25 ms·
I’m facing this challenge right now with a regulator. We have a financial system, that uses managed cloud SQL hosted in one of the regions. The database is als
by artellectual 6y ago
I’m facing this challenge right now with a regulator.
We have a financial system, that uses managed cloud SQL hosted in one of the regions. The database is also in high availability mode and has daily backup scattered all over the various regions.
All this is being managed by the cloud provider we are using.
One of the regulator has asked us to maintain a “local backup” of the database. When I asked what the reason is they just said “we require it”.
Since creating another copy of the database outside the managed environment increases risk I told them “based on my assessment we are deliberately increasing risk of a vulnerability, it’s my job to report and you to sign that you have acknowledged the increase in risk based on assessment”.... No response from the regulator that this is now required.
I can relate to what these guys are going through mostly I find regulators just read an old book and since they are usually regulators not engineers they use the rule book to make engineering decisions. While regulators have to follow a book and its their job its also important for them to understand that every system is different and that they are not experts, and that the book they follow are not always up-to-date.
Sometimes the regulators job is also to say “let me check on that” and find another expert or better yet consult with the person who wrote the book to “update” and improve on the “standard” to ensure that the highest standard is being propagated to all the parties they manage.
- nalekberov 6y agoWithout local backup you cannot be sure of integrity of the data. In that sense the regulator is right. I would even question why the data is stored in cloud?
- artellectual 6y agoLol you obviously didn’t read my comment. We have backups... scattered all through out the multiple regions. They just want it on “local soil”. As in it should not be in another country. > why is it in the cloud? Because we’re allowed to use cloud.
- nalekberov 6y agonevertheless you cannot completely trust public cloud provider when it comes to data integrity.
- artellectual 6y agoThen what can you trust? Your own hardware? What about if they go bad? Make multiple copies? How many? And what are the implications of managing multiple local backups scattered everywhere on your own hardware? What are the costs involved? How many people should handle that? Who should hold the encryption key? How many keys? What happens if key is exposed and we have to regenerate? At the end of the day every system has risks. It’s about what is acceptable. It’s engineer’s job to reduce risk. In my case I didn’t say what is right or wrong I just mentioned that increased risk is coming at regulator’s decision they should acknowledge and sign a piece of paper. When you make decisions there are repercussions, you have to accept. That’s all.
- nalekberov 6y agoOkay step by step: You can trust your own hardware more than someone else’s hardware. Everything can go bad, but if you physically have access, it increases the probability of recovery. (Since you care more) Usually one copy where you have easy physical access and sure other than certain people cannot access this room (has all the required indicators and alarms in case of high temperature etc) another one within the space of governmentally approved area (usually this area has the least probably of seeing natural disaster) should be enough. Costs? Data security cannot be subject to tradeoffs. Usually two people own two physical keys to the backup machine, without one , the machine should not allow any access (in case one of them threatened to give up the data). you ought to keep the keys in secure place. It’s firstly information security engineer’s responsibility to take care of the Information security.
- artellectual 6y agoOr you can just pay for all that stuff to be managed. That's the whole point of the cloud. Everything you just listed is done by our cloud provider.
- dyu 6y agoI've had luck showing that the cloud provider fulfills the 'local backup' requirement as part of their compliance (provided they do meet the same framework that you're trying to meet), and us inheriting the control from the cloud provider.