SlideShare a Scribd company logo
1 of 15
Download to read offline
Claude Baudoin & Geoff Rayner
27 February 2018
Where’s My Data?
Managing the Data
Residency Challenge
2/27/2018 Copyright © 2018 OMG. All rights reserved. 1
2/27/2018 Copyright © 2018 OMG. All rights reserved. 2
Speakers
Tracie Berardi Director of Program Management, OMG
Program Manager, Cloud Standards Customer Council
Moderator
tracie@omg.org
Claude Baudoin Principal, cébé IT & Knowledge Management
Steering Committee member, Cloud Standards Customer Council
cbaudoin@cebe-itkm.com
Geoff Rayner CEO, Data Advantage Group
grayner@dag.com
• Data Residency definition
• History of OMG’s work on data residency
• Types of information that pose risks
• Nature of the risks – examples
• Laws and regulations around the world
• Potential applicable standards
• OMG Discussion Paper
• OMG Data Residency Maturity Model (DRMM)
• How to contribute
2/27/2018 Copyright © 2018 OMG. All rights reserved. 3
Topics Covered in this Webinar
New
“Data residency is the set of issues and practices related to the
location of data and metadata, the movement of (meta)data
across geographies and jurisdictions, and the protection of that
(meta)data against unintended access and other location-related
risks.”
• Scope
• Not just about the protection of personally identifiable information (PII)
• Also concerns the right to move “sovereign” data, such as oil reserves data;
international licensing of genomics data; distribution of biometrics data for
security purposes; etc.
2/27/2018 Copyright © 2018 OMG. All rights reserved. 4
Data Residency: Definition
• March 2015: initial request from an OMG member
• June 2015: first OMG Data Residency WG meeting (Berlin)
• Q4 2015: Prepared and issued an RFI
• Q2 2016: Processed RFI results, decided to create a discussion paper as first
deliverable
• Q4 2016: Drafted discussion paper, agreed to collaborate with CSCC and
issue two separate but almost identical papers
• Q1 2017: Collected contributions, edited paper, agreement to release
• Q2 2017: Create CSCC companion white paper, press releases, webinar
• June-Dec. 2017: Successive tutorials, created and released a maturity
model, discussed standards roadmap
2/27/2018 Copyright © 2018 OMG. All rights reserved. 5
OMG’s Work on Data Residency
• Multiple laws and regulations restrict what an organization can do
with certain types of data, or potentially prevent its protection:
• Personally identifiable information (PII)
• Patient health information (PHI)
• Proprietary corporate information
• Communications (e-mail, etc.)
• Government information (incl. military)
• Information subject to trade controls and embargoes
• Information on natural resources
• Banking records
• Other regulated data, e.g., “sovereign” data
2/27/2018 Copyright © 2018 OMG. All rights reserved. 6
Sources of Risk
• Owners of such data may:
• Relocate this data intentionally, for convenience or cost reduction
• Data center consolidation and managed hosting
• Centralized employee or customer database
• Business process outsourcing
• Helpdesk outsourcing
• Be unaware of its location
• Cloud service optimization by the provider
• IoT data collection
• Acquisitions and expansion to new countries change the risk
• The Internet of Things exacerbates the challenge
2/27/2018 Copyright © 2018 OMG. All rights reserved. 7
Sources of Risk (cont.)
• Difficulty of providing IT services across borders from few locations
• Higher cost for customers (less competition for local services)
• Inability to consolidate operations
• Inability to provide shared employee services
• Need for multiple local IT operations teams (skills and cost issues)
• Limitations in backup locations
• Restrictions against strong data encryption
• Legal exposure
• Conflict with authorities
• Public mistrust
2/27/2018 Copyright © 2018 OMG. All rights reserved. 8
Nature of the Risks
• Multiple, inconsistent, overlapping, and still evolving laws and
regulations around the world
• Range from non-existent to severe
• Sometimes (but not always) apply to government data / public
records, not to private companies’ data
• The European Union’s General Data Protection Regulation (GDPR), in
effect from 25 May 2018, is among the most comprehensive
• Multiple motivations behind the laws:
• Protecting the privacy of citizens
• Enabling police and tax authorities to inspect data
• Protectionism – force companies to create domestic facilities
• Monetize the flow of data
2/27/2018 Copyright © 2018 OMG. All rights reserved. 9
Data Residency Laws and Regulations
2/27/2018 Copyright © 2018 OMG. All rights reserved. 10
A Proliferation of Laws
• There is currently no standard that deals specifically with data
residency
• Data residency is related to the security and privacy aspects of
• Several NIST publications (800-144, 500-299, 1500)
• Several ISO/IEC standards (27001, 27017, 27018)
• NIST Big Data Standard, http://fedscoop.com/nist-big-data-framework
• The work of the CSA’s International Standardization Council (ISC)
• Work being considered in ISO/IEC JTC 1/SC 38
• The “Voluntary Data Protection Code” of CISPE (Cloud Infrastructure Service
Providers in Europe)
2/27/2018 Copyright © 2018 OMG. All rights reserved. 11
Potential Useful Standards
• Two very close versions (OMG and CSCC)
2/27/2018 Copyright © 2018 OMG. All rights reserved. 12
OMG’s First Discussion Paper
• Issued by OMG in
December 2017 as
a second
“discussion paper”
• Structured in a
similar manner to
the SEI CMM for
software
engineering
(1990)
• 5 levels and 20
“key process
areas” that need
to be put in place
to “climb” to
higher levels of
maturity
Copyright © 2018 OMG. All rights reserved.
13
The Data Residency Maturity Model (DRMM)
Level
SEI CMM
Name
Definition (under
construction)
Key Process Areas
5 Optimizing
There is continuous
monitoring and
improvement of data
residency policies,
procedures and
implementation
● Active monitoring and auditing of data location, transfer, and remote
access
● Regular review of changes in business, data content, technology, laws
and regulations
● Formal process to evolve policies, procedures, practices and
technology
● Formal process to review all incidents and take corrective action
4 Managed
Active management takes
place at all levels of the
organization
● Executive accountability
● Governance (e.g., steering committee)
● Assign roles and responsibilities for DR policy and implementation
● Formal policies
● Data storage location assignment is part of information modeling
● Logging / audit trail of data creation, movement, access right changes
● Formal program of employee training
3 Defined
Policies, procedures,
practices are documented
and institutionalized, and
data location impact is
formally documented
● Active executive involvement
● Formally documented processes
● Taxonomy of sensitive data
● Informal training resources
● People are formally assigned to data owner/steward/custodian roles
2 Repeatable
The organization
performs on the basis of
human knowledge,
informally shared
● Executive awareness (e.g., evidenced by a letter from each C-level
stakeholder stating their belief in the importance of the issue)
● Informal practices and guidelines to identify and locate data
● Employees know who to go to in order to arbitrate a d.r. question
● People act informally in roles of data owners/steward/custodians
1 Initial
None of above practices
exist
• Participate in OMG’s Data Residency Working Group
• Review the existing discussion papers and provide comments
• http://www.omg.org/cgi-bin/doc?mars/17-03-22.pdf (“Challenges and Opportunities” paper)
• http://www.omg.org/cgi-bin/doc?mars/17-12-18.pdf (DRMM)
• Consider adopting the DRMM
• OMG is interested in partnering with organizations that would want to “adopt
and adapt” the DRMM and give it broader recognition
• Suggest applicable standards – and if you work in standards group on
security and privacy, give them input about data residency issues
• Our current intent
• Coordinate with other OMG groups working on Data Provenance & Pedigree
and on Data Tagging & Labeling – seek a unified “data governance” approach
• Develop a standard to represent the various data residency laws and
regulations in a uniform formal manner
2/27/2018 Copyright © 2018 OMG. All rights reserved. 14
How to Contribute
• Thanks for your attention
• Please ask questions using the BrightTalk interface
• Ask to be added to our mailing list
• Send an e-mail to request@omg.org and ask to be added to the
“dataresidency” list
• Participate in our next meetings
• Reston, Va., March 20, 2018
• Boston, Mass., week of June 18-22
• Ottawa, Ont., Canada, week of Sept. 24-28 (2-day event on various
information governance and security topics for the Canadian government)
• Contact Tracie Berardi, tracie@omg.org, for additional questions or
comments
2/27/2018 Copyright © 2018 OMG. All rights reserved. 15
Discussion

More Related Content

What's hot

Govern and Protect Your End User Information
Govern and Protect Your End User InformationGovern and Protect Your End User Information
Govern and Protect Your End User InformationDenodo
 
IT Solutions for 3 Common Small Business Problems
IT Solutions for 3 Common Small Business ProblemsIT Solutions for 3 Common Small Business Problems
IT Solutions for 3 Common Small Business ProblemsBrooke Bordelon
 
Secure Data Sharing with the Denodo Platform
Secure Data Sharing with the Denodo PlatformSecure Data Sharing with the Denodo Platform
Secure Data Sharing with the Denodo PlatformDenodo
 
2010 07 BSidesLV Mobilizing The PCI Resistance 1c
2010 07 BSidesLV Mobilizing The PCI Resistance 1c2010 07 BSidesLV Mobilizing The PCI Resistance 1c
2010 07 BSidesLV Mobilizing The PCI Resistance 1cGene Kim
 
Expanded top ten_big_data_security_and_privacy_challenges
Expanded top ten_big_data_security_and_privacy_challengesExpanded top ten_big_data_security_and_privacy_challenges
Expanded top ten_big_data_security_and_privacy_challengesTom Kirby
 
Data Marketplace and the Role of Data Virtualization
Data Marketplace and the Role of Data VirtualizationData Marketplace and the Role of Data Virtualization
Data Marketplace and the Role of Data VirtualizationDenodo
 
Peter Grimmond – Harnessing the power of data
Peter Grimmond – Harnessing the power of dataPeter Grimmond – Harnessing the power of data
Peter Grimmond – Harnessing the power of dataVeritas Technologies LLC
 
Modernizing Data Architecture using Data Virtualization for Agile Data Delivery
Modernizing Data Architecture using Data Virtualization for Agile Data DeliveryModernizing Data Architecture using Data Virtualization for Agile Data Delivery
Modernizing Data Architecture using Data Virtualization for Agile Data DeliveryDenodo
 
KASHTECH AND DENODO: ROI and Economic Value of Data Virtualization
KASHTECH AND DENODO: ROI and Economic Value of Data VirtualizationKASHTECH AND DENODO: ROI and Economic Value of Data Virtualization
KASHTECH AND DENODO: ROI and Economic Value of Data VirtualizationDenodo
 
Cloud computing Risk management
Cloud computing Risk management  Cloud computing Risk management
Cloud computing Risk management Padma Jella
 
Securing Data in the Cloud - GISEC2017
Securing Data in the Cloud - GISEC2017Securing Data in the Cloud - GISEC2017
Securing Data in the Cloud - GISEC2017Sohaib Mahmood
 
Moving beyond Big Data, BAE Systems Detica
Moving beyond Big Data, BAE Systems Detica Moving beyond Big Data, BAE Systems Detica
Moving beyond Big Data, BAE Systems Detica Internet World
 
eDiscovery platform EMEA user conference 2017
eDiscovery platform EMEA user conference 2017eDiscovery platform EMEA user conference 2017
eDiscovery platform EMEA user conference 2017Veritas Technologies LLC
 
Improve network safety through better visibility – Netmagic
Improve network safety through better visibility – NetmagicImprove network safety through better visibility – Netmagic
Improve network safety through better visibility – NetmagicNetmagic Solutions Pvt. Ltd.
 
Cloud Security - Emerging Facets and Frontiers
Cloud Security - Emerging Facets and FrontiersCloud Security - Emerging Facets and Frontiers
Cloud Security - Emerging Facets and FrontiersGokul Alex
 
Webinar: How to Design a Compliant and GDPR Ready Collaboration System
Webinar: How to Design a Compliant and GDPR Ready Collaboration SystemWebinar: How to Design a Compliant and GDPR Ready Collaboration System
Webinar: How to Design a Compliant and GDPR Ready Collaboration SystemStorage Switzerland
 
Rethink business with OpenText Core applications and services
Rethink business with OpenText Core applications and servicesRethink business with OpenText Core applications and services
Rethink business with OpenText Core applications and servicesOpenText
 
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™Intralinks
 
Silicon Valley Code Camp Blockchain Oct 2017
Silicon Valley Code Camp Blockchain Oct 2017Silicon Valley Code Camp Blockchain Oct 2017
Silicon Valley Code Camp Blockchain Oct 2017Nelson Petracek
 
Cloud Governance Framework - Required Cloud Sourcing Capabilities
Cloud Governance Framework - Required Cloud Sourcing CapabilitiesCloud Governance Framework - Required Cloud Sourcing Capabilities
Cloud Governance Framework - Required Cloud Sourcing CapabilitiesSusanneT
 

What's hot (20)

Govern and Protect Your End User Information
Govern and Protect Your End User InformationGovern and Protect Your End User Information
Govern and Protect Your End User Information
 
IT Solutions for 3 Common Small Business Problems
IT Solutions for 3 Common Small Business ProblemsIT Solutions for 3 Common Small Business Problems
IT Solutions for 3 Common Small Business Problems
 
Secure Data Sharing with the Denodo Platform
Secure Data Sharing with the Denodo PlatformSecure Data Sharing with the Denodo Platform
Secure Data Sharing with the Denodo Platform
 
2010 07 BSidesLV Mobilizing The PCI Resistance 1c
2010 07 BSidesLV Mobilizing The PCI Resistance 1c2010 07 BSidesLV Mobilizing The PCI Resistance 1c
2010 07 BSidesLV Mobilizing The PCI Resistance 1c
 
Expanded top ten_big_data_security_and_privacy_challenges
Expanded top ten_big_data_security_and_privacy_challengesExpanded top ten_big_data_security_and_privacy_challenges
Expanded top ten_big_data_security_and_privacy_challenges
 
Data Marketplace and the Role of Data Virtualization
Data Marketplace and the Role of Data VirtualizationData Marketplace and the Role of Data Virtualization
Data Marketplace and the Role of Data Virtualization
 
Peter Grimmond – Harnessing the power of data
Peter Grimmond – Harnessing the power of dataPeter Grimmond – Harnessing the power of data
Peter Grimmond – Harnessing the power of data
 
Modernizing Data Architecture using Data Virtualization for Agile Data Delivery
Modernizing Data Architecture using Data Virtualization for Agile Data DeliveryModernizing Data Architecture using Data Virtualization for Agile Data Delivery
Modernizing Data Architecture using Data Virtualization for Agile Data Delivery
 
KASHTECH AND DENODO: ROI and Economic Value of Data Virtualization
KASHTECH AND DENODO: ROI and Economic Value of Data VirtualizationKASHTECH AND DENODO: ROI and Economic Value of Data Virtualization
KASHTECH AND DENODO: ROI and Economic Value of Data Virtualization
 
Cloud computing Risk management
Cloud computing Risk management  Cloud computing Risk management
Cloud computing Risk management
 
Securing Data in the Cloud - GISEC2017
Securing Data in the Cloud - GISEC2017Securing Data in the Cloud - GISEC2017
Securing Data in the Cloud - GISEC2017
 
Moving beyond Big Data, BAE Systems Detica
Moving beyond Big Data, BAE Systems Detica Moving beyond Big Data, BAE Systems Detica
Moving beyond Big Data, BAE Systems Detica
 
eDiscovery platform EMEA user conference 2017
eDiscovery platform EMEA user conference 2017eDiscovery platform EMEA user conference 2017
eDiscovery platform EMEA user conference 2017
 
Improve network safety through better visibility – Netmagic
Improve network safety through better visibility – NetmagicImprove network safety through better visibility – Netmagic
Improve network safety through better visibility – Netmagic
 
Cloud Security - Emerging Facets and Frontiers
Cloud Security - Emerging Facets and FrontiersCloud Security - Emerging Facets and Frontiers
Cloud Security - Emerging Facets and Frontiers
 
Webinar: How to Design a Compliant and GDPR Ready Collaboration System
Webinar: How to Design a Compliant and GDPR Ready Collaboration SystemWebinar: How to Design a Compliant and GDPR Ready Collaboration System
Webinar: How to Design a Compliant and GDPR Ready Collaboration System
 
Rethink business with OpenText Core applications and services
Rethink business with OpenText Core applications and servicesRethink business with OpenText Core applications and services
Rethink business with OpenText Core applications and services
 
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™
 
Silicon Valley Code Camp Blockchain Oct 2017
Silicon Valley Code Camp Blockchain Oct 2017Silicon Valley Code Camp Blockchain Oct 2017
Silicon Valley Code Camp Blockchain Oct 2017
 
Cloud Governance Framework - Required Cloud Sourcing Capabilities
Cloud Governance Framework - Required Cloud Sourcing CapabilitiesCloud Governance Framework - Required Cloud Sourcing Capabilities
Cloud Governance Framework - Required Cloud Sourcing Capabilities
 

Similar to Where's My Data? Managing the Data Residency Challenge

Practical steps to GDPR compliance
Practical steps to GDPR compliance Practical steps to GDPR compliance
Practical steps to GDPR compliance Jean-Michel Franco
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerCapgemini
 
Embedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceEmbedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceCILIPScotland
 
Get doing GDPR right now! IRMS May 2018
Get doing GDPR right now!  IRMS May 2018Get doing GDPR right now!  IRMS May 2018
Get doing GDPR right now! IRMS May 2018Metataxis
 
RFT for Business Intelligence and Data Strategy
RFT for Business Intelligence and Data StrategyRFT for Business Intelligence and Data Strategy
RFT for Business Intelligence and Data StrategySustainableEnergyAut
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionInfoGoTo
 
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...Denodo
 
Beyond GDPR Compliance - Role of Internal Audit
Beyond GDPR Compliance - Role of Internal AuditBeyond GDPR Compliance - Role of Internal Audit
Beyond GDPR Compliance - Role of Internal AuditOmo Osagiede
 
¿En qué se parece el Gobierno del Dato a un parque de atracciones?
¿En qué se parece el Gobierno del Dato a un parque de atracciones?¿En qué se parece el Gobierno del Dato a un parque de atracciones?
¿En qué se parece el Gobierno del Dato a un parque de atracciones?Denodo
 
Enough Talk – Solving GDPR Problems Through Metadata-Driven Compliance Webinar
Enough Talk – Solving GDPR Problems Through Metadata-Driven Compliance WebinarEnough Talk – Solving GDPR Problems Through Metadata-Driven Compliance Webinar
Enough Talk – Solving GDPR Problems Through Metadata-Driven Compliance WebinarConcept Searching, Inc
 
Policy Management: An Overview
Policy Management: An OverviewPolicy Management: An Overview
Policy Management: An OverviewMarco Casassa Mont
 
How to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected DataHow to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected DataNeo4j
 
Tim Willoughby - Presentation to Innovation Masters 2016
Tim Willoughby - Presentation to Innovation Masters 2016Tim Willoughby - Presentation to Innovation Masters 2016
Tim Willoughby - Presentation to Innovation Masters 2016Tim Willoughby
 
Implications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMAImplications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMAForgeRock
 
GDPR Noncompliance: Avoid the Risk with Data Virtualization
GDPR Noncompliance: Avoid the Risk with Data VirtualizationGDPR Noncompliance: Avoid the Risk with Data Virtualization
GDPR Noncompliance: Avoid the Risk with Data VirtualizationDenodo
 
The value of big data analytics
The value of big data analyticsThe value of big data analytics
The value of big data analyticsMarc Vael
 
Discovery, Risk, and Insight in a Metadata-Driven World Webinar
Discovery, Risk, and Insight in a Metadata-Driven World WebinarDiscovery, Risk, and Insight in a Metadata-Driven World Webinar
Discovery, Risk, and Insight in a Metadata-Driven World WebinarConcept Searching, Inc
 
Personal data and the blockchain – how will the GDPR influence blockchain app...
Personal data and the blockchain – how will the GDPR influence blockchain app...Personal data and the blockchain – how will the GDPR influence blockchain app...
Personal data and the blockchain – how will the GDPR influence blockchain app...BigchainDB
 
What Are you Waiting For? Remediate your File Shares and Govern your Informat...
What Are you Waiting For? Remediate your File Shares and Govern your Informat...What Are you Waiting For? Remediate your File Shares and Govern your Informat...
What Are you Waiting For? Remediate your File Shares and Govern your Informat...Everteam
 

Similar to Where's My Data? Managing the Data Residency Challenge (20)

Practical steps to GDPR compliance
Practical steps to GDPR compliance Practical steps to GDPR compliance
Practical steps to GDPR compliance
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offer
 
Embedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library ServiceEmbedding GDPR Within Your Information and Library Service
Embedding GDPR Within Your Information and Library Service
 
Get doing GDPR right now! IRMS May 2018
Get doing GDPR right now!  IRMS May 2018Get doing GDPR right now!  IRMS May 2018
Get doing GDPR right now! IRMS May 2018
 
RFT for Business Intelligence and Data Strategy
RFT for Business Intelligence and Data StrategyRFT for Business Intelligence and Data Strategy
RFT for Business Intelligence and Data Strategy
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and Retention
 
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
 
GDPR- The Buck Stops Here
GDPR-  The Buck Stops HereGDPR-  The Buck Stops Here
GDPR- The Buck Stops Here
 
Beyond GDPR Compliance - Role of Internal Audit
Beyond GDPR Compliance - Role of Internal AuditBeyond GDPR Compliance - Role of Internal Audit
Beyond GDPR Compliance - Role of Internal Audit
 
¿En qué se parece el Gobierno del Dato a un parque de atracciones?
¿En qué se parece el Gobierno del Dato a un parque de atracciones?¿En qué se parece el Gobierno del Dato a un parque de atracciones?
¿En qué se parece el Gobierno del Dato a un parque de atracciones?
 
Enough Talk – Solving GDPR Problems Through Metadata-Driven Compliance Webinar
Enough Talk – Solving GDPR Problems Through Metadata-Driven Compliance WebinarEnough Talk – Solving GDPR Problems Through Metadata-Driven Compliance Webinar
Enough Talk – Solving GDPR Problems Through Metadata-Driven Compliance Webinar
 
Policy Management: An Overview
Policy Management: An OverviewPolicy Management: An Overview
Policy Management: An Overview
 
How to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected DataHow to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected Data
 
Tim Willoughby - Presentation to Innovation Masters 2016
Tim Willoughby - Presentation to Innovation Masters 2016Tim Willoughby - Presentation to Innovation Masters 2016
Tim Willoughby - Presentation to Innovation Masters 2016
 
Implications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMAImplications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMA
 
GDPR Noncompliance: Avoid the Risk with Data Virtualization
GDPR Noncompliance: Avoid the Risk with Data VirtualizationGDPR Noncompliance: Avoid the Risk with Data Virtualization
GDPR Noncompliance: Avoid the Risk with Data Virtualization
 
The value of big data analytics
The value of big data analyticsThe value of big data analytics
The value of big data analytics
 
Discovery, Risk, and Insight in a Metadata-Driven World Webinar
Discovery, Risk, and Insight in a Metadata-Driven World WebinarDiscovery, Risk, and Insight in a Metadata-Driven World Webinar
Discovery, Risk, and Insight in a Metadata-Driven World Webinar
 
Personal data and the blockchain – how will the GDPR influence blockchain app...
Personal data and the blockchain – how will the GDPR influence blockchain app...Personal data and the blockchain – how will the GDPR influence blockchain app...
Personal data and the blockchain – how will the GDPR influence blockchain app...
 
What Are you Waiting For? Remediate your File Shares and Govern your Informat...
What Are you Waiting For? Remediate your File Shares and Govern your Informat...What Are you Waiting For? Remediate your File Shares and Govern your Informat...
What Are you Waiting For? Remediate your File Shares and Govern your Informat...
 

More from Cloud Standards Customer Council

Kubernetes and Container Technologies from Cloud Native Computing Foundation
Kubernetes and Container Technologies from Cloud Native Computing FoundationKubernetes and Container Technologies from Cloud Native Computing Foundation
Kubernetes and Container Technologies from Cloud Native Computing FoundationCloud Standards Customer Council
 
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0Cloud Standards Customer Council
 
Cloud Customer Architecture for Big Data and Analytics V2.0
Cloud Customer Architecture for Big Data and Analytics V2.0Cloud Customer Architecture for Big Data and Analytics V2.0
Cloud Customer Architecture for Big Data and Analytics V2.0Cloud Standards Customer Council
 
Cloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Customer Architecture for Securing Workloads on Cloud ServicesCloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Customer Architecture for Securing Workloads on Cloud ServicesCloud Standards Customer Council
 
Cloud Customer Architecture for Enterprise Social Collaboration
Cloud Customer Architecture for Enterprise Social CollaborationCloud Customer Architecture for Enterprise Social Collaboration
Cloud Customer Architecture for Enterprise Social CollaborationCloud Standards Customer Council
 
Latest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and PrivacyLatest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and PrivacyCloud Standards Customer Council
 
Interoperability and Portability for Cloud Computing: A Guide
Interoperability and Portability for Cloud Computing: A GuideInteroperability and Portability for Cloud Computing: A Guide
Interoperability and Portability for Cloud Computing: A GuideCloud Standards Customer Council
 
Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Security Standards: What to Expect and What to Negotiate V2.0Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Security Standards: What to Expect and What to Negotiate V2.0Cloud Standards Customer Council
 
Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0
Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0
Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0Cloud Standards Customer Council
 

More from Cloud Standards Customer Council (20)

Kubernetes and Container Technologies from Cloud Native Computing Foundation
Kubernetes and Container Technologies from Cloud Native Computing FoundationKubernetes and Container Technologies from Cloud Native Computing Foundation
Kubernetes and Container Technologies from Cloud Native Computing Foundation
 
What's New in Cloud Foundry
What's New in Cloud FoundryWhat's New in Cloud Foundry
What's New in Cloud Foundry
 
Hyperledger: Market, Technology & Community Update
Hyperledger: Market, Technology & Community UpdateHyperledger: Market, Technology & Community Update
Hyperledger: Market, Technology & Community Update
 
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
 
Hybrid Cloud Considerations for Big Data and Analytics
Hybrid Cloud Considerations for Big Data and AnalyticsHybrid Cloud Considerations for Big Data and Analytics
Hybrid Cloud Considerations for Big Data and Analytics
 
Cloud Customer Architecture for Big Data and Analytics V2.0
Cloud Customer Architecture for Big Data and Analytics V2.0Cloud Customer Architecture for Big Data and Analytics V2.0
Cloud Customer Architecture for Big Data and Analytics V2.0
 
Practical Guide to Cloud Management Platforms
Practical Guide to Cloud Management PlatformsPractical Guide to Cloud Management Platforms
Practical Guide to Cloud Management Platforms
 
Cloud Foundry Road Map in 2017
Cloud Foundry Road Map in 2017Cloud Foundry Road Map in 2017
Cloud Foundry Road Map in 2017
 
Hyperledger: Advancing Blockchain Technology for Business
Hyperledger: Advancing Blockchain Technology for BusinessHyperledger: Advancing Blockchain Technology for Business
Hyperledger: Advancing Blockchain Technology for Business
 
Cloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Customer Architecture for Securing Workloads on Cloud ServicesCloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Customer Architecture for Securing Workloads on Cloud Services
 
Cloud Customer Architecture for API Management
Cloud Customer Architecture for API ManagementCloud Customer Architecture for API Management
Cloud Customer Architecture for API Management
 
Cloud Customer Architecture for Hybrid Integration
Cloud Customer Architecture for Hybrid IntegrationCloud Customer Architecture for Hybrid Integration
Cloud Customer Architecture for Hybrid Integration
 
Cloud Customer Architecture for Enterprise Social Collaboration
Cloud Customer Architecture for Enterprise Social CollaborationCloud Customer Architecture for Enterprise Social Collaboration
Cloud Customer Architecture for Enterprise Social Collaboration
 
Latest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and PrivacyLatest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and Privacy
 
Interoperability and Portability for Cloud Computing: A Guide
Interoperability and Portability for Cloud Computing: A GuideInteroperability and Portability for Cloud Computing: A Guide
Interoperability and Portability for Cloud Computing: A Guide
 
Cloud Customer Architecture for e-Commerce
Cloud Customer Architecture for e-CommerceCloud Customer Architecture for e-Commerce
Cloud Customer Architecture for e-Commerce
 
Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Security Standards: What to Expect and What to Negotiate V2.0Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Security Standards: What to Expect and What to Negotiate V2.0
 
Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0
Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0
Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0
 
Cloud Foundry Roadmap in 2016
Cloud Foundry Roadmap in 2016Cloud Foundry Roadmap in 2016
Cloud Foundry Roadmap in 2016
 
Practical Guide to Platform-as-a-Service
Practical Guide to Platform-as-a-Service Practical Guide to Platform-as-a-Service
Practical Guide to Platform-as-a-Service
 

Recently uploaded

Determinants of health, dimensions of health, positive health and spectrum of...
Determinants of health, dimensions of health, positive health and spectrum of...Determinants of health, dimensions of health, positive health and spectrum of...
Determinants of health, dimensions of health, positive health and spectrum of...shambhavirathore45
 
VidaXL dropshipping via API with DroFx.pptx
VidaXL dropshipping via API with DroFx.pptxVidaXL dropshipping via API with DroFx.pptx
VidaXL dropshipping via API with DroFx.pptxolyaivanovalion
 
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptxBPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptxMohammedJunaid861692
 
Accredited-Transport-Cooperatives-Jan-2021-Web.pdf
Accredited-Transport-Cooperatives-Jan-2021-Web.pdfAccredited-Transport-Cooperatives-Jan-2021-Web.pdf
Accredited-Transport-Cooperatives-Jan-2021-Web.pdfadriantubila
 
Edukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFxEdukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFxolyaivanovalion
 
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 night
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 nightCheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 night
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 nightDelhi Call girls
 
BDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort Service
BDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort ServiceBDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort Service
BDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort ServiceDelhi Call girls
 
Invezz.com - Grow your wealth with trading signals
Invezz.com - Grow your wealth with trading signalsInvezz.com - Grow your wealth with trading signals
Invezz.com - Grow your wealth with trading signalsInvezz1
 
CebaBaby dropshipping via API with DroFX.pptx
CebaBaby dropshipping via API with DroFX.pptxCebaBaby dropshipping via API with DroFX.pptx
CebaBaby dropshipping via API with DroFX.pptxolyaivanovalion
 
Call Girls in Sarai Kale Khan Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts S...
Call Girls in Sarai Kale Khan Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts S...Call Girls in Sarai Kale Khan Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts S...
Call Girls in Sarai Kale Khan Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts S...Delhi Call girls
 
Week-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interactionWeek-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interactionfulawalesam
 
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...amitlee9823
 
Ravak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptxRavak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptxolyaivanovalion
 
BigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptxBigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptxolyaivanovalion
 
Market Analysis in the 5 Largest Economic Countries in Southeast Asia.pdf
Market Analysis in the 5 Largest Economic Countries in Southeast Asia.pdfMarket Analysis in the 5 Largest Economic Countries in Southeast Asia.pdf
Market Analysis in the 5 Largest Economic Countries in Southeast Asia.pdfRachmat Ramadhan H
 
Call me @ 9892124323 Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
Call me @ 9892124323  Cheap Rate Call Girls in Vashi with Real Photo 100% SecureCall me @ 9892124323  Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
Call me @ 9892124323 Cheap Rate Call Girls in Vashi with Real Photo 100% SecurePooja Nehwal
 
Generative AI on Enterprise Cloud with NiFi and Milvus
Generative AI on Enterprise Cloud with NiFi and MilvusGenerative AI on Enterprise Cloud with NiFi and Milvus
Generative AI on Enterprise Cloud with NiFi and MilvusTimothy Spann
 
Delhi Call Girls Punjabi Bagh 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Punjabi Bagh 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls Punjabi Bagh 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Punjabi Bagh 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Callshivangimorya083
 

Recently uploaded (20)

Determinants of health, dimensions of health, positive health and spectrum of...
Determinants of health, dimensions of health, positive health and spectrum of...Determinants of health, dimensions of health, positive health and spectrum of...
Determinants of health, dimensions of health, positive health and spectrum of...
 
VidaXL dropshipping via API with DroFx.pptx
VidaXL dropshipping via API with DroFx.pptxVidaXL dropshipping via API with DroFx.pptx
VidaXL dropshipping via API with DroFx.pptx
 
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptxBPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
 
Accredited-Transport-Cooperatives-Jan-2021-Web.pdf
Accredited-Transport-Cooperatives-Jan-2021-Web.pdfAccredited-Transport-Cooperatives-Jan-2021-Web.pdf
Accredited-Transport-Cooperatives-Jan-2021-Web.pdf
 
Edukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFxEdukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFx
 
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 night
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 nightCheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 night
Cheap Rate Call girls Sarita Vihar Delhi 9205541914 shot 1500 night
 
BDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort Service
BDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort ServiceBDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort Service
BDSM⚡Call Girls in Mandawali Delhi >༒8448380779 Escort Service
 
Invezz.com - Grow your wealth with trading signals
Invezz.com - Grow your wealth with trading signalsInvezz.com - Grow your wealth with trading signals
Invezz.com - Grow your wealth with trading signals
 
CebaBaby dropshipping via API with DroFX.pptx
CebaBaby dropshipping via API with DroFX.pptxCebaBaby dropshipping via API with DroFX.pptx
CebaBaby dropshipping via API with DroFX.pptx
 
Call Girls in Sarai Kale Khan Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts S...
Call Girls in Sarai Kale Khan Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts S...Call Girls in Sarai Kale Khan Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts S...
Call Girls in Sarai Kale Khan Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts S...
 
Week-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interactionWeek-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interaction
 
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
 
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
Call Girls Indiranagar Just Call 👗 7737669865 👗 Top Class Call Girl Service B...
 
Ravak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptxRavak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptx
 
BigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptxBigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptx
 
Market Analysis in the 5 Largest Economic Countries in Southeast Asia.pdf
Market Analysis in the 5 Largest Economic Countries in Southeast Asia.pdfMarket Analysis in the 5 Largest Economic Countries in Southeast Asia.pdf
Market Analysis in the 5 Largest Economic Countries in Southeast Asia.pdf
 
Call me @ 9892124323 Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
Call me @ 9892124323  Cheap Rate Call Girls in Vashi with Real Photo 100% SecureCall me @ 9892124323  Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
Call me @ 9892124323 Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
 
Generative AI on Enterprise Cloud with NiFi and Milvus
Generative AI on Enterprise Cloud with NiFi and MilvusGenerative AI on Enterprise Cloud with NiFi and Milvus
Generative AI on Enterprise Cloud with NiFi and Milvus
 
Delhi Call Girls Punjabi Bagh 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Punjabi Bagh 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls Punjabi Bagh 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Punjabi Bagh 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
 
Delhi 99530 vip 56974 Genuine Escort Service Call Girls in Kishangarh
Delhi 99530 vip 56974 Genuine Escort Service Call Girls in  KishangarhDelhi 99530 vip 56974 Genuine Escort Service Call Girls in  Kishangarh
Delhi 99530 vip 56974 Genuine Escort Service Call Girls in Kishangarh
 

Where's My Data? Managing the Data Residency Challenge

  • 1. Claude Baudoin & Geoff Rayner 27 February 2018 Where’s My Data? Managing the Data Residency Challenge 2/27/2018 Copyright © 2018 OMG. All rights reserved. 1
  • 2. 2/27/2018 Copyright © 2018 OMG. All rights reserved. 2 Speakers Tracie Berardi Director of Program Management, OMG Program Manager, Cloud Standards Customer Council Moderator tracie@omg.org Claude Baudoin Principal, cébé IT & Knowledge Management Steering Committee member, Cloud Standards Customer Council cbaudoin@cebe-itkm.com Geoff Rayner CEO, Data Advantage Group grayner@dag.com
  • 3. • Data Residency definition • History of OMG’s work on data residency • Types of information that pose risks • Nature of the risks – examples • Laws and regulations around the world • Potential applicable standards • OMG Discussion Paper • OMG Data Residency Maturity Model (DRMM) • How to contribute 2/27/2018 Copyright © 2018 OMG. All rights reserved. 3 Topics Covered in this Webinar New
  • 4. “Data residency is the set of issues and practices related to the location of data and metadata, the movement of (meta)data across geographies and jurisdictions, and the protection of that (meta)data against unintended access and other location-related risks.” • Scope • Not just about the protection of personally identifiable information (PII) • Also concerns the right to move “sovereign” data, such as oil reserves data; international licensing of genomics data; distribution of biometrics data for security purposes; etc. 2/27/2018 Copyright © 2018 OMG. All rights reserved. 4 Data Residency: Definition
  • 5. • March 2015: initial request from an OMG member • June 2015: first OMG Data Residency WG meeting (Berlin) • Q4 2015: Prepared and issued an RFI • Q2 2016: Processed RFI results, decided to create a discussion paper as first deliverable • Q4 2016: Drafted discussion paper, agreed to collaborate with CSCC and issue two separate but almost identical papers • Q1 2017: Collected contributions, edited paper, agreement to release • Q2 2017: Create CSCC companion white paper, press releases, webinar • June-Dec. 2017: Successive tutorials, created and released a maturity model, discussed standards roadmap 2/27/2018 Copyright © 2018 OMG. All rights reserved. 5 OMG’s Work on Data Residency
  • 6. • Multiple laws and regulations restrict what an organization can do with certain types of data, or potentially prevent its protection: • Personally identifiable information (PII) • Patient health information (PHI) • Proprietary corporate information • Communications (e-mail, etc.) • Government information (incl. military) • Information subject to trade controls and embargoes • Information on natural resources • Banking records • Other regulated data, e.g., “sovereign” data 2/27/2018 Copyright © 2018 OMG. All rights reserved. 6 Sources of Risk
  • 7. • Owners of such data may: • Relocate this data intentionally, for convenience or cost reduction • Data center consolidation and managed hosting • Centralized employee or customer database • Business process outsourcing • Helpdesk outsourcing • Be unaware of its location • Cloud service optimization by the provider • IoT data collection • Acquisitions and expansion to new countries change the risk • The Internet of Things exacerbates the challenge 2/27/2018 Copyright © 2018 OMG. All rights reserved. 7 Sources of Risk (cont.)
  • 8. • Difficulty of providing IT services across borders from few locations • Higher cost for customers (less competition for local services) • Inability to consolidate operations • Inability to provide shared employee services • Need for multiple local IT operations teams (skills and cost issues) • Limitations in backup locations • Restrictions against strong data encryption • Legal exposure • Conflict with authorities • Public mistrust 2/27/2018 Copyright © 2018 OMG. All rights reserved. 8 Nature of the Risks
  • 9. • Multiple, inconsistent, overlapping, and still evolving laws and regulations around the world • Range from non-existent to severe • Sometimes (but not always) apply to government data / public records, not to private companies’ data • The European Union’s General Data Protection Regulation (GDPR), in effect from 25 May 2018, is among the most comprehensive • Multiple motivations behind the laws: • Protecting the privacy of citizens • Enabling police and tax authorities to inspect data • Protectionism – force companies to create domestic facilities • Monetize the flow of data 2/27/2018 Copyright © 2018 OMG. All rights reserved. 9 Data Residency Laws and Regulations
  • 10. 2/27/2018 Copyright © 2018 OMG. All rights reserved. 10 A Proliferation of Laws
  • 11. • There is currently no standard that deals specifically with data residency • Data residency is related to the security and privacy aspects of • Several NIST publications (800-144, 500-299, 1500) • Several ISO/IEC standards (27001, 27017, 27018) • NIST Big Data Standard, http://fedscoop.com/nist-big-data-framework • The work of the CSA’s International Standardization Council (ISC) • Work being considered in ISO/IEC JTC 1/SC 38 • The “Voluntary Data Protection Code” of CISPE (Cloud Infrastructure Service Providers in Europe) 2/27/2018 Copyright © 2018 OMG. All rights reserved. 11 Potential Useful Standards
  • 12. • Two very close versions (OMG and CSCC) 2/27/2018 Copyright © 2018 OMG. All rights reserved. 12 OMG’s First Discussion Paper
  • 13. • Issued by OMG in December 2017 as a second “discussion paper” • Structured in a similar manner to the SEI CMM for software engineering (1990) • 5 levels and 20 “key process areas” that need to be put in place to “climb” to higher levels of maturity Copyright © 2018 OMG. All rights reserved. 13 The Data Residency Maturity Model (DRMM) Level SEI CMM Name Definition (under construction) Key Process Areas 5 Optimizing There is continuous monitoring and improvement of data residency policies, procedures and implementation ● Active monitoring and auditing of data location, transfer, and remote access ● Regular review of changes in business, data content, technology, laws and regulations ● Formal process to evolve policies, procedures, practices and technology ● Formal process to review all incidents and take corrective action 4 Managed Active management takes place at all levels of the organization ● Executive accountability ● Governance (e.g., steering committee) ● Assign roles and responsibilities for DR policy and implementation ● Formal policies ● Data storage location assignment is part of information modeling ● Logging / audit trail of data creation, movement, access right changes ● Formal program of employee training 3 Defined Policies, procedures, practices are documented and institutionalized, and data location impact is formally documented ● Active executive involvement ● Formally documented processes ● Taxonomy of sensitive data ● Informal training resources ● People are formally assigned to data owner/steward/custodian roles 2 Repeatable The organization performs on the basis of human knowledge, informally shared ● Executive awareness (e.g., evidenced by a letter from each C-level stakeholder stating their belief in the importance of the issue) ● Informal practices and guidelines to identify and locate data ● Employees know who to go to in order to arbitrate a d.r. question ● People act informally in roles of data owners/steward/custodians 1 Initial None of above practices exist
  • 14. • Participate in OMG’s Data Residency Working Group • Review the existing discussion papers and provide comments • http://www.omg.org/cgi-bin/doc?mars/17-03-22.pdf (“Challenges and Opportunities” paper) • http://www.omg.org/cgi-bin/doc?mars/17-12-18.pdf (DRMM) • Consider adopting the DRMM • OMG is interested in partnering with organizations that would want to “adopt and adapt” the DRMM and give it broader recognition • Suggest applicable standards – and if you work in standards group on security and privacy, give them input about data residency issues • Our current intent • Coordinate with other OMG groups working on Data Provenance & Pedigree and on Data Tagging & Labeling – seek a unified “data governance” approach • Develop a standard to represent the various data residency laws and regulations in a uniform formal manner 2/27/2018 Copyright © 2018 OMG. All rights reserved. 14 How to Contribute
  • 15. • Thanks for your attention • Please ask questions using the BrightTalk interface • Ask to be added to our mailing list • Send an e-mail to request@omg.org and ask to be added to the “dataresidency” list • Participate in our next meetings • Reston, Va., March 20, 2018 • Boston, Mass., week of June 18-22 • Ottawa, Ont., Canada, week of Sept. 24-28 (2-day event on various information governance and security topics for the Canadian government) • Contact Tracie Berardi, tracie@omg.org, for additional questions or comments 2/27/2018 Copyright © 2018 OMG. All rights reserved. 15 Discussion