<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.blackbaud.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PCI Compliance Blog : compliance</title><link>http://forums.blackbaud.com/blogs/pci/archive/tags/compliance/default.aspx</link><description>Tags: compliance</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP2 (Debug Build: 20611.960)</generator><item><title>Who Is Managing Risks in the Clouds?</title><link>http://forums.blackbaud.com/blogs/pci/archive/2009/05/01/who-is-managing-risks-in-the-clouds.aspx</link><pubDate>Fri, 01 May 2009 19:03:00 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:41202</guid><dc:creator>Jake Marcinko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/pci/rsscomments.aspx?PostID=41202</wfw:commentRss><comments>http://forums.blackbaud.com/blogs/pci/archive/2009/05/01/who-is-managing-risks-in-the-clouds.aspx#comments</comments><description>&lt;p&gt;There&amp;#39;s no mistaking the buzz that cloud computing has created. From board rooms to break rooms, everyone these days is taking about &amp;quot;the Cloud&amp;quot;. Let&amp;#39;s face it, cloud services--whether they be software-as-a-service (SaaS), infrastructure as a service (IaaS), or platform-as-a-service (PaaS) offerings--are a compelling alternative to traditional IT functions. Cloud services offer increased collaboration, agility, scale, availability and cost reductions.&amp;nbsp; They can simplify and accelerate compliance initiatives and provide for greater security. However, simply outsourcing traditional business and IT functions to cloud service providers is no guarantee that these benefits will be realized. Organizations must continue to take active participation in managing the risks associated with outsourcing such services, particularly those that involve highly-regulated information such as constituent data. Otherwise, those organizations might actually be increasing their business risks by outsourcing rather than transferring or mitigating them.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Outsourcing the processing and storage of constituent information doesn&amp;#39;t make it inherently more secure. &amp;nbsp;The nature of cloud services, by definition, lacks boundaries and therefore raises concerns with respect to privacy legislation. Regardless of what contractual obligations you may have negotiated with the provider, the requirement to protect your constituent information remains your responsibility regardless of where the data is located, including the cloud. Does your service provider outsource any data processing or storage functions to third-parties? Do those third-parties have adequate security programs? How do you know whether or not your service provider (and their service providers) have adequate security programs? While better than nothing at all, independent security assessments (such as those performed as part of a SAS70 or PCI audit) are point-in-time evaluations. Additionally, the scope of such assessments can be directed at the provider&amp;#39;s discretion and may not provide accurate insight into the provider&amp;#39;s ongoing security activities. &lt;/p&gt;
&lt;p&gt;The bottom line is that many questions still remain with respect to Cloud Governance and Enterprise Risk. Non-profit organizations considering migrating their fundraising activities and solutions to cloud services should first evaluate its own practices, needs and restrictions in order to identify legal barriers and compliance requirements. The security of the cloud computing environment isn&amp;#39;t mutually exclusive of your organization&amp;#39;s internal policies, procedures, standards, guidelines, and processes. Security is a process, not a product and therefore the technical security of your constituent data is only as strong as your organization&amp;#39;s weakest process. Comprehensive initial and ongoing due diligence&amp;nbsp;audits of&amp;nbsp;both your business practices as well as your provider&amp;#39;s practices is required when making the decision to push sensitive constituent information to the cloud.&lt;/p&gt;&lt;img src="http://forums.blackbaud.com/aggbug.aspx?PostID=41202" width="1" height="1"&gt;</description><category domain="http://forums.blackbaud.com/blogs/pci/archive/tags/PCI+DSS/default.aspx">PCI DSS</category><category domain="http://forums.blackbaud.com/blogs/pci/archive/tags/security/default.aspx">security</category><category domain="http://forums.blackbaud.com/blogs/pci/archive/tags/privacy/default.aspx">privacy</category><category domain="http://forums.blackbaud.com/blogs/pci/archive/tags/compliance/default.aspx">compliance</category><category domain="http://forums.blackbaud.com/blogs/pci/archive/tags/sas70/default.aspx">sas70</category><category domain="http://forums.blackbaud.com/blogs/pci/archive/tags/cloud/default.aspx">cloud</category><category domain="http://forums.blackbaud.com/blogs/pci/archive/tags/policies+and+procedures/default.aspx">policies and procedures</category></item></channel></rss>