<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Regulators highlighting Multi-Cloud Benefits in Cloud Security</title>
    <link>https://community.isc2.org/t5/Cloud-Security/Regulators-highlighting-Multi-Cloud-Benefits/m-p/55147#M260</link>
    <description>&lt;P&gt;We see more and more regulatory comments on multi-cloud solutions. As a result, particularly financial institutions are asking for multi-cloud workflows (e.g. AWS and Azure), instead of single-cloud providers. If you also experience increased requests by regulatory bodies on multi-cloud deployments (or just would like to provide some comments), please share your feedback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Examples of regulator statements:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In July, the &lt;STRONG&gt;Bank for International Settlements&lt;/STRONG&gt; said that the financial sector‘s increased resilience on cloud computing was ‘&lt;EM&gt;forming single point of failure&lt;/EM&gt;’ and ‘&lt;EM&gt;creating new forms of concentration risk at the technology services level&lt;/EM&gt;’.&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;Federal Reserve Bank of New York&lt;/STRONG&gt; also warned about the ‘&lt;EM&gt;transmission of a shock throughout the network&lt;/EM&gt;’ should financial services be ‘&lt;EM&gt;connected through a shared vulnerability&lt;/EM&gt;’.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Monetary Authority of Singapore&lt;/STRONG&gt;&amp;nbsp;states: ‘&lt;EM&gt;Cloud workloads could also be deployed in multiple geographically separated data centers (e.g. ‘zones’ or ‘regions’) to mitigate location-specific issues that may disrupt the delivery of public cloud services. ’&amp;nbsp;&lt;/EM&gt;Furthermore, it is stated: ‘&lt;EM&gt;To mitigate CSP concentration risks, FIs may consider implementing vendor diversity.’&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EU&lt;/STRONG&gt;&amp;nbsp;passed&amp;nbsp;&lt;A href="https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52020PC0595&amp;amp;from=EN" target="_blank"&gt;Digital Operational Resilience Act (DORA)&lt;/A&gt;, defines ICT Concentration Risk:&amp;nbsp;&lt;EM&gt;‘ICT concentration risk means an exposure to individual or multiple related critical ICT third-party service providers creating a degree of dependency on such providers so that the unavailability, failure or other type of shortfall of the latter may potentially endanger the ability of a financial entity, and ultimately of the Union’s financial system as a whole, to deliver critical functions, or to suffer other type of adverse effects, including large losses. ’&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Moreover, the following is stated:&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;‘&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;Financial entities shall weigh the benefits and costs of alternative solutions, such as the use of different ICT third-party service providers, taking into account if and how envisaged solutions match the business needs and objectives set out in their digital resilience strategy.’&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Nov 2022 12:02:02 GMT</pubDate>
    <dc:creator>PeterHainz</dc:creator>
    <dc:date>2022-11-14T12:02:02Z</dc:date>
    <item>
      <title>Regulators highlighting Multi-Cloud Benefits</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Regulators-highlighting-Multi-Cloud-Benefits/m-p/55147#M260</link>
      <description>&lt;P&gt;We see more and more regulatory comments on multi-cloud solutions. As a result, particularly financial institutions are asking for multi-cloud workflows (e.g. AWS and Azure), instead of single-cloud providers. If you also experience increased requests by regulatory bodies on multi-cloud deployments (or just would like to provide some comments), please share your feedback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Examples of regulator statements:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In July, the &lt;STRONG&gt;Bank for International Settlements&lt;/STRONG&gt; said that the financial sector‘s increased resilience on cloud computing was ‘&lt;EM&gt;forming single point of failure&lt;/EM&gt;’ and ‘&lt;EM&gt;creating new forms of concentration risk at the technology services level&lt;/EM&gt;’.&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;Federal Reserve Bank of New York&lt;/STRONG&gt; also warned about the ‘&lt;EM&gt;transmission of a shock throughout the network&lt;/EM&gt;’ should financial services be ‘&lt;EM&gt;connected through a shared vulnerability&lt;/EM&gt;’.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Monetary Authority of Singapore&lt;/STRONG&gt;&amp;nbsp;states: ‘&lt;EM&gt;Cloud workloads could also be deployed in multiple geographically separated data centers (e.g. ‘zones’ or ‘regions’) to mitigate location-specific issues that may disrupt the delivery of public cloud services. ’&amp;nbsp;&lt;/EM&gt;Furthermore, it is stated: ‘&lt;EM&gt;To mitigate CSP concentration risks, FIs may consider implementing vendor diversity.’&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EU&lt;/STRONG&gt;&amp;nbsp;passed&amp;nbsp;&lt;A href="https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52020PC0595&amp;amp;from=EN" target="_blank"&gt;Digital Operational Resilience Act (DORA)&lt;/A&gt;, defines ICT Concentration Risk:&amp;nbsp;&lt;EM&gt;‘ICT concentration risk means an exposure to individual or multiple related critical ICT third-party service providers creating a degree of dependency on such providers so that the unavailability, failure or other type of shortfall of the latter may potentially endanger the ability of a financial entity, and ultimately of the Union’s financial system as a whole, to deliver critical functions, or to suffer other type of adverse effects, including large losses. ’&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Moreover, the following is stated:&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;‘&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;Financial entities shall weigh the benefits and costs of alternative solutions, such as the use of different ICT third-party service providers, taking into account if and how envisaged solutions match the business needs and objectives set out in their digital resilience strategy.’&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 12:02:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Regulators-highlighting-Multi-Cloud-Benefits/m-p/55147#M260</guid>
      <dc:creator>PeterHainz</dc:creator>
      <dc:date>2022-11-14T12:02:02Z</dc:date>
    </item>
  </channel>
</rss>

