Compliance Complexities Challenge Cloud Adoption

By Shawn R. Chaput

March 31, 2011

Cloud and infrastructure compliance expert, Shawn R. Chaput, lends his understanding of the range of regulatory and other constraints that affect a number of users of high-performance computing. This week he took a look at the challenges of compliance burdens and what to consider when weighing cloud computing options based on lessons learned during his compliance consulting experiences. Although not intended to provide a comprehensive listing of considerations, it should provide some guidance as to some of the more commonplace examples of items warranting specific attention.

In recent experiences helping decision makers evaluate infrastructure options, we’ve encountered several clients who have decided that, given the specific sensitivity of data, the related systems should be hosted by professional hosting organizations well versed in the security of systems.

As it turns out, these data centers offer private cloud infrastructure as a service, which seemed particularly desirable to them. One of the clients in particular was looking for a provider who could guarantee the data would continue to reside within Canada as prescribed by provincial legislation as the data in question was health-related. In this specific example, this requirement became so difficult to accomplish that all other requirements seemingly fell by the wayside.

Ultimately, they found a private cloud provider but the level of security (and ultimately the compliance associated with those systems) may be insufficient for their desires.

Requirements & Obligations

The first things to understand are your regulatory and legislative obligations. Depending on your industry or geographic location, you may be subject to a variety of different laws and agreements governing the way you do business. From a security perspective, some of the more obvious ones include Sarbanes Oxley, PCI DSS, NERC CIP, and a variety of privacy regulations. Don’t expect your cloud provider to explain to you which are applicable and which they adhere to by default. For the most part, the providers are competing on price and security is not typically something organizations are really willing to pay for (although nearly all organizations expect it).

Just because the provider is a massive organization with a good track record for security and has good reference clients doesn’t mean that they’re giving you the same service at the price you’ve been quoted. You need to formalize your requirements and ensure the quotes you solicit capture them all. This likely means you need to talk to your legal counsel to understand and document these obligations. If the price is remarkably lower than the others, you need to look critically at the differences in service and specifically security. 

Cloud Compliance

As I alluded, it is entirely possible that cloud services can be compliant with the obligations your organization has set forth but, by default, it’s probably good to assume the initial proposal provided by them will not be sufficient. It’s also realistic to assume that the more burdensome your requirements are, the more the solution will cost to implement and maintain. 

If we refer back to that example of the Canadian health care provider looking to use cloud services, the foremost requirement they had pertained to the physical location of the data and how it must reside within the province of British Columbia. This requirement alone immediately eliminates most of the very large cloud service providers and brings it down to a handful of local providers to choose from. It’s safe to assume that the price of the niche market players would typically be higher that the massive internationals but that requirement precludes the use of the cheaper providers. Similarly, if you’re looking for a PCI DSS compliant service provider, the list is relatively short and the prices not easily comparable to non-compliant service providers.

If you combine the two requirements (PCI DSS compliant and local BC company), it’s unlikely that list would be very large at all. In some cases, you may have to choose a local provider and help them to become PCI compliant, in the event that none of the companies fit both requirements. Clearly, the cost of that endeavour is not immediately comparable to posted monthly service charges from Microsoft or Amazon, as examples. Clearly, the organizational strategy of outsourcing to the cloud is not one to be taken lightly.

Information Security Organization

Ultimately, the success of your cloud compliance project hinges on your organization’s existing IT security and compliance maturity as well as how your organization manages third parties.  Although it could be argued that there is significant overlap between the two concepts, we’ll treat them as relatively mutually exclusive for the purposes of this discussion. 

With respect to the individual security elements pertaining to outsourcing to the cloud, there are a few basic principles which need specific consideration.

Data Classification

If you’re outsourcing anything, your organization needs to have a solid understanding of the type of data you’re sending outside of your organization’s physical premises. For example, in the event your organization is allowed to safeguard government classified documents at the level of Secret, you would not be able to have that data hosted anywhere that isn’t appropriate certified by the government for those purposes (and verified as such). This means you need to understand the sensitivity of the data to be hosted and the related obligations.

The exercise of data classification, system classification and labeling is intrinsic to the success and efficient use of resources for all information security programs and should be conducted long before you consider trusting a third party to host your data.

Ultimately, as data custodians, the cloud provider will do exactly whatever you tell them to do with the data and only that. They will not have the insight or capability to examine your data for sensitive information like credit card numbers then decide that that specific file or database should have an additional level of protection (unless, of course, you pay them to classify your data and systems for you as part of a consulting project). You need to identify the specific systems of concern and consider whether the costs associated with the protection of those systems in cloud are ultimately less than that you’re already spending. 

Access Control & Connectivity

Authentication and authorization are another two areas you need to understand with respect to outsourcing to the cloud.  Specifically you need to understand who owns and manages the authentication mechanism (such as LDAP, Active Directory, etc.) and who assigns the appropriate permissions to the individuals accessing the data or otherwise using the systems. 

We’ve seen cloud deployments use a variety of different methods from standalone servers which don’t have any central management, to an extension of your corporate Active Directory environment to a fully managed authentication LDAP directory. Each of these options has different concerns pertaining to how they’re secured (and who is responsible for that security). This all needs to be documented and formalized. From a documentation perspective, there are many procedures which would need to be reviewed including user provisioning and deprovisioning to fully ensure you understand what you’re getting.

Another specific area to ensure is considered is the accounting and auditing of users as required by specific compliance regulation. From a security perspective, logging and monitoring does not apply to just the service logs which are generated by default by the operating system. The way we view logging and monitoring is that it is a means to forensically recreate events which have occurred to understand where they came from, what happened and hopefully why. This means that your provider should have some sort of Security Information and Event Management System (SIEM) in place to consider the security events which may occur and not just whether a service has stopped running. This, again, is likely not a standard offering by the less expensive cloud providers but needs to be considered if you’re looking to sufficiently secure your hosted environment to meet compliance obligations. 

Additional considerations should include how the data stored in the cloud are secured as well as how that data is transmitted. Encryption tends to be the “easy answer” for questions about how the data gets from your office to the cloud using SSL or IPSEC. Data stored on hard disks may use full disk encryption or BitLocker or some other comparable technology but how often does the process by which the encryption keys are managed get mentioned? Rarely.  You need to understand if the keys used are unique? Does key rotation occur? Ultimately, without a solid understanding of cryptography principles as part of a mature security and compliance program, it’s unlikely you’ll capture the requirements sufficiently within the contract with the cloud provider. Its further doubtful that the cloud provider will volunteer this level of detail without you asking the question.

Segmentation and Separation

Considering the nature of cloud infrastructure, to maintain specific compliance obligations you may seek to validate how the logical Virtual Machines (VM) in your environment are separated and secured from other customer’s VMs. Even if the hosted environment is a “Private Cloud” or perhaps using “dedicated hardware”, it’s in your best interest to understand the methods and mechanism in place separating the provider’s customer systems (and data, if stored on shared storage) and evaluate whether those controls are sufficient to your needs. 

Ask for diagrams and evidence and don’t trust informal communications describing the environment. Further investigation into how the systems are managed (i.e. what access their staff has?) and what happens if the management consoles are compromised should also be considered. Additionally, from that perspective, the provisioning process of hypervisor users should be reviewed. Furthermore, how the hypervisor is secured or hardened should be considered and whether it is consistent with best practices such as NIST SP 800-125 Guide to Security for Full Virtualization Technologies.

Roles and Responsibilities

From a less technological perspective, another area warranting through review and formalization is a comprehensive responsibility matrix outlining who is responsible for what under each circumstance. This document needs to exist to ensure all parties are aware of their responsibilities under the contract and ensure aligned expectations. This goes for initial provisioning of virtual machines, patching and updating, log management, all the way through user management and incident response plan execution. Incident response is of specific importance for most organizations and, if you’re in one of the many jurisdictions subject to breach notification laws, you need to ensure that it’s well understood who is responsible for contacting your customers in the event your provider suffers a breach, as an example. 

Risk Assessments

As with any new endeavor or outsourcing effort, a variety of evaluations and assessments should be conducted to ensure the concept makes business sense. This means ensuring a capable individual or company conducts a business impact assessment and perhaps a privacy impact assessment, depending on the nature of the systems and data you’re considering sending to the cloud. Threat and risk assessments are also commonplace for evaluating whether a technical solution meets the business requirements stipulated and addresses all the non-negligible concerns. 

Due Diligence & Provider Contract Requirements

Really, when it comes down to any outsourcing deal, be it cloud computing related or not, contracts are the most important part of the arrangement and just like any other contract, due diligence should be conducted to ensure you are getting what you want.

As part of the diligence process, many organizations may mandate things like ISO/IEC 27001 compliance or PCI DSS service provider compliance. One must pay particular attention to the scope of the environments being assessed within each of these types of attestations to ensure the applicability to your potential environment. Just because an organization is ISO 27001 certified doesn’t mean the systems they intend to host for you will be within that certified environment.

Similarly, a lot of organizations use SAS70 type 2 audits to show they’re secure. SAS70 is in the process of being replaced by SSAE No. 16 with the intention of showing similar details about a service provider organization. These reports ultimately verify whether an organization follows the documented procedures they have, not whether they adhere to best practices or are inherently secure. When provided with one of these types of audits as evidence of security controls in place, review them carefully to ensure they cover the desired areas and procedures.

With respect to specific contract terms you should insist upon, clauses covering portability & interoperability should exist to ensure, in the event you want to retrieve your data and transfer it to a different provider or bring it back in house, it will be technically possible. Similarly, you should insist on the Right to Audit clause, which hopefully you’ll never use but should things go badly, you can exercise. And lastly, ensure you have a strong collection of metrics within the Service Level Agreement against which performance can be measured and tracked.

Conclusions

As you’ve probably discovered by now, cloud computing technology can easily extend your organization but many of the components security conscious organization consider “Standard” or expect may not be initially included in the contract and treated as a la carte. With that in mind, pricing associated with outsourcing data and systems subject to compliance obligations can considerably increase to the point that these specific costs should be thoroughly investigated prior to trying to outsource the responsibility of managing those systems.  Furthermore, placing those items in the cloud do not necessarily allow you to abdicate all responsibility associated with those systems and, in fact, can make things more difficult to manage if appropriate roles and responsibilities haven’t been formalized.  At any point, you’ll likely be obligated to validate that your service providers are compliant as part of your compliancy initiatives. 

Privity Systems Inc. (Privity) is a boutique-style Western Canada based Information security consulting practice with a focus on compliance matters and strategic planning. As a Payment Card Industry Qualified Security Assessor (PCI QSA) company, Privity provides guidance and assurance to its Canadian clients dealing with these complicated regulations.  Privity is a Microsoft Silver Partner with a competency in Identity & Security as well as Mid-Market Solutions. Privity is also a Symantec Silver Partner, Cisco Select Partner and VMWare Professional Service Provider. 

About the Author

Shawn R. Chaput, CISA, CISM, CGEIT, CRISC, CISSP, ISSAP, ISSMP, CIPP/C, CFE, CIA, PMP, ITIL, ABCP, MCITP, MCTS, CCDA, STS, QSA; Chief Architect & Executive Consultant, Privity Systems Inc.

Shawn R. Chaput is an Executive Security Consultant and Chief Architect for Privity Systems Inc., an information security services company in Vancouver, Canada.  With a past of working for large consulting firms like IBM, EDS and Accenture, he has over 16 year’s tenure in IT and more specifically within the information security and compliance professions.  

As a trusted business advisor to many large and well known organizations, Mr. Chaput tends to fill the role of a chief security strategist helping organizations overcome tremendous roadblocks affecting their IT compliance initiatives such as PCI DSS, FISMA, NERC and SOX. 

His role has lead him to advise executive management of some very large and well known organizations on how to effectively govern and manage IT risk; design enterprise security architectures, strategies and plans; develop cost-effective and sustainable security management policies and practices for governance frameworks.

An accomplished author, patent holder and public speaker, he has contributed to several articles and books as well as other formal academic publications. He participates in the Canadian Advisory Committee for the ISO SC27, which develops the ISO/IEC 27000 series Security Standards and is also a contributing member of many special interest groups within the PCI Community responsible for shaping the related official guidance and future versions of PCI DSS. A foremost expert on IT and security compliance, he was asked to author the inaugural “compliance” section of the Cloud Security Alliance’s “guidance” document and has managed all revisions since.  Since his participation in the founding of the CSA, he has been published several times and spoken at several large conferences on the topic.

Shawn holds a Masters of Business Administration, Management of Technology from the Beedie School of Business at Simon Fraser University and an Honours Baccalaureate in Economics and Political Science from the University of Winnipeg.  He also holds more than twenty industry certifications across multiple technical and best practices disciplines and is continually adding more.
 

Subscribe to HPCwire's Weekly Update!

Be the most informed person in the room! Stay ahead of the tech trends with industy updates delivered to you every week!

Silicon Startup Raises ‘Prodigy’ for Hyperscale/AI Workloads

May 23, 2018

There's another silicon startup coming onto the HPC/hyperscale scene with some intriguing and bold claims. Silicon Valley-based Tachyum Inc., which has been emerging from stealth over the last year and a half, is unveili Read more…

By Tiffany Trader

Scientists Conduct First Quantum Simulation of Atomic Nucleus

May 23, 2018

OAK RIDGE, Tenn., May 23, 2018—Scientists at the Department of Energy’s Oak Ridge National Laboratory are the first to successfully simulate an atomic nucleus using a quantum computer. The results, published in Ph Read more…

By Rachel Harken, ORNL

Pattern Computer – Startup Claims Breakthrough in ‘Pattern Discovery’ Technology

May 23, 2018

If it weren’t for the heavy-hitter technology team behind start-up Pattern Computer, which emerged from stealth today in a live-streamed event from San Francisco, one would be tempted to dismiss its claims of inventing Read more…

By John Russell

HPE Extreme Performance Solutions

HPC and AI Convergence is Accelerating New Levels of Intelligence

Data analytics is the most valuable tool in the digital marketplace – so much so that organizations are employing high performance computing (HPC) capabilities to rapidly collect, share, and analyze endless streams of data. Read more…

IBM Accelerated Insights

Mastering the Big Data Challenge in Cognitive Healthcare

Patrick Chain, genomics researcher at Los Alamos National Laboratory, posed a question in a recent blog: What if a nurse could swipe a patient’s saliva and run a quick genetic test to determine if the patient’s sore throat was caused by a cold virus or a bacterial infection? Read more…

First Xeon-FPGA Integration Launched by Intel

May 22, 2018

Ever since Intel’s acquisition of FPGA specialist Altera in 2015 for $16.7 billion, it’s been widely acknowledged that some day, Intel would release a processor that integrates its mainstream Xeon CPU server chip wit Read more…

By Doug Black

Silicon Startup Raises ‘Prodigy’ for Hyperscale/AI Workloads

May 23, 2018

There's another silicon startup coming onto the HPC/hyperscale scene with some intriguing and bold claims. Silicon Valley-based Tachyum Inc., which has been eme Read more…

By Tiffany Trader

Pattern Computer – Startup Claims Breakthrough in ‘Pattern Discovery’ Technology

May 23, 2018

If it weren’t for the heavy-hitter technology team behind start-up Pattern Computer, which emerged from stealth today in a live-streamed event from San Franci Read more…

By John Russell

Japan Meteorological Agency Takes Delivery of Pair of Crays

May 21, 2018

Cray has supplied two identical Cray XC50 supercomputers to the Japan Meteorological Agency (JMA) in northwestern Tokyo. Boasting more than 18 petaflops combine Read more…

By Tiffany Trader

ASC18: Final Results Revealed & Wrapped Up

May 17, 2018

It was an exciting week at ASC18 in Nanyang, China. The student teams braved extreme heat, extremely difficult applications, and extreme competition in order to cross the cluster competition finish line. The gala awards ceremony took place on Wednesday. The auditorium was packed with student teams, various dignitaries, the media, and other interested parties. So what happened? Read more…

By Dan Olds

Spring Meetings Underscore Quantum Computing’s Rise

May 17, 2018

The month of April 2018 saw four very important and interesting meetings to discuss the state of quantum computing technologies, their potential impacts, and th Read more…

By Alex R. Larzelere

Quantum Network Hub Opens in Japan

May 17, 2018

Following on the launch of its Q Commercial quantum network last December with 12 industrial and academic partners, the official Japanese hub at Keio University is now open to facilitate the exploration of quantum applications important to science and business. The news comes a week after IBM announced that North Carolina State University was the first U.S. university to join its Q Network. Read more…

By Tiffany Trader

Democratizing HPC: OSC Releases Version 1.3 of OnDemand

May 16, 2018

Making HPC resources readily available and easier to use for scientists who may have less HPC expertise is an ongoing challenge. Open OnDemand is a project by t Read more…

By John Russell

PRACE 2017 Annual Report: Exascale Aspirations; Industry Collaboration; HPC Training

May 15, 2018

The Partnership for Advanced Computing in Europe (PRACE) today released its annual report showcasing 2017 activities and providing a glimpse into thinking about Read more…

By John Russell

MLPerf – Will New Machine Learning Benchmark Help Propel AI Forward?

May 2, 2018

Let the AI benchmarking wars begin. Today, a diverse group from academia and industry – Google, Baidu, Intel, AMD, Harvard, and Stanford among them – releas Read more…

By John Russell

How the Cloud Is Falling Short for HPC

March 15, 2018

The last couple of years have seen cloud computing gradually build some legitimacy within the HPC world, but still the HPC industry lies far behind enterprise I Read more…

By Chris Downing

Russian Nuclear Engineers Caught Cryptomining on Lab Supercomputer

February 12, 2018

Nuclear scientists working at the All-Russian Research Institute of Experimental Physics (RFNC-VNIIEF) have been arrested for using lab supercomputing resources to mine crypto-currency, according to a report in Russia’s Interfax News Agency. Read more…

By Tiffany Trader

Nvidia Responds to Google TPU Benchmarking

April 10, 2017

Nvidia highlights strengths of its newest GPU silicon in response to Google's report on the performance and energy advantages of its custom tensor processor. Read more…

By Tiffany Trader

Deep Learning at 15 PFlops Enables Training for Extreme Weather Identification at Scale

March 19, 2018

Petaflop per second deep learning training performance on the NERSC (National Energy Research Scientific Computing Center) Cori supercomputer has given climate Read more…

By Rob Farber

AI Cloud Competition Heats Up: Google’s TPUs, Amazon Building AI Chip

February 12, 2018

Competition in the white hot AI (and public cloud) market pits Google against Amazon this week, with Google offering AI hardware on its cloud platform intended Read more…

By Doug Black

US Plans $1.8 Billion Spend on DOE Exascale Supercomputing

April 11, 2018

On Monday, the United States Department of Energy announced its intention to procure up to three exascale supercomputers at a cost of up to $1.8 billion with th Read more…

By Tiffany Trader

HPC and AI – Two Communities Same Future

January 25, 2018

According to Al Gara (Intel Fellow, Data Center Group), high performance computing and artificial intelligence will increasingly intertwine as we transition to Read more…

By Rob Farber

Leading Solution Providers

Lenovo Unveils Warm Water Cooled ThinkSystem SD650 in Rampup to LRZ Install

February 22, 2018

This week Lenovo took the wraps off the ThinkSystem SD650 high-density server with third-generation direct water cooling technology developed in tandem with par Read more…

By Tiffany Trader

Google Chases Quantum Supremacy with 72-Qubit Processor

March 7, 2018

Google pulled ahead of the pack this week in the race toward "quantum supremacy," with the introduction of a new 72-qubit quantum processor called Bristlecone. Read more…

By Tiffany Trader

CFO Steps down in Executive Shuffle at Supermicro

January 31, 2018

Supermicro yesterday announced senior management shuffling including prominent departures, the completion of an audit linked to its delayed Nasdaq filings, and Read more…

By John Russell

HPE Wins $57 Million DoD Supercomputing Contract

February 20, 2018

Hewlett Packard Enterprise (HPE) today revealed details of its massive $57 million HPC contract with the U.S. Department of Defense (DoD). The deal calls for HP Read more…

By Tiffany Trader

Deep Learning Portends ‘Sea Change’ for Oil and Gas Sector

February 1, 2018

The billowing compute and data demands that spurred the oil and gas industry to be the largest commercial users of high-performance computing are now propelling Read more…

By Tiffany Trader

Nvidia Ups Hardware Game with 16-GPU DGX-2 Server and 18-Port NVSwitch

March 27, 2018

Nvidia unveiled a raft of new products from its annual technology conference in San Jose today, and despite not offering up a new chip architecture, there were still a few surprises in store for HPC hardware aficionados. Read more…

By Tiffany Trader

Hennessy & Patterson: A New Golden Age for Computer Architecture

April 17, 2018

On Monday June 4, 2018, 2017 A.M. Turing Award Winners John L. Hennessy and David A. Patterson will deliver the Turing Lecture at the 45th International Sympo Read more…

By Staff

Part One: Deep Dive into 2018 Trends in Life Sciences HPC

March 1, 2018

Life sciences is an interesting lens through which to see HPC. It is perhaps not an obvious choice, given life sciences’ relative newness as a heavy user of H Read more…

By John Russell

  • arrow
  • Click Here for More Headlines
  • arrow
Share This