Using the cloud for data processing and storage may have its advantages in terms of simplicity and cost, but ensuring regulatory compliance will not be nearly so simple.
What it all comes down to, ultimately, is that the user organization is responsible for figuring out who is doing what to its data and requiring assurances about the data staying in compliance.
[ Also check out the analysis "What if your storage cloud turns stormy?" and its related sidebar: Tips for safe cloud storage | Also: Can you trust your data to storage cloud providers? | Learn more about What cloud computing really means | And follow the cloud with InfoWorld's Cloud Computing blog ]
"In certain cases, compliance will be impossible," predicted Jim Haskin, senior vice president at Websense, a security services vendor in San Diego. "It is difficult to take full responsibility for who can access data, who sees it and how it is stored, since the premise of the cloud is that customers don't necessarily need to know or care where their data is," he added.
"As enterprises start to run their entire networks on the cloud, existing certifications [such as Gramm-Leach-Bliley, etc.] start to break down," added Jonathan Bryce, co-founder of Mosso, the cloud division of Rackspace, a hosting firm in San Antonio. "The certifications assume that the enterprise controls everything, and it's all located within their office building."
But some observers make the point that the cloud doesn't necessarily complicate compliance issues. "The concept of auditing is to track everything that goes on, whether it's across the cloud or across multiple datacenters of the same firm -- tracking is no different no matter where the various components are," said Mike Karp, senior analyst at Enterprise Management Associates, an enterprise IT consultancy based in Boulder, Colo.
In fact, various sources agreed that regulatory compliance is often possible with cloud computing, although it takes special effort. As noted by Chris Day, senior vice president at Terremark Worldwide, a cloud service in Miami that offers what it claims is a fully compliant cloud, "There is no magic solution." The basis of Terremark's compliance is that Terremark claims to know where the client's data is and what parts of the network it passes through, even if that complexity is invisible to the client.
That said, each separate compliance environment requires specific attention, Day added.