What makes a good IT logo? http://t.co/aIsc7TSm via @zdnetasia
6 minutes ago by Designabsolu on twitterZDNet is available in the following editions:
perspective It appears unwise to ignore risks of moving to the cloud. Alan Calder, chief executive of IT Governance, provides a security checklist.
perspective The cloud is increasingly dominating the IT horizon. The problem is some people seem to think that it is all silver lining--and no rain.
Software-as-a-service (SaaS) and the increasing use of the 'free' Web IT infrastructure is being treated as the way to cut investment in hardware, software and IT staff. And of course we have all become very familiar with the argument that SaaS is a much more cost-effective alternative to licensed software.
Many of the reasons for opting for computing in the cloud are sound. But security and privacy concerns are just as pertinent here as in all other areas of IT. In fact, whether you subscribe to SaaS or implement Web services on your in-house servers, cloud computing does not make these issues go away.
Hostile electronic environment
Indeed, they may even end up becoming even more critical. Data stored on your SaaS partner's servers is exposed to the same hostile electronic environment and data compliance requirements as your own.
Even at one remove, you are still responsible for personal information under the Data Protection Act, credit card data under Payment Card Industry compliance and corporate information.
In practical terms, a cloud computing project is no different to a conventional software installation and requires significant project management and time to make sure it is controlled effectively.
That is not to down play the positives. When you subscribe to a SaaS service, the investment associated with implementing and supporting conventional systems is unquestionably avoided. The capital and operating expenditure savings can be significant.
In addition, when you subscribe to a Web-hosted application, you free your team from supporting high-cost, time-consuming in-house IT functions. But the economies of scale that SaaS brings through multi-tenancy also increase security concerns.
Like any other branch of business IT, cloud-based services are shadowed by the drive to compliance, good data hygiene and best practice in information management. The same range of essential topics has to be addressed, from ISO27001 compliance, rigorous development lifecycles, threat profiling and security testing, all the way to secure coding guidelines.
A simple checklist of your cloud supplier's credentials is the basic starting point. When considering a SaaS subscription, look for organizations that are ISO27001 certified. Ask to see the supplier's Statement of Applicability to check the right controls are in place to meet your particular industry or organizational compliance needs.
Also check:
You will also want to know what sort of continuity arrangements are in place--look for BS25999 certification. Check that there is a service-level agreement that guarantees a specific amount of uptime. Also, find out what happens in the case of equipment breakdown and power failure? In addition, is the facility scalable? And is it monitored continuously?
Finally, there are big challenges involved in getting any sort of IT service right, let alone a new one like SaaS. However flexible SaaS is, you still have a significant time investment to get your application set up and configured so that it meets your business needs. Never underestimate the time required: a move to the cloud will need a project team, with a clear timeline, and lots of end user participation.
Then there is the impact on users: remember you may have to change internal processes to accommodate the limitations of whatever you are deploying.
All in all, approached with some forethought the specific cloud and general IT good-practice issues can be resolved. The subscription-based computing model offers benefits that cannot easily be ignored, but do not ignore the associated risks either.
Alan Calder is chief executive of security and compliance organization IT Governance. IT Governance is the publisher of Application security in the ISO27001 environment.
What makes a good IT logo? http://t.co/aIsc7TSm via @zdnetasia
6 minutes ago by Designabsolu on twitterRT @WellesleyInfoSv: Why #HTML5 makes justifying #native #apps more difficult http://t.co/GeyfXx3L
6 minutes ago by bdicecca on twitterWhat makes a good IT logo?: By Ryan Huang , ZDNet Asia on February 24, 2012 (3 hours ago) Besides fundamentals, ... http://t.co/GZjr7ihA
1 hour ago by DefineMeMore on twitterWhat makes a good IT logo? http://t.co/lh5PsvBh Featuring opinions from me on the Windows 8 logo.
1 hour ago by justcreative on twitterRT @justcreative: What makes a good IT logo? http://t.co/lh5PsvBh Featuring opinions from me on the Windows 8 logo.
1 hour ago by calumhall on twitterWhat makes a good IT logo? - ZDNet Asia http://t.co/dP5g1KMB
3 hours ago by Mygraphicstudio on twitterRT @YQLiauZDNetAsia: Intel distributes LibreOffice, can Microsoft be pleased? http://t.co/cHNbk7Ui via @zdnet
3 hours ago by asian_angel on twitterWhat makes a good IT logo? - ZDNet Asia - What makes a good IT logo?ZDNet AsiaThe new logo for Microsoft's Windo... http://t.co/tmUJVzPH
3 hours ago by golddotonline on twitterWhat makes a good IT logo? - ZDNet Asia: What makes a good IT logo?ZDNet Asia"Keep the logo design simple with y... http://t.co/BxWn0kVx
3 hours ago by Mygraphicstudio on twitterHave you ever wondered what goes into a good logo, especially for IT companies? http://t.co/2E6iEEwY
3 hours ago by RyanZDNetAsia on twitterKok bisa sih? the same bank breached twice with the same method? Dbs indo aman kan? http://t.co/aZKqCer2
3 hours ago by dikylung on twitterDBS needs reputation damage control - ZDNet Asia: DBS needs reputation damage controlZDNet AsiaEdison Yu, i... http://t.co/ZNWY0lxD #orm
3 hours ago by bettybrowser on twitterWhy HTML5 makes justifying native applications more difficult http://t.co/CbKRL7tD via @zite
3 hours ago by krbenedict on twitterThe signature didn't make it above - so here we go:
Peter Moskovits
Developer Evangelist - Kaazing
Great post - especially like you calling out the HTML5 features that are closing the gap with native apps. I assume your list wasn't mean...
8 hours ago by pmoskovi on Why HTML5 makes justifying native applications more difficultEmployees will most likely not be required to use certain social networks, but I'm sure bosses can be pretty influential. This is an oppo...
9 hours ago by dwightturner on Do firms have right to compel employees to be social?The mandarins at Treasury dept. should know these facts: 1. IBM does local business of $ 4 Billion/year in India. If India applied the s...
10 hours ago by kseshasayee on Obama proposes tax reforms to curb US outsourcingDataWind has been taking advantage of the Aakash brand created by the Government. The primary beneficiary of the Aakash tablet project is...
15 hours ago by skydrive100 on India's $35 tablet project hits snagOf course they are 'open', that was the game plan from the start! What a weasel!
2 days ago by mingnow on China firm open to settle iPad dispute with Applemy maxim: Never say or do something online that you wouldn't say or do in a room full of people.
2 days ago by mingnow on Do firms have right to compel employees to be social?Fascinating to see the Asian market reacting to 'social business'. It really re-emphasises for me the most valuable facet opening up foll...
6 days ago by onedesk on APAC firms still grappling with social bizTechnology Innovation, Strategy & Integration for CIOs and IT professionals in Asia Pacific
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.