4
Most read
8
Most read
9
Most read
Cloud computing risk & challenges
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 2
Private
Public
Hybrid
FINANCIAL 
MANAGEMENT
• CAPEX to OPEX 
• Capital can be on used for growth 
of business.
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 3
Opportunities
• Cloud may create a permanent establishment (PE) for:
– Service provider through its infrastructure
– Client through the use of servers in a territory outside the 
home jurisdiction. 
• A business conducted in the cloud creates practical 
difficulties in determining where that income was 
sourced.
– Cloud uses shared resources, servers can be located in 
multiple jurisdictions, a simple transaction may be 
processed in multiple countries. 
– The place where a transaction takes place is difficult to 
ascertain in these circumstances, as only part of 
a transaction may be completed in any one jurisdiction. 
• Consumption‐based taxes – GST / VAT apply where the 
service is consumed or content is delivered 
• Organizations that transfer data, software and other 
Cloud services across border need to be aware of the 
potential liability to export controls.
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 4
Businesses risk getting taxed in more than one place
LEAKING CLOUDS?
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 5
SECURITY AND PRIVACY
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 6
For a large, 
regulated 
organization: it 
may be a 
nightmare…
For a small 
organization: it 
may offer 
much better 
security
Private
Public
Hybrid
SECURITY
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 7
IDENTITY & 
ACCESS
ENCRYPTION STORAGE
COLLATERAL 
DAMAGE
AVAILABILITY & 
DESTRUCTION
HUMAN THREAT
OPERATIONAL 
CHALLENGES
Control and 
Governance
SLA
Change 
Management
BCP & DR 
Investigations 
and Audit
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 8
REGULATIONS & COMPLIANCE
 Data Privacy Laws and Regulations
 IT Act, 
 RBI / IRDA regulations…
 Encryption / Lawful interception 
 Who owns the data?
 Under the ITA, a corporate entity when transferring sensitive personal 
information to another entity should ensure, that the entity to whom such 
information is being transferred should have similar security practices to 
protect such information.
 Further, a corporate entity in possession of sensitive personal information 
should ensure that the provider of such information is aware of the 
agency collecting and retaining information, the intended recipients of the 
information and the purpose for which the information shall be used.
 As per ITA, data security audits need to be carried by companies through 
approved auditors at least once a year or when significant changes / 
upgrades happen.
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 9
16 JULY 2014 PARAG DEODHAR ‐ 3rd Annual Asian GRC & IT Security Conference 2014 10

More Related Content

PPTX
Cloud Computing Architecture
PPT
Cloud computing ppt
PDF
Introduction to virtualization
PPTX
PPTX
basic concept of Cloud computing and its architecture
PDF
Cloud Computing - An Introduction
PPTX
Azure Fundamentals || AZ-900
PPT
Security Issues of Cloud Computing
Cloud Computing Architecture
Cloud computing ppt
Introduction to virtualization
basic concept of Cloud computing and its architecture
Cloud Computing - An Introduction
Azure Fundamentals || AZ-900
Security Issues of Cloud Computing

What's hot (20)

PDF
Microsoft Azure Cloud Services
PPT
Introduction to Cloud Computing
PPTX
Top 10 cloud service providers
PPTX
Cloud Computing Fundamentals
PDF
Introduction to Azure
PPTX
Cloud Computing & CloudStack Open Source
PDF
Cloud Computing Architecture
PPTX
Multi Cloud Architecture Approach
PDF
Introduction to Microsoft Azure Cloud
PPTX
Cloud Migration, Application Modernization, and Security
PPTX
Cloud computing
PDF
Microsoft Azure Overview
PPTX
Cloud migration
PPTX
Microsoft azure
PPTX
presentation on Edge computing
PPT
Cloud Computing
PPTX
Software Defined Networking (SDN)
PPTX
Cloud computing
PPTX
Cloud computing
PPTX
Introduction to Mobile Cloud Computing
Microsoft Azure Cloud Services
Introduction to Cloud Computing
Top 10 cloud service providers
Cloud Computing Fundamentals
Introduction to Azure
Cloud Computing & CloudStack Open Source
Cloud Computing Architecture
Multi Cloud Architecture Approach
Introduction to Microsoft Azure Cloud
Cloud Migration, Application Modernization, and Security
Cloud computing
Microsoft Azure Overview
Cloud migration
Microsoft azure
presentation on Edge computing
Cloud Computing
Software Defined Networking (SDN)
Cloud computing
Cloud computing
Introduction to Mobile Cloud Computing
Ad

Viewers also liked (20)

PDF
Securing the mobile enterprise - Sydney 24 Mar 2014
PDF
Moving to the Cloud – Risk, Control, and Accounting Considerations
PDF
Evaluating Cloud Computing Risk :Recounting PBB’s Journey into the Cloud - Ke...
PPT
Cloud Security Alliance's GRC Stack Overview
PPTX
Cloud computing Risk management
PPT
Top challenges in cloud computing
PPTX
Evaluating an Instructional Sequence with Interactive Simulations (ISIS)
PPT
синеглазая гжель»
PPTX
Grand Chase
PDF
MobileDiagnosis Project technical Presentation 2014
PPTX
Ist storyboard final
PPT
New era
PPSX
UP BUSINESS MART
PDF
Cleaning Out Your IT Closet - SPSRED 2013
DOCX
Insert latest articles on blogger
PDF
Happier teams by cesario ramos and pascal dufour
PDF
36448696 alege-jucariile-potrivite-bebelusului-tau
ODP
Amazon summit 2015
PPTX
The Connected Company - Event Anders Vergaderen
PPTX
Ex louisville 2011
Securing the mobile enterprise - Sydney 24 Mar 2014
Moving to the Cloud – Risk, Control, and Accounting Considerations
Evaluating Cloud Computing Risk :Recounting PBB’s Journey into the Cloud - Ke...
Cloud Security Alliance's GRC Stack Overview
Cloud computing Risk management
Top challenges in cloud computing
Evaluating an Instructional Sequence with Interactive Simulations (ISIS)
синеглазая гжель»
Grand Chase
MobileDiagnosis Project technical Presentation 2014
Ist storyboard final
New era
UP BUSINESS MART
Cleaning Out Your IT Closet - SPSRED 2013
Insert latest articles on blogger
Happier teams by cesario ramos and pascal dufour
36448696 alege-jucariile-potrivite-bebelusului-tau
Amazon summit 2015
The Connected Company - Event Anders Vergaderen
Ex louisville 2011
Ad

Similar to Cloud computing risk & challenges (20)

PDF
cloudcomputingriskschallenges-140717051705-phpapp02.pdf
PPTX
HKCS CCSIG Cloud Executive Forum keynote
PPTX
Banking Cores and Clouds in Asia Pacific: understanding Banks Use of Cloud Co...
PDF
26 Nov 2013 - Law and Policy Meet the Cloud, by Bernie Trudel [IIC-TRPC Singa...
PPTX
Cloud Security for Regulated Firms - Securing my cloud and proving it
PDF
Veejay Jadhaw, Digital and Cloud Computing in Financial Services
PPTX
The Impact of Cloud: Cloud Computing Security and Privacy
PDF
Security & Compliance in the Cloud [2019]
PDF
Challenges of adopting cloud Governance-Prabin.pdf
PPTX
Cloud is not an option, but is security?
PDF
Data Sovereignty, Security, and Performance Panacea: Why Mastercard Sets the ...
PDF
Cloud Computing and Data Governance
PPTX
GRC Dynamics in Securing Cloud
PPTX
Practical Security for the Cloud
PDF
Data Sovereignty and the Cloud
PPT
Presentation to Irish ISSA Conference 12-May-11
PDF
Security & Compliance in the Cloud - Hadoop Magazine Column Version 1.2 by Ja...
PPTX
Cloud Computing & IT in the Boardroom
PDF
Whitepaper: Security of the Cloud
PDF
Security of the Cloud
cloudcomputingriskschallenges-140717051705-phpapp02.pdf
HKCS CCSIG Cloud Executive Forum keynote
Banking Cores and Clouds in Asia Pacific: understanding Banks Use of Cloud Co...
26 Nov 2013 - Law and Policy Meet the Cloud, by Bernie Trudel [IIC-TRPC Singa...
Cloud Security for Regulated Firms - Securing my cloud and proving it
Veejay Jadhaw, Digital and Cloud Computing in Financial Services
The Impact of Cloud: Cloud Computing Security and Privacy
Security & Compliance in the Cloud [2019]
Challenges of adopting cloud Governance-Prabin.pdf
Cloud is not an option, but is security?
Data Sovereignty, Security, and Performance Panacea: Why Mastercard Sets the ...
Cloud Computing and Data Governance
GRC Dynamics in Securing Cloud
Practical Security for the Cloud
Data Sovereignty and the Cloud
Presentation to Irish ISSA Conference 12-May-11
Security & Compliance in the Cloud - Hadoop Magazine Column Version 1.2 by Ja...
Cloud Computing & IT in the Boardroom
Whitepaper: Security of the Cloud
Security of the Cloud

More from Parag Deodhar (11)

PDF
Cyber Crime - How New Age Criminals Function
PDF
Risks Beyond the Boundary: Data Protection & Privacy Challenges, OpRiskAsia 2...
PDF
How to implement and align Technology within your GRC Framework
PDF
BCM Continuous improvement - Audit & Assessment
PDF
IT Risk Management - the right posture
PDF
Scouting For Fraud - Parag Deodhar
PDF
The Social Media Bait - Fraud & Cybercrime
PPTX
Mobile Workplace Risks
PPTX
Defining effective governance structures and nurturing collaboration
PPTX
Frauds making fs companies uncompetitive parag deodhar
PPT
Acfe bangalore pdm 2 fraud risk - parag deodhar
Cyber Crime - How New Age Criminals Function
Risks Beyond the Boundary: Data Protection & Privacy Challenges, OpRiskAsia 2...
How to implement and align Technology within your GRC Framework
BCM Continuous improvement - Audit & Assessment
IT Risk Management - the right posture
Scouting For Fraud - Parag Deodhar
The Social Media Bait - Fraud & Cybercrime
Mobile Workplace Risks
Defining effective governance structures and nurturing collaboration
Frauds making fs companies uncompetitive parag deodhar
Acfe bangalore pdm 2 fraud risk - parag deodhar

Recently uploaded (20)

PDF
The influence of sentiment analysis in enhancing early warning system model f...
DOCX
search engine optimization ppt fir known well about this
PDF
giants, standing on the shoulders of - by Daniel Stenberg
PDF
Lung cancer patients survival prediction using outlier detection and optimize...
PPT
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
PDF
Auditboard EB SOX Playbook 2023 edition.
PDF
Enhancing plagiarism detection using data pre-processing and machine learning...
PDF
CXOs-Are-you-still-doing-manual-DevOps-in-the-age-of-AI.pdf
PPTX
Build Your First AI Agent with UiPath.pptx
PDF
Accessing-Finance-in-Jordan-MENA 2024 2025.pdf
PDF
5-Ways-AI-is-Revolutionizing-Telecom-Quality-Engineering.pdf
PDF
INTERSPEECH 2025 「Recent Advances and Future Directions in Voice Conversion」
PDF
Transform-Your-Supply-Chain-with-AI-Driven-Quality-Engineering.pdf
PPTX
AI IN MARKETING- PRESENTED BY ANWAR KABIR 1st June 2025.pptx
PDF
Early detection and classification of bone marrow changes in lumbar vertebrae...
PDF
NewMind AI Weekly Chronicles – August ’25 Week IV
PDF
Transform-Your-Streaming-Platform-with-AI-Driven-Quality-Engineering.pdf
PPTX
Microsoft User Copilot Training Slide Deck
PDF
Statistics on Ai - sourced from AIPRM.pdf
PDF
AI.gov: A Trojan Horse in the Age of Artificial Intelligence
The influence of sentiment analysis in enhancing early warning system model f...
search engine optimization ppt fir known well about this
giants, standing on the shoulders of - by Daniel Stenberg
Lung cancer patients survival prediction using outlier detection and optimize...
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
Auditboard EB SOX Playbook 2023 edition.
Enhancing plagiarism detection using data pre-processing and machine learning...
CXOs-Are-you-still-doing-manual-DevOps-in-the-age-of-AI.pdf
Build Your First AI Agent with UiPath.pptx
Accessing-Finance-in-Jordan-MENA 2024 2025.pdf
5-Ways-AI-is-Revolutionizing-Telecom-Quality-Engineering.pdf
INTERSPEECH 2025 「Recent Advances and Future Directions in Voice Conversion」
Transform-Your-Supply-Chain-with-AI-Driven-Quality-Engineering.pdf
AI IN MARKETING- PRESENTED BY ANWAR KABIR 1st June 2025.pptx
Early detection and classification of bone marrow changes in lumbar vertebrae...
NewMind AI Weekly Chronicles – August ’25 Week IV
Transform-Your-Streaming-Platform-with-AI-Driven-Quality-Engineering.pdf
Microsoft User Copilot Training Slide Deck
Statistics on Ai - sourced from AIPRM.pdf
AI.gov: A Trojan Horse in the Age of Artificial Intelligence

Cloud computing risk & challenges