No. 1 Story

Construction needs cloud flexibility

Australia’s embattled construction sector could benefit from cloud based information systems that can be switched on and off in lockstep with individual projects – with the exception of those organisations based in remote areas like the Kimberleys.

read more

Risks of cloud computing outweigh benefits: survey

IT Industry - Market

Almost half of Oceania IT professionals say that the risks of cloud computing outweigh the benefits, according to the first ISACA Oceania IT Risk/Reward Barometer survey.

ISACA says that CIOs are increasingly interested in cloud computing because of its potential to deliver lower total cost of ownership (TCO), higher return on investment (ROI), increased efficiency and pay-as-you-go services, and that IDC has said that cloud services will outpace traditional IT spending over the next five years, representing approximately $51 billion by 2013.

'Yet IT professionals see risks in entrusting information assets to the cloud,' according ISACA which recently surveyed 218 Australia and New Zealand-based IT professionals who are members of the global, non-profit professional association.

According to ISACA's Oceania IT Risk/Reward Barometer, fewer than 10 percent of respondents' organisations plan to use cloud computing for mission-critical IT services and almost one third (30 percent) do not plan to use it for any IT services.

The association says that, consistent with this attitude is the appetite for overall IT-related risk in 2010. 'In the face of continued global economic uncertainty, and despite the potential to drive greater rewards, almost 60 percent of respondents believe projects should offer the same or lower level of risk as 2009,' said Ria Lucas, CISA, CGEIT, international vice president of ISACA and investment manager at Telstra.

According to Lucas, however, 'this is significantly lower than the North American results, where 78 percent of those surveyed were comfortable with the same or lower level of risk than 2009, highlighting the greater confidence levels currently experienced in Australia and New Zealand. Not surprisingly, though, almost one third (32 percent) identified budget limits as being their enterprise's greatest hurdle when addressing IT-related business risk.'

Lucas said that 'moving to cloud computing represents a significant shift in how companies utilise resources, so it is not surprising that IT and business professionals feel there could be a number of potential risks in entrusting information to the cloud.

'However the advantages of speed, cost, flexibility and access to high value services will drive the business demand for cloud services, as the rewards have the potential to outweigh the risk.  What is important, is that the transition to cloud computing needs to be viewed as requiring major governance review involving a broad range of stakeholders and a governance framework to address the changed risk landscape.'

The risks and rewards of cloud computing will be discussed at the Oceania CACS2010 Masters of Change conference in Melbourne from 2 to 4 August 2-4, with speakers discussing issues surrounding risk management and cloud computing, as well as data loss prevention and the metamorphosis of assurance. 

ISACA's online survey also gauged organisations' attitudes and behaviours related to IT risk management, and found that according to IT professionals, only 17 percent of organisations in Australia and New Zealand are very effective at integrating IT risk management with their overall business risk management.  The survey also found that the most common reason for practising IT risk management was to ensure that current functionality aligns with business needs (25 percent), showing the need for sound business reasons to underpin IT change. 

'The economic climate has had serious impacts on all aspects of business, including IT-related risk management activities,' according to ISACA director, Tony Hayes.

'On the performance side, about 10 percent of IT professionals see cost management as a driver for risk management; 12 percent see business change as the most important driver; and 13 percent choose improving risk-return balance. Respondents are also concerned with complying with industry and government regulations, with almost 20 percent reporting this being the main impetus behind risk management in IT systems.

'The key driver for IT related risk-management should be balancing risk vs. return to drive profitable growth. Senior management should view risk management as a powerful tool to create value and we urge enterprises to focus on the performance side of the equation,' Hayes added.

The ISACA survey also looked at what IT professionals thought about employee behaviour, and according to the results, the top three high-risk ways in which employees contribute to 'risky business' are:

'¢    Not fully understanding IT policies (56 percent)

'¢    Checking personal e-mails or visiting social networking sites from work devices (52 percent)