1 / 9

David A. Cass Senior Vice President & CISO Elsevier

Integrating Cloud Computing into Your Data Security Program. David A. Cass Senior Vice President & CISO Elsevier. Integrating Cloud Computing into Your Data Security Program. Agenda Approach Challenges Key security risks Risk mitigation Score card Best practices.

ayame
Download Presentation

David A. Cass Senior Vice President & CISO Elsevier

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. Integrating Cloud Computing into Your Data Security Program David A. Cass Senior Vice President & CISO Elsevier

  2. Integrating Cloud Computing into Your Data Security Program • Agenda • Approach • Challenges • Key security risks • Risk mitigation • Score card • Best practices

  3. Integrating Cloud Computing into Your Data Security Program • Elsevier Cloud Approach • Prevalence • Business drivers • Score card

  4. Integrating Cloud Computing into Your Data Security Program • Challenges the classical security attributes • Confidentiality, integrity, availability • System is no longer on premises • The infrastructure is shared • Access is through the internet

  5. Integrating Cloud Computing into Your Data Security Program • Key Security Risks • Governance & compliance • Data management • Cotenants/isolation failure • Security procedures of providers • Outsourcing • Abuse of privileges by provider • Regulatory & legal • Business continuity & disaster recovery

  6. Integrating Cloud Computing into Your Data Security Program • Risk Mitigation • Contracts & SLAs • Encryption • Auditing • Security certifications • Provider insurance policy

  7. Integrating Cloud Computing into Your Data Security Program • Cloud Readiness Scorecard • Technology stack • Integration complexity • Business drivers • SLA • Regulatory • Data transfer/networking • Information security

  8. Integrating Cloud Computing into Your Data Security Program • Best Practices • Calculate ROI of on-premises vs. cloud • Evaluate Scorecard rating • Review information security practices of provider • Review SLAs • Evaluate elasticity & scalability

  9. Integrating Cloud Computing into Your Data Security Program • Questions? • David Cass, SVP & CISO • Elsevier • Office: (215) 239-3210 • E-mail: d.cass@elsevier.com

More Related