Do We Really Know ‘The Cloud’ At All?
Jan 01, 0001
Jan 01, 0001
Storing your photos, videos, documents and other information in “the cloud” sounds rather benign, to some degree – it conjures up light, airy thoughts of data at your fingertips, floating where it is easily accessible.
March 2014
By Scott Patterson, CFE
Storing your photos, videos, documents and other information in the cloud sounds rather benign, to some degree — it conjures up light, airy thoughts of data at your fingertips, floating where it is easily accessible. Within the relatively new phenomenon of cloud computing, there are cloud providers, from small, private firms to tech giants like Google, Apple and Microsoft. Yet, the concept of the cloud in terms of high tech information storage and transfer is still not entirely defined. In some general sense it just means “on the Internet,” but it has become a common part of our jargon and marketing-speak.
The vague manner in which the phrase cloud computing developed, however, might be enough to lend some serious concern in regards to where it might take us in terms of security. ACFE faculty member Walter W. Manning, CFE, provided some background on the cloud during an interview with the ACFE about the concept. Manning, founder of Investigations MD, described how cloud computing entered our lexicon. He also discussed the reasons to worry about the security of information when it takes to the clouds.
“Back in the early days of the Internet, network engineers would draw diagrams of how data was transmitted from point A to point B,” Manning said. “But when that involved going into the Internet, because it can go multiple different paths, they couldn’t detail and diagram that anymore. So they started creating their diagrams to go until the point got to the Internet, and then it went into the cloud. And then it got to point B, by whatever methodology the Internet allowed it to go by.”
Given the climate of nervousness following the massive data breaches that have made headlines recently, that piece of history about the cloud is not likely to be spun into a commercial for cloud computing services. Manning explained, however, how the concept has grown since its early days.
“Today, (the term cloud computing) is used not just for data transmission, but data storage and processing. So, companies are migrating to the cloud. But they’re migrating everything in their IT infrastructure to the cloud. They’re migrating applications, they’re migrating data storage. And individuals are also now able to use the cloud for data storage and applications … So, you can access any application, any item of data from any device, from anywhere — because the applications and the data are all stored in the cloud.”
While this may sound, at first, like a step forward in terms of accessibility and control over one’s data, Manning says that in the latter case, the opposite is true. For companies, when it comes to safeguarding their information (or their clients’ information), the implications of data being stored in the cloud may involved increased risk.
“From a security standpoint, that raises a lot of concerns, because now the IT Infrastructure that used to be managed by the enterprise is now distributed out to the cloud. So, it becomes somebody else’s responsibility,” Manning said. “So, all of the expertise that went into developing the security protocols to secure corporate data are now being managed by someone else.
“Particularly when you get into some of these cloud providers, you don’t know where the data is. You don’t know what security protocols are in place. You don’t know what country the data might be stored in. So, it could be literally stored in any country, anywhere in the world.”
At that point, the problems go beyond just safeguarding data, according to Manning. The nature of the cloud itself, and the unknown factor of where data is actually stored, could have further legal ramifications and impact investigations.
“Now you have different legal structures that come into play — different legal jurisdictions with different rules and regulations,” Manning said. “Different privacy regulations come into play that could have an impact on Investigations as well as security. The cloud has made a lot of things easier, and more convenient. But it’s also created a lot of new complexities, as well."
For computer security professionals, that might be enough to steer them away from using cloud providers. However, for many entrepreneurs looking to ride the high-tech wave, cloud computing might still be appealing enough for them to take the leap. Manning and other experts have provided some key points of advice for fraud examiners who serve clients who have decided to put their data, in whole or in part, in the cloud:
Pay attention to the risk associated with each end point. How is the data going to be accessed — from where, and by whom?
Find out what security protocols are in place by the cloud provider. A lot of large providers, like Google, Microsoft and Amazon, won’t even tell you what security protocols they have in place, even if you ask. And you’re a paying client. If they won’t tell you, how can you be sure that they’re adequate?
Conduct due diligence on the provider as you would with any company providing a critical service. What is the financial health of the company? What is its reputation and how long has it been in business? Are there any complaints or other red flags associated with it?
Note that publicly traded CSPs must include “risk factors” in their annual reports, which include vulnerabilities to security breaches, hacking attacks, system interruptions and other factors.
Preview any contract carefully to determine who maintains ownership of the data – the client company, or the cloud provider.
For any company looking to trust a third party with the storage and protection of their data, the above should just be the tip of the iceberg. Due diligence should be thorough, and no decision should be made in haste or based purely on financial comparisons.
Cloud computing provides some unique opportunities for data sharing and access, and it isn’t going away, with icons like Google, Apple and Microsoft leading the charge. However, companies that step into this brave new world without being cautious face the prospect of putting their client's (and their own) information at risk.