The most popular and comprehensive Open Source ECM platform
Compliance: Organizations Worry About Compliance and Risk Management for the Cloud
While Cloud Computing continues to grow in hype and number of deployments, seemingly out of step of the trends, many IT departments remain unconvinced that cloud computing is ready for prime time. A survey by ISACA found that 45 percent of IT professionals still think that cloud computing is still too risk and insecure. In fact, only 10 percent of IT professionals said that they’d even consider moving a mission critical application to the cloud.
But that doesn’t mean that IT is totally ignoring the cloud. The cost savings of cloud based solutions are well understood, and because of that, IT departments are closely monitoring developments in the world of cloud computing and assessing the risks. Strategies for moving to the cloud are being developed, and a primary element of every strategy blueprint is the risk assessment. IT departments want to be able to understand the sensitivity of the data managed by each of their applications and the risks involved with moving application data from an on-premise infrastructure to a cloud-based one.
The ISACA report found that compliance, governance and information security management are the top concerns of IT departments today. Tony Noble, a member of ISACA’s guidance and practices committee, said that “from the growing number of government regulations to consumer privacy concerns to ‘hacktivist’ attacks, enterprise IT assets are being challenged in ways that go far beyond the server room.”
IT is increasingly being tasked with ensuring that their data management policies comply with numerous regulations. Just a few of these regulations include Basel, Frank-Dodd, Sarbanes-Oxley, PII, Do Not Track, Solvency II and HITECH Meaningful Use. Complicating the problem is that regulations are often very much a moving target — new ones are continually being introduced, and existing one change frequently or expire.
The ordered list of IT concerns listed in the ISACA report are as follows:
- Regulatory compliance
- Enterprise-based IT management and governance
- Information security management
- Disaster recovery and Business continuity
- Managing IT risks at five
- Vulnerability management
- Continuous process improvement and business agility
- Cloud Computing
- Mobile Device management
- Virtualization
- Business Development
53 percent of IT staff say that regulatory compliance is now their top concern. 80 percent say that senior management are slow to realize that data security is an important issue. 45 percent are concerned about how to best manage IT project risk.













