Q

What's most important to know about my cloud privacy policy?

A good cloud provider privacy policy should cover not only physical and logical security, but geographic and personnel constraints as well.

When it comes to choosing a cloud service provider, the first thing you should do is make sure that they do, in fact, have an information privacy policy that is published somewhere you can find it, and that it addresses your concerns. Beyond that, whether it is available online and updated as it needs to be should be of concern. Sometimes policies can even prompt you to think about things that you hadn't before. 

Important areas that the cloud privacy policy should cover focus on physical and logical security. But just as important is identity management and access control -- policies that are specific to people who could gain access to your data.

You should also pay attention to what the policy covers in terms of different geographies. For example, if I have data that can't leave the US, then the provider should have geographic controls and constraints as part of their policy.

It's also important to know how a cloud provider manages their different clients as well as their own employees and contractors who may have logical or physical access to the information. A cloud provider should be able to articulate to you how they have responded or would respond to a security breach. Do they run and hide, do they put up a smoke mirror, or do they step up and explain exactly what happened, why it happened, what they would do in the event that it happened again, and how they plan to prevent it in the future? But most importantly, it's also your responsibility as a user to be sure you fully understand a cloud privacy policy and that it covers areas most important to your business processes.

Next Steps

NSA scandal spurs cloud privacy innovation

What you can expect from a cloud service level agreement

This was first published in August 2014

Dig deeper on Public Cloud Storage

Pro+

Features

Enjoy the benefits of Pro+ membership, learn more and join.

Have a question for an expert?

Please add a title for your question

Get answers from a TechTarget expert on whatever's puzzling you.

You will be able to add details on the next page.
Related Discussions

Greg Schulz asks:

What aspect of a cloud provider's privacy policy do you find most important?

0  Responses So Far

Join the Discussion

0 comments

Oldest 

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to:

-ADS BY GOOGLE

SearchStorage

SearchSolidStateStorage

SearchVirtualStorage

SearchAWS

SearchDisasterRecovery

SearchDataBackup

SearchSMBStorage

Close