SlideShare ist ein Scribd-Unternehmen logo
1 von 8
Downloaden Sie, um offline zu lesen
Unintended Regulatory
Consequences And The
       Cloud
              Kirk Wylie
        kirk@kirkwylie.com
    http://kirkwylie.blogspot.com

          3 February, 2009
         Powered By Cloud
Nobody Says You Can’t
Use Cloud Computing
• Regulators don’t talk about the Cloud
• Regulators about what you must do
 • You must protect client data
 • You must protect against fraud
 • You must complete computations in time
Auditors Interprets
         Rules
• Auditors (internal and external) ensure
  compliance with regulations
• They follow best practice guides
• Violating guides requires strong IT
  leadership
  • You can do it, but your CIO better have a
    lot of political capital built up!
Best Practice Guides
 Don’t Understand
 Cloud Computing
Example: Client Data
• Applies to client or counterparty data
• Could use S3 to store and EC2 to process
• Best Practice is that your data never leave
  your premise
  • And you audit all access internally
  • And your data centre is completely
    secure
• What about extrusion?
Example: Risk Runs

• BASEL limits set by overnight risk runs
• Risk runs must complete by a given time, or
  you can’t trade
• What if it turns out Amazon IS finite?
• What if the market explodes at once?
Example: Fraud

• Must prevent nefarious teams from
  injecting P&L related code
• Must audit all injection vectors
• How can you do that in the cloud?
Conclusion
• Regulations don’t directly limit Cloud use
 • FSA doesn’t understand Virtualization
• Interpretation of regulations implicitly
  restrict cloud use
• Until compliance and audit teams
  understand new best practices, adoption
  will be limited

Weitere ähnliche Inhalte

Andere mochten auch

Identive | Press Release | Identive Group Announces Preliminary First Quarter...
Identive | Press Release | Identive Group Announces Preliminary First Quarter...Identive | Press Release | Identive Group Announces Preliminary First Quarter...
Identive | Press Release | Identive Group Announces Preliminary First Quarter...
Identive
 

Andere mochten auch (14)

Online Reputation
Online ReputationOnline Reputation
Online Reputation
 
Rechtssicheres E-Mail-Marketing 2013
Rechtssicheres E-Mail-Marketing 2013Rechtssicheres E-Mail-Marketing 2013
Rechtssicheres E-Mail-Marketing 2013
 
idOnDemand | Article | Looking For An ID Solution? Get It From idOnDemand!
idOnDemand | Article | Looking For An ID Solution? Get It From idOnDemand!idOnDemand | Article | Looking For An ID Solution? Get It From idOnDemand!
idOnDemand | Article | Looking For An ID Solution? Get It From idOnDemand!
 
NFC Forum Compliance Program Overview
NFC Forum Compliance Program OverviewNFC Forum Compliance Program Overview
NFC Forum Compliance Program Overview
 
How Social Data boosts Conversion
How Social Data boosts ConversionHow Social Data boosts Conversion
How Social Data boosts Conversion
 
An algorithm for decomposition coordination of large scale convex programmimg...
An algorithm for decomposition coordination of large scale convex programmimg...An algorithm for decomposition coordination of large scale convex programmimg...
An algorithm for decomposition coordination of large scale convex programmimg...
 
How to build and manage a superior customer experience leading to a better bo...
How to build and manage a superior customer experience leading to a better bo...How to build and manage a superior customer experience leading to a better bo...
How to build and manage a superior customer experience leading to a better bo...
 
Identive | Press Release | Identive Group Announces Preliminary First Quarter...
Identive | Press Release | Identive Group Announces Preliminary First Quarter...Identive | Press Release | Identive Group Announces Preliminary First Quarter...
Identive | Press Release | Identive Group Announces Preliminary First Quarter...
 
Kompetenz-Häppchen Nr. 03 zu Effizienz in der HR von Thomas Eggert
Kompetenz-Häppchen Nr. 03 zu Effizienz in der HR von Thomas Eggert Kompetenz-Häppchen Nr. 03 zu Effizienz in der HR von Thomas Eggert
Kompetenz-Häppchen Nr. 03 zu Effizienz in der HR von Thomas Eggert
 
Appetizer Corporate Design
Appetizer Corporate DesignAppetizer Corporate Design
Appetizer Corporate Design
 
Studienergebnisse vertriebsklima-Index
Studienergebnisse vertriebsklima-IndexStudienergebnisse vertriebsklima-Index
Studienergebnisse vertriebsklima-Index
 
Mobile Convention Amsterdam 2015 - MEF/ Wirecard - Jack Harris
Mobile Convention Amsterdam 2015 - MEF/ Wirecard - Jack HarrisMobile Convention Amsterdam 2015 - MEF/ Wirecard - Jack Harris
Mobile Convention Amsterdam 2015 - MEF/ Wirecard - Jack Harris
 
250 Diapositivas
250 Diapositivas250 Diapositivas
250 Diapositivas
 
Technische Innovationen vs. Erfüllung erforderter IT-Sicherheit?
Technische Innovationen vs. Erfüllung erforderter IT-Sicherheit?Technische Innovationen vs. Erfüllung erforderter IT-Sicherheit?
Technische Innovationen vs. Erfüllung erforderter IT-Sicherheit?
 

Kürzlich hochgeladen

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Kürzlich hochgeladen (20)

Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 

Powered By Cloud 2009-02-03

  • 1. Unintended Regulatory Consequences And The Cloud Kirk Wylie kirk@kirkwylie.com http://kirkwylie.blogspot.com 3 February, 2009 Powered By Cloud
  • 2. Nobody Says You Can’t Use Cloud Computing • Regulators don’t talk about the Cloud • Regulators about what you must do • You must protect client data • You must protect against fraud • You must complete computations in time
  • 3. Auditors Interprets Rules • Auditors (internal and external) ensure compliance with regulations • They follow best practice guides • Violating guides requires strong IT leadership • You can do it, but your CIO better have a lot of political capital built up!
  • 4. Best Practice Guides Don’t Understand Cloud Computing
  • 5. Example: Client Data • Applies to client or counterparty data • Could use S3 to store and EC2 to process • Best Practice is that your data never leave your premise • And you audit all access internally • And your data centre is completely secure • What about extrusion?
  • 6. Example: Risk Runs • BASEL limits set by overnight risk runs • Risk runs must complete by a given time, or you can’t trade • What if it turns out Amazon IS finite? • What if the market explodes at once?
  • 7. Example: Fraud • Must prevent nefarious teams from injecting P&L related code • Must audit all injection vectors • How can you do that in the cloud?
  • 8. Conclusion • Regulations don’t directly limit Cloud use • FSA doesn’t understand Virtualization • Interpretation of regulations implicitly restrict cloud use • Until compliance and audit teams understand new best practices, adoption will be limited