12.07.2015 Views

Negotiating in the cloud - legal issues in cloud ... - About AGIMO

Negotiating in the cloud - legal issues in cloud ... - About AGIMO

Negotiating in the cloud - legal issues in cloud ... - About AGIMO

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>the</strong> <strong>in</strong>clusion of standard Commonwealth exceptions to confidentiality <strong>in</strong>clud<strong>in</strong>g <strong>the</strong> right toprovide <strong>in</strong>formation to <strong>the</strong> relevant m<strong>in</strong>ister as well as houses of Parliament.Records management requirementsAgencies should refer to Records management and <strong>the</strong> <strong>cloud</strong> - a checklist 6 prepared by <strong>the</strong>National Archives of Australia for records management considerations <strong>in</strong> <strong>cloud</strong> comput<strong>in</strong>g. Thatadvice requires agencies to <strong>in</strong>clude appropriate controls and protections (for example throughagreement with <strong>the</strong> <strong>cloud</strong> service provider) that match <strong>the</strong> value of <strong>the</strong> records and address <strong>the</strong>risks of <strong>cloud</strong> comput<strong>in</strong>g for an agency’s records.AuditAll <strong>the</strong> protections described <strong>in</strong> this section may potentially be worthless unless <strong>the</strong> agency isable to confirm that required <strong>in</strong>formation protection requirements are <strong>in</strong> fact be<strong>in</strong>g met. Audit of<strong>cloud</strong> comput<strong>in</strong>g arrangements is one way of check<strong>in</strong>g compliance. Audit of such arrangementsis however potentially complicated by:<strong>the</strong> location of <strong>the</strong> data – which, unless specifically identified and locked down <strong>in</strong> <strong>the</strong>agreement, may be unknown to <strong>the</strong> agency, and could be located <strong>in</strong> one or more discretesites <strong>in</strong> foreign countries<strong>the</strong> nature of <strong>cloud</strong> comput<strong>in</strong>g itself which may <strong>in</strong>volve agency data be<strong>in</strong>g spread across alarge number of different provider comput<strong>in</strong>g devices (<strong>in</strong> order to harness <strong>the</strong> economies ofscale and on-demand provision of comput<strong>in</strong>g that <strong>cloud</strong> comput<strong>in</strong>g services offer).As a result, agencies should consider <strong>in</strong>clud<strong>in</strong>g <strong>the</strong> follow<strong>in</strong>g rights <strong>in</strong> any agreement: restrict<strong>in</strong>g <strong>the</strong> locations/countries <strong>in</strong> which agency data may be held (with movement tonew locations permitted with advance approval <strong>in</strong> writ<strong>in</strong>g from <strong>the</strong> agency) rights to audit <strong>the</strong> provider’s compliance with <strong>the</strong> agreement <strong>in</strong>clud<strong>in</strong>g rights of access to <strong>the</strong>provider’s premises where relevant records and agency data is be<strong>in</strong>g held audit rights for <strong>the</strong> agency (or its nom<strong>in</strong>ee), <strong>the</strong> Auditor-General and <strong>the</strong> InformationCommissioner a right for <strong>the</strong> agency to appo<strong>in</strong>t a commercial auditor as its nom<strong>in</strong>ee (as this allows <strong>the</strong>agency to appo<strong>in</strong>t an auditor <strong>in</strong> <strong>the</strong> same location as <strong>the</strong> provider’s data centre to save costsand ensure compliance with relevant jurisdictional laws) where technically available, <strong>the</strong> right for <strong>the</strong> agency to remotely monitor access to its dataand where this is not possible, a requirement that <strong>the</strong> provider ma<strong>in</strong>ta<strong>in</strong> an audit log ofaccess to <strong>the</strong> agency's data and provide that log to <strong>the</strong> agency on request.Compensation for data loss/misuseIt is possible that data could be permanently lost by a <strong>cloud</strong> comput<strong>in</strong>g services provider <strong>in</strong> anumber of circumstances such as technical or operator error as well as fire or o<strong>the</strong>r disasters.Similarly, <strong>the</strong>re is always <strong>the</strong> risk of misuse of data by rogue employees of <strong>the</strong> provider orcompromise by external parties.While <strong>the</strong> probability of such problems can be m<strong>in</strong>imised by <strong>the</strong> provider ensur<strong>in</strong>g offsite databack-up, proper technical and security tra<strong>in</strong><strong>in</strong>g and hardware ma<strong>in</strong>tenance, it is important for6 http://www.naa.gov.au/records-management/publications/<strong>cloud</strong>-checklist.aspx<strong>Negotiat<strong>in</strong>g</strong> <strong>the</strong> <strong>cloud</strong> – <strong>legal</strong> <strong>issues</strong> <strong>in</strong> <strong>cloud</strong> comput<strong>in</strong>g agreements | 8

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!