bill Roth added to this thought by discussing the HITECH Act of 2009, which just went into effect in February and now adds stiff penalties in the form of dramatic fines and now jail time to the direct misuse and mishandling of personal information. “The effect of this has been both good and bad — laws like this have a chilling effect on the move to cloud for more conservative companies who will now look several times before they engage, but it also motivates the rest of us to do better on security and auditing frameworks and technologies to roll things out sooner — the point is, no one wants to wear an orange jumpsuit.”

It’s Not Just the Enterprise That Should Be Worried…

There is no doubt that the increase in regulation is going to affect far more than the enterprises as they make sure they are compliant. Cloud vendors are going to face mounting challenges as well as they tailor their agreements to be suitable for those businesses who have made the brave decision to put some of their operations into the public cloud in particular.

Chris Hoff, a network and information security architecture expert who currently serves as the Director of Cloud and Virtualization and Data Center Solutions at Cisco Systems stated in January, “Almost all of the cloud providers I have spoken to are being absolutely hammered by customers acting on their ‘right to audit’ clauses in contracts. This is a change in behavior. Most customers have traditionally not acted on these clauses as they used them more as contingency/insurance options. With the uncertainty relating to confidentiality, integrity and availability of cloud services, this is no more. Cloud providers continue to lament that they really, really want a standardized way of responding to these requests.”

Compliance and auditing over time could mean that the ever-so attractive cloud pricing models that have brought some on board already could start to increase as cloud vendors keep pace with the staffing and support required to contend with their end of agreements.

The ultimate question becomes to what degree will compliance alone negate the benefits of using clouds in the first place? And moreover, why should firms bother with clouds when they have much bigger metaphorical fish to fry?

For more on the regulatory environment for another sector that this is of particular importance to, the life sciences industry, check out some of the more recent posts from Bruce Maches.

Subscribe to HPCwire's Weekly Update!

Be the most informed person in the room! Stay ahead of the tech trends with industy updates delivered to you every week!

Women Coders from Russia, Italy, and Poland Top Study

January 17, 2017

According to a study posted on HackerRank today the best women coders as judged by performance on HackerRank challenges come from Russia, Italy, and Poland. Read more…

By John Russell

Spurred by Global Ambitions, Inspur in Joint HPC Deal with DDN

January 17, 2017

Inspur, the fast-growth cloud computing and server vendor from China that has several systems on the current Top500 list, and DDN, a leader in high-end storage, have announced a joint sales and marketing agreement to produce solutions based on DDN storage platforms integrated with servers, networking, software and services from Inspur. Read more…

By Doug Black

Weekly Twitter Roundup (Jan. 12, 2017)

January 12, 2017

Here at HPCwire, we aim to keep the HPC community apprised of the most relevant and interesting news items that get tweeted throughout the week. Read more…

By Thomas Ayres

NSF Seeks Input on Cyberinfrastructure Advances Needed

January 12, 2017

In cased you missed it, the National Science Foundation posted a “Dear Colleague Letter” (DCL) late last week seeking input on needs for the next generation of cyberinfrastructure to support science and engineering. Read more…

By John Russell

HPE Extreme Performance Solutions

Remote Visualization: An Integral Technology for Upstream Oil & Gas

As the exploration and production (E&P) of natural resources evolves into an even more complex and vital task, visualization technology has become integral for the upstream oil and gas industry. Read more…

NSF Approves Bridges Phase 2 Upgrade for Broader Research Use

January 12, 2017

The recently completed phase 2 upgrade of the Bridges supercomputer at the Pittsburgh Supercomputing Center (PSC) has been approved by the National Science Foundation (NSF) making it now available for research allocations to the national scientific community, according to an announcement posted this week on the XSEDE web site. Read more…

By John Russell

Clemson Software Optimizes Big Data Transfers

January 11, 2017

Data-intensive science is not a new phenomenon as the high-energy physics and astrophysics communities can certainly attest, but today more and more scientists are facing steep data and throughput challenges fueled by soaring data volumes and the demands of global-scale collaboration. Read more…

By Tiffany Trader

For IBM/OpenPOWER: Success in 2017 = (Volume) Sales

January 11, 2017

To a large degree IBM and the OpenPOWER Foundation have done what they said they would – assembling a substantial and growing ecosystem and bringing Power-based products to market, all in about three years. Read more…

By John Russell

UberCloud Cites Progress in HPC Cloud Computing

January 10, 2017

200 HPC cloud experiments, 80 case studies, and a ton of hands-on experience gained, that’s the harvest of four years of UberCloud HPC Experiments. Read more…

By Wolfgang Gentzsch and Burak Yenier

Spurred by Global Ambitions, Inspur in Joint HPC Deal with DDN

January 17, 2017

Inspur, the fast-growth cloud computing and server vendor from China that has several systems on the current Top500 list, and DDN, a leader in high-end storage, have announced a joint sales and marketing agreement to produce solutions based on DDN storage platforms integrated with servers, networking, software and services from Inspur. Read more…

By Doug Black

For IBM/OpenPOWER: Success in 2017 = (Volume) Sales

January 11, 2017

To a large degree IBM and the OpenPOWER Foundation have done what they said they would – assembling a substantial and growing ecosystem and bringing Power-based products to market, all in about three years. Read more…

By John Russell

UberCloud Cites Progress in HPC Cloud Computing

January 10, 2017

200 HPC cloud experiments, 80 case studies, and a ton of hands-on experience gained, that’s the harvest of four years of UberCloud HPC Experiments. Read more…

By Wolfgang Gentzsch and Burak Yenier

A Conversation with Women in HPC Director Toni Collis

January 6, 2017

In this SC16 video interview, HPCwire Managing Editor Tiffany Trader sits down with Toni Collis, the director and founder of the Women in HPC (WHPC) network, to discuss the strides made since the organization’s debut in 2014. Read more…

By Tiffany Trader

BioTeam’s Berman Charts 2017 HPC Trends in Life Sciences

January 4, 2017

Twenty years ago high performance computing was nearly absent from life sciences. Today it’s used throughout life sciences and biomedical research. Genomics and the data deluge from modern lab instruments are the main drivers, but so is the longer-term desire to perform predictive simulation in support of Precision Medicine (PM). There’s even a specialized life sciences supercomputer, ‘Anton’ from D.E. Shaw Research, and the Pittsburgh Supercomputing Center is standing up its second Anton 2 and actively soliciting project proposals. There’s a lot going on. Read more…

By John Russell

Fast Rewind: 2016 Was a Wild Ride for HPC

December 23, 2016

Some years quietly sneak by – 2016 not so much. It’s safe to say there are always forces reshaping the HPC landscape but this year’s bunch seemed like a noisy lot. Among the noisemakers: TaihuLight, DGX-1/Pascal, Dell EMC & HPE-SGI et al., KNL to market, OPA-IB chest thumping, Fujitsu-ARM, new U.S. President-elect, BREXIT, JR’s Intel Exit, Exascale (whatever that means now), NCSA@30, whither NSCI, Deep Learning mania, HPC identity crisis…You get the picture. Read more…

By John Russell

AWI Uses New Cray Cluster for Earth Sciences and Bioinformatics

December 22, 2016

The Alfred Wegener Institute, Helmholtz Centre for Polar and Marine Research (AWI), headquartered in Bremerhaven, Germany, is one of the country's premier research institutes within the Helmholtz Association of German Research Centres, and is an internationally respected center of expertise for polar and marine research. In November 2015, AWI awarded Cray a contract to install a cluster supercomputer that would help the institute accelerate time to discovery. Now the effort is starting to pay off. Read more…

By Linda Barney

Addison Snell: The ‘Wild West’ of HPC Disaggregation

December 16, 2016

We caught up with Addison Snell, CEO of HPC industry watcher Intersect360, at SC16 last month, and Snell had his expected, extensive list of insights into trends driving advanced-scale technology in both the commercial and research sectors. Read more…

By Doug Black

AWS Beats Azure to K80 General Availability

September 30, 2016

Amazon Web Services has seeded its cloud with Nvidia Tesla K80 GPUs to meet the growing demand for accelerated computing across an increasingly-diverse range of workloads. The P2 instance family is a welcome addition for compute- and data-focused users who were growing frustrated with the performance limitations of Amazon's G2 instances, which are backed by three-year-old Nvidia GRID K520 graphics cards. Read more…

By Tiffany Trader

US, China Vie for Supercomputing Supremacy

November 14, 2016

The 48th edition of the TOP500 list is fresh off the presses and while there is no new number one system, as previously teased by China, there are a number of notable entrants from the US and around the world and significant trends to report on. Read more…

By Tiffany Trader

Vectors: How the Old Became New Again in Supercomputing

September 26, 2016

Vector instructions, once a powerful performance innovation of supercomputing in the 1970s and 1980s became an obsolete technology in the 1990s. But like the mythical phoenix bird, vector instructions have arisen from the ashes. Here is the history of a technology that went from new to old then back to new. Read more…

By Lynd Stringer

For IBM/OpenPOWER: Success in 2017 = (Volume) Sales

January 11, 2017

To a large degree IBM and the OpenPOWER Foundation have done what they said they would – assembling a substantial and growing ecosystem and bringing Power-based products to market, all in about three years. Read more…

By John Russell

Container App ‘Singularity’ Eases Scientific Computing

October 20, 2016

HPC container platform Singularity is just six months out from its 1.0 release but already is making inroads across the HPC research landscape. It's in use at Lawrence Berkeley National Laboratory (LBNL), where Singularity founder Gregory Kurtzer has worked in the High Performance Computing Services (HPCS) group for 16 years. Read more…

By Tiffany Trader

Dell EMC Engineers Strategy to Democratize HPC

September 29, 2016

The freshly minted Dell EMC division of Dell Technologies is on a mission to take HPC mainstream with a strategy that hinges on engineered solutions, beginning with a focus on three industry verticals: manufacturing, research and life sciences. "Unlike traditional HPC where everybody bought parts, assembled parts and ran the workloads and did iterative engineering, we want folks to focus on time to innovation and let us worry about the infrastructure," said Jim Ganthier, senior vice president, validated solutions organization at Dell EMC Converged Platforms Solution Division. Read more…

By Tiffany Trader

Lighting up Aurora: Behind the Scenes at the Creation of the DOE’s Upcoming 200 Petaflops Supercomputer

December 1, 2016

In April 2015, U.S. Department of Energy Undersecretary Franklin Orr announced that Intel would be the prime contractor for Aurora: Read more…

By Jan Rowell

Enlisting Deep Learning in the War on Cancer

December 7, 2016

Sometime in Q2 2017 the first ‘results’ of the Joint Design of Advanced Computing Solutions for Cancer (JDACS4C) will become publicly available according to Rick Stevens. He leads one of three JDACS4C pilot projects pressing deep learning (DL) into service in the War on Cancer. Read more…

By John Russell

Leading Solution Providers

D-Wave SC16 Update: What’s Bo Ewald Saying These Days

November 18, 2016

Tucked in a back section of the SC16 exhibit hall, quantum computing pioneer D-Wave has been talking up its new 2000-qubit processor announced in September. Forget for a moment the criticism sometimes aimed at D-Wave. This small Canadian company has sold several machines including, for example, ones to Lockheed and NASA, and has worked with Google on mapping machine learning problems to quantum computing. In July Los Alamos National Laboratory took possession of a 1000-quibit D-Wave 2X system that LANL ordered a year ago around the time of SC15. Read more…

By John Russell

CPU Benchmarking: Haswell Versus POWER8

June 2, 2015

With OpenPOWER activity ramping up and IBM’s prominent role in the upcoming DOE machines Summit and Sierra, it’s a good time to look at how the IBM POWER CPU stacks up against the x86 Xeon Haswell CPU from Intel. Read more…

By Tiffany Trader

Nvidia Sees Bright Future for AI Supercomputing

November 23, 2016

Graphics chipmaker Nvidia made a strong showing at SC16 in Salt Lake City last week. Read more…

By Tiffany Trader

New Genomics Pipeline Combines AWS, Local HPC, and Supercomputing

September 22, 2016

Declining DNA sequencing costs and the rush to do whole genome sequencing (WGS) of large cohort populations – think 5000 subjects now, but many more thousands soon – presents a formidable computational challenge to researchers attempting to make sense of large cohort datasets. Read more…

By John Russell

Beyond von Neumann, Neuromorphic Computing Steadily Advances

March 21, 2016

Neuromorphic computing – brain inspired computing – has long been a tantalizing goal. The human brain does with around 20 watts what supercomputers do with megawatts. And power consumption isn’t the only difference. Fundamentally, brains ‘think differently’ than the von Neumann architecture-based computers. While neuromorphic computing progress has been intriguing, it has still not proven very practical. Read more…

By John Russell

The Exascale Computing Project Awards $39.8M to 22 Projects

September 7, 2016

The Department of Energy’s Exascale Computing Project (ECP) hit an important milestone today with the announcement of its first round of funding, moving the nation closer to its goal of reaching capable exascale computing by 2023. Read more…

By Tiffany Trader

Dell Knights Landing Machine Sets New STAC Records

November 2, 2016

The Securities Technology Analysis Center, commonly known as STAC, has released a new report characterizing the performance of the Knight Landing-based Dell PowerEdge C6320p server on the STAC-A2 benchmarking suite, widely used by the financial services industry to test and evaluate computing platforms. The Dell machine has set new records for both the baseline Greeks benchmark and the large Greeks benchmark. Read more…

By Tiffany Trader

What Knights Landing Is Not

June 18, 2016

As we get ready to launch the newest member of the Intel Xeon Phi family, code named Knights Landing, it is natural that there be some questions and potentially some confusion. Read more…

By James Reinders, Intel

  • arrow
  • Click Here for More Headlines
  • arrow
Share This