Monday, February 1, 2010

IT Governance Offers Safe Route to the Benefits of Cloud Computing

IT Governance (ITG) is helping companies find the efficiencies and savings of cloud computing without putting business information at risk. Through cloud computing, a company’s IT functions are moved to an external, shared service provider and accessed over the Internet. Data is no longer stored in-house and software applications are no longer owned by the company. IT Governance’s latest book, Above the Clouds: Managing Risk in the World of Cloud Computing (http://www.itgovernance.co.uk/products/2826), explains the potential benefits of adopting this approach.

Author Kevin T. McDonald challenges the misconception that cloud computing must necessarily offer weaker data protection than an in-house server. In fact, he argues that cloud computing can help to defend an organisation from IT security threats such as denial-of-service attacks, viruses and worms. The risk management process begins when choosing a service provider. McDonald says: “You need to be confident that your business information will be secure. You need to make sure you carry out due diligence on the service provider before you entrust this firm with your vital data. The challenge for procurement professionals is determining what questions to ask, what assurances should be in the contracts and how much risk is being assumed when a service is moved to the ‘cloud’.”

McDonald says the concept of ‘outsourcing to the cloud’ is proving increasingly attractive to companies seeking to save money. “The cost is falling dramatically, which means it’s no longer rare for a company to consider cloud computing.” A company is charged for the use of software applications, and for data storage, just like being charged for electricity. In only paying for the resources used, therefore, operating costs can be reduced. After all, as McDonald explains, in-house data centres typically leave 85%-90% of available capacity idle. Visit the ITG portal for complete service details

0 comments:

Post a Comment

Topics-Tags

GRC (7) Compliance (6) Governance (4) ISACA (4) IT security (3) PCI (3) Andy Greenawalt (2) CPE credit hours (2) Continuity Engine (2) ControlPanelGRC (2) FFIEC (2) IT Governance (2) ITG (2) Information Security and Risk Management Conference. Jim Reavis President (2) Management software (2) Mega (2) PCI DSS (2) Risk (2) SaaS (2) SymSoft (2) best practices (2) eIQnetworksm (2) enterprise (2) enterprise risk management (2) hipaa (2) international conference (2) regulatory compliance (2) system administrators (2) 2010 Corporate Governance and Compliance Hotline Benchmarking Report (1) AML (1) ANSI (1) Above the Clouds (1) Accellion (1) ActOFAC (1) ActionPacks (1) Alan Calder (1) Apple® iPad™ (1) Archer Exchange (1) Archer SmartSuite Framework (1) Archer Technologies (1) Archer Threat Management (1) BAM™ (1) BDO Consulting (1) BSA (1) BSA Express™ (1) BSI (British Standards Institution (1) BWise (1) Bankers Toolbox (1) BoardDocs LT (1) BoardDocs Pro (1) CAMS (1) CGEIT (1) CRN (1) CTO (1) Campaign management (1) Certified Anti Money Laundering Specialists (1) Cloud Computing (1) Compliance Module (1) ComplianceVue (1) Control (1) Control testing (1) Cypress Software Systems (1) Data Security Standard (1) Datactics (1) ECQM (1) ERM (1) Enterprise Compliance and Quality Management (1) Enterprise GRC Controls (1) Enterprise Security Reporter® 3.7 (1) FISMA (1) Facebook (1) File System Auditor™ 2.5 (1) First Round Capital (1) Forrester (1) Forrester Research (1) GLBA (1) GRC Manager (1) GRC platform market (1) HIPAAVue (1) ICBM (1) IEC (1) IT Risk Reward Barometer (1) Jim Forrester (1) Luc Brandts (1) Lucio de Risi (1) MDM (1) MEGA Solution for Compliance (1) Mainline Information Systems (1) Managed File Transfer (1) Managing Risk (1) Mark IV (1) Meenu Gupta (1) Mittal Technologies (1) Multi-compliance support (1) NERCVue™ (1) Oracle (1) PA-DSS (1) PCI SSC (1) PCI Security Standards Council (1) PCI compliance (1) PCIVue™ (1) PED (1) PIN Entry Device (1) Payment Application Data Security Standard (1) Payment Card Industry Data Security Standard (1) Philippe Courtot (1) Pilgrim Software (1) Pironti (1) President (1) Qualys (1) QualysGuard (1) Reavis Consulting Group (1) Red Flag PATRIOT (1) Robert Pijselman (1) SAP (1) SAP Security and Technical administration (1) STEP (1) ScriptLogic (1) SecureVue (1) SecureVue Central Server (1) SmartInsight™ Report Writer (1) SmartSolve (1) Software as a Service (1) Steve Croft (1) Stibo Systems (1) The Network (1) Twitter (1) Yorgen Edholm (1) analytics (1) application (1) attributes (1) audit tools (1) compliance issues (1) compliance officers (1) compliance platform (1) compliance reporting (1) compliance tax relief (1) complianceISO27000 (1) confidential data (1) control management (1) credit card data (1) credit risk management (1) cyberspace (1) denial-of-service attacks (1) eGovernance (1) email-like interface (1) engine (1) enterprise customers (1) evidence-based healthcare (1) examine account activity (1) financial institutions (1) fraud reporting (1) holistic approach (1) identity theft (1) in-progress attacks (1) initiatives (1) internal auditors (1) large enterprises (1) loan application process (1) log data management (1) management (1) mandates (1) market (1) master data management (1) mitigation (1) mobile device (1) money laundering (1) outsourced monitoring services (1) oversubscribed funding round (1) payment card industry (1) platform (1) processes (1) remote location (1) risk and compliance (1) risk identification (1) risk managers (1) risk-based modeling (1) second-generation suite (1) sem (1) sim (1) suite (1) system security (1) toolset (1) transparent (1) vendor (1) viruses (1)