The Engagement of ‘Cloud’ Computing Services Policy Version 1.1 TRIM file number Short description Engaging Computing in Cloud Services Relevant to All employees Authority This Policy has been approved by the Executive Director of Division of Information Technology Responsible officer Administrative Assistant of Executive Director of Division of Information Technology Responsible office Office of Executive Director Division of Information Technology Date introduced 27 July 2011 Date(s) modified 2 Sep 2012 Next scheduled review date Sep 2014 Related University documents Related legislation Privacy Act 1998 Telecommunications Act 2004 Key words Cloud Computing, Outsource, Insource, Hosted, Private Cloud, Public Cloud, Community Cloud The Engagement of ‘Cloud’ Computing Style Services Policy 1.1 – Sep 2012 Page 1 1. PURPOSE The term “Cloud Computing” is a generic term, describing a range of facilities available for use, given a set of circumstances. Sample Definitions of Cloud Computing 2. Cloud A style of computing in which scalable and elastic IT-enabled capabilities are delivered as a service to customers using Internet technologies. The Internet has always been diagrammatically described as a cloud, hence the term that a service can be hosted ‘somewhere in the cloud’, or externally hosted Outsourced The service is delivered by an external IT organization using either the vendors’ infrastructure or CSU infrastructure. Insourced Service The service is delivered by CSU using CSU infrastructure Private Cloud The underlying infrastructure is dedicated to a single customer. On Demand Able to request increased infrastructure and services as demand grows whilst such cloud services are attractive, for a range of reasons, thorough investigation is required by the services of a provider are engaged (free or costed) as there are many legislative and reputation issues in the failure of such a service. Community Cloud The underlying infrastructure is shared by the community e.g. ARCs. Where there is a need to actually share information or services across a community. This will become more important with the increased need for sharing of research data, in particular Public Cloud The infrastructure is shared by a service providers’ customer base in general SCOPE This policy does not intend to be prescriptive in describing the process for the engagement of a provider of a cloud service, but to point the reader toward qualified staff to advise the appropriate strategy to utilise a cloud based service. 3. OBJECTIVES To ensure any staff member intending to engage the provider of a cloud-style service is well informed and guided by appropriate staff before any agreement and/or information is transferred between the university and provider. The Engagement of ‘Cloud’ Computing Style Services Policy 1.1 – Sep 2012 Page 2 4. TIMING This policy is to be used whenever a cloud-style service is to be engaged, whether through a formal project (via the ISIP or ICT:SWR), committee, working party, research project or any other avenue of engagement. 5. RESPONSIBILITIES CSU is compelled by law and reputation to ensure the lowest possible risk of exposure of the personal and private information of its students and staff, or the confidential information of CSU. Any CSU staff member with delegated authority, who stores or transmits personal/private information of CSU students, staff, or other associated body, will, before undertaking any task that will result in such storage or transmission, ensure that they are compliant with the appropriate policies mentioned. Where the transmission or storage is to be an ongoing process, then before any agreements or subsequent implementation is considered, DIT will be engaged to ensure that the process and the information assets comply appropriately. The Executive Director, DIT, (or nominee) will co-ordinate and engage the services of CSU Legal, the custodian(s) of the information and the CSU Ombudsman, as appropriate to assist in the formation of any agreement required to support the storage and/or transport of information. 6. METHOD Any staff member contemplating the use of a Cloud-based services, or the transfer or storage of CSU information externally, will first engage the services of DIT to ensure that resulting solution is viable and secure. 7. REFERENCES a. b. c. d. e. f. g. h. i. j. CSU Privacy Management Plan CSU Privacy Statement DIT Privacy Statement DIT Enterprise Architecture and Liaison Standards and Principles DIT Enterprise Architecture and Liaison Master Data Governance Framework Delegations – IT & Records (I&T2) CSU Records Policy CSU Information Security Policy CSU Data Governance Committee Personal Information Storage & Transmission Policy The Engagement of ‘Cloud’ Computing Style Services Policy 1.1 – Sep 2012 Page 3 Table of amendments Version number 1.0 1.1 Date 27 July 2011 2 Sep 2012 Short description of amendment Creation of Policy Minor modifications by Policy Review Team The Engagement of ‘Cloud’ Computing Style Services Policy 1.1 – Sep 2012 Page 4