SlideShare a Scribd company logo
4
Most read
8
Most read
9
Most read
Cloud computing risk & challenges
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 2
Private
Public
Hybrid
FINANCIAL 
MANAGEMENT
• CAPEX to OPEX 
• Capital can be on used for growth 
of business.
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 3
Opportunities
• Cloud may create a permanent establishment (PE) for:
– Service provider through its infrastructure
– Client through the use of servers in a territory outside the 
home jurisdiction. 
• A business conducted in the cloud creates practical 
difficulties in determining where that income was 
sourced.
– Cloud uses shared resources, servers can be located in 
multiple jurisdictions, a simple transaction may be 
processed in multiple countries. 
– The place where a transaction takes place is difficult to 
ascertain in these circumstances, as only part of 
a transaction may be completed in any one jurisdiction. 
• Consumption‐based taxes – GST / VAT apply where the 
service is consumed or content is delivered 
• Organizations that transfer data, software and other 
Cloud services across border need to be aware of the 
potential liability to export controls.
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 4
Businesses risk getting taxed in more than one place
LEAKING CLOUDS?
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 5
SECURITY AND PRIVACY
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 6
For a large, 
regulated 
organization: it 
may be a 
nightmare…
For a small 
organization: it 
may offer 
much better 
security
Private
Public
Hybrid
SECURITY
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 7
IDENTITY & 
ACCESS
ENCRYPTION STORAGE
COLLATERAL 
DAMAGE
AVAILABILITY & 
DESTRUCTION
HUMAN THREAT
OPERATIONAL 
CHALLENGES
Control and 
Governance
SLA
Change 
Management
BCP & DR 
Investigations 
and Audit
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 8
REGULATIONS & COMPLIANCE
 Data Privacy Laws and Regulations
 IT Act, 
 RBI / IRDA regulations…
 Encryption / Lawful interception 
 Who owns the data?
 Under the ITA, a corporate entity when transferring sensitive personal 
information to another entity should ensure, that the entity to whom such 
information is being transferred should have similar security practices to 
protect such information.
 Further, a corporate entity in possession of sensitive personal information 
should ensure that the provider of such information is aware of the 
agency collecting and retaining information, the intended recipients of the 
information and the purpose for which the information shall be used.
 As per ITA, data security audits need to be carried by companies through 
approved auditors at least once a year or when significant changes / 
upgrades happen.
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 9
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 10

More Related Content

PPTX
Cloud Computing Architecture
PPTX
Cloud computing ppt
PPT
Cloud computing
PPTX
Cloud Computing Fundamentals
PDF
Introduction to virtualization
PDF
A brief history of cloud computing
PPT
Cloud computing
PPT
Cloud deployment models
Cloud Computing Architecture
Cloud computing ppt
Cloud computing
Cloud Computing Fundamentals
Introduction to virtualization
A brief history of cloud computing
Cloud computing
Cloud deployment models

What's hot (20)

DOCX
The seminar report on cloud computing
PPTX
Cloud Deployments Models
PDF
Cloud computing - Risks and Mitigation - GTS
PPTX
Implementation of cloud computing
PPTX
Cloud Computing Project
PDF
CS8791 Cloud Computing - Question Bank
PPT
Cloud computing
PPTX
basic concept of Cloud computing and its architecture
PPT
Cloud computing
PPTX
Cloud computing
PPTX
PPTX
Various Cloud offerings AWS/AZURE/GCP
PDF
Cloud computing présenté par Doumbia tidiane
PPTX
cloud computing 5.pptx
PPTX
Cloud computing(ppt)
PDF
GREEN CLOUD COMPUTING-A Data Center Approach
PPTX
Cloud computing ppt
PDF
CS878 Green Computing Anna University Question Paper
PPTX
Cloud computing benefits
The seminar report on cloud computing
Cloud Deployments Models
Cloud computing - Risks and Mitigation - GTS
Implementation of cloud computing
Cloud Computing Project
CS8791 Cloud Computing - Question Bank
Cloud computing
basic concept of Cloud computing and its architecture
Cloud computing
Cloud computing
Various Cloud offerings AWS/AZURE/GCP
Cloud computing présenté par Doumbia tidiane
cloud computing 5.pptx
Cloud computing(ppt)
GREEN CLOUD COMPUTING-A Data Center Approach
Cloud computing ppt
CS878 Green Computing Anna University Question Paper
Cloud computing benefits
Ad

Viewers also liked (20)

PDF
Securing the mobile enterprise - Sydney 24 Mar 2014
PDF
Moving to the Cloud – Risk, Control, and Accounting Considerations
PDF
Evaluating Cloud Computing Risk :Recounting PBB’s Journey into the Cloud - Ke...
PPT
Cloud Security Alliance's GRC Stack Overview
PPTX
Cloud computing Risk management
PPT
Top challenges in cloud computing
PPTX
Evaluating an Instructional Sequence with Interactive Simulations (ISIS)
PPT
синеглазая гжель»
PPTX
Grand Chase
PDF
MobileDiagnosis Project technical Presentation 2014
PPTX
Ist storyboard final
PPT
New era
PPSX
UP BUSINESS MART
PDF
Cleaning Out Your IT Closet - SPSRED 2013
DOCX
Insert latest articles on blogger
PDF
Happier teams by cesario ramos and pascal dufour
PDF
36448696 alege-jucariile-potrivite-bebelusului-tau
ODP
Amazon summit 2015
PPTX
The Connected Company - Event Anders Vergaderen
PPTX
Ex louisville 2011
Securing the mobile enterprise - Sydney 24 Mar 2014
Moving to the Cloud – Risk, Control, and Accounting Considerations
Evaluating Cloud Computing Risk :Recounting PBB’s Journey into the Cloud - Ke...
Cloud Security Alliance's GRC Stack Overview
Cloud computing Risk management
Top challenges in cloud computing
Evaluating an Instructional Sequence with Interactive Simulations (ISIS)
синеглазая гжель»
Grand Chase
MobileDiagnosis Project technical Presentation 2014
Ist storyboard final
New era
UP BUSINESS MART
Cleaning Out Your IT Closet - SPSRED 2013
Insert latest articles on blogger
Happier teams by cesario ramos and pascal dufour
36448696 alege-jucariile-potrivite-bebelusului-tau
Amazon summit 2015
The Connected Company - Event Anders Vergaderen
Ex louisville 2011
Ad

Similar to Cloud computing risk & challenges (20)

PDF
cloudcomputingriskschallenges-140717051705-phpapp02.pdf
PPTX
HKCS CCSIG Cloud Executive Forum keynote
PPTX
Banking Cores and Clouds in Asia Pacific: understanding Banks Use of Cloud Co...
PDF
26 Nov 2013 - Law and Policy Meet the Cloud, by Bernie Trudel [IIC-TRPC Singa...
PPTX
Cloud Security for Regulated Firms - Securing my cloud and proving it
PDF
Veejay Jadhaw, Digital and Cloud Computing in Financial Services
PPTX
The Impact of Cloud: Cloud Computing Security and Privacy
PDF
Security & Compliance in the Cloud [2019]
PDF
Challenges of adopting cloud Governance-Prabin.pdf
PPTX
Cloud is not an option, but is security?
PDF
Data Sovereignty, Security, and Performance Panacea: Why Mastercard Sets the ...
PDF
Cloud Computing and Data Governance
PPTX
GRC Dynamics in Securing Cloud
PPTX
Practical Security for the Cloud
PDF
Data Sovereignty and the Cloud
PPT
Presentation to Irish ISSA Conference 12-May-11
PDF
Security & Compliance in the Cloud - Hadoop Magazine Column Version 1.2 by Ja...
PPTX
Cloud Computing & IT in the Boardroom
PDF
Whitepaper: Security of the Cloud
PDF
Security of the Cloud
cloudcomputingriskschallenges-140717051705-phpapp02.pdf
HKCS CCSIG Cloud Executive Forum keynote
Banking Cores and Clouds in Asia Pacific: understanding Banks Use of Cloud Co...
26 Nov 2013 - Law and Policy Meet the Cloud, by Bernie Trudel [IIC-TRPC Singa...
Cloud Security for Regulated Firms - Securing my cloud and proving it
Veejay Jadhaw, Digital and Cloud Computing in Financial Services
The Impact of Cloud: Cloud Computing Security and Privacy
Security & Compliance in the Cloud [2019]
Challenges of adopting cloud Governance-Prabin.pdf
Cloud is not an option, but is security?
Data Sovereignty, Security, and Performance Panacea: Why Mastercard Sets the ...
Cloud Computing and Data Governance
GRC Dynamics in Securing Cloud
Practical Security for the Cloud
Data Sovereignty and the Cloud
Presentation to Irish ISSA Conference 12-May-11
Security & Compliance in the Cloud - Hadoop Magazine Column Version 1.2 by Ja...
Cloud Computing & IT in the Boardroom
Whitepaper: Security of the Cloud
Security of the Cloud

More from Parag Deodhar (11)

PDF
Cyber Crime - How New Age Criminals Function
PDF
Risks Beyond the Boundary: Data Protection & Privacy Challenges, OpRiskAsia 2...
PDF
How to implement and align Technology within your GRC Framework
PDF
BCM Continuous improvement - Audit & Assessment
PDF
IT Risk Management - the right posture
PDF
Scouting For Fraud - Parag Deodhar
PDF
The Social Media Bait - Fraud & Cybercrime
PPTX
Mobile Workplace Risks
PPTX
Defining effective governance structures and nurturing collaboration
PPTX
Frauds making fs companies uncompetitive parag deodhar
PPT
Acfe bangalore pdm 2 fraud risk - parag deodhar
Cyber Crime - How New Age Criminals Function
Risks Beyond the Boundary: Data Protection & Privacy Challenges, OpRiskAsia 2...
How to implement and align Technology within your GRC Framework
BCM Continuous improvement - Audit & Assessment
IT Risk Management - the right posture
Scouting For Fraud - Parag Deodhar
The Social Media Bait - Fraud & Cybercrime
Mobile Workplace Risks
Defining effective governance structures and nurturing collaboration
Frauds making fs companies uncompetitive parag deodhar
Acfe bangalore pdm 2 fraud risk - parag deodhar

Recently uploaded (20)

PDF
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Sensors and Actuators in IoT Systems using pdf
PDF
cuic standard and advanced reporting.pdf
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Electronic commerce courselecture one. Pdf
PDF
CIFDAQ's Market Wrap: Ethereum Leads, Bitcoin Lags, Institutions Shift
PDF
Transforming Manufacturing operations through Intelligent Integrations
PDF
GamePlan Trading System Review: Professional Trader's Honest Take
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
Big Data Technologies - Introduction.pptx
PDF
madgavkar20181017ppt McKinsey Presentation.pdf
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Advanced Soft Computing BINUS July 2025.pdf
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PPTX
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Chapter 3 Spatial Domain Image Processing.pdf
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Sensors and Actuators in IoT Systems using pdf
cuic standard and advanced reporting.pdf
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Electronic commerce courselecture one. Pdf
CIFDAQ's Market Wrap: Ethereum Leads, Bitcoin Lags, Institutions Shift
Transforming Manufacturing operations through Intelligent Integrations
GamePlan Trading System Review: Professional Trader's Honest Take
20250228 LYD VKU AI Blended-Learning.pptx
Big Data Technologies - Introduction.pptx
madgavkar20181017ppt McKinsey Presentation.pdf
NewMind AI Monthly Chronicles - July 2025
Spectral efficient network and resource selection model in 5G networks
Advanced Soft Computing BINUS July 2025.pdf
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf

Cloud computing risk & challenges