Sudden departure of Pacnet CEO, no explanation - ZDNet Asia: Sudden departure of Pacnet CEO, no explanationZDNet... http://t.co/UVG3OKCG
5 minutes ago by NGTsummit_ASIA on twitterZDNet is available in the following editions:
U.S. federal and international regulators have suggested they may have to re-examine privacy and security standards to take into account cloud computing.
information privacy, crime and law, kristin lovejoy, u.s. federal trade commission, google, science and technology, technology, information technology, distributed computing, computer technology
WASHINGTON -- Federal regulators on Tuesday met to hear about whether the benefits of cloud computing justify increased regulation, as privacy activists claim, or whether such an approach would do more harm than good.
"We need to be smarter about dealing with technology, and cloud computing is posing (a) risk for us," said Hugh Stephenson, deputy director for international consumer protection at the Federal Trade Center's Office of International Affairs.
The FTC convened the two-day meeting in its Washington offices, which follows a series of similar workshops held in previous years on topics like spam, privacy, and behavioral advertising. The agency may file lawsuits to halt "unfair or deceptive acts or practices," meaning that if cloud computing is not unfair or deceptive, the FTC would likely not have jurisdiction.
In order to secure personal information on the cloud, regulators may have to answer questions such as which entities have jurisdiction over data as it flows across borders, whether governments can access that information as it changes jurisdiction, and whether there is more risk in storing personal information in data centers that belong to a single entity rather than multiple data centers.
The current panoply of laws at the state, national, and international level have had insufficient results; FTC Commissioner Pamela Jones Harbour cited a 2008 PricewaterhouseCoopers information security survey (PDF) in which 71 percent of organizations queried said they did not have an accurate inventory of where personal data for employees and customers is stored.
With data management practices that are not always clear and are subject to change, companies that offer cloud computing services are steering consumers into dangerous territory, said Marc Rotenberg, executive director of the Electronic Privacy Information Center.
Already, problems of identity theft are skyrocketing, he said, and without more regulation, data management services may experience a collapse analogous to that of the financial sector.
"I predict we are going to experience something very similar with respect to privacy within the emerging information economy," Rotenberg said. "We are going to realize we allowed very similar complex transactions to occur between nontransparent organizations, and we will pay."
Later on Tuesday, EPIC asked the FTC to pull the plug on Gmail, Google Docs, Google Calendar, and the company's other Web apps until government-approved "safeguards are verifiably established."
FTC Commissioner Harbour said at Tuesday's conference that it would be preferable if more than one large company such as Google were responsible for storing personal data.
"I see a lot of overlap between competition analysis and security," she said.
Jane Horvath, senior policy counsel for Google, said "privacy by design is ingrained in our culture, and security is one of our fundamental design principles."
If customers do not feel their data is secure in Google products, nothing prohibits them from transferring their data elsewhere, she said.
"Cloud computing is a very new market place," Horvath said. "As more and more services become available, there will be more and more providers entering this market."
Furthermore, said Kristin Lovejoy, IBM's director of governance and risk management strategy, companies that lease server space from companies like Google to launch their own applications are ultimately responsible for security standards. She also said a large-scale cloud model is easier to secure than a heterogeneous data center.
The cloud computing sector would benefit, Lovejoy said, from standards similar to the PCI Security Standards, which were formed by major credit card companies to regulate payment account data security.
"We could define for the commercial sector a set of simplistic foundational controls, give them the ability to understand what they must do, and then build on top of that," she said.
In the industry's current state, "we don't know what we need to do, we don't know what we need to protect," Lovejoy said. "The technologies are there but not able to fully help us."
She said IBM is currently developing technology to allow individuals to create profiles to share with third parties, giving consumers the ability to manage elements of their identity. However, she said there is not enough R&D funding for such technology.
"There needs to be innovation around the technologies which push choice to the individuals," Lovejoy said.
While the FTC did not comment directly on any regulatory actions or changes in policy, international regulators said they plan to examine the implications of cloud computing on data security and privacy. The Organization for Economic Co-operation and Development should broach the subject of cloud computing at a meeting in Paris in October, said Michael Donohue, the privacy and information security administrator for the OECD.
This May, the European Union will launch a broad consultation on whether it should consider revising the 1995 data protection directive, said Hana Pechackova, the justice liberty security directorate general for the European Commission.
"We cannot pretend the technologies are the same as they were in 1995," Pechackova said. "Cloud computing and new business models are really challenging our systems. We've heard that the directive may be outdated, but we do not want to step back from our basic principles."
Currently, around 90 percent of organizations in the EU do not engage in transfers of data outside the region, said Billy Hawkes, Ireland's data protection commissioner. Cloud computing is very likely to change that, however.
This article was first published as a blog post on CNET News.
Sudden departure of Pacnet CEO, no explanation - ZDNet Asia: Sudden departure of Pacnet CEO, no explanationZDNet... http://t.co/UVG3OKCG
5 minutes ago by NGTsummit_ASIA on twitter@ChemarieMonica : Malaysia organizations don't realize severity of cyberattacks - ZDN... http://t.co/iO8wdbz8 http://t.co/1QrdIsaV #tech
5 minutes ago by mcjimmm on twitterMalaysia organizations don't realize severity of cyberattacks. http://t.co/QK7PKdaP
20 minutes ago by zdnetasia on twitterRT @daryllau: Malaysia offers some manufacturing benefits over China http://t.co/mH23Uumr
20 minutes ago by nickstersss on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/HniF8J72 #news
20 minutes ago by Nathiet on twitter#InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity
35 minutes ago by SecMash on twitterhttp://t.co/bTDnDh7J Malaysia organizations don't realize severity of cyberattacks - ZDNet Asi... http://t.co/CzsMF2zn #infosec #security
35 minutes ago by CYSEC_COM on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizat... http://t.co/iUpDhbeU #cloud #fail #TCN
35 minutes ago by Cloud_Fail on twitterPacnet CEO departs; acquisition rumors gain steam. http://t.co/Nu2Mdcj0
35 minutes ago by zdnetasia on twitterMalaysia organizations don't realize severity of cyberattacks http://t.co/zeaxHbYa http://t.co/erFSwAUB #arcavir
35 minutes ago by V_RaV on twitterhttp://t.co/VNaUVSe1 Malaysia organizations don't realize severity of cyberattacks: Cyberatt... http://t.co/TA5zWvUI http://t.co/wiqTBKkj
35 minutes ago by RavtachSolution on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizations don't realize... http://t.co/x1BJ0qSK
35 minutes ago by p_maju on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizations don't realize... http://t.co/3Yaa40JE
50 minutes ago by InfoSecurityVid on twitterMalaysia organizations don't realize severity of cyberattacks, country's minister of sci, tech, innovation says http://t.co/KGEHLi18 #in
50 minutes ago by EllyZDNetAsia on twitterMalaysia offers some manufacturing benefits over China http://t.co/mH23Uumr
1 hour ago by daryllau on twitterSo much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...
1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoidI reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...
2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than socialThis video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...
2 days ago by TradeBrother on A quick fill handle trick for Microsoft Excelwaiting...
4 days ago by eapete on What should count in a company's market value?Boy, you've opened a can of worms now.
Wait for the rants & raves.
I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...
5 days ago by wykoong on Drop the egos, copy ideas, then innovateEchelon 2012 - The Awesomer Tech Event in Asia
Echelon 2012 – SEA’s longest running tech startup event goes Awesomer. Catch 50 of Asia’s most promising startups & over 40 international speakers on June 11-12.
Startup Asia Jakarta showcases new product-ready tech startups. Plus: hackathon, exhibition, and speakers. Use promo code CBSi50 for 50% discount.
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.