cloud computing starting points for privacy and
play

Cloud Computing - Starting Points for Privacy and Transparency Ina - PowerPoint PPT Presentation

Cloud Computing - Starting Points for Privacy and Transparency Ina Schiering Ostfalia University of Applied Science Wolfenbttel, Germany IFIP Summerschool: Privacy and Identity Management for Life, Helsingborg, August 2nd, 2010 Cloud


  1. Cloud Computing - Starting Points for Privacy and Transparency Ina Schiering Ostfalia University of Applied Science Wolfenbüttel, Germany IFIP Summerschool: Privacy and Identity Management for Life, Helsingborg, August 2nd, 2010

  2. Cloud Services ● Dynamically utilisable, scalable IT services Introduction Interacting ● ● Use of virtualisation and scalability Partners Service ● Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 2

  3. Interacting Partners Introduction The different interacting partners in a cloud Interacting ● environment are Partners Service ● Cloud Users ● Delivery Model ● Cloud Providers Cloud ● Deployment ● Resource Owners Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 3

  4. Cloud User ● Uses a cloud service Introduction Interacting ● ● A person, a company or an organisation Partners Service ● can be a cloud user Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 4

  5. Cloud Provider ● Cloud services are offered by cloud Introduction Interacting ● providers Partners Service ● Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 5

  6. Resource Owner ● Resource Owner is an interacting party Introduction Interacting ● who owns resources Partners Service ● Resources are e.g. virtual instances and ● Delivery Model storage Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 6

  7. Service Delivery Model Introduction Cloud services are distinguished concerning Interacting ● the complexity of the technology stack they Partners deliver. Service ● Delivery Model Types of cloud services are: Cloud ● Deployment ● IaaS - Infrastructure as a Service Model Privacy in Cloud ● PaaS - Platform as a Service Services Audits and ● SaaS - Software as a Service Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 7

  8. IaaS Introduction Infrastructure as a Service Interacting ● Partners Service ● Storage ● Delivery Model (Amazon S3, ScaleUp) Cloud ● Deployment Model ● Virtual instances Privacy in Cloud Services (Amazon EC2) Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 8

  9. PaaS Introduction Platform as a Service Interacting ● Infrastructure software as (e.g. LAMP-Stack) Partners Service ● Web servers, ● Delivery Model application servers Cloud ● Deployment Model ● Data bases Privacy in Cloud Services Audits and Assessments ● Asynchronous queues (Microsoft Azure, Amazon Web Services, Google App Engine, Force.com) Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 9

  10. SaaS Introduction Software as a Service Interacting ● Software for complex processes e.g. Partners Service ● Email ● Delivery Model ● Text Processing Cloud ● Deployment ● CRM (Customer Relationship Model Privacy in Cloud Management) Services Audits and (Google Docs, Salesforce.com, Facebook, Assessments Picasa) Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 10

  11. Cloud Deployment Model Introduction Cloud services are distinguished concerning Interacting ● the relation between cloud provider and cloud Partners user: Service ● Delivery ● Private clouds Model Cloud ● Deployment ● Public clouds Model Privacy in Cloud ● Hybrid clouds Services Audits and ● Community Clouds Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 11

  12. Private Clouds ● Cloud user, cloud provider and resource Introduction Interacting ● owner are the same instance Partners Service ● Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 12

  13. Public Clouds ● Cloud services offered by an external Introduction Interacting ● supplier Partners ● All physical resources are out of reach Service ● Delivery of the cloud user Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 13

  14. Hybrid Clouds ● Mixture of private and public cloud Introduction Interacting ● Partners Service ● Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 14

  15. Community Clouds ● Several organisations have similar Introduction Interacting requirements and share the infrastructure ● Partners (e.g. model for public sector) Service ● Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 15

  16. Cloud Network Introduction Interacting partners in a cloud can be Interacting ● visualized as a Partners Service ● finite, directed graph Delivery Model Cloud ● Deployment Model Privacy in Cloud Services Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 16

  17. Privacy in Cloud Services Introduction We concentrate Privacy in ● on cloud services for organisations, Cloud Services Privacy ● ● on technical measures. Requirem. Cloud ● Services What data of organisations? IaaS ● ● Personal data of employees, customers PaaS ● SaaS ● ● Confidential (business-related) data Audits and Assessments ● Intellectual property Responsibility rests always with the cloud user. Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 17

  18. Responsibility for Personal Data Introduction Personal data Privacy in ● fairly and lawfully processed Cloud Services Privacy ● ● processed for limited purpose Requirem. Cloud ● ● adequate, relevant, not excessive Services IaaS ● ● accurate, PaaS ● SaaS ● ● not kept longer than necessary Audits and Assessments ● processed in accordance with data subjects rights ● secure Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 18

  19. Multilateral Privacy Introduction Allows all parties of an interaction Privacy in ● to express their privacy objectives Cloud Services Privacy ● ● with no party taking precedence over Requirem. Cloud ● another. Services IaaS ● Mechanisms of effective control are needed. PaaS ● SaaS ● Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 19

  20. Requirements for Data Privacy Introduction Standard requirements for data privacy: Privacy in ● Confidentiality, Cloud Services Privacy ● ● Integrity, Requirem. Cloud ● ● Availability Services IaaS ● ● Authenticity PaaS ● SaaS ● ● Accountability Audits and Assessments ● Non-repudiability ● Restrict the location of data Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 20

  21. Operational Requirements ● Identity and Access Management Introduction Privacy in ● Monitoring, reporting, logging Cloud Services Privacy ● (e.g. based on service level, legal Requirem. requirements) Cloud ● Services ● Backup, archiving of data IaaS ● PaaS ● ● Deletion of data SaaS ● Audits and ● Interfaces to other Systems Assessments (e.g. data warehouse) Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 21

  22. Characteristics of Cloud Services ● Shared resources Introduction Privacy in ● Communication over public networks Cloud Services Privacy ● (Internet) Requirem. Cloud ● Location of resources not transparent ● Services IaaS ● ● Operated by third parties PaaS ● SaaS ● Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 22

  23. Approach to Requirements Introduction Requirements have to be met by the Privacy in application, resp. the service: Cloud Services ● SaaS: Requirements are actual Privacy ● Requirem. requirements for the service Cloud ● Services ● IaaS, PaaS : Support the realisation of IaaS ● PaaS ● requirements in applications SaaS ● Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 23

  24. Components of an IT-Service Introduction We start with an example of an IT-Service Privacy in realised traditional : Cloud Services Privacy ● Requirem. Cloud ● Services IaaS ● PaaS ● SaaS ● Audits and Assessments Ina Schiering, Cloud Computing - Starting Points for Privacy and Transparency 24

Recommend


More recommend