A guest article by Gerd Schramm, <data>S Data Protection and Information Security, Ulm
These days, it seems to be quite easy to keep software and hardware costs relatively low. For founders in particular, reducing costs related to storage capacity, servers, or dedicated software is a relief. That’s why cloud services are so popular.
A distinction is made between
- the outsourcing of entire hardware environments (infrastructure,“infrastructure as a service,” or IaaS for short, such as Dropbox),
- the outsourcing of software and applications (software,“software as a service,”or SaaS for short, such as Microsoft Office 365)
- and the outsourcing of individual services (such as“platform as a service,”or PaaS for short), such as operating a web server with an online store or MySpace.
In these cases, your data will be processed on computer systems that may be located anywhere in the world (!). Of course, special regulations apply to these platforms and the data stored and processed there, but legal provisions such as the U.S. Patriot Act grant U.S. authorities leeway that is incompatible with our data protection regulations in Germany. Even your cloud data stored on European soil is not safe from U.S. access.
The provisions of the Patriot Act allow U.S. agencies such as the FBI, the NSA, or the CIA to access the servers of U.S. companies, their subsidiaries, or affiliated companies—even those located outside the United States—without a court order.
Even if you might say, “So what? I have nothing to hide,” the fact remains that when sensitive company data is stored in the cloud, it is not—and cannot be—immune to hackers. Especially via internet connections and passwords, many instances of data theft are highly attractive—and quite lucrative—to the advertising industry, fraudsters, competitors, and various governments. Furthermore, you bear responsibility for the data of your customers and suppliers and are liable for it.
What should you do? How can you take advantage of cloud features while still maintaining a certain level of security?
- Think carefully about which cloud features you want to use and what sensitive data you (might) be entrusting to third parties.
- Keep in mind that you must have an Internet connection available at all times to use cloud computing. No Internet—no work.
- Classify your information by sensitivity
- Use appropriate encryption mechanisms
- If possible, choose a German or European cloud service provider and make sure they guarantee that data will not be stored outside the EU.
- As a general rule, exercise a certain degree of restraint in your online communication. Revealing less about yourself means more privacy.
- Use encryption methods not only for data storage but also for data exchange, such as via email
To wrap things up, here’s an image. Cloud computing (cloud) is marketed to us as a wonderful summer day with scattered fair-weather clouds. Anyone who’s ever been in the mountains knows how quickly the weather can change and how it feels to have to find your way through a cloud when visibility is just five meters. Cloud computing can be just as opaque and full of surprises—both legally and financially. Therefore: Conduct an objective risk assessment.
We’d be happy to help you with that.
<data>S
Dipl.-Inf. (FH)
Gerd Schramm
Sonnenweg 3
89081 Ulm
Tel.: 0731 8023688
Fax: 0731 8023699
info@data-S-ulm.de
http://www.data-S-ulm.de