From: FutureGov/Asia

Rob Livingstone, Fellow, University of Technology, Sydney, Australia

The whole topic of cloud computing has been dominating the IT agenda. Conversations have been very intense in 2012 – we were barraged by new opinions, fuelled by new cloud product offerings and innovative, compelling solutions.

Given the inconsistency in the maturity of understanding across industry as to the intrinsic value of cloud technologies, I expected 2012 to be an interesting year indeed as organisations struggle with balancing the promise of significant benefits with the perceived (or actual) concerns such as risk and security.

In my view, the cloud hype cycle differs from almost all the previous hype cycles as it is turbo-charged by the consumerisation of IT technology, where anyone can access immediately, at minimal to zero cost, powerful IT systems previously only available within organisations.

When executives and staff at all levels step into the work environment, they often feel as if they are both entering the IT straight-jacket and stepping back in time due to the perceived restrictions of their enterprise IT systems and the often poor user experience in using the technology.

How does this affect government agencies? All governments are coming to grips with the cloud in its various forms – but not as quickly as the vendors would prefer!

Governments, and especially those most affected by the cloud, are under considerable budgetary pressure to cut expenditure and reduce debt. This is where cloud computing would presumably be of immediate appeal.

On the one hand, the lure of avoiding capital expenditure, whilst reducing cost, increasing flexibility, speeding up IT project implementations and immediately accessing ‘production ready’ IT applications and infrastructure, makes for a compelling value proposition indeed.

The twin elephants in the room for a majority of governments are security and data jurisdictional considerations. How can these be ignored? Which government would feel relaxed about its data being located in a foreign country?

In Australia, a report by Longhaus indicates a slowdown in the adoption of cloud in the private sector. This was attributed to the rapidly maturing appreciation for security, risk and other factors in cloud computing for both public and private sectors, not to mention the realisation that the cost, complexity and effort in managing the transition of legacy, mission critical enterprise applications from on-premise to cloud is anything but trivial.

By contrast, US Federal and State governments do not face the risks associated with international jurisdictional issues, as most cloud providers are US corporations, so this transition is somewhat easier from a jurisdictional perspective.

In the context of the Australian Government, there are a number of key cloud policies and initiatives set at the federal Level, including the Australian Government Data Centre Strategy 2010-2025, which sets the scene for data centre consolidation, and the Cloud Computing Strategic Direction Paper as published by the Australian Government Information Management Office (AGIMO).

Other controls are mandated in specific agency’s legislation and policies, such as the Department of Defence’s mandate for on-shore data residency.

At the end of the day, the Australian Federal Government is taking a very deliberate and considered position on cloud computing. State and local governments are at varying levels of evolution, with some still at the initial stages, one such example being the New South Wales State Government’s Digital Economy Taskforce that was established in October 2011.

In contrast to government agencies, the private sector has generally fewer layers of mandated governance and is therefore better able to dynamically trade off risk and security with the promise of greater profitability.

Being primarily accountable to shareholders and not the public at large, the private sector is therefore more able to dial up the appetite for risk, which means a greater willingness to be aggressive adopters of Cloud technologies.

IT changes at a faster pace than the speed of legislation, and Government agencies in Australia appear to be taking a deliberately cautious approach to adopting solutions where the legislation is silent on a particular issue.

For example, the legalities associated with the right to access data by a government in whose jurisdiction the data centre is located, does not yet appear to be tested in court at this stage for organisations. There needs to be a legislative clarity, or a clear legal precedence set to provide both governments and the private industry with some baseline certainty.

Further research and action is therefore needed on universally-adopted standards, and to provide precise legislative certainty. These are going to be hard to achieve in reality, if not impossible, due to the lack of global standards, when compounded with the complexities of international law.

From my perspective, streamlining inter and intra-governmental collaboration will allow for the creation of a set of standard operational, security and risk frameworks, covering policies and mitigation procedures at all levels of government.

This will reduce cost, increase efficiency and simplify the overall process of engaging with industry, whether at a Federal/State level or across different government agencies. The G-Cloud concept has the potential to enable significant savings, as it provides an access point for ICT services, applications and assets.

Agencies can source capacity on an ‘on-demand’ basis, avoiding the costs and delays involved in purchasing and running their own IT infrastructure.

The hosting of government applications and websites can be undertaken strategically, rather than individually implemented using multiple third parties.

The G-Cloud has the potential to reduce energy, and therefore CO2 consumption, by consolidation existing ICT hardware, and reducing the number of data centres and associated infrastructure.

The position I would be suggesting for governments that are serious about the international jurisdictional and related challenges associated with cloud for their sensitive data and information assets, is to take the default position to not use the public cloud.

The default should be Private or in-country Hybrid cloud, where the potential, agility and value of the cloud computing technology ecosystem can be harnessed with cost, risk, data sovereignty certainty.

Moreover, emerging research is starting to seriously challenge the common perception that public cloud is significantly more cost-effective than the private cloud for large enterprises.

The next few years will be a heady mix of opportunity mixed with risks, so all organisations, government or private, should proceed to adopt cloud, but only from a fully-informed basis, and after exhaustive evidence.