Introduction
Cloud computing has transformed how organizations utilize Information Technology resources and infrastructures. The pay-as-you-go model enabled by cloud platforms provides organizations scalability, flexibility and lower upfront costs compared to traditional on-premises IT infrastructure (Marston et al., 2011). One of the key enabling technologies of cloud computing is cloud storage, which allows users to store and access data and files from any Internet-connected device instead of relying on local storage (Armbrust et al., 2010). The benefits of cloud storage include virtually unlimited and elastic storage capacity, high availability and reliability through data replication, easy access to data from anywhere and cost savings from avoided upfront investments in storage hardware and maintenance costs (Rittinghouse & Ransome, 2010).
Given the transformational impact of cloud computing, cloud storage has emerged as an attractive alternative to traditional on-premises file servers and storage for many organizations (Vaquero et al., 2008). Industry analysts estimate that the global public cloud storage market size was $18.8 billion in 2016 and is expected to grow to $47.8 billion by 2022 at a CAGR of 18.8% from 2017 to 2022 (MarketsandMarkets, 2017). According to RightScale’s 2016 State of the Cloud Report, 95% of surveyed organizations were using some form of cloud computing and 74% use public cloud storage services such as Amazon S3, Microsoft Azure Blob Storage and Google Cloud Storage (RightScale, 2016).
Despite the growing popularity and adoption of cloud storage, concerns around security, control, compliance and vendor lock-in still pose challenges for organizations (Armbrust et al., 2010; Leavitt, 2011; Rittinghouse & Ransome, 2010). While cloud service providers implement robust access controls and security best practices, customers worry about loss of control and security breaches putting sensitive data at risk (Pearson, 2013). Regulatory compliance with industry and government mandates around data governance, privacy and retention also present challenges in outsourcing data to public cloud providers (Armbrust et al., 2010; Leavitt, 2011). Furthermore, depending solely on a single cloud vendor exposes organizations to risks of vendor lock-in and higher switching costs if they decide to migrate workloads later (Armbrust et al., 2010; Rittinghouse & Ransome, 2010).
Given these critical considerations around security, compliance and vendor lock-in, organizations must carefully evaluate their cloud storage requirements, adopt a risk-based approach and implement appropriate safeguards before moving mission-critical data and applications to the cloud. While public cloud storage provides significant business benefits, a hybrid cloud model leveraging both on-premise and cloud infrastructures can help address various concerns (Marston et al., 2011; Pandey et al., 2012). This paper aims to provide organizations a framework to assess the suitability of cloud storage based on their workload characteristics and risk tolerance levels. It also suggests best practices to maximize benefits while mitigating risks when adopting cloud storage solutions.
Evaluating Cloud Storage Suitability
To determine if cloud storage is a good fit, organizations must first characterize different types of data based on sensitivity, regulatory requirements, access patterns and retention policies. Data can then be classified into various categories to adequately assess risks and identify appropriate storage locations. A commonly used framework classifies data into three broad categories (Catteddu & Hogben, 2009):
Public Data: Includes marketing collateral, press releases, product brochures and other non-sensitive information that can be freely shared online. Public cloud storage is well-suited for such low-risk data.
Internal Data: Comprises HR records, financial documents, source code repositories etc. which are non-critical from confidentiality perspective but require access control and availability assurances. A hybrid cloud model with disaster recovery in the public cloud can address requirements.
Confidential Data: Encompasses personally identifiable information (PII), intellectual property, patient health records etc. that impose strict regulatory and compliance obligations. Such sensitive workloads are best kept on-premises or in a private dedicated cloud due to control and compliance needs.
In addition to data sensitivity, other aspects like data volumes, growth rates, access patterns, retention periods and geographical distribution must also be evaluated. For example, infrequently accessed archival data can be better suited to lower cost public cloud object storage tiers while frequently accessed active datasets require high performance public or private cloud block storage (Rittinghouse & Ransome, 2010; Vaquero et al., 2008). Analyzing these multidimensional characteristics helps identify candidate cloud storage tiers from a functional, regulatory and cost optimization perspective.
Risk Mitigation Best Practices
While cloud platforms offer robust security controls, adopting a defense-in-depth strategy helps address residual risks and regulatory requirements more effectively (Rittinghouse & Ransome, 2010):
Encrypt All Data At-Rest: Leverage server-side or client-side encryption using standards-based algorithms before uploading data to cloud storage. This protects against malware, insider threats and physical compromise of storage media.
Control Credentials & Access: Implement least privilege access controls, multi-factor authentication and monitor access logs centrally for anomaly detection. Rotate passwords/keys regularly as per policy.
Classify & Label Sensitive Data: Apply classification and data loss prevention techniques to scan for regulated information and enforce security controls accordingly.
Prepare Disaster Recovery Plan: Maintain synchronized on-premise copies of critical data and automate failover processes to minimize downtime and data loss risks.
Conduct Regular Audits: Leverage audit logs, activity monitoring and compliance reporting functions of cloud platforms to assess controls effectiveness periodically. Address deviations promptly.
Perform Due Diligence On Providers: Evaluate providers based on certifications, risk management practices, data sovereignty and contractual commitments before onboarding workloads.
Adopting a hybrid storage model further enables organizations to retain control over sensitive data while leveraging cloud efficiencies for other use cases. It also distributes risks across on-premise and cloud-based architectures. Additional security practices like threat modeling, penetration testing and security incident response planning help achieve comprehensive risk mitigation postures.
Concerns can also be addressed by negotiating appropriate service level agreements with credible cloud providers, adopting Infrastructure as Code practices for consistent configuration management and automating infrastructure security monitoring (Pan et al., 2014; RightScale, 2016). Overall, combining technology, process and people controls as per identified risks delivers optimal security and compliance assurance for cloud storage adoption.
Conclusion
Cloud storage presents significant business opportunities to organizations by offering virtually unlimited, on-demand and elastic storage capacity. Concerns around security, control and compliance still pose adoption challenges for certain mission-critical and regulated workloads. This paper provided a framework to methodically assess cloud storage suitability based on data sensitivity, access patterns and regulatory requirements. It also suggested a risk-based, defense-in-depth strategy incorporating industry-leading practices like encryption, access controls, contingency planning and provider due diligence. A hybrid cloud model split between on-premise and cloud infrastructures further helps balance requirements around functionality, governance and costs optimization. With careful evaluation and implementation of recommended safeguards, cloud storage presents a scalable, agile and cost-effective storage infrastructure for most organizational needs while mitigating residual organizational risks. Overall, adopting an informed risk management approach enables organizations to maximize cloud benefits securely based on individual risk profiles and regulatory mandates.
