Projects do not manage the risks of using the Cloud
Mariano J. Benito, CISO of GMV Secure e-Solutions, shared in Valencia the GMV's expertise in security around Cloud Computing projects with a paper entitled "XaaS Projects. Avoid safety errors" in the day of Cloud Project Management organized by ISACA and PMI, with the collaboration of the Official College of IT and Telecommunications Engineers and the Valencia Association (COIICV and COGITCV).
The contribution of GMV highlighted the most common risks in projects that rely on cloud services for deployment, since this support is increasingly widespread, by financial advantages or runtime, but projects are often not "have into account the risks, difficulties and safety requirements associated with the use of these technologies", such as legal compliance, the impact on users, the complexities of SLAs, causing the existence of scenarios where using cloud services is not the optimal solution. Sometimes, "we turn to the cloud with blind eyes... without making a study of possible risks, without analyzing security, without raising that something can go wrong..." and in such cases, the cloud" can become expensive". For the expert on cybersecurity, cloud "is a technological solution that is an improvement but, like any other technology, requires training and must learn the properly use to benefit from it".
Mariano J. Benito, CISO of GMV Secure e-Solutions, also spoke of ShadowIT. Its positive side, as a way for the departments of companies to streamline their initiatives; and a negative side, the non-participation of other areas difficult to implement adequate business controls on these initiatives. In short, he concluded, "for the global organization can be an opportunity, but also the increased of the participation leads to increase the risk that must be contemplated". Mariano J. Benito concluded his participation noting that the cloud is a very useful and interesting tool, but it doesn’t mean that is the best option: it is necessary to analyze the risks before going to assume the use of the Cloud for organizations and projects.