IT Risk Assessment Report: Aztek's Cloud Migration Strategy

Verified

Added on  2020/04/07

|21
|5687
|37
Report
AI Summary
This report provides an IT risk assessment for Aztek, an Australian financial services company, planning to migrate its business-critical applications and data to an external cloud hosting solution. The report outlines the merits of cloud computing, including cost reduction, reliability, resource management, and scalability. It also discusses the impact of cloud computing in the financial sector, emphasizing relevant government regulations, such as the Australian Privacy Act, and their implications for data security and customer information. Furthermore, the report analyzes the potential risks associated with cloud services, including data security threats and the impact on the company's current security posture, employee training, and integration. The assessment highlights the importance of implementing robust security measures to protect sensitive data and ensure compliance with legal and regulatory requirements. The conclusion emphasizes the necessity for Aztek to carefully manage these risks to ensure a successful and secure cloud migration.
Document Page
IT Risk Assessment
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
Executive Summary
Aztek is an Australia based company which offers services in the financial sector. The senior
executives and the IT department of the company are trying to develop new business model by
changing the IT infrastructure in the company. The selected change for the business is migrating
the present data and information to the external cloud services. The cloud services are advanced
system in which the company uploads its data and information on the internet by using the secure
system of interconnection.
Presently, the company is using the traditional model for data and information storage. The cloud
service helps the company and its customers to develop effective interactions and also it helps to
receive unique services. It brings many opportunities and helps the business to reduce cost. The
employees of the company will also need to spend less time in managing information. However,
there are some potential challenges which can effects business and its operations. The main
challenge for the company is to maintain IT security and data. On the cloud, there is sensitive
information about the company and if any hackers can steel data from cloud then it may create
many problems for the company.
Therefore, the company is adopting high security methodology such as firewalls; use
vulnerability scanner and intrusion detection system. Through which, the company can control on
the IT threats and develop security on the high level.
Document Page
Table of Contents
INTRODUCTION.......................................................................................................................................4
MERITS OF THE EXTERNAL CLOUD SOLUTION...............................................................................4
CLOUD COMPUTING IN FINANCIAL SECTOR AND OTHER REGULATIONS...............................6
EXTERNAL SYSTEM’S IMPACT ON PRESENT SECURITY POSTURE SYSTEM............................9
RISK OF USING THE EXTERNAL CLOUD SERVICES......................................................................11
DATA SECURITY THREATS FOR USING THE EXTERNAL CLOUD COMPUTING......................16
CONCLUSION.........................................................................................................................................17
REFERENCES..............................................................................................................................................19
Document Page
Topic:
Migrating business-critical applications and their associated data sources to an external Cloud
hosting solution
INTRODUCTION
Information technology has become an integrated part of each business. By adopting the IT
technology, business can improve their customer’s services and the present business conditions.
Through using the IT technologies, the business can easily overcome many other issues such as
geographical limitation and the limited number of customers and high prices services. In this,
the cloud hosting solution is one of the major emerging technologies in the IT. It refers to the
upload the data from the manual format to the internet (Taylor, Haggerty, Gresty and Lamb,
2011). The use of the cloud services has increased in many industries such as finance, sports and
many others. Aztek is an Australia based finance services provide company, which is moving to
the adoption of external cloud services. Through this, the company can offer services to the 24/7
hours to customers and also they can access data from anywhere. In the present report, analysis is
made on different aspects of the cloud computing (Ward and Sipior, 2010). It includes the merits
of the cloud computing, cloud computing in financial sector and other regulations which create
impact on the business. At last, it provides risks which are associated with cloud computing.
MERITS OF THE EXTERNAL CLOUD SOLUTION
Aztek is an Australia based company which offers different types of the financial services to its
customers. The company is expanding its business services and using Information Technology
(IT) for it. The company is presently trying to migrate with the business-critical applications and
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
data resources into the cloud hosting solution (Almorsy, Grundy and Müller, 2016.). Through the
external cloud services, they can easily transfer data to the cloud. This cloud is remotely handled
by the other person. Following are the merits of the present project:
Fewer capital expenses
The most significant cloud computing benefit is in terms of IT cost savings. The cloud solution
helps the company to maintain the cost and charged to the minimum operations costs without
matter of the size of the project. The lack of on-premises infrastructure also removes the
associated operational costs in the form of power, air conditioning and administration costs
(Bisong and Rahman, 2011). For the Aztek Company, it brings many opportunities and helps the
business to maintain costs and through this, the companies also do not worry about the security
of the cloud services.
Reliability
The external cloud services are much better than in-house services. In the external services, the
company can easily store the data and other sensitive information about their company. It offers
services 24/7 hours and organization can benefit from a massive pool of redundant IT resources.
If any server fails to work then the company can easily transfer all data and the information to
any other available server (Bruneo, 2014). Along with this, the company can also increase or
decrease the scale of business operations according to its requirements.
Management of use of resources
Through the cloud services, the company can efficiently use its resources. With the help of
present cloud services, the business can efficiently use its projects and reduce the operational
Document Page
costs incurred. The employees of the company need to spend less time on information managing
and they can use their time in more useful activities (Buyya, Broberg and Goscinski, 2010).
Another benefit of the company for resources is that it helps the company to enjoy the scalability
of economics. The cloud services have less energy consumption and required less physical
resources in order to maintain the services.
High level of storage capacity and flexibility
The external cloud services can offer high level of storage services to their customers. With the
cloud, the company can easily store any type of the data without any limitation. Along with this
the company also receives a high level of the flexibility. The cloud services offered to the
company test and develop cloud services effectively (Dinh, Lee, Niyato and Wang, 2013). If one
cloud is not working properly then the company can switch to another cloud. Along with this,
Aztek can also able to access the own file through the internet anywhere.
CLOUD COMPUTING IN FINANCIAL SECTOR AND OTHER REGULATIONS
The external cloud services in the financial services help to the company to manage their
activities and operations costs effectively. The financial sector is also now engaged with the
internet services. There are many organizations like Aztek which are using cloud services to
efficiently use their resources. The main role of cloud services in the financial services to offers
the financial services and also helps the company to maintain its internet services (Furht, 2010).
Through the external cloud services, the business can offer a large number of services and they
can also provides high level of the security to store personal information of customers.
However, there are many types of the rules and the regulation which are needed to be
maintained. The Australian government develops some laws and regulation through which they
Document Page
can control the activities and security of the cloud services. It imposed in accordance to the data
security and the privacy act in which the company has obligation for not sharing personal
information about the customers to any third party.
Government Regulations
Storing data in the cloud, rather than on other devices or on an inadequately secured in-house
system, if done well, may reduce these risks (Bisong and Rahman, 2011). Following are the
government and industrial regulations which should be implemented by the company:
The Privacy Act
The Australian Privacy Act is designed to regulate the collection and handling of the personal
information of individuals. It states that the company cannot share any type of the information
about the customers to any third party. In Aztec, there are many types of the customers who take
the financial services. While, the receiving these services, they can also provide their information
such as back detail, ID card detail and much more. It can lead to harm if the company provide
this information to third party (Garg, Versteeg and Buyya, and 2013). Some personal information
also involve sensitive information such as the person's race or ethnicity, their religious, political
or philosophical beliefs or affiliations, and health information, including genetic information. All
these laws are also applied to the company which is using the cloud services. While doing the
business on the cloud, there are chances that the information may leak from the cloud. The
business has to face many types of problems because it is considered as the breach of
information.
Information on the cloud
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
The government is also provided guidelines to the organization to provide information about the
cloud services. The company has to; under the privacy provide information about who can use
their information. The major dealing in the cloud services is based on the cloud provider and the
organizations (Iosup, Prodan and Epema, 2014 ). Aztek, in the cloud services, need to provide
disclosure to the customers who can assess information and by what purpose. So, in future, no
other problems can be created.
Collection of the information
The Privacy Act also involves the collection of the data. The company can collect only the data
when it required for maintain its business functions. The company in order to monitor the
personal records of the customers’ needs to take care of the information before providing
services or data to the cloud vendor (Jadeja, and Modi, 2012). Along with this, the company also
needs to provide information to the customers if the company is sharing the perusal data with any
other third party.
Security
In the cloud services, the company should concern about the security. The external cloud
hosting services are control by the third party in the remote area. The Aztek Company needs to
make sure to use the high security in order to protect the data from the hackers (Jansen, 2011).
In the privacy act, it is stated that if the company does not require any customer’s information
then it is suggested as per the security point of view to destroy the data or permanently de-
identify it. Through this, the companies can safely store on the cloud and also they can maintain
the security of the data.
Law on breach of information
Document Page
If the company fail to implement security measures on the data and personal information to the
company’s database, and if any type of the information is leaked from the database, then it is
considered as the breach of the information under which the company may face any type of the
lawsuit from the government or customer. In the financial sector, the business needs to take care
of the personal details of customer’s bank (Jansen, 2011). If such details are leaked and any type
of the damaged occurred then it would be payable by the company. So, the Aztek Company
needs to maintain its data information effectively and adequately.
EXTERNAL SYSTEM’S IMPACT ON PRESENT SECURITY POSTURE SYSTEM
The Security Posture refers to the company’s network, information and the systems based on the
IA resources (e.g., people, hardware, software, policies) and the capabilities in place to manage
the defiance of the enterprise and to reach as the situation changes. The company has presently
stored the data and the information within the personal database center. The company is moving
to adopt the external cloud services to store the data and the personal information of the
customers and the employees as well (Khajeh-Hosseini, Greenwood and Sommerville, 2010).
There are many impact which will be created through the external services on present services.
The company needs to change its structure, policies and provide training to their employees, so
Aztek can effectively make interaction with the system. The business need to make sure that the
external cloud services are integrated with present system effectively so they can reduce the IT
threats and other security concerns. Following are the impact on external cloud services on the
present security posture.
Impact on the Employees
Document Page
The employees are big and important assets for the company. Employees are the major concern
for the company while adopting external cloud services. For Aztek, it is essential to develop
effective interactions between the cloud system and workers (Krutz, and Vines, 2010). By using
the external services, the business can overcome with many problems but there are some security
issues as well which are needed to be addressed the employees. The impact of the external
services is that if the employees are not aware of the system then they need to face problems. In
order to overcome these problems, the company needs to provide training to employees so they
can understand the current services and also cloud system.
Impact on hardware and software
The impact of cloud services on hardware and the software of the company is that it needs to be
updated according to the cloud system. The cloud is automatically updated; however, it is
required to also update other IT functions effectively. The impact on the hardware and software
of the company should be modified and it is also needed to make the focus on the integrated with
new system effectively (Manvi and Shyam, 2014). When the company is using its own hardware
and software, they can easily take control over the data and the sensitive information of the
company; while, using the cloud services the business needs to make sure that they have to
develop leverage between the present system and the prosed system. If any disaster appears the
company can use its traditional system to recover or store the data.
Policies
At present the company is using the In-build cloud services; however, in order to improve the
services the company should move to the external cloud services. The business needs to make
sure that all the services are an offer to the customers effectively. In order to offer services the
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
business needs to follow the security and the data integration act (O’Driscoll, Daugelaite and
Sleator, 2013). Through it, they can control over the data integration and the security in an
effective manner. The HR and administration should be making focus that all the laws and the
regulations are effectively followed by the company.
Capabilities
At present, the company is offering services in the financial sector. Through the cloud services,
the companies can offer its services to wide range of the people and they can also increase the
number of customers in an effective manner (Ren, WangandWang, 2012). By using the cloud
services, the business can collect the information and also they can offer efficient internet
services. The impact of the cloud services on the current security posture is that it increases the
capability of the system and the employees. They can attract more customers to the business and
also they can offer better services. Although, use the external cloud services can increase the
burden such as to maintained data and personal information, use of encryption while sending
information to the cloud (Rittinghouse and Ransome, 2016). For using all of these, the company
needs to hire experts such that information remains secure and also the company can use
resources effectively.
RISK OF USING THE EXTERNAL CLOUD SERVICES
The cloud computing brings any type of the new business opportunities for the company. Aztek
which is financial company offer many types of the services which offer to the company.
However, there are several other risks which are associated with the company. The cloud
computing is handled by the third party in the remote environment. The company does not have
any type of the control over the security network (Sanaei, Abolfazli, Ganiand, Buyya, 2014 ). It
Document Page
is identified that if the security vendors do not follow the guideline or while sending the data
from the manual to the cloud system, then it can be access by the malicious users. So, the
company needs to develop high level of security. Following are the risks of the using the
external cloud servicing
Data Breaches
The first risks which occurred are the data breach. It refers to that if the sensitive data are leaked
or use by any unauthorized users then it create problems for the company. The company has to
face lawsuits and other regulations. It can create problems for the company (Sultan, 2014). The
external cloud services have large amount of storage capacity so anyone can easily store the data
on the cloud and the use the information by accessing the data. It is serious threats for the Aztek,
because it can also damage the brand image and customer’s trust.
Permanent data loss
The permanent data loss is another IT threats which is faced by the company while using the
cloud services. It is important for the business in order to protect data from the loss. Sometimes
malicious hackers may delete or modification the data. It can increase threats for the customers
and also for the company (Taylor, Haggerty, Gresty and Lamb, 2011). The company may lose
their sensitive data and information from the database. Through this, the company has to face
loss which can be in financial value or any other terms. The management of the company need to
provide high security and the limit the access so no such harm can occur.
Increased Vulnerability
chevron_up_icon
1 out of 21
circle_padding
hide_on_mobile
zoom_out_icon
[object Object]