Email Alerts
-
HIPAA cloud computing advice: Ensuring cloud computing compliance
How can an enterprise ensure their cloud service provider is compliant with HIPAA? This HIPAA cloud computing guide offers advice on how to ensure cloud computing compliance. Tutorial
-
Eye On: Cloud Compliance
SearchSecurity.com's "Eye On" series looks at the emerging compliance issues due to the explosion of enterprise adoption of cloud computing services. News | 23 Jan 2012
-
FedRAMP cloud computing standards initiative spurs optimism, criticism
Federal cloud security framework aims to speed cloud security assessments and agency cloud adoption. News | 12 Jan 2012
-
Cloud risk management: CSA on its Cloud Controls Matrix
Co-chair of CSA project talks about the CCM and how organizations can leverage it. News | 03 Oct 2011
-
Amazon launches U.S. government cloud
AWS GovCloud supports ITAR compliance requirements. News | 17 Aug 2011
-
AWS cloud computing compliance paper details customer responsibilities
Cloud giant makes it clear the onus is on customers when it comes to HIPAA, GLBA and other regulations. News | 28 Jun 2011
-
White House CIO talks up cloud computing strategy
Sprawling IT infrastructure hard to manage and secure, Vivek Kundra tells CSA crowd. News | 15 Feb 2011
-
HIPAA business associate agreement key to company’s cloud migration
Wound therapy provider moves IT infrastructure to cloud provider. News | 08 Feb 2011
-
Cloud computing technologies and financial services
Cloud computing offers cost savings but how does it fit into the highly regulated financial services industry? Article | 02 Dec 2010
-
Cloud computing risks outweigh benefits, survey finds
The risks of cloud computing outweigh the benefits according to a survey of more than 1,800 U.S.-based IT professionals who are members of the ISACA organization. Article | 08 Apr 2010
-
Forrester advises cautious approach to cloud computing services
While it could save money, many firms should understand the security, privacy and legal issues when using cloud-based services. Article | 14 May 2009
-
Development of NIST cloud security guidelines a complex process
Several public-private partnerships are working to develop specifications to support the NIST roadmap. Tip
-
Massachusetts 201 CMR 17.00 and cloud services
Organizations face a March 1 deadline for ensuring their cloud and other service providers comply with Massachusetts’ data protection regulation. Tip
-
Are cloud providers HIPAA business associates?
Deciding whether your cloud provider is a business associate comes down to a judgment call based on the type of cloud usage. Tip
-
Stepping carefully into health care cloud computing
Health care providers must plan any cloud migration carefully to protect patient safety and maintain HIPAA compliance. Tip
-
NIST guidance cites cloud security gaps, need for standards
The NIST roadmap was designed to foster government cloud adoption but is helpful for private businesses as well. Tip
-
E-Discovery Cloud Considerations
What happens if your company needs to preserve evidence stored with a cloud provider? Tip
-
Cloud computing and health care DR planning
Downtime is bad for any company, but in health care it can have devastating consequences. Understand how the cloud impacts your disaster recovery plans. Tip
-
Are dedicated EC2 instances enough for compliance?
A review of Amazon’s new dedicated instances and whether they make the cloud safe for highly regulated companies. Tip
-
Maintaining compliance with HIPAA security requirements in the cloud
What do you do if you discover after the fact that PHI has already been moved to a cloud provider? Tip
-
Compensating controls can help boost cloud compliance
Cloud computing can be attractive for IT services, except when it's time to figure out a compliance strategy. Chenxi Wang of Forrester Research explains the cloud compliance complexities and offers four compensating controls that can help. Tip
- See More: Tips on Cloud Compliance: Federal Regulations and Industry Regulations
-
SSAE 16
SSAE 16, also called Statement on Standards for Attestation Engagements 16, is a regulation created by the Auditing Standards Board (ASB) of the American Institute of Certified Public Accountants (AICPA) for redefining and updating how service compan... Definition
-
Cloud Controls Matrix
The Cloud Controls Matrix is a baseline set of security controls created by the Cloud Security Alliance to help enterprises assess the risk associated with a cloud computing provider. Definition
-
CloudAudit
CloudAudit is a specification for the presentation of information about how a cloud computing service provider addresses control frameworks. The specification provides a standard way to present and share detailed, automated statistics about performan... Definition
-
Cloud computing pros and cons for regulated data
Has your company considered moving regulated data to the cloud? Expert Richard E. Mackey Jr. explains the pros, cons and security challenges of doing so. Video
-
Google Apps security director discusses compliance within the cloud
Google Apps Security Director, Eran Feigenbaum discusses compliance within the cloud, including his thoughts on emerging cloud security standards. Video
-
Q&A: Forrester's Chenxi Wang discusses cloud compliance
Forrester's Chenxi Wang discusses cloud compliance and the issues involved with maintaining compliance with PCI, SOX and HIPAA and using cloud-based services. Video
-
Social media and cloud computing for financial services
Paul Smocer of BITS discusses the use of social media and cloud computing by financial services firms, including the inherent risks, and what you can do to mitigate them Video
-
SSAE 16
SSAE 16, also called Statement on Standards for Attestation Engagements 16, is a regulation created by the Auditing Standards Board (ASB) of the American Institute of Certified Public Accountants (AICPA) for redefining and updating how service compan... Definition
-
HIPAA cloud computing advice: Ensuring cloud computing compliance
How can an enterprise ensure their cloud service provider is compliant with HIPAA? This HIPAA cloud computing guide offers advice on how to ensure cloud computing compliance. Tutorial
-
Development of NIST cloud security guidelines a complex process
Several public-private partnerships are working to develop specifications to support the NIST roadmap. Tip
-
Massachusetts 201 CMR 17.00 and cloud services
Organizations face a March 1 deadline for ensuring their cloud and other service providers comply with Massachusetts’ data protection regulation. Tip
-
Are cloud providers HIPAA business associates?
Deciding whether your cloud provider is a business associate comes down to a judgment call based on the type of cloud usage. Tip
-
Eye On: Cloud Compliance
SearchSecurity.com's "Eye On" series looks at the emerging compliance issues due to the explosion of enterprise adoption of cloud computing services. News
-
FedRAMP cloud computing standards initiative spurs optimism, criticism
Federal cloud security framework aims to speed cloud security assessments and agency cloud adoption. News
-
Stepping carefully into health care cloud computing
Health care providers must plan any cloud migration carefully to protect patient safety and maintain HIPAA compliance. Tip
-
NIST guidance cites cloud security gaps, need for standards
The NIST roadmap was designed to foster government cloud adoption but is helpful for private businesses as well. Tip
-
Cloud Controls Matrix
The Cloud Controls Matrix is a baseline set of security controls created by the Cloud Security Alliance to help enterprises assess the risk associated with a cloud computing provider. Definition
- See More: All on Cloud Compliance: Federal Regulations and Industry Regulations
About Cloud Compliance: Federal Regulations and Industry Regulations
Companies in highly regulated industries such as financial services and health care must comply with regulations such as SOX, GLBA and HIPAA. This section covers compliance regulations and the cloud. Learn about critical SOX, GLBA and HIPAA considerations surrounding cloud compliance, as well as industry regulations such as NERC.
Cloud Computing Strategies for the CIO