

InterviewSolution
1. |
My organization prefers to deal with a cloud vendor that has implemented certain standards for quite a while. It will provide us with greater confidence in doing business with them. Is there any ISO standard out there related to Cloud? |
Answer» To date, there is a great number of ISO standards applied to the cloud. Taking out the expired and withdrawn versions, here is the list:
Information Technology -- Cloud computing – Overview and vocabulary
Information Technology -- Cloud computing -- Reference architecture
Information Technology -- Cloud Data Management INTERFACE (CDMI)
Information Technology -- Cloud computing -- Service level agreement (SLA) framework -- Part 1: Overview and concepts
Cloud computing -- Service level agreement (SLA) framework -- Part 2: Metric model
Information Technology -- Cloud computing -- Service level agreement (SLA) framework -- Part 3: Core conformance requirements
Cloud computing -- Service level agreement (SLA) framework -- Part 4: Components of security and of protection of PII (Personally Identifiable Information)
Information Technology -- VIRTUALIZATION Management Specification
Cloud Infrastructure Management Interface (CIMI) Model and RESTful HTTP-based Protocol -- An Interface for Managing Cloud Infrastructure
Information Technology -- Cloud computing -- Interoperability and portability
Information Technology -- Cloud computing -- Cloud services and devices: Data flow, data categories and data use
Information Technology -- Cloud computing -- Guidance for policy development
Information Technology -- Cloud computing -- Framework of TRUST for processing of multi-sourced data
Information Technology -- Security techniques -- Code of practice for information security controls based on ISO/IEC 27002 for cloud services
Information Technology -- Security techniques -- Code of practice for protection of PII in public clouds acting as PII processors Like any other ISO standards, conforming to them has many benefits for the provider’s businesses: building credibility at the international level, saving time and money by identifying and solving recurring problems, improving and enhancing the system and process efficiency and effectiveness. On top of that, it is also a living proof, publicly accessible, that the provider has properly managed their information security including its risk, fulfilled their audit requirements and established trust both internally and EXTERNALLY that controls are properly placed and implemented in order to serve their customers better and HENCE increase their satisfaction level. You, as the user, are urged to assess the ISO certification they have. Critical points to reflect on are: which product, service, location does it actually cover? Is the certification for the entire organization or only for their head office exclusive of their branches? Who issues the certification and whether the issuer is one of ISO accredited bodies? For certain you must see the original certificate and witness what information revealed there. |
|