HOME / NEWS / CLOUD COMPUTING / COS LIKELY TO USE SAAS FOR SENSITIVE DATA THAN FOR MISSION-CRITICAL DATA
Cos Likely To Use SaaS For Sensitive Data Than For Mission-Critical Data
These findings are based on Gartner's latest annual survey of the state of risk management programs globally, which questioned 425 respondents from IT risk management disciplines in the U.S., U.K., Germany and Canada from December 2011 to January 2012.
The survey results show that organisations take different approaches to risk management when confronted with a need or opportunity to share data with different types of external party.
Assessment Practices For External Parties
Survey respondents were asked if they had processes in place to assess external party security, risk management, compliance, privacy and BCP/DR for four different situations. Respondents answered: “Do not allow use for sensitive data or processes" almost twice as often in the case of business partners (38 percent) as for Platform-as-a-Service (PaaS) and Infrastructure-as-a-Service (IaaS) (20 percent).
Compared with PaaS/IaaS, organisations are about 30 percent more likely to have a policy against putting sensitive data into SaaS (26 percent), and about 45 percent more likely to have a policy against putting it into outsourced datacentres (29 percent).
PaaS/IaaS Risk Assessment Practices
Only 57 percent of IaaS/PaaS buyers are using a questionnaire to support their risk assessment, and unlike for SaaS, the questionnaire is more likely to be a proprietary one, unique to the buyer's organisation, and less likely to be based on standards. As in the case of SaaS, 26 percent are also evaluating information from the provider. The most dramatic change over the past three years is the increased willingness to use IaaS and PaaS for sensitive processes.
Outsourced Datacentre Risk Assessment Practices
Thirty-six percent of respondents said they had a policy against putting mission-critical data into an outsourced datacentre, making avoidance the most chosen mechanism for dealing with datacentre risk. The level of response for this choice is significantly higher than for either of the other two service models. 29 percent said this policy applied to SaaS, and only 22 percent said it applied to IaaS/PaaS.
"One of the biggest drivers is probably an expectation that the packaged service offerings, which typically claim to be based on cloud computing, are more reliable," said Heiser. "While fault tolerance is a feature of many such offerings, we consider it premature to assume that mission-critical data is safer in a cloud than in a traditional datacentre in which buyers usually make very specific choices about how data will be backed up."
The most significant reduction in the use of risk assessment practices has been in the practice of sending company staff to evaluate a partner's controls on-site, which has dropped by over 40 percent over three years. Use of standards-based questionnaires has increased, while the use of proprietary surveys has dropped by the same degree, leaving the prevalence of questionnaires virtually the same.
16th May, 2013 by Biztech2.com Staff
SAP Introduces New Solutions To Line-Of-Business Cloud Applications
16th May, 2013 by Biztech2.com Staff
Cloud Services Cannibalise Software And IT Services Spend: IDC
16th May, 2013 by Reuters
![]()
MORE IN CLOUD COMPUTING
Trend Micro Ramps Up Its Cloud Security Optimised For AWS
21st May, 2013 by Biztech2.com Staff
Trend Micro Deep Security as a Service provides security capabilities delivered...
Cloud Strategy Crucial To Social-Based Collab
17th May, 2013 by Sharon D'Souza
Sunil Jose, VP Oracle India talks about why cloud suite offerings are the craze...
SAP Introduces New Solutions To Line-Of-Business Cloud Applications
16th May, 2013 by Biztech2.com Staff
To empower line-of-business users, SAP delivers line-of-business cloud...
Cloud Services Cannibalise Software And IT Services Spend: IDC
16th May, 2013 by Biztech2.com Staff
IDC analyses spend patterns in the face of economic uncertainty surrounding the...
Amazon Gets Help To Lure Big Business To The Cloud
16th May, 2013 by Reuters
The online retailer is roping in thousands of consulting and technology...
















There are no comments on this article yet. Why don't you post one?