Skip to main content

Posts

Showing posts with the label Governance

Cloud Computing will be all about GRC!

3. Data Regulations: Each jurisdiction around the world has slightly different approaches to the regulation of data privacy and the Australian Law Reform Commission has recently released a report suggesting significant strengthening of Australia's data privacy regime. Therefore it is important that customers understand where their data will ultimately be stored and by whom so that they can ensure compliance with Australian privacy and also record retention regulations. Many SaaS providers work on the basis of centralised infrastructure that is not based in Australia. The customer must ensure that contractually the provider is bound to comply with Australian privacy laws before allowing the data to be exported. The issue is further compounded if the SaaS provider then uses a third party to do the storage of the data. Such is the complexity that EMC announced recently that it is having difficulty choosing a location to build the data centres to run its storage-as-a-service offering...

OpenService announces Risk-Based Security Metrics in InfoCenter 5.1

A quick look at the OpenService Architecture OpenService, a provider of log and IT risk management solutions, has announced a new risk-based security metrics reporting system to help corporations monitor their IT risk trends and determine the effectiveness of their security controls. Available in the new release of its software product, InfoCenter 5.1, this solution was beta tested and first deployed on IBM BladeCenter servers. According to OpenService, InfoCenter 5.1 measures risk automatically by analyzing events reported by security and network devices, operating systems, databases and applications. The risk level of each event is scored as a function of threat, vulnerability, and asset value - an industry standard approach for calculating risk. The company said that the algorithm it developed, called Risk-Weighted Event Scoring and Thresholding (RWEST), scores and correlates events from a wide range of servers, devices and applications and, based on this, supports the visualization...

Cloud Computing Governance: Regulatory and Legal requirements shouldn't be forgotten!

An RCC, or a Regulated Cloud Computing is all we must strive for. More here... "Businesses must ensure they select only cloud computing services that enable them to avoid risk entirely or manage it to a reasonable level," says Scott. Cloud computing is still animmature business model and issues around risk and compliance still need to be ironed out. Kelly Dempski, director of research at Accenture Technology Labs in France says everyone is still trying to figure out how best to use the cloud computing model. "We are still in the period of learning and just beginning to come up with best practices," he says. A lack of business process management to go with the services offered by cloud computing is another reason businesses should be cautious about the model. Although companies are saving up to 40% on project costs by deploying CRM applications using the cloud computing model, the benefits could be short term says Michael Maoz, analyst at Gartner Research. These serv...

Satyam Foundation launches CSR in Vizag!

Satyam Foundation’s CSR activities in Visakhapatnam began in February 2008, when initiatives to help local communities were taken up as part of Satyam’s 20-year anniversary celebrations. Today’s launch will reinforce those efforts to enable social transformation in and around the city. Initial efforts in Vizag include encouraging volunteerism and creating enabling platforms, alliances, and partnerships with the community, NGOs, government agencies, and businesses. These efforts will help identify and prioritize Satyam Foundation programs, which extensively leverage key Satyam differentiators, such as technology, innovation and leadership “Wherever Satyam has a significant presence, we lead programs that serve both the corporation and society,” said Naveen Yelloji, the chief executive officer and director of Satyam Foundation. “The incubation of the Call 104 Health Helpline and the subsequent scaling up of comprehensive health services to all residents of Andhra Pradesh are excellent ex...

Compliance challenges while virtualizing

Chris @ Fortisphere writes: Here are five challenging aspects of IT compliance when dealing with virtualisation: Discovery and inventory: You can't measure what you can't see (or for that matter, don't even know exists). Determining which virtual machines (VMs) are active, which are abandoned or dormant and what data they are accessing is a fundamental part of defining your scope of compliance and applying the appropriate IT controls. Perhaps of a greater concern is how organisations cope with unapproved or rogue VMs. Chain of custody: Can you provide an audit trail for critical VMs as they move from development to testing to production? Are only approved changes occurring and are they made by the appropriate personnel? Due to the dynamic and mobile nature of virtualisation, keeping track of where the VMs are, who touched them and what changed is key for audit documentation and a true lifesaver in incident response scenarios. Separation of critical assets (especially in a ...