Cloud Computing - Starting Points for Privacy and Transparency Ina Schiering Ostfalia University of Applied Science Wolfenbüttel, Germany IFIP Summerschool: Privacy and Identity Management for Life, Helsingborg, August 2nd, 2010
Cloud Services ● Dynamically utilisable, scalable IT services Introduction Interacting ● ● Use of virtualisation and scalability Partners Service ● Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 2
Interacting Partners Introduction The different interacting partners in a cloud Interacting ● environment are Partners Service ● Cloud Users ● Delivery Model ● Cloud Providers Cloud ● Deployment ● Resource Owners Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 3
Cloud User ● Uses a cloud service Introduction Interacting ● ● A person, a company or an organisation Partners Service ● can be a cloud user Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 4
Cloud Provider ● Cloud services are offered by cloud Introduction Interacting ● providers Partners Service ● Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 5
Resource Owner ● Resource Owner is an interacting party Introduction Interacting ● who owns resources Partners Service ● Resources are e.g. virtual instances and ● Delivery Model storage Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 6
Service Delivery Model Introduction Cloud services are distinguished concerning Interacting ● the complexity of the technology stack they Partners deliver. Service ● Delivery Model Types of cloud services are: Cloud ● Deployment ● IaaS - Infrastructure as a Service Model Privacy in Cloud ● PaaS - Platform as a Service Services Audits and ● SaaS - Software as a Service Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 7
IaaS Introduction Infrastructure as a Service Interacting ● Partners Service ● Storage ● Delivery Model (Amazon S3, ScaleUp) Cloud ● Deployment Model ● Virtual instances Privacy in Cloud Services (Amazon EC2) Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 8
PaaS Introduction Platform as a Service Interacting ● Infrastructure software as (e.g. LAMP-Stack) Partners Service ● Web servers, ● Delivery Model application servers Cloud ● Deployment Model ● Data bases Privacy in Cloud Services Audits and Assessments ● Asynchronous queues (Microsoft Azure, Amazon Web Services, Google App Engine, Force.com) Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 9
SaaS Introduction Software as a Service Interacting ● Software for complex processes e.g. Partners Service ● Email ● Delivery Model ● Text Processing Cloud ● Deployment ● CRM (Customer Relationship Model Privacy in Cloud Management) Services Audits and (Google Docs, Salesforce.com, Facebook, Assessments Picasa) Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 10
Cloud Deployment Model Introduction Cloud services are distinguished concerning Interacting ● the relation between cloud provider and cloud Partners user: Service ● Delivery ● Private clouds Model Cloud ● Deployment ● Public clouds Model Privacy in Cloud ● Hybrid clouds Services Audits and ● Community Clouds Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 11
Private Clouds ● Cloud user, cloud provider and resource Introduction Interacting ● owner are the same instance Partners Service ● Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 12
Public Clouds ● Cloud services offered by an external Introduction Interacting ● supplier Partners ● All physical resources are out of reach Service ● Delivery of the cloud user Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 13
Hybrid Clouds ● Mixture of private and public cloud Introduction Interacting ● Partners Service ● Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 14
Community Clouds ● Several organisations have similar Introduction Interacting requirements and share the infrastructure ● Partners (e.g. model for public sector) Service ● Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 15
Cloud Network Introduction Interacting partners in a cloud can be Interacting ● visualized as a Partners Service ● finite, directed graph Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 16
Privacy in Cloud Services Introduction We concentrate Privacy in ● on cloud services for organisations, Cloud Services Privacy ● ● on technical measures. Requirem. Cloud ● Services What data of organisations? IaaS ● ● Personal data of employees, customers PaaS ● SaaS ● ● Confidential (business-related) data Audits and Assessments ● Intellectual property Responsibility rests always with the cloud user. Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 17
Responsibility for Personal Data Introduction Personal data Privacy in ● fairly and lawfully processed Cloud Services Privacy ● ● processed for limited purpose Requirem. Cloud ● ● adequate, relevant, not excessive Services IaaS ● ● accurate, PaaS ● SaaS ● ● not kept longer than necessary Audits and Assessments ● processed in accordance with data subjects rights ● secure Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 18
Multilateral Privacy Introduction Allows all parties of an interaction Privacy in ● to express their privacy objectives Cloud Services Privacy ● ● with no party taking precedence over Requirem. Cloud ● another. Services IaaS ● Mechanisms of effective control are needed. PaaS ● SaaS ● Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 19
Requirements for Data Privacy Introduction Standard requirements for data privacy: Privacy in ● Confidentiality, Cloud Services Privacy ● ● Integrity, Requirem. Cloud ● ● Availability Services IaaS ● ● Authenticity PaaS ● SaaS ● ● Accountability Audits and Assessments ● Non-repudiability ● Restrict the location of data Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 20
Operational Requirements ● Identity and Access Management Introduction Privacy in ● Monitoring, reporting, logging Cloud Services Privacy ● (e.g. based on service level, legal Requirem. requirements) Cloud ● Services ● Backup, archiving of data IaaS ● PaaS ● ● Deletion of data SaaS ● Audits and ● Interfaces to other Systems Assessments (e.g. data warehouse) Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 21
Characteristics of Cloud Services ● Shared resources Introduction Privacy in ● Communication over public networks Cloud Services Privacy ● (Internet) Requirem. Cloud ● Location of resources not transparent ● Services IaaS ● ● Operated by third parties PaaS ● SaaS ● Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 22
Approach to Requirements Introduction Requirements have to be met by the Privacy in application, resp. the service: Cloud Services ● SaaS: Requirements are actual Privacy ● Requirem. requirements for the service Cloud ● Services ● IaaS, PaaS : Support the realisation of IaaS ● PaaS ● requirements in applications SaaS ● Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 23
Components of an IT-Service Introduction We start with an example of an IT-Service Privacy in realised traditional : Cloud Services Privacy ● Requirem. Cloud ● Services IaaS ● PaaS ● SaaS ● Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 24
Recommend
More recommend