making the cloud work for you: institutional risk and governance

24
Making the cloud work for you: institutional risk and governance Dr Richard Hall, De Montfort University slideshare.net/richardhall @hallymk1 [email protected]

Upload: richard-hall

Post on 14-May-2015

399 views

Category:

Education


0 download

DESCRIPTION

My presentation at BETT13 on cloud computing and HE institutions. See also: http://www.richard-hall.org/2012/06/13/the-university-and-the-cloud-a-health-warning/

TRANSCRIPT

Page 1: Making the cloud work for you: institutional risk and governance

Making the cloud work for you:

institutional risk and governance

Dr Richard Hall, De Montfort Universityslideshare.net/richardhall@[email protected]

Page 2: Making the cloud work for you: institutional risk and governance

context: organisation and risk

Page 3: Making the cloud work for you: institutional risk and governance

Cloud(s) or hosted or in-house?

Amplified issues around the following [risks].

1. Curriculum control/change-management: ad hoc vs strategic control vs staff digital/technical literacy.

2. Support and skills in-house: quality/distinctive or interesting vs boring.

3. Elasticity of demand and service-provision: developing technologies that will enable emerging and future web applications.

Page 4: Making the cloud work for you: institutional risk and governance

See: http://bit.ly/VXKGTQ

Page 5: Making the cloud work for you: institutional risk and governance

Value and institutional risk:

a competitive cloud

Page 6: Making the cloud work for you: institutional risk and governance

Education markets are one facet of the neoliberal strategy to manage the structural crisis of capitalism by opening the public sector to capital accumulation. The roughly $2.5 trillion global market in education is a rich new arena for capital investment.

(Lipman, P. 2009: http://bit.ly/qDl6sV)

Page 7: Making the cloud work for you: institutional risk and governance

See: http://bit.ly/WqABKq

Page 8: Making the cloud work for you: institutional risk and governance

The UK Treasury position, on shared services:

2.191 VAT: cost sharing – Following the announcement at Autumn Statement 2011 the Government will introduce a VAT exemption for services shared between VAT exempt bodies including charities and universities.

HM Treasury (2012) http://bit.ly/GCRYCy

Page 9: Making the cloud work for you: institutional risk and governance

See: http://bit.ly/GI2nP4

Page 10: Making the cloud work for you: institutional risk and governance

See: http://bit.ly/MNPOpn

Page 11: Making the cloud work for you: institutional risk and governance

See: http://bit.ly/11NUoLR

Page 12: Making the cloud work for you: institutional risk and governance

Technology deployed inside hegemonic, fiscal “realities”.

1. Public-private partnerships: services; re-engineering; applications; outsourcing; consultancy.

2. Discourses of efficiency/productivity to be rooted: analytics; big data; reduced circulation time; changes in production; workload monitoring.

3. Legitimation of R&D: value-for-money; commercial efficiency; business process re-engineering (c.f. European Vision 2020; HEFCE 2012).

4. Moral depreciation and constant innovation/value-creation.

Page 13: Making the cloud work for you: institutional risk and governance

Governance and institutional risk

Page 14: Making the cloud work for you: institutional risk and governance

See: http://zd.net/oE0oq3

Page 15: Making the cloud work for you: institutional risk and governance

See: http://bit.ly/yqsrps

Page 16: Making the cloud work for you: institutional risk and governance

See: http://bit.ly/QvjavY

Page 17: Making the cloud work for you: institutional risk and governance

1. Twitter: EFF/American Civil Liberties Union; Birgitta Jonsdottir; U.S. Department of Justice; Wikileaks.

2. LinkedIn: cracking a service; aggregating data for future cracking; confirming guesses about passwords; comparing hacked data against pre-computed versions; broadening "guessable” data.

3. Facebook, Google and Twitter: new obligation to identify “trolls” ; internet companies will have to surrender the details of those posting libellous messages.

4. Leveson: Hunt’s private Gmail account; role of the information commissioner; use of private (email) accounts to conduct official business is subject to FoI.

Service resilience; confidentiality/privacy; copyright/copyleft/content distribution; data security/back-ups; control/deletion

Page 18: Making the cloud work for you: institutional risk and governance

See: http://bit.ly/SmGgoz

Page 19: Making the cloud work for you: institutional risk and governance

See: http://ars.to/RY2NXC

Page 20: Making the cloud work for you: institutional risk and governance

See: http://bit.ly/WeQmGx

Page 21: Making the cloud work for you: institutional risk and governance

the legal standard for production of information by a third party, including cloud computing services under US civil (http://www.law.cornell.edu/rules/frcp/rule_45) and criminal (http://www.law.cornell.edu/rules/frcrmp/rule_16) law is whether the information is under the "possession, custody or control" of a party that is subject to US jurisdiction.

It doesn’t matter where the information is physically stored, where the company is headquartered or, importantly, where the person whose information is sought is located.

The issue for users is whether the US has jurisdiction over the cloud computing service they use, and whether the cloud computing service has “possession, custody or control” of their data, wherever it rests physically.

EFF (2012): http://bit.ly/yqsrps

Page 22: Making the cloud work for you: institutional risk and governance

• We have a Governance Unit, a set of IT regulations and an IT Governance Group: http://infogov.our.dmu.ac.uk/

“The cloud has its own challenges, not least of which is the fact that the name can lead non-tech savvy folks to imagine that their data is bits of magic floating about in the ether rather than sitting on a server subject to the laws of the land in which it is located. There are concerns about ensuring safety of information.”

“Additionally, potentially big problems with 'offshoring' corporate assets outside of corporate governance.”

Page 23: Making the cloud work for you: institutional risk and governance

• Risk-management at a range of scales: does it matter if someone accesses your stuff? [Dropbox; subject to FoI]

• What about corporate governance, including access to services that are marketised? [Google-Verizon and a two-speed internet; costs of accessing data in marketised HE?]

• Does it matter if the responsible academic gets hit by a bus? [assessment; what should be managed in-house or hosted via a contract?]

• Do we understand that data is being transferred into a service and that we have responsibilities? [T&Cs; IP; protected characteristics; indemnities for libel]

• How do we work-up the digital literacies of our staff/students in this space? [staff guidelines http://bit.ly/LnazH5 ]

Page 24: Making the cloud work for you: institutional risk and governance

The University and the Cloud: a health warning is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Unported License.