You are on page 1of 2

Risk, Compliance and Governance in

the Cloud
New delivery model brings new concerns

The journey to cloud is one that has many Chief Financial Officers “As a global corporation, you have to be cognizant of the laws in
(CFOs) paying attention, and for good reason. Cloud has the every country where you operate,” says Forbes Alexander, CFO of
potential to bring significant business benefit through increased US-based Jabil Circuit1. “In parts of Western Europe, it is illegal to
agility, reduced time to market, not to mention cost savings. share personal and private information. How does a law account
Alongside these benefits lie risks as well. To best prepare the for you putting it off in a cloud somewhere? I don’t know enough
enterprise or government for the journey to cloud, CFOs must about that, but I suspect it’s not just as easy as flipping a switch
understand and assess these risks. The key areas of concern are: and putting everything out on a cloud. We’re in the early stages of
• Governance and compliance figuring all this out.”

• Data security Beyond the location of the data, cloud services can quickly
• Vendor reliability and quality and easily be provisioned by anyone within the business. This
raises new issues around governance, so Chief Financial Officers
should review existing policies and procedures to ensure that
Compliance in the cloud the provisioning of cloud services is handled in accordance with
company requirements.
For most large multi-national businesses, regulatory compliance,
corporate governance and risk management are areas of growing
complexity and considerable focus. For CFOs, this is arguably the
single most important area of responsibility.
Concerns about data security
Closely linked to the issue of compliance is the issue of data
The disruptive nature of cloud and its ability to change the security. For many CFOs and CIOs, this is the primary concern
fundamental operating rules for IT and business can have a associated with moving to a cloud-based solution provided by a
significant impact on the areas of governance, compliance and third party. Data breaches already occur, despite sophisticated
risk. Perceived risks differ depending on the cloud delivery security solutions and state of the-art firewall technologies. For
models, so CFOs must carefully assess how cloud services are many C-suite executives, the concept of storing highly sensitive
provisioned as well as what data, applications and processes are data with a third party operation, and accessing it remotely adds a
moved to cloud, whether public, hybrid or private. level of security risk that today, they are unwilling to contemplate.
However, a number of applications are seeing wide acceptance as
As cloud solutions are deployed by an enterprise or government, candidates for cloud, including email and customer relationship
CFOs may need to establish new processes and policies to ensure management applications.
that corporate compliance and governance maintain the highest
standard. In cloud, there is the potential for data to be stored
not just outside the firewall of the enterprise or government, but
also in another country or geography. So, CFOs must consider
the impact on compliance that passing data across international
borders may have.
However, there exists the potential that cloud service providers Cloud solutions are available for a wide range of business
may have best-in class security solutions in place. As Forrester functions and applications. Thoughtfully determining which
analyst Chenxi Wang puts it in a recent report2, “Moving to a cloud business applications are ready for public cloud and those that
service may actually improve your security posture. Think about require private or dedicated operation is an important area for
it: Is it more secure to store sensitive corporate information on CFO and CIO collaboration. Non-mission critical applications and
end user laptops and USBs rather than in a central repository with less sensitive company data may be prime candidates for early
a cloud provider that you have thoroughly vetted?” experimentation with cloud. Longer term, CIOs and CFOs should
work together to plan a roadmap to cloud—both financial and
Careful consideration must be given to what types of data may technological—that maximizes the opportunities of cloud while
be shared and where it is stored. CFOs must also be cautious in addressing the associated risks.
choosing which cloud vendors to trust with their company’s data.
Call your local HP Financial Services representative now or find us
on the web at hp.com/go/hpfs_countries
Vetting—and trusting—vendors
The assessment of vendor reliability and quality is important in
determining which type of business applications can and should 1
CFO Publishing LLC: “Exploring New Models for Enterprise IT”, November 2011
be moved to the cloud. Most large companies will already have 2
Forrester: “Q&A Demystifying Cloud Security”, October 29, 2010
policies and procedures in place to handle the selection and 3
CFO Publishing LLC: “Exploring New Models for Enterprise IT”, November 2011
management of vendors. These policies will need to be assessed
and potentially refined to include cloud vendors. This can ensure
sufficient vendor resources are in place to fully support business
applications outsourced to cloud and other long term needs for
the business. Carsten Krogsgaard Thomsen, CFO of DONG Energy
in Denmark, puts it quite simply3: “You want to be sure that
whoever provides the cloud computing is financially strong and
very solid, so that you can be sure they are also there next month.
Also, security of data is a must when using cloud computing.”

Get connected
hp.com/go/getconnected
Get the insider view on tech trends,
support alerts, and HP solutions

© Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and
services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors
or omissions contained herein.

4AA3-8422ENW, September 2012

You might also like