How Does SEC’s OCIE Cybersecurity Initiative Affect Cloud Computing?
Grazed from Stratosec.co. Author: Editorial Staff.
In April, the SEC’s Office of Compliance Inspections and Examinations (OCIE) made headlines as they released a Risk Alert stating they would be examining the information security posture of “more than 50” registered broker-dealers and investment advisors. As we provide secure cloud services to organizations that may be examined as part of this process, we’re watching with interest. In particular, we wanted to know: how does the OCIE cybersecurity initiative affect cloud computing?
The OCIE is basing their questions on NIST’s Framework for Improving Critical Infrastructure Cybersecurity. Generally, the NIST document is a common-sense framework for an organization to describe their existing security posture, describe the organization’s target security state, and then prioritize how to get there. For organizations that do not have a mature information security program, the NIST Framework provides a great way to understand their current security posture, and create a plan to improve it…


Running distributed applications on cloud computing capacity means, in theory, that IT shops never have to do capacity planning again. For large enough aggregations of lines of business inside of a company or enterprises that share capacity on a public cloud, the ups and downs across time zones and workloads should all balance out.