+1 (970) 414-2609
  • Active Campaign
  • Global News
Sunday, June 4, 2023
  • Home
  • About Us
  • Our Experts
  • AI Tools
  • Our Work
    • Education
    • Community
    • Humanitarian
No Result
View All Result
Boys & Girls Clubs of Senegal
No Result
View All Result
Home Africa News

Due diligence is Ever More Critical as the Battle for

by nancie geddes
April 30, 2023
in Africa News
Reading Time: 6 mins read
A A
464
SHARES
1.8k
VIEWS
Share on FacebookShare on Twitter

It is becoming increasingly essential for organisations to ensure cloud due diligence amid evolving data sovereignty requirements.

The IT industry has recently seen some interesting activity from global hyperscale cloud providers surrounding their cloud sovereignty ambitions, and their scrutiny by the regulators covering some basics compliance requirements, like the European Union’s (EU) General Data Protection Regulation (GDPR).

Firstly, AWS made a public pledge called the “AWS Digital Sovereignty Pledge”, consisting of a commitment to provide “the most advanced set of sovereignty controls and features available in the cloud”. After Google’s cooperation with T-Systems and the “Delos” offer from Microsoft, SAP, and Arvato, AWS now follows suit. These initiatives reinforce the growing potential of sovereign cloud services in a world increasingly dominated by questions of cloud choice and control, and complex compliance requirements.

So, what does a pledge mean? The dictionary defines this as a “solemn promise” – which would reasonably beg the question: isn’t this an admission there is little sovereignty in the offering today? Otherwise, why would it be a pledge? A pledge is forward-looking, something that has not been performed or delivered yet. Also, shouldn’t an announcement like this ideally be backed up with a roadmap? Where is the guarantee that items in this pledge will be fulfilled? Instead, AWS mentions what the pledge will generally cover: control over the location of your data, verifiable control over data access, the ability to encrypt everything everywhere, and the resilience of their cloud. The pledge sounds excellent, but does it meet the minimum standards of most data sovereignty requirements worldwide? It appears, from the general language, that none of it addresses the critical concerns around hyperscale usage, jurisdictional control, legal rights to access the data, and complying with sovereign data requirements that require protection from the US Cloud Act or Section 702 of the US Foreign Intelligence Surveillance Act (FISA).

Secondly, Microsoft has run aground in Germany with Office 365 reportedly not complying with GDPR. GDPR is 4+ years old and is a huge issue that most companies have joined in the rush not to be penalised by the EU. With Germany’s federal and state data protection authorities (DSK) raising concerns about the compatibility of 365 with data protection laws in Germany and the wider EU, it makes you wonder how other companies may also be falling short in their obligations to protect EU customers’ data.

Also, how many other regulatory requirements (such as data sovereignty requirements) that global public cloud providers believe they comply with are prone to be scrutinised by the regulators? This news, of course, is food for thought. Microsoft has denied that this is correct and issued a statement asking for more clarification regarding the view that DSK has. IT executives should therefore take this news as a noteworthy case study to fuel the decisions of their cloud choice, as regulatory requirements concerning data sovereignty are much more complex and niche to comply with than GDRP.

ADVERTISEMENT

All these issues and many more are putting US and global hyperscale cloud providers in a precarious position when operating a sovereign cloud or other regulated cloud solution, in jurisdictions such the EU, where they must adhere to the EU’s GDPR and US legislation. Indeed, it puts the EU in a precarious position as well, given that 72% of the European cloud market spend was aligned with AWS, Microsoft, and Google in Q2 2022.

The EU wants a fair market and a protected European cloud without compromising cloud functionality. However, continued investment by customers in US hyperscale and continual investment in the region of $4bn in US hyperscale organisations into expansion means that no European cloud company will ever seriously challenge this market today. The EU certainly has a quandary: on the one hand, enforcing sovereignty would mean no foreign clouds could be used, which would severely damage the EU cloud market; and on the other hand, how to legislate enough to maintain a level of sovereignty that doesn’t exclude foreign providers with some level of external jurisdictional control? It seems that for the foreseeable future, there will be little answer to this quandary. The most prudent approach to compliance appears to be a national, purpose-built sovereign cloud, using external clouds when your data classification meets the needs of unregulated or non-sovereign environments – this seems to be cloud smart!

European cloud providers tend to be more specialised in their services, with nearly all providing managed services, something not found directly in the major US hyperscale cloud provider offerings. I believe this is a good thing. VMware has consistently stated that the future of a well-run cloud-smart IT strategy is multi-cloud and hybrid cloud and that being cloud-smart means we cannot ignore hyperscale offerings. We need them, especially as there are significant innovations and market-leading scalability in these clouds.

This is where VMware’s strategy is unique: VMware encourages multi-cloud and helps organisations maintain a cloud strategy that avoids lock-in and maintains quality and security while monitoring performance. The VMware Sovereign Cloud initiative provides national and local cloud provider partners the capability to build purpose-built sovereign clouds, including ones that deliver locally specific requirements in areas such as data sovereignty, including data residency and jurisdictional control, data access and integrity, data security and compliance, data independence and mobility, and data innovation and analytics.

The common misunderstanding when considering using a global hyperscale cloud provider as an option for workloads requiring data sovereignty is that there is compliance because the portfolio, data and applications will be limited to only what can be run in a region. This still doesn’t make it sovereign – it is simply a farce. To be clear, physical location (or data residency), while necessary for data sovereignty, does not constitute data sovereignty entirely for almost if not all data sovereignty requirements around the globe.

Data sovereignty requirements are unique to each jurisdiction, but all have many more needs than simple data residency. For example, they all also require jurisdictional control – which cannot be assumed to be met with a data resident cloud, particularly for US or global cloud providers subject to the Cloud Act and FISA ruling. It’s therefore essential to recognise that VMware sovereign cloud providers are independent third-party partners across the globe who also manage extensive portfolios of cloud capabilities. Based on VMware solutions and ecosystem vendors, with tools and competitive advantage (under the current regulatory climate) to be able to provide the highest levels of compliance comfort with data sovereignty requirements and/or other regulations such as GDPR.

getty

So, what is the answer here? VMware’s position has not changed; the usage of “trusted” hyperscale clouds denotes a level of trust whereby data that should be placed in a hyperscale cloud is not top secret or restricted, can be protected (using encryption, bring your own key, confidential computing, or privacy-enhancing compute (PEC)) and should be public—i.e., only low-risk data should be placed in any hyperscale cloud, whether trusted or native. Whilst the battles between the hyperscale clouds continue to attempt to achieve sovereign status in Europe. Across the globe, customers should not wait any longer for a magical one size fits all solution or ever trust that their due diligence of regulatory requirements can be delegated to any vendor. Instead, consider a strategy that utilises the best of all multi-cloud solutions and establishes cloud choices based on data classification, data operations, and risk.

VMware

As the diagram shows, there is increased risk associated with non-sovereign cloud solutions, as jurisdictional control is negated in a trusted or hyperscale public cloud. The volume of data applicable to non-sovereign services that should be considered may be lower when you have conducted a thorough data classification exercise. Remember that a sovereign cloud provider delivers services suited to your vertical, whether government, public sector, financial, or many other verticals, and managed services to help you with your cloud adoption strategy. Some also innovate solutions for secure data exchange to enable monetising your data, a critical component in the growing data market. In addition, VMware Sovereign Cloud Providers may be best suited to support you in managing locally tailored privacy, classifications, and risk analysis, ensuring compliance with the most stringent of standards. As data pertains to personal and non-personal data (think industrial and IoT), a classification exercise will help you understand your risks and how to protect them in alignment with regulatory requirements and mitigate future threats from new data classification standards that are indeed to come.
 
As data markets evolve and data exchange for supply chain and monetisation become a critical component of how we do business, it is essential that the right strategy is decided at day 0 and that the limitations of a cloud choice do not compromise the principles of sovereignty you encompass. Additionally, ensure that the cloud provider you select has the right technology capabilities, security infrastructure, and data governance processes to protect your data, meet compliance standards, and provide a secure platform for your business.

Find your closest VMware Sovereign Cloud provider today

Previous Post

Russia’s Lavrov warns of EU militarisation, says similar to NATO

Next Post

Georgian PM Pushes EU, NATO Aspirations

Related Posts

Paul O’Sullivan: Wolves guarding sheep at new SAPS Kidnapping Unit; and ‘it’s personal’ vendetta against State Capture law firm

by tiffani sherman
June 3, 2023

Ace forensic investigator Paul O’Sullivan says South Africa’s new specialist unit to counter a surge in kidnapping has all the...

Read more

Red tape tangles South Africa’s economic growth, falling behind in the race for prosperity

by erin walsh
June 3, 2023

In a world where economic freedom leads to prosperous outcomes, South Africa finds itself lagging behind. Ranked 99th globally in...

Read more

Morgues in North Africa full with migrants who died trying to reach Europe, Immigration Minister warns

by augustine mischke
June 3, 2023

MORGUES in North Africa are overflowing with the bodies of dead migrants trying to get to Europe, the Immigration Minister...

Read more

We’ll be swift with Ghana’s economic recovery – Ofori-Atta

by dion grumbles
June 3, 2023

The Minister of Finance, Ken Ofori-Atta, has reiterated the government’s commitment to swiftly restore Ghana’s economic fortunes in the shortest...

Read more

SCORPIO INVESTIGATION: BadFellas – Did businessman Patrick Monyeki bribe then SARS boss Tom Moyane in Gartner tech deal?

by oluwapelumi adejumo
June 3, 2023

On Friday, 26 May, the US Securities and Exchange Commission (SEC) published an order that found Connecticut-based tech firm Gartner...

Read more

An honour for T&T, says PM | Local News |

by edith m. ledererap
June 3, 2023

Permanent representative of Trinidad and Tobago to the United Nations in New York Ambassador Dennis Francis is the new president...

Read more
Next Post

Georgian PM Pushes EU, NATO Aspirations

ADVERTISEMENT

Trending Posts

Cybersecurity

Today’s Cyber Threats Require Modern Cloud Network Security

by editorial@africanews.com redaction africanews
June 3, 2023

Tweet Post Share Annotate Save Print By Narayan Annamalai When cybersecurity measures fail, the results can be devastating and costly....

Read more

Today’s Cyber Threats Require Modern Cloud Network Security

Injective (INJ) Price All Set For Massive Surge in Coming Days

Bitcoin Live News: What’s Ahead For BTC Price in June?

Why Did Bitcoin’s Price Rise? BTC Hovers Over $27K as Investors Shrug Off Hot Jobs Data

Mercado Bitcoin, Brazil’s Largest Crypto Exchange, Receives License as a Payment Institution

Marathon Digital Mined 77% More Bitcoin in May With the Help of Its Software

Load More

Popular Posts

How to be a good manager?

by BGC Senegal
January 26, 2023

  How to be a Good Manager Being a good manager isn't easy. It requires strong leadership, dedication, discipline, and...

How to write a resume?

by BGC Senegal
January 25, 2023

  How to Write a Resume Writing a resume can be a stressful task. It is important to take your...

How to be a team player?

by BGC Senegal
January 26, 2023

  How to be a Team Player? Being a team player is not as difficult as it sounds; it means...

Facebook Twitter LinkedIn Youtube

NEWSLETTER

Subscribe to our newsletter and be the first to know about our upcoming events and programs.

QUICK LINKS

  • About Us
  • Learning Center
  • Active Campaign
  • Privacy Policy
  • Terms and Conditions
  • Contact us
  • Global News

CONTACT INFO

  • info@senegalbgc.org
  • For donations contact us at: donate@senegalbgc.org

© 2019-2023 Boys & Girls Clubs of Senegal. We are a 501 (C)(3) organization and donations are tax deductible. - EIN: 83-3699796

No Result
View All Result
  • Home
  • About Us
  • Our Experts
  • AI Tools
  • Our Work
    • Education
    • Community
    • Humanitarian

© 2019-2023 Boys & Girls Clubs of Senegal. We are a 501 (C)(3) organization and donations are tax deductible. - EIN: 83-3699796

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT