Anticipating Law Enforement Move to the Cloud, Assocation Publishes Guide

Today, the International Association of Chiefs of Police (IACP) released “Guiding Principles on Cloud Computing in Law Enforcement” at the Leveraging the Cloud for Law Enforcement Symposium held at the Newseum.  Developed in collaboration with key law enforcement subject matter experts from around the nation as well as experts from SafeGov.org, the principles establish clear and concise parameters and a path forward for the exploration of cloud-based computing solutions and services by law enforcement.  The IACP principles come after a newly released IACP/Ponemon Institute/SafeGov.org commissioned survey showed that over half of law enforcement agencies surveyed indicated that they had implemented, were planning or considering implementing cloud-based solutions in the next two years.

“Cloud computing represents an important shift in the way information resources are managed and deployed by law enforcement agencies,” said Bart R. Johnson , Executive Director, IACP. “Realizing the substantial potential benefits of cloud computing, however, requires that we recognize the sensitivity of law enforcement information, make every effort to maintain the security and availability of key systems and data, and that we work closely with industry to build solutions that meet the critical and evolving needs of law enforcement.”

The IACP principles focus on addressing some of the most tangible benefits that cloud computing offers, including cost savings, rapid deployment of critical resources, off-site storage and disaster recovery as well as meeting dynamic operational needs, while maintaining the security of systems and the proper use of data.

Key principles include:

  • FBI CJIS Security Policy Compliance – Services provided by a cloud service provider must comply with the requirements of the Criminal Justice Information Services (CJIS) Security Policy.
  • Data Ownership – Law enforcement agencies should ensure that they retain ownership of all data.
  • Impermissibility of Data Mining – Law enforcement agencies should ensure that the cloud service provider does not mine or otherwise process or analyze data for any purpose not explicitly authorized by the law enforcement agency.
  • Confidentiality – The cloud service provider should ensure the confidentiality of law enforcement data it maintains on behalf of a law enforcement agency.

IACP will be working in the coming months to develop model policies associated with cloud computing through the IACP National Law Enforcement Policy Center. Model policies are expected to be released at the IACP Annual Conference, scheduled for October 19-23, 2013 in Philadelphia, Pennsylvania.

To view the IACP principles and results and methodology of the IACP/Ponemon Institute/SafeGov.org commissioned survey, please visit http://www.theiacp.org/cloudcomputing.

Datanami Named “Media Sponsor” of Cloud Expo New York & Silicon Valley

SYS-CON Events announced today that Datanami has been named “Media Sponsor” of SYS-CON’s 12th International Cloud Expo, which will take place on June 10–13, 2013, at the Javits Center in New York City, New York, and the 13th International Cloud Expo, which will take place on November 4–7, 2013, at the Santa Clara Convention Center in Santa Clara, CA.
Datanami is a news portal dedicated to providing insight, analysis and up-to-the-minute information about emerging trends and solutions in Big Data. The portal sheds light on all cutting edge technologies including networking, storage and applications, and their effect upon business, industry, government, and research. The publication examines the avalanche of unprecedented amounts of data and the impact the high-end data explosion is having across the IT, enterprise, and commercial markets.

read more

Data Privacy Day reminds us of the importance of transparency

Luca Schiavoni, Analyst, Regulation, Ovum

The celebration of the Data Privacy Day on January 28, 2013 came at a moment when awareness of the importance of the matter is higher than it has ever been. However, many obstacles get in the way of full data privacy, including companies’ unwillingness to fully disclose what they do with their users’ data, consumers’ unwillingness to actually read lengthy terms and conditions pages when signing up to a service, and the fact that some companies’ business models rely on their users’ data to distribute targeted advertising.

Regulation in this area is often quite confusing and obsolete, and it can be it unclear whether the rules that apply are those of the service provider’s country or the user’s country. There is a clear need for coordinated approaches between regulators around the world.

The rise of OTT services is prompting policymakers to take action …

HPC in the Cloud “Media Sponsor” of Cloud Expo NY & Silicon Valley

SYS-CON Events announced today that HPC in the Cloud has been named “Media Sponsor” of SYS-CON’s 12th International Cloud Expo, which will take place on June 10–13, 2013, at the Javits Center in New York City, New York, and the 13th International Cloud Expo, which will take place on November 4–7, 2013, at the Santa Clara Convention Center in Santa Clara, CA.
HPC in the Cloud is the only portal dedicated to covering high-end cloud computing in science, industry and the data center. The publication provides technology decision-makers and stakeholders in the high performance computing industry (spanning government, industry, and academia) with the most accurate and current information on developments happening in the point where high performance and cloud computing intersect. Subscribe now at http://www.hpcinthecloud.com

read more

Solving Substantiation with SAML

Organizations are deploying distributed, hybrid architectures that can span multiple security domains. At any moment, a user could be accessing the corporate data center, the organization’s cloud infrastructure, or even a third party, SaaS web application. SAML can provide the identity information necessary to implement an enterprise-wide single sign-on solution.
Proving or asserting one’s identity in the physical world is often as simple as showing a driver’s license or state ID card. As long as the photo matches the face, that’s typically all that is needed to verify identity. This substantiation of identity is a physical form of authentication, and depending on the situation, the individual is then authorized either to receive something or to do something, for instance, enter a bar, complete a purchase, etc.
In the digital world, identity verification is not as easy as showing the computer monitor a driver’s license. To gain entry, you must provide information like a name, password, randomly generated token number—something you have, something you know, or something you are—to prove you are who you say you are.

read more

Cloud Computing Service Models

In this post I will look at the three different service models for cloud computing as defined by NIST. More specifically I will look at the management and operations overhead for each one of the models and compare it…
Let’s look at how things have been done in the past. Traditionally enterprises have been responsible for managing their own IT infrastructure as well as the software stack that runs their applications. For small companies that meant hiring polyglot employees with wide range of skills varying from low level networking to high level application support. For larger ones, that can afford more staff, it meant creating specialized teams responsible for only networking infrastructure, or only storage or servers and virtualization. However for lot of those enterprises the core business has never been managing IT infrastructure – the only thing they are interested in is to manage their line-of-business (LOB) apps.

read more

Project Communications to the C-Suite

By Tobi Evangelisti, Senior VP of PMO, and Craig Mullen, Engagement Manager

Project communications to the C-Suite must include as much rational objectivity as possible to provide a pragmatic update taking into consideration identification of the C-Suite stakeholder’s interest.

The importance of constructing a projects’ communications to the C-Suite, starts with conscious development of the subject line. The first couple of sentences must address directly the project status and communicate whether action (or reading is required) or that the communication is providing a summarized update. It should have detail to understand the big picture but not overly granular. C level execs will always come back if they require more.

Communications to the C-Suite are not project status reports. Do not lead off with issues, items, or ideas, unless they are strategic or business oriented. Management functions within the C-Suite typically have functional expertise, but their focus usually would be different than a department because of their focus on the larger business environment. Ideally, the project communications role to the C-Suite would be as trusted advisor. A communication should be concise and clearly outline project status, open issues requiring attention and specifics as to how the project may require assistance. If the communication is in regards to issues that may be occurring an overview of the timeline is important for the C level person to understand the magnitude and the sense of urgency. In C level communications it is important to make sure the message includes a next step or a move forward plan. This creates a confidence that you are continuing to work the issue.

There is a time and place for email communication, phone calls and in person communication:

  • Rule number one: Understand how your audience prefers to be communicated with.
  • Rule number two: Do not hide behind email. Sending an email does not mean that the issue is resolved and if the topic is hot it is imperative to either call or find the person face to face if possible.
  • Rule number three: Sense of urgency should assist in choosing your communication method.
  • Rule number four: IF you are using email: Use proper use of the to and cc fields. If you do not require action use the cc. If you are requiring action, use the to field.

Effective communications start with using simple words and clear thoughts. C-Suite communications is essentially the project manager’s version of the sales elevator pitch. It may help to have a co-worker proof your message, or at least make sure you re-validate the initial draft to ensure clarity, emotional tone (balanced), accuracy, and timeliness.

 

To learn more about how GreenPages can help you click here.

Scalable Data Management and Protection Solutions for the Enterprise

“CommVault and Coraid complement each other perfectly for organizations that need a scalable, comprehensive, cost-effective approach to data protection,” said Doug Dooley, vice president of product management at Coraid, as Coraid today announced certification for its EtherDrive storage system with CommVault Simpana.

“Advanced data management paired with a scale-out, flexible storage infrastructure ensures data growth can be managed effectively. A joint solution with CommVault and Coraid demonstrates the flexibility and power of an open system architecture.”

read more

Tape is still alive – or at least in conversations and discussions

By Greg Schulz

Depending on whom you talk to or ask, you will get different views and opinions, some of them stronger than others on if magnetic tape is dead or alive as a data storage medium. However an aspect of tape that is alive are the discussions by those for, against or that simply see it as one of many data storage mediums and technologies whose role is changing.

Here is a link to an a ongoing discussion over in one of the LinkedIn group forums (Backup & Recovery Professionals) titled About Tape and disk drives.

Rest assured, there is plenty of FUD (fear, uncertainty and doubt) and hype on both sides of the tape is dead (or alive) arguments, not very different from the disk is dead vs. SSD or cloud arguments. After all, not everything is the same in data centres, clouds and information factories.

For what it …

The cloud news categorized.