对于对其客户隐私高度负责的组织来说,AWS 等服务是否足够安全?
好的,所以我们必须在线存储客户的私人医疗记录,而且网站会有很多请求,所以我们必须使用一些扩展解决方案。
我们可以拥有自己的数据中心并在其上运行 Zend Server Cluster Manager 之类的东西,但像 Amazon EC2 这样的服务看起来更容易管理,而且它们也非常便宜。我们只是不知道它们是否足够安全!
他们是吗?
还有更好的解决方案吗?
更多信息:我知道有一个参考服务器,并且它是高度安全的,没有它,即使云服务器上的解密数据也毫无用处。这将是一堆毫无意义的数字,甚至彼此之间没有联系。
问题更明确了:有没有安全的存储和处理服务提供商可以保证他们不会泄漏?
Okay, so we have to store our clients` private medical records online and also the web site will have a lot of requests, so we have to use some scaling solutions.
We can have our own share of a datacenter and run something like Zend Server Cluster Manager on it, but services like Amazon EC2 look a lot easier to manage, and they are incredibly cheaper too. We just don't know if they are secure enough!
Are they?
Any better solutions?
More info: I know that there is a reference server and it's highly secured and without it, even the decrypted data on the cloud server would be useless. It would be a bunch of meaningless numbers that aren't even linked to each other.
Making the question more clear: Are there any secure storage and process service providers that guarantee there won't be leaks from their side?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
首先,您应该联系 AWS 并解释您要构建的内容以及您处理的数据类型。据我记得,他们制定了法规来满足大多数(如果不是全部)隐私问题。
例如,在德国,这样的事情被称为“Auftragsdatenvereinbarung”。我不知道这与其他国家有什么关系和转化。 AWS 提供了这一点。
但无论您使用 AWS 还是其他云计算服务,问题都是一样的。因此,无论什么可能,最好由律师来回答,并且基于希望受过良好教育(且昂贵)的建议,我会去云购物,或者可能不会。如果您在欧盟,会有大量法规,特别是在医疗记录方面 - 一些国家/地区还添加了更多法规。
据我记得,当你处理这些事情时,基本上需要进行端到端加密。
最后但并非最不重要的安全性还取决于设置和应用程序等。
为了完整和全面的安全性,我建议使用未连接到互联网的系统。所有其他人都可能失败。
First off, you should contact AWS and explain what you're trying to build and the kind of data you deal with. As far as I remember, they have regulations in place to accommodate most if not all the privacy concerns.
E.g., in Germany such thing is a called a "Auftragsdatenvereinbarung". I have no idea how this relates and translates to other countries. AWS offers this.
But no matter if you go with AWS or another cloud computing service, the issue stays the same. And therefor, whatever is possible is probably best answered by a lawyer and based on the hopefully well educated (and expensive) recommendation, I'd go cloud shopping, or maybe not. If you're in the EU, there are a ton of regulations especially in regards to medical records -- some countries add more to it.
From what I remember it's basically required to have end to end encryption when you deal with these things.
Last but not least security also depends on the setup and the application, etc..
For complete and full security, I'd recommend a system that is not connected to the Internet. All others can fail.
您永远不应该外包高度敏感的数据。您的公司并且只有您的公司应该有权访问它 - 无论是软件还是硬件方面。即使您的托管服务商通常受到信任,也可能有人会窃取硬件。
根据您公司的规模,您应该拥有自定义服务器 - 最好甚至数据中心的技术人员无法访问(假设您不拥有该数据中心;)。
因此,数据越重要,外国人以任何方式获取数据的机会就越少。在最好的情况下,您可以命名所有有权以任何方式访问它们的人。
(更新:这可能不适用于匿名数据,但当您谈论客户时,我认为这不适用于此处?)
(第三个想法:可能有一些法律可以考虑您必须如何处理此类信息;)
You should never outsource highly sensitive data. Your company and only your company should have access to it - in both software and hardware terms. Even if your hoster is generally trusted someone there might just steal hardware.
Depending on the size of your company you should have your custom servers - preferable even unaccessible for the technicans in your datacenter (supposing you don't own the datacenter ;).
So the more important the data is, the less foreign people should have access to it in any means. In the best case you can name all people that have access to them in any way.
(Update: This might not apply to anonymous data, but as you're speaking of customers I don't think that applies here?)
(On a third thought: There're are probably laws to take into consideration of how you have to handle that kind of information ;)