SlideShare a Scribd company logo
Claude Baudoin & Geoff Rayner
27 February 2018
Where’s My Data?
Managing the Data
Residency Challenge
2/27/2018 Copyright © 2018 OMG. All rights reserved. 1
2/27/2018 Copyright © 2018 OMG. All rights reserved. 2
Speakers
Tracie Berardi Director of Program Management, OMG
Program Manager, Cloud Standards Customer Council
Moderator
tracie@omg.org
Claude Baudoin Principal, cébé IT & Knowledge Management
Steering Committee member, Cloud Standards Customer Council
cbaudoin@cebe-itkm.com
Geoff Rayner CEO, Data Advantage Group
grayner@dag.com
• Data Residency definition
• History of OMG’s work on data residency
• Types of information that pose risks
• Nature of the risks – examples
• Laws and regulations around the world
• Potential applicable standards
• OMG Discussion Paper
• OMG Data Residency Maturity Model (DRMM)
• How to contribute
2/27/2018 Copyright © 2018 OMG. All rights reserved. 3
Topics Covered in this Webinar
New
“Data residency is the set of issues and practices related to the
location of data and metadata, the movement of (meta)data
across geographies and jurisdictions, and the protection of that
(meta)data against unintended access and other location-related
risks.”
• Scope
• Not just about the protection of personally identifiable information (PII)
• Also concerns the right to move “sovereign” data, such as oil reserves data;
international licensing of genomics data; distribution of biometrics data for
security purposes; etc.
2/27/2018 Copyright © 2018 OMG. All rights reserved. 4
Data Residency: Definition
• March 2015: initial request from an OMG member
• June 2015: first OMG Data Residency WG meeting (Berlin)
• Q4 2015: Prepared and issued an RFI
• Q2 2016: Processed RFI results, decided to create a discussion paper as first
deliverable
• Q4 2016: Drafted discussion paper, agreed to collaborate with CSCC and
issue two separate but almost identical papers
• Q1 2017: Collected contributions, edited paper, agreement to release
• Q2 2017: Create CSCC companion white paper, press releases, webinar
• June-Dec. 2017: Successive tutorials, created and released a maturity
model, discussed standards roadmap
2/27/2018 Copyright © 2018 OMG. All rights reserved. 5
OMG’s Work on Data Residency
• Multiple laws and regulations restrict what an organization can do
with certain types of data, or potentially prevent its protection:
• Personally identifiable information (PII)
• Patient health information (PHI)
• Proprietary corporate information
• Communications (e-mail, etc.)
• Government information (incl. military)
• Information subject to trade controls and embargoes
• Information on natural resources
• Banking records
• Other regulated data, e.g., “sovereign” data
2/27/2018 Copyright © 2018 OMG. All rights reserved. 6
Sources of Risk
• Owners of such data may:
• Relocate this data intentionally, for convenience or cost reduction
• Data center consolidation and managed hosting
• Centralized employee or customer database
• Business process outsourcing
• Helpdesk outsourcing
• Be unaware of its location
• Cloud service optimization by the provider
• IoT data collection
• Acquisitions and expansion to new countries change the risk
• The Internet of Things exacerbates the challenge
2/27/2018 Copyright © 2018 OMG. All rights reserved. 7
Sources of Risk (cont.)
• Difficulty of providing IT services across borders from few locations
• Higher cost for customers (less competition for local services)
• Inability to consolidate operations
• Inability to provide shared employee services
• Need for multiple local IT operations teams (skills and cost issues)
• Limitations in backup locations
• Restrictions against strong data encryption
• Legal exposure
• Conflict with authorities
• Public mistrust
2/27/2018 Copyright © 2018 OMG. All rights reserved. 8
Nature of the Risks
• Multiple, inconsistent, overlapping, and still evolving laws and
regulations around the world
• Range from non-existent to severe
• Sometimes (but not always) apply to government data / public
records, not to private companies’ data
• The European Union’s General Data Protection Regulation (GDPR), in
effect from 25 May 2018, is among the most comprehensive
• Multiple motivations behind the laws:
• Protecting the privacy of citizens
• Enabling police and tax authorities to inspect data
• Protectionism – force companies to create domestic facilities
• Monetize the flow of data
2/27/2018 Copyright © 2018 OMG. All rights reserved. 9
Data Residency Laws and Regulations
2/27/2018 Copyright © 2018 OMG. All rights reserved. 10
A Proliferation of Laws
• There is currently no standard that deals specifically with data
residency
• Data residency is related to the security and privacy aspects of
• Several NIST publications (800-144, 500-299, 1500)
• Several ISO/IEC standards (27001, 27017, 27018)
• NIST Big Data Standard, http://fedscoop.com/nist-big-data-framework
• The work of the CSA’s International Standardization Council (ISC)
• Work being considered in ISO/IEC JTC 1/SC 38
• The “Voluntary Data Protection Code” of CISPE (Cloud Infrastructure Service
Providers in Europe)
2/27/2018 Copyright © 2018 OMG. All rights reserved. 11
Potential Useful Standards
• Two very close versions (OMG and CSCC)
2/27/2018 Copyright © 2018 OMG. All rights reserved. 12
OMG’s First Discussion Paper
• Issued by OMG in
December 2017 as
a second
“discussion paper”
• Structured in a
similar manner to
the SEI CMM for
software
engineering
(1990)
• 5 levels and 20
“key process
areas” that need
to be put in place
to “climb” to
higher levels of
maturity
Copyright © 2018 OMG. All rights reserved.
13
The Data Residency Maturity Model (DRMM)
Level
SEI CMM
Name
Definition (under
construction)
Key Process Areas
5 Optimizing
There is continuous
monitoring and
improvement of data
residency policies,
procedures and
implementation
● Active monitoring and auditing of data location, transfer, and remote
access
● Regular review of changes in business, data content, technology, laws
and regulations
● Formal process to evolve policies, procedures, practices and
technology
● Formal process to review all incidents and take corrective action
4 Managed
Active management takes
place at all levels of the
organization
● Executive accountability
● Governance (e.g., steering committee)
● Assign roles and responsibilities for DR policy and implementation
● Formal policies
● Data storage location assignment is part of information modeling
● Logging / audit trail of data creation, movement, access right changes
● Formal program of employee training
3 Defined
Policies, procedures,
practices are documented
and institutionalized, and
data location impact is
formally documented
● Active executive involvement
● Formally documented processes
● Taxonomy of sensitive data
● Informal training resources
● People are formally assigned to data owner/steward/custodian roles
2 Repeatable
The organization
performs on the basis of
human knowledge,
informally shared
● Executive awareness (e.g., evidenced by a letter from each C-level
stakeholder stating their belief in the importance of the issue)
● Informal practices and guidelines to identify and locate data
● Employees know who to go to in order to arbitrate a d.r. question
● People act informally in roles of data owners/steward/custodians
1 Initial
None of above practices
exist
• Participate in OMG’s Data Residency Working Group
• Review the existing discussion papers and provide comments
• http://www.omg.org/cgi-bin/doc?mars/17-03-22.pdf (“Challenges and Opportunities” paper)
• http://www.omg.org/cgi-bin/doc?mars/17-12-18.pdf (DRMM)
• Consider adopting the DRMM
• OMG is interested in partnering with organizations that would want to “adopt
and adapt” the DRMM and give it broader recognition
• Suggest applicable standards – and if you work in standards group on
security and privacy, give them input about data residency issues
• Our current intent
• Coordinate with other OMG groups working on Data Provenance & Pedigree
and on Data Tagging & Labeling – seek a unified “data governance” approach
• Develop a standard to represent the various data residency laws and
regulations in a uniform formal manner
2/27/2018 Copyright © 2018 OMG. All rights reserved. 14
How to Contribute
• Thanks for your attention
• Please ask questions using the BrightTalk interface
• Ask to be added to our mailing list
• Send an e-mail to request@omg.org and ask to be added to the
“dataresidency” list
• Participate in our next meetings
• Reston, Va., March 20, 2018
• Boston, Mass., week of June 18-22
• Ottawa, Ont., Canada, week of Sept. 24-28 (2-day event on various
information governance and security topics for the Canadian government)
• Contact Tracie Berardi, tracie@omg.org, for additional questions or
comments
2/27/2018 Copyright © 2018 OMG. All rights reserved. 15
Discussion

More Related Content

What's hot (20)

PDF
Govern and Protect Your End User Information
Denodo
 
PDF
IT Solutions for 3 Common Small Business Problems
Brooke Bordelon
 
PDF
Secure Data Sharing with the Denodo Platform
Denodo
 
PPTX
2010 07 BSidesLV Mobilizing The PCI Resistance 1c
Gene Kim
 
PDF
Expanded top ten_big_data_security_and_privacy_challenges
Tom Kirby
 
PDF
Data Marketplace and the Role of Data Virtualization
Denodo
 
PDF
Peter Grimmond – Harnessing the power of data
Veritas Technologies LLC
 
PDF
Modernizing Data Architecture using Data Virtualization for Agile Data Delivery
Denodo
 
PDF
KASHTECH AND DENODO: ROI and Economic Value of Data Virtualization
Denodo
 
PPTX
Cloud computing Risk management
Padma Jella
 
PPTX
Securing Data in the Cloud - GISEC2017
Sohaib Mahmood
 
PPTX
Moving beyond Big Data, BAE Systems Detica
Internet World
 
PDF
eDiscovery platform EMEA user conference 2017
Veritas Technologies LLC
 
PDF
Improve network safety through better visibility – Netmagic
Netmagic Solutions Pvt. Ltd.
 
PDF
Cloud Security - Emerging Facets and Frontiers
Gokul Alex
 
PPTX
Webinar: How to Design a Compliant and GDPR Ready Collaboration System
Storage Switzerland
 
PPTX
Rethink business with OpenText Core applications and services
OpenText
 
PDF
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™
Intralinks
 
PDF
Silicon Valley Code Camp Blockchain Oct 2017
Nelson Petracek
 
PDF
Cloud Governance Framework - Required Cloud Sourcing Capabilities
SusanneT
 
Govern and Protect Your End User Information
Denodo
 
IT Solutions for 3 Common Small Business Problems
Brooke Bordelon
 
Secure Data Sharing with the Denodo Platform
Denodo
 
2010 07 BSidesLV Mobilizing The PCI Resistance 1c
Gene Kim
 
Expanded top ten_big_data_security_and_privacy_challenges
Tom Kirby
 
Data Marketplace and the Role of Data Virtualization
Denodo
 
Peter Grimmond – Harnessing the power of data
Veritas Technologies LLC
 
Modernizing Data Architecture using Data Virtualization for Agile Data Delivery
Denodo
 
KASHTECH AND DENODO: ROI and Economic Value of Data Virtualization
Denodo
 
Cloud computing Risk management
Padma Jella
 
Securing Data in the Cloud - GISEC2017
Sohaib Mahmood
 
Moving beyond Big Data, BAE Systems Detica
Internet World
 
eDiscovery platform EMEA user conference 2017
Veritas Technologies LLC
 
Improve network safety through better visibility – Netmagic
Netmagic Solutions Pvt. Ltd.
 
Cloud Security - Emerging Facets and Frontiers
Gokul Alex
 
Webinar: How to Design a Compliant and GDPR Ready Collaboration System
Storage Switzerland
 
Rethink business with OpenText Core applications and services
OpenText
 
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™
Intralinks
 
Silicon Valley Code Camp Blockchain Oct 2017
Nelson Petracek
 
Cloud Governance Framework - Required Cloud Sourcing Capabilities
SusanneT
 

Similar to Where's My Data? Managing the Data Residency Challenge (20)

PDF
GDPR for Non-European Region - Financial Services EL
Eugene Lee
 
PPTX
New Zealand - Data use and frameworks.
Corporate Registers Forum
 
PPTX
Vuzion Love Cloud GDPR Event
Vuzion
 
PDF
GDPR - Context, Principles, Implementation, Operation, Impact on Outsourcing,...
Alan McSweeney
 
PDF
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
ARMA International
 
PPTX
Educause 2015 RDM Maturity
ResearchSpace
 
PDF
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
One North
 
PDF
Jadu GDPR guide: A easy to follow guide for Digital Service Managers and Webs...
Jadu
 
PPTX
Teradata's approach to addressing GDPR
Paul O'Carroll
 
PPTX
GDPR Workshop
Curt Lewis
 
PPTX
Associates quick guide to gdpr v 1.0
Aaron Banham
 
PPTX
Webinar: How to Design Primary Storage for GDPR
Storage Switzerland
 
PPTX
Gdpr brief and controls ver2.0
Finto Thomas , CISSP, TOGAF, CCSP, ITIL. JNCIS
 
PPTX
12th July GDPR event slides
Exponential_e
 
PPTX
Ritz 4th-july-gdpr
Exponential_e
 
PDF
Data management plans – EUDAT Best practices and case study | www.eudat.eu
EUDAT
 
PPTX
How to turn GDPR into a Strategic Advantage using Connected Data
Neo4j
 
PPTX
Sophie's Privacy - a story about GDPR
Hans Demeyer
 
PPTX
CBC GDPR The Physics
Jason Chapman
 
PDF
SureSkills GDPR - Discover the Smart Solution
Google
 
GDPR for Non-European Region - Financial Services EL
Eugene Lee
 
New Zealand - Data use and frameworks.
Corporate Registers Forum
 
Vuzion Love Cloud GDPR Event
Vuzion
 
GDPR - Context, Principles, Implementation, Operation, Impact on Outsourcing,...
Alan McSweeney
 
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
ARMA International
 
Educause 2015 RDM Maturity
ResearchSpace
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
One North
 
Jadu GDPR guide: A easy to follow guide for Digital Service Managers and Webs...
Jadu
 
Teradata's approach to addressing GDPR
Paul O'Carroll
 
GDPR Workshop
Curt Lewis
 
Associates quick guide to gdpr v 1.0
Aaron Banham
 
Webinar: How to Design Primary Storage for GDPR
Storage Switzerland
 
Gdpr brief and controls ver2.0
Finto Thomas , CISSP, TOGAF, CCSP, ITIL. JNCIS
 
12th July GDPR event slides
Exponential_e
 
Ritz 4th-july-gdpr
Exponential_e
 
Data management plans – EUDAT Best practices and case study | www.eudat.eu
EUDAT
 
How to turn GDPR into a Strategic Advantage using Connected Data
Neo4j
 
Sophie's Privacy - a story about GDPR
Hans Demeyer
 
CBC GDPR The Physics
Jason Chapman
 
SureSkills GDPR - Discover the Smart Solution
Google
 
Ad

More from Cloud Standards Customer Council (20)

PDF
Kubernetes and Container Technologies from Cloud Native Computing Foundation
Cloud Standards Customer Council
 
PDF
What's New in Cloud Foundry
Cloud Standards Customer Council
 
PDF
Hyperledger: Market, Technology & Community Update
Cloud Standards Customer Council
 
PDF
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Cloud Standards Customer Council
 
PPTX
Hybrid Cloud Considerations for Big Data and Analytics
Cloud Standards Customer Council
 
PPTX
Cloud Customer Architecture for Big Data and Analytics V2.0
Cloud Standards Customer Council
 
PPTX
Practical Guide to Cloud Management Platforms
Cloud Standards Customer Council
 
PPTX
Cloud Foundry Road Map in 2017
Cloud Standards Customer Council
 
PDF
Hyperledger: Advancing Blockchain Technology for Business
Cloud Standards Customer Council
 
PDF
Cloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Standards Customer Council
 
PDF
Cloud Customer Architecture for API Management
Cloud Standards Customer Council
 
PDF
Cloud Customer Architecture for Hybrid Integration
Cloud Standards Customer Council
 
PDF
Cloud Customer Architecture for Enterprise Social Collaboration
Cloud Standards Customer Council
 
PDF
Latest Developments in Cloud Security Standards and Privacy
Cloud Standards Customer Council
 
PDF
Interoperability and Portability for Cloud Computing: A Guide
Cloud Standards Customer Council
 
PDF
Cloud Customer Architecture for e-Commerce
Cloud Standards Customer Council
 
PDF
Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Standards Customer Council
 
PDF
Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0
Cloud Standards Customer Council
 
PPTX
Cloud Foundry Roadmap in 2016
Cloud Standards Customer Council
 
PDF
Practical Guide to Platform-as-a-Service
Cloud Standards Customer Council
 
Kubernetes and Container Technologies from Cloud Native Computing Foundation
Cloud Standards Customer Council
 
What's New in Cloud Foundry
Cloud Standards Customer Council
 
Hyperledger: Market, Technology & Community Update
Cloud Standards Customer Council
 
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Cloud Standards Customer Council
 
Hybrid Cloud Considerations for Big Data and Analytics
Cloud Standards Customer Council
 
Cloud Customer Architecture for Big Data and Analytics V2.0
Cloud Standards Customer Council
 
Practical Guide to Cloud Management Platforms
Cloud Standards Customer Council
 
Cloud Foundry Road Map in 2017
Cloud Standards Customer Council
 
Hyperledger: Advancing Blockchain Technology for Business
Cloud Standards Customer Council
 
Cloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Standards Customer Council
 
Cloud Customer Architecture for API Management
Cloud Standards Customer Council
 
Cloud Customer Architecture for Hybrid Integration
Cloud Standards Customer Council
 
Cloud Customer Architecture for Enterprise Social Collaboration
Cloud Standards Customer Council
 
Latest Developments in Cloud Security Standards and Privacy
Cloud Standards Customer Council
 
Interoperability and Portability for Cloud Computing: A Guide
Cloud Standards Customer Council
 
Cloud Customer Architecture for e-Commerce
Cloud Standards Customer Council
 
Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Standards Customer Council
 
Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0
Cloud Standards Customer Council
 
Cloud Foundry Roadmap in 2016
Cloud Standards Customer Council
 
Practical Guide to Platform-as-a-Service
Cloud Standards Customer Council
 
Ad

Recently uploaded (20)

PPTX
How to Add Columns and Rows in an R Data Frame
subhashenia
 
PDF
5- Global Demography Concepts _ Population Pyramids .pdf
pkhadka824
 
PPTX
01_Nico Vincent_Sailpeak.pptx_AI_Barometer_2025
FinTech Belgium
 
PPTX
04_Tamás Marton_Intuitech .pptx_AI_Barometer_2025
FinTech Belgium
 
DOCX
INDUSTRIAL BENEFIT FROM MICROSOFT AZURE.docx
writercontent500
 
PDF
Technical-Report-GPS_GIS_RS-for-MSF-finalv2.pdf
KPycho
 
PDF
Business implication of Artificial Intelligence.pdf
VishalChugh12
 
PPTX
办理学历认证InformaticsLetter新加坡英华美学院毕业证书,Informatics成绩单
Taqyea
 
PDF
IT GOVERNANCE 4-1 - Information System Security (1).pdf
mdirfanuddin1322
 
PDF
apidays Singapore 2025 - Trustworthy Generative AI: The Role of Observability...
apidays
 
PDF
Group 5_RMB Final Project on circular economy
pgban24anmola
 
PPTX
Krezentios memories in college data.pptx
notknown9
 
PPTX
big data eco system fundamentals of data science
arivukarasi
 
PDF
apidays Singapore 2025 - How APIs can make - or break - trust in your AI by S...
apidays
 
PPTX
thid ppt defines the ich guridlens and gives the information about the ICH gu...
shaistabegum14
 
PPTX
Comparative Study of ML Techniques for RealTime Credit Card Fraud Detection S...
Debolina Ghosh
 
PDF
apidays Singapore 2025 - From API Intelligence to API Governance by Harsha Ch...
apidays
 
PDF
Development and validation of the Japanese version of the Organizational Matt...
Yoga Tokuyoshi
 
PDF
apidays Singapore 2025 - The API Playbook for AI by Shin Wee Chuang (PAND AI)
apidays
 
How to Add Columns and Rows in an R Data Frame
subhashenia
 
5- Global Demography Concepts _ Population Pyramids .pdf
pkhadka824
 
01_Nico Vincent_Sailpeak.pptx_AI_Barometer_2025
FinTech Belgium
 
04_Tamás Marton_Intuitech .pptx_AI_Barometer_2025
FinTech Belgium
 
INDUSTRIAL BENEFIT FROM MICROSOFT AZURE.docx
writercontent500
 
Technical-Report-GPS_GIS_RS-for-MSF-finalv2.pdf
KPycho
 
Business implication of Artificial Intelligence.pdf
VishalChugh12
 
办理学历认证InformaticsLetter新加坡英华美学院毕业证书,Informatics成绩单
Taqyea
 
IT GOVERNANCE 4-1 - Information System Security (1).pdf
mdirfanuddin1322
 
apidays Singapore 2025 - Trustworthy Generative AI: The Role of Observability...
apidays
 
Group 5_RMB Final Project on circular economy
pgban24anmola
 
Krezentios memories in college data.pptx
notknown9
 
big data eco system fundamentals of data science
arivukarasi
 
apidays Singapore 2025 - How APIs can make - or break - trust in your AI by S...
apidays
 
thid ppt defines the ich guridlens and gives the information about the ICH gu...
shaistabegum14
 
Comparative Study of ML Techniques for RealTime Credit Card Fraud Detection S...
Debolina Ghosh
 
apidays Singapore 2025 - From API Intelligence to API Governance by Harsha Ch...
apidays
 
Development and validation of the Japanese version of the Organizational Matt...
Yoga Tokuyoshi
 
apidays Singapore 2025 - The API Playbook for AI by Shin Wee Chuang (PAND AI)
apidays
 

Where's My Data? Managing the Data Residency Challenge

  • 1. Claude Baudoin & Geoff Rayner 27 February 2018 Where’s My Data? Managing the Data Residency Challenge 2/27/2018 Copyright © 2018 OMG. All rights reserved. 1
  • 2. 2/27/2018 Copyright © 2018 OMG. All rights reserved. 2 Speakers Tracie Berardi Director of Program Management, OMG Program Manager, Cloud Standards Customer Council Moderator [email protected] Claude Baudoin Principal, cébé IT & Knowledge Management Steering Committee member, Cloud Standards Customer Council [email protected] Geoff Rayner CEO, Data Advantage Group [email protected]
  • 3. • Data Residency definition • History of OMG’s work on data residency • Types of information that pose risks • Nature of the risks – examples • Laws and regulations around the world • Potential applicable standards • OMG Discussion Paper • OMG Data Residency Maturity Model (DRMM) • How to contribute 2/27/2018 Copyright © 2018 OMG. All rights reserved. 3 Topics Covered in this Webinar New
  • 4. “Data residency is the set of issues and practices related to the location of data and metadata, the movement of (meta)data across geographies and jurisdictions, and the protection of that (meta)data against unintended access and other location-related risks.” • Scope • Not just about the protection of personally identifiable information (PII) • Also concerns the right to move “sovereign” data, such as oil reserves data; international licensing of genomics data; distribution of biometrics data for security purposes; etc. 2/27/2018 Copyright © 2018 OMG. All rights reserved. 4 Data Residency: Definition
  • 5. • March 2015: initial request from an OMG member • June 2015: first OMG Data Residency WG meeting (Berlin) • Q4 2015: Prepared and issued an RFI • Q2 2016: Processed RFI results, decided to create a discussion paper as first deliverable • Q4 2016: Drafted discussion paper, agreed to collaborate with CSCC and issue two separate but almost identical papers • Q1 2017: Collected contributions, edited paper, agreement to release • Q2 2017: Create CSCC companion white paper, press releases, webinar • June-Dec. 2017: Successive tutorials, created and released a maturity model, discussed standards roadmap 2/27/2018 Copyright © 2018 OMG. All rights reserved. 5 OMG’s Work on Data Residency
  • 6. • Multiple laws and regulations restrict what an organization can do with certain types of data, or potentially prevent its protection: • Personally identifiable information (PII) • Patient health information (PHI) • Proprietary corporate information • Communications (e-mail, etc.) • Government information (incl. military) • Information subject to trade controls and embargoes • Information on natural resources • Banking records • Other regulated data, e.g., “sovereign” data 2/27/2018 Copyright © 2018 OMG. All rights reserved. 6 Sources of Risk
  • 7. • Owners of such data may: • Relocate this data intentionally, for convenience or cost reduction • Data center consolidation and managed hosting • Centralized employee or customer database • Business process outsourcing • Helpdesk outsourcing • Be unaware of its location • Cloud service optimization by the provider • IoT data collection • Acquisitions and expansion to new countries change the risk • The Internet of Things exacerbates the challenge 2/27/2018 Copyright © 2018 OMG. All rights reserved. 7 Sources of Risk (cont.)
  • 8. • Difficulty of providing IT services across borders from few locations • Higher cost for customers (less competition for local services) • Inability to consolidate operations • Inability to provide shared employee services • Need for multiple local IT operations teams (skills and cost issues) • Limitations in backup locations • Restrictions against strong data encryption • Legal exposure • Conflict with authorities • Public mistrust 2/27/2018 Copyright © 2018 OMG. All rights reserved. 8 Nature of the Risks
  • 9. • Multiple, inconsistent, overlapping, and still evolving laws and regulations around the world • Range from non-existent to severe • Sometimes (but not always) apply to government data / public records, not to private companies’ data • The European Union’s General Data Protection Regulation (GDPR), in effect from 25 May 2018, is among the most comprehensive • Multiple motivations behind the laws: • Protecting the privacy of citizens • Enabling police and tax authorities to inspect data • Protectionism – force companies to create domestic facilities • Monetize the flow of data 2/27/2018 Copyright © 2018 OMG. All rights reserved. 9 Data Residency Laws and Regulations
  • 10. 2/27/2018 Copyright © 2018 OMG. All rights reserved. 10 A Proliferation of Laws
  • 11. • There is currently no standard that deals specifically with data residency • Data residency is related to the security and privacy aspects of • Several NIST publications (800-144, 500-299, 1500) • Several ISO/IEC standards (27001, 27017, 27018) • NIST Big Data Standard, http://fedscoop.com/nist-big-data-framework • The work of the CSA’s International Standardization Council (ISC) • Work being considered in ISO/IEC JTC 1/SC 38 • The “Voluntary Data Protection Code” of CISPE (Cloud Infrastructure Service Providers in Europe) 2/27/2018 Copyright © 2018 OMG. All rights reserved. 11 Potential Useful Standards
  • 12. • Two very close versions (OMG and CSCC) 2/27/2018 Copyright © 2018 OMG. All rights reserved. 12 OMG’s First Discussion Paper
  • 13. • Issued by OMG in December 2017 as a second “discussion paper” • Structured in a similar manner to the SEI CMM for software engineering (1990) • 5 levels and 20 “key process areas” that need to be put in place to “climb” to higher levels of maturity Copyright © 2018 OMG. All rights reserved. 13 The Data Residency Maturity Model (DRMM) Level SEI CMM Name Definition (under construction) Key Process Areas 5 Optimizing There is continuous monitoring and improvement of data residency policies, procedures and implementation ● Active monitoring and auditing of data location, transfer, and remote access ● Regular review of changes in business, data content, technology, laws and regulations ● Formal process to evolve policies, procedures, practices and technology ● Formal process to review all incidents and take corrective action 4 Managed Active management takes place at all levels of the organization ● Executive accountability ● Governance (e.g., steering committee) ● Assign roles and responsibilities for DR policy and implementation ● Formal policies ● Data storage location assignment is part of information modeling ● Logging / audit trail of data creation, movement, access right changes ● Formal program of employee training 3 Defined Policies, procedures, practices are documented and institutionalized, and data location impact is formally documented ● Active executive involvement ● Formally documented processes ● Taxonomy of sensitive data ● Informal training resources ● People are formally assigned to data owner/steward/custodian roles 2 Repeatable The organization performs on the basis of human knowledge, informally shared ● Executive awareness (e.g., evidenced by a letter from each C-level stakeholder stating their belief in the importance of the issue) ● Informal practices and guidelines to identify and locate data ● Employees know who to go to in order to arbitrate a d.r. question ● People act informally in roles of data owners/steward/custodians 1 Initial None of above practices exist
  • 14. • Participate in OMG’s Data Residency Working Group • Review the existing discussion papers and provide comments • http://www.omg.org/cgi-bin/doc?mars/17-03-22.pdf (“Challenges and Opportunities” paper) • http://www.omg.org/cgi-bin/doc?mars/17-12-18.pdf (DRMM) • Consider adopting the DRMM • OMG is interested in partnering with organizations that would want to “adopt and adapt” the DRMM and give it broader recognition • Suggest applicable standards – and if you work in standards group on security and privacy, give them input about data residency issues • Our current intent • Coordinate with other OMG groups working on Data Provenance & Pedigree and on Data Tagging & Labeling – seek a unified “data governance” approach • Develop a standard to represent the various data residency laws and regulations in a uniform formal manner 2/27/2018 Copyright © 2018 OMG. All rights reserved. 14 How to Contribute
  • 15. • Thanks for your attention • Please ask questions using the BrightTalk interface • Ask to be added to our mailing list • Send an e-mail to [email protected] and ask to be added to the “dataresidency” list • Participate in our next meetings • Reston, Va., March 20, 2018 • Boston, Mass., week of June 18-22 • Ottawa, Ont., Canada, week of Sept. 24-28 (2-day event on various information governance and security topics for the Canadian government) • Contact Tracie Berardi, [email protected], for additional questions or comments 2/27/2018 Copyright © 2018 OMG. All rights reserved. 15 Discussion