In my last posting I wrote about what you can do to protect your company assets if you decide to move your ESI (electronically stored information) into the cloud. I pointed out that you should be sure that your cloud provider adheres to or is at least aware of US – EU Safe Harbor. This has been a topic of concern for multinational or at least transatlantic corporations. But now with the advent of the cloud your data could be stored in Dublin, Ireland or Stuttgart, Germany even though you may be a medium-sized business in Laredo, TX. The cloud will now essentially force you to start thinking about your data as if you were a multinational even if your business doesn’t expand past Texas. This is because you have now tossed your ESI into the cloud and it will reside in any country your provider finds fit. So as you take that “Journey to the Cloud’ I want to share some suggestions from Greg Buckles from the Discovery Journal, http://ediscoveryjournal.com/2011/06/moving-your-esi-to-the-cloud/
You need to understand and ask the questions to your cloud provider about the basic infrastructure and data flow process that your ESI will experience:
- How is it transferred to the cloud?
- Where does it physically reside?
- Is it transformed for storage?
- How is it kept separate from other customers?
- Does the company own all the infrastructure outright?
- What is the disaster recovery or co-location arrangement?
- What are your guarantees on uptime, accessibility and Service Level Agreements (SLAs) for issues?
- What are the company policies on data privacy, subpoenas and security?
- How can your ESI be accessed, searched and retrieved?
- What are reasonable restoration rates for retrievals?
- Is there an established migration/transfer mechanism in case you want to change providers?
From a regulatory, internal investigation and litigation perspective, the points to pay particular attention to are: Where does your data reside, Company policies on data privacy, subpoenas and security, and how can your ESI be accessed, searched and retrieved?
Moving to the cloud may be inevitable but just make sure you have a plan and are taking safeguards.