Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've worked in Canberra (Aust. government) IT circles, and this comes as absolutely no surprise - you could probably count the number of federal government departments that store their data (even public data) on any public cloud provider on one hand.

Yeah, there are a bunch of non-security reasons for this (latency, bandwidth costs, variable service costs), but in my experience it's always come down to security; and with what happened to Megaupload, the potential widespread (mis)use of National Security Letters / FISA Surveillance, and the general lacking of concrete privacy / security / SLA guarantees from the providers, it really doesn't surprise me that they're saying that putting your data overseas isn't a great idea.

There's no reason that US-based companies can't host infrastructure in Australia and certify that it's compliant with the DSD's ISM (which is part of where all of this is coming from), which itself says that it doesn't preclude the use of foreign owned service operators, but that they should ensure that information is hosted in and doesn't leave Australian borders. Which, in the context of what's above, makes 100% sense.



All the government departments I've worked with that made use of cloud infrastructure had agreements with the providers to have there own dedicated servers, giving then a private cloud to work with.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: