Wednesday, February 8, 2017

Cloud storage dilemma in a Corporate setting - Top10

How much do you really know about the providers’ encryption key management, or the shared virtualized environment?

Would a 3-tiered model for cloud storage be applicable e.g. Sanctioned, Tolerated and Unsanctioned. Taking into account the following consideration - Top 10:
  1. Policy driven - Acceptable Use, Data Classification and Retention
  2. Strong password 
  3. Multi-factor authentication
  4. MDM: Access via managed devices only and limit linked applications or unsupported software connection
  5. Granular file security including share provisioning
  6. Encryption at-rest, in transit
  7. Timely patching – full cycle, all devices
  8. Data Loss Prevention enabled
  9. Country location based storage
  10. Rich feature enabled e.g. user notification for login of new devices
What’s your flavor: SharePoint, Saleforce, Box, IDrive, OneDrive, GoogleDrive, DropBox, JustCLoud, SurgarSync, Prezi, Mega, Zippyshare, Carbonite, BackBlaze, CrashPlan, Mozy

6 comments: