Cloud Computing
Yes No
Data centre filled Virtual compute, No with identical storage and network hardware modules • Fit and forget; • Software defined Because … • Use commodity • Failed hardware hardware; component(s) simply bypassed • Replace when it fails and you get the time, like a bulb in a large chandelier
A bank’s locker service Hosts your property in service provider’s facility
Characteristics of the service
Elastic compute, storage and network 1 2 3 4 Available on In predefined Hired for Multitenancy demand units required length of time
Need for Customer Protection
• Reasonable security safeguards to prevent loss, unauthorised access, etc. • Protection of legal liabilities Customer • Ownership issues needs to trust • Quality of Service the service • Lock-in • Portability provider • Interoperability • Commercial tie-in • Billing and metering
1 2 3 May be left to the Disclosure mechanism Telecommunications market forces for transparency Standards Development regarding Society, India (TSDSI) for interoperability development of standards Interoperability and Portability
• Thriving Business • Licensing Regulation of • Industry Practices • Compliance Industry • Disclosure • Self Regulation
1 2 3 4 5 Specified terms and Not for profit Cloud service To develop the code of Government to keep a governance structure. providers above a conduct for members watch May be derecognized, threshold as members if warranted Registered Industry Bodies for self- regulation
Cloud Service Advisory Group for oversight 1 2 3 4 5 Representatives of MSME Consumer Industry experts Representatives of state IT associations advocacy groups Law Enforcement departments agencies
Legal Framework
Notice , before personal information is collected Choice and consent Collection limitation , only for the purposes identified and informed Adequate to the individual. Purpose limitation : use personal information only for the stated protection to purposes sensitive Access and correction : users have the right to access their personal information and correct, if necessary personal Disclosure of information : cannot disclose personal information to third parties, without notice and consent information Security : Required to install “reasonable security safeguards” to prevent loss, unauthorised access, etc. Openness : to implement practices, procedures, policies and systems to the scale, scope, and sensitivity Accountability : for complying with measures that satisfy the privacy principles.
Law enforcement • Interception Legal • Access framework • Due process Jurisdiction
1 2 3 Data Protection Law Provisions to govern Robust MLATs, with cross-border provisions for transfer of data interception or access. Data Protection Law
Indian Government has a policy to promote cloud services for government services Cloud No need for incentive services to large customers and CSPs scenario Ministry of MSME may continue to promote adoption of ICT in this sector
Thank you!
Recommend
More recommend