t

Justice to come? Tunisia’s Truth and Dignity Commission

The Brookings Doha Center (BDC) hosted a keynote event on March 4, 2020 featuring Sihem Bensedrine, the president of the Tunisian Truth and Dignity Commission (Instance Vérité et Dignité; IVD) and a veteran Tunisian human rights activist and journalist. Bensedrine helped found the Tunisian Human Rights League (LTDH), which is part of the National Dialogue…

       




t

COVID in the Maghreb: Responses and impacts

       




t

Stepping Back from the Brink on Iran

Neither the United States nor Iran wants to go to war. That’s the good news. The bad news is that in the fog of crisis — similar in many ways to the fog of war — the danger of inadvertently stumbling into war is dangerously high.




t

The Overwhelming Case for No First Use

The arguments in favor of the United States' declaring that the only purpose of its nuclear weapons is to deter others who possess them from using theirs — in other words, that in no circumstances will this country use nuclear weapons first — are far stronger than the arguments against this stance. It must be hoped that the next US administration will take this no-first-use step promptly.




t

Why is the United States So Bad at Foreign Policy?

Stephen Walt writes that the United States' unusual historical experience, geographic isolation, large domestic market, and general ignorance have weakened its ability to make viable foreign-policy strategies.




t

The U.S.-China Relationship is at a Crossroads

Joseph Nye writes that some decoupling of interdependence is likely, particularly in areas related to technology that directly affect national security. But will Washington and Beijing go too far?




t

What Makes for a Moral Foreign Policy?

Joseph Nye's new book rates the efforts of presidents from FDR to Trump.




t

The Low-Yield Nuclear Warhead: A Dangerous Weapon Based on Bad Strategic Thinking

In the unintuitive world of nuclear weapons strategy, it’s often difficult to identify which decisions can serve to decrease the risk of a devastating nuclear conflict and which might instead increase it. Such complexity stems from the very foundation of the field: Nuclear weapons are widely seen as bombs built never to be used. Historically, granular—even seemingly mundane—decisions about force structure, research efforts, or communicated strategy have confounded planners, sometimes causing the opposite of the intended effect.




t

Accumulating Evidence Using Crowdsourcing and Machine Learning: A Living Bibliography about Existential Risk and Global Catastrophic Risk

The study of existential risk — the risk of human extinction or the collapse of human civilization — has only recently emerged as an integrated field of research, and yet an overwhelming volume of relevant research has already been published. To provide an evidence base for policy and risk analysis, this research should be systematically reviewed. In a systematic review, one of many time-consuming tasks is to read the titles and abstracts of research publications, to see if they meet the inclusion criteria. The authors show how this task can be shared between multiple people (using crowdsourcing) and partially automated (using machine learning), as methods of handling an overwhelming volume of research.




t

The Need for Creative and Effective Nuclear Security Vulnerability Assessment and Testing

Realistic, creative vulnerability assessment and testing are critical to finding and fixing nuclear security weaknesses and avoiding over-confidence. Both vulnerability assessment and realistic testing are needed to ensure that nuclear security systems are providing the level of protection required. Systems must be challenged by experts thinking like adversaries, trying to find ways to overcome them. Effective vulnerability assessment and realistic testing are more difficult in the case of insider threats, and special attention is needed. Organizations need to find ways to give people the mission and the incentives to find nuclear security weaknesses and suggest ways they might be fixed. With the right approaches and incentives in place, effective vulnerability assessment and testing can be a key part of achieving and sustaining high levels of nuclear security.




t

The Risks and Rewards of Emerging Technology in Nuclear Security

Nuclear security is never finished. Nuclear security measures for protecting all nuclear weapons, weapons-usable nuclear materials, and facilities whose sabotage could cause disastrous consequences should protect against the full range of plausible threats. It is an ongoing endeavor that requires constant assessment of physical protection operations and reevaluation of potential threats. One of the most challenging areas of nuclear security is how to account for the impact–positive and negative—of non-nuclear emerging technologies. The amended Convention on the Physical Protection of Nuclear Material (amended CPPNM) states it should be reviewed in light of the prevailing situation, and a key part of the prevailing situation is technological evolution. Therefore, the upcoming review conference in 2021, as well as any future review conferences, should examine the security threats and benefits posed by emerging technologies.




t

The Past and Potential Role of Civil Society in Nuclear Security

Civil society has played a very important role in nuclear security over the years, and its role could be strengthened in the future. Some nuclear organizations react against the very idea of civil society involvement, thinking of only one societal role—protesting. In fact, however, civil society has played quite a number of critical roles in nuclear security over the years, including highlighting the dangers of nuclear terrorism; providing research and ideas; nudging governments to act; tracking progress and holding governments and operators accountable; educating the public and other stakeholders; promoting dialogue and partnerships; helping with nuclear security implementation; funding initial steps; and more. Funding organizations (both government and non-government) should consider ways to support civil society work and expertise focused on nuclear security in additional countries. Rather than simply protesting and opposing, civil society organizations can help build more effective nuclear security practices around the world.




t

Assessing Progress on Nuclear Security Action Plans

Participants at the final Nuclear Security Summit in 2016 agreed on “action plans” for initiatives they would support by five international organizations and groups—the International Atomic Energy Agency, the Global Initiative to Combat Nuclear Terrorism, INTERPOL, the United Nations, and the Global Partnership Against the Spread of Weapons and Materials of Destruction. These institutions were supposed to play key roles in bolstering ongoing nuclear security cooperation after the summit process ended. The action plans were modest documents, largely endorsing activities already underway, and there have been mixed results in implementing them. To date, these organizations have not filled any substantial part of the role once played by the nuclear security summits.




t

Arms Control Agreement With Russia Should Cover More Than Nuclear Weapons

With the Russia investigation and impeachment behind him, President Trump finally may feel empowered to engage with Russian President Vladimir Putin and pursue an arms control deal.  




t

How Do Past Presidents Rank in Foreign Policy?

How do presidents incorporate morality into decisions involving the national interest? Moral considerations explain why Truman, who authorized the use of nuclear weapons in Japan during World War II, later refused General MacArthur's request to use them in China during the Korean War. What is contextual intelligence, and how does it explain why Bush 41 is ranked first in foreign policy, but Bush 43 is found wanting? Is it possible for a president to lie in the service of the public interest? In this episode, Professor Joseph S. Nye considers these questions as he explores the role of morality in presidential decision-making from FDR to Trump.




t

Secrecy, Public Relations and the British Nuclear Debate

The opening of the British archives has seen historians uncover the secrets of the UK's nuclear weapons programme since the 1990s. While a growing number have sought to expose these former secrets, there has been less effort to consider government secrecy itself. What was kept a secret, when and why? And how and why, notably from the 1980s, did the British government decide to officially disclose greater information about the British nuclear weapons programme to Members of Parliament, journalists, defence academics and the tax-paying general public. 




t

Budapest Memorandum at 25: Between Past and Future

On December 5, 1994, leaders of the United States, the United Kingdom, and the Russian Federation met in Budapest, Hungary, to pledge security assurances to Ukraine in connection with its accession to the Treaty on the Nonproliferation of Nuclear Weapons (NPT) as a non-nuclear-weapons state. The signature of the so-called Budapest Memorandum concluded arduous negotiations that resulted in Ukraine’s agreement to relinquish the world’s third-largest nuclear arsenal, which the country inherited from the collapsed Soviet Union, and transfer all nuclear warheads to Russia for dismantlement. The signatories of the memorandum pledged to respect Ukraine’s territorial integrity and inviolability of its borders, and to refrain from the use or threat of military force. Russia breached these commitments with its annexation of Crimea in 2014 and aggression in eastern Ukraine, bringing the meaning and value of security assurance pledged in the Memorandum under renewed scrutiny.

On the occasion of the 25th anniversary of the memorandum’s signature, the Project on Managing the Atom at the Belfer Center for Science & International Affairs at the Harvard Kennedy School, with the support of the Center for U.S.-Ukrainian Relations and the Harvard Ukrainian Research Institute, hosted a conference to revisit the history of the Budapest Memorandum, consider the repercussions of its violation for international security and the broader nonproliferation regime, and draw lessons for the future. The conference brought together academics, practitioners, and experts who have contributed to developing U.S. policy toward post-Soviet nuclear disarmament, participated in the negotiations of the Budapest Memorandum, and dealt with the repercussions of its breach in 2014. The conference highlighted five key lessons learned from the experience of Ukraine’s disarmament, highlighted at the conference.




t

Public Testimony on Trump Administration Funding for Nuclear Theft Preventing Programs

A nuclear explosion detonated anywhere by a terrorist group would be a global humanitarian, economic, and political catastrophe. The current COVID-19 pandemic reminds us not to ignore prevention of and preparation for low-probability, high-consequence disasters. For nuclear terrorism, while preparation is important, prevention must be the top priority. The most effective strategy for keeping nuclear weapons out of the hands of terrorists is to ensure that nuclear materials and facilities around the world have strong and sustainable security. Every president for more than two decades has made strengthening nuclear security around the globe a priority. This includes the Trump administration, whose 2018 Nuclear Posture Review states: “[n]uclear terrorism remains among the most significant threats to the security of the United States, allies, and partners.”




t

Living with Uncertainty: Modeling China's Nuclear Survivability

A simplified nuclear exchange model demonstrates that China’s ability to launch a successful nuclear retaliatory strike in response to an adversary’s nuclear first strike has been and remains far from assured. This study suggests that China’s criterion for effective nuclear deterrence is very low.




t

So Do Morals Matter in U.S. Foreign Policy? I Asked the Expert.

In his new book, Do Morals Matter? Presidents and Foreign Policy from FDR to Trump, Joseph S. Nye developed a scorecard to determine how U.S. presidents since 1945 factored questions of ethics and morality into their foreign policy. In an interview, Henry Farrell asked him a few questions to get to the heart of his findings.




t

Poll: What the American Public Likes and Hates about Trump's Nuclear Policies

The authors conducted a study which highlights how the U.S. public as a whole and various demographic groups view President Donald Trump's positions on nuclear weapons.




t

Maxwell Taylor's Cold War: From Berlin to Vietnam

Nathaniel Moir reviews Maxwell Taylor's Cold War: From Berlin to Vietnam by Ingo Trauschweizer.




t

Joseph S. Nye: U.S. and China Need a More Cooperative Security Stance

Joseph S. Nye: U.S. and China Need a More Cooperative Security Stance




t

Breaking Down the Huawei v. Pentagon Dispute

If nothing else, the long-running Huawei situation shows the importance of considering the supply chain when it comes to cybersecurity. Huawei being the Chinese telecommunications equipment maker basically banned by the federal government. Bruce Schneier joins Host Tom Temin on Federal Drive.




t

COVID-19's Painful Lesson About Strategy and Power

Joseph Nye writes that while trade wars have set back economic globalization,  the environmental globalization represented by pandemics and climate change is unstoppable. Borders are becoming more porous to everything from drugs to infectious diseases to cyber terrorism, and the United States must use its soft power of attraction to develop networks and institutions that address these new threats.




t

An Interview with Bruce Schneier, Renowned Security Technologist

Bruce Schneier discusses current security technology concerns with The Politic's Eric Wallach.




t

Spies Are Fighting a Shadow War Against the Coronavirus

Calder Walton describes four ways how intelligence services are certain to contribute to defeating COVID-19 and why pandemic intelligence will become a central part of future U.S. national security.




t

No, the Coronavirus Will Not Change the Global Order

Joseph Nye advises skepticism toward claims that the pandemic changes everything. China won't benefit, and the United States will remain preeminent.




t

Getting Smart on Pandemics: Intelligence in the Wake of COVID-19

This episode of Horns of a Dilemma touches on whether the failure to properly anticipate and warn about the novel coronavirus constitutes an intelligence failure, what changes might be required in the intelligence community in the wake of the pandemic, and what type of investigation or inquiry might be appropriate in order to learn lessons and incorporate changes for both the intelligence community and the whole of government moving forward.




t

There's No Such Thing as Good Liberal Hegemony

Stephen Walt argues that as democracies falter, it's worth considering whether the United States made the right call in attempting to create a liberal world order.




t

So Do Morals Matter in U.S. Foreign Policy? I Asked the Expert.

In his new book, Do Morals Matter? Presidents and Foreign Policy from FDR to Trump, Joseph S. Nye developed a scorecard to determine how U.S. presidents since 1945 factored questions of ethics and morality into their foreign policy. In an interview, Henry Farrell asked him a few questions to get to the heart of his findings.




t

This Virus Is Tough, but History Provides Perspective: The 1968 Pandemic and the Vietnam War

Nathaniel L. Moir recounts the events of 1968: The war in Vietnam and extensive civil unrest in the United States — and yet another big problem that made life harder. In 1968, the H3N2 pandemic killed more individuals in the United States than the combined total number of American fatalities during both the Vietnam and Korean Wars.




t

To Pressure Iran, Pompeo Turns to the Deal Trump Renounced

The secretary of state is preparing an argument that the U.S. remains a participant in the Obama-era nuclear deal, with the goal of extending an arms embargo or destroying the accord.




t

Poll: What the American Public Likes and Hates about Trump's Nuclear Policies

The authors conducted a study which highlights how the U.S. public as a whole and various demographic groups view President Donald Trump's positions on nuclear weapons.




t

How the Pentagon Is Struggling to Stay out of Politics

 Gen. Mark. A. Milley’s job is to provide sound military advice to the president. But at a deeper level, his responsibility is to safeguard the independence and integrity of the armed forces. The last thing the country needs is a military leadership that’s trying to curry favor with any commander in chief, particularly one who’s hungry for affirmation.




t

Why Bernie Sanders Will Win in 2020, No Matter Who Gets Elected

Stephen Walt writes that even though Bernie Sanders is out of the presidential race, the time has come for many of the policies that he promoted: Universal Healthcare; Democratic Socialism; Income Redistribution; and Foreign Policy.




t

Oil's Collapse Is a Geopolitical Reset In Disguise

The world is on the cusp of a geopolitical reset. The global pandemic could well undermine international institutions, reinforce nationalism and spur de-globalization. But far-sighted leadership could also rekindle cooperation, glimmers of which appeared in the G-20’s offer of debt relief for some of the world’s poorest countries, a joint plea from more than 200 former national leaders for a more coordinated pandemic response and an unprecedented multinational pact to arrest the crash in oil markets.  




t

Romney's Reckless China Rhetoric Risks New Cold War

Rachel Esplin Odell argues for a wiser and more conservative strategy that resists the temptation to exaggerate the challenge posed by China.




t

The United States Forgot Its Strategy for Winning Cold Wars

Stephen Walt writes that arguments against U.S. offshore balancing misunderstand history. The strategy that worked against the Soviet Union can work against China.




t

Maxwell Taylor's Cold War: From Berlin to Vietnam

Nathaniel Moir reviews Maxwell Taylor's Cold War: From Berlin to Vietnam by Ingo Trauschweizer.




t

Breaking the Ice: How France and the UK Could Reshape a Credible European Defense and Renew the Transatlantic Partnership

History is replete with irony, but rarely more poignantly than in the summer of 2016 when, on 23 June, the UK voted to leave the European Union and the next day, 24 June, the EU published its Global Strategy document asserting its ambition of “strategic autonomy.” Whither Franco-British defense cooperation in such chaotic circumstances? This paper attempts to provide the outline of an answer to that question.




t

The Economic Gains of Cloud Computing: An Address by Federal Chief Information Officer Vivek Kundra

Event Information

April 7, 2010
9:00 AM - 11:00 AM EDT

Falk Auditorium
The Brookings Institution
1775 Massachusetts Ave., NW
Washington, DC

Register for the Event

Cloud computing services over the Internet have the potential to spur a significant increase in government efficiency and decrease technology costs, as well as to create incentives and online platforms for innovation. Adoption of cloud computing technologies could lead to new, efficient ways of governing.

On April 7, the Brookings Institution hosted a policy forum that examines the economic benefits of cloud computing for local, state, and federal government. Federal Chief Information Officer Vivek Kundra delivered a keynote address on the role of the government in developing and promoting cloud computing. Brookings Vice President Darrell West moderated a panel of experts and detailed the findings in his paper, "Saving Money through Cloud Computing," which analyzes its governmental cost-savings potential.

After the program, panelists took audience questions.

Video

Audio

Transcript

Event Materials

     
 
 




t

Innovating through Cloud Computing


Technology offers the greatest source for innovation in the public sector and one of the best examples falls within the area of cloud computing. As I noted in a recent paper, the U.S. federal government spends nearly $76 billion each year on information technology, and $20 billion of that is devoted to hardware, software, and file servers. Traditionally, computing services have been delivered through desktops or laptops operated by proprietary software. But new advances in cloud computing have made it possible for public sector agencies alike to access software, services, and data storage through remote file servers.

I looked at possible cost savings a federal agency might expect from migrating to the cloud. After undertaking case studies of government agencies that made the move, I found that the agencies generally saw between 25 and 50 percent savings in moving to the cloud. Public officials can save money by reducing the number of file servers they need to purchase, cutting software costs, relying on fewer information technology specialists, and improving the efficiency of their data storage utilization.

In 2008, Washington, D.C. city government shifted many of its 38,000 employee email services across 86 agencies to the cloud, and the migration saved 48 percent on email expenditures. In 2009, the city of Los Angeles moved email service for its 30,000 employees to the cloud. An analysis undertaken by City Administrative Officer Miguel Santana for the City Council found that the five-year costs of running the new Google system would be $17,556,484, which was 23.6 percent less than the $22,996,242 for operating GroupWise during that same period. And in terms of personnel savings, the city needed nine fewer people in its information technology department.

The U.S. Air Force 45th Space Wing is responsible for launching and tracking unmanned space vehicles from Cape Canaveral Air Force Station and employs more than 10,000 workers. The Wing had 60 distinct file servers, but found that it utilized only 10 percent of central processing unit capacity. Commanders modernized their system and saved $180,000 per year in annual computing costs. In addition, the unit saved money by not buying new hardware or deploying new software. These are just some of the ways the government is using technology to save money and increase efficiency of its operations.

Authors

Image Source: © HANNIBAL HANSCHKE / Reuters
     
 
 




t

Steps to Improve Cloud Computing in the Public Sector


Executive Summary

Government information technology is subject to a variety of rules, regulations, and procurement policies.  Computing is treated differently depending on whether the platform is based on desktops, laptops, mobile devices, or remote file servers known as cloud computing.  There are differences between the executive, legislative, and judicial branches of government, as well as in the level of privacy and security expected for various applications.  

Some people perceive higher security on desktop or laptop computers and lower security with the cloud because the latter’s information is stored remotely through third-party commercial providers.  In reality, though, there are serious security threats to all electronic information regardless of platform, and cloud server providers often take security more seriously than mass consumers or government officials employing weak passwords on their local computers. 

In this paper, I review current federal IT policy and discuss rules, practices, and procedures that limit innovation.  There are a variety of obstacles that make it difficult for policymakers to take full advantage of the technological revolution that has unfolded in recent years.  After outlining these issues, I make recommendations on policy changes required to improve the efficiency and effectiveness of federal computing. 

My specific recommendations include:

  1. Public officials should develop more consistent rules on computing across desktop, laptop, mobile, and cloud platforms.  
  2. The use of video, collaboration, and social networking should be authorized for congressional offices.  This would make legislative branch policy consistent with that of the executive branch.
  3. Judicial branch computing should be modernized, with greater emphasis on cloud computing. 
  4. There should be a more uniform certification process for federal agencies.  Right now, each agency is responsible for certifying its own applications.  It makes sense to have a “joint authorization board” with the power to review management services and certify particular products for use across the government. 
  5. Congress should update the Electronic Communications Privacy Act to change the process by which law enforcement agents obtain electronic information.  Instead of using a prosecutor’s subpoena, legislation should require a “probable cause” search warrant that is approved by a judge.  This would provide greater safeguards in terms of online content, pictures, geolocation data, and e-mails.
  6. Privacy rights should be placed on the same footing regardless of whether a person is using desktop or cloud computing.  It makes little sense to have weaker standards on one platform than another.  Consumers and government decision-makers expect the same level of protection whether they are accessing information on a desktop, laptop, mobile, or cloud storage system. 
  7. Congress should amend the Computer Fraud and Abuse Act to strengthen penalties for unwanted intrusion into computing systems.  The law has inconsistent penalties and prosecutors have found that it is hard to prosecute cyber-crimes. 
  8. Apps.gov represents a big step forward and government use should be expanded because it makes procurement easier and speeds public sector innovation.  It is a model of how the government can reinvent itself through digital technology in ways that improve efficiency and effectiveness.
  9. Countries need to harmonize their laws on cloud computing so as to reduce current inconsistencies in regard to privacy, data storage, security processes, and personnel training,  
  10. There should be mechanisms for data exchange that encourage portability across platforms.  We should avoid vendor lock-in that precludes data exchange.
  11. Data on uptime, downtime, recover time, archiving, and maintenance schedules would help build public trust by providing information on computing performance.

Downloads

Authors

Image Source: Martin Barraud
     
 
 




t

Moving to the Cloud: How the Public Sector Can Leverage the Power of Cloud Computing

Event Information

July 21, 2010
10:00 AM - 12:00 PM EDT

Falk Auditorium
The Brookings Institution
1775 Massachusetts Ave., NW
Washington, DC

Register for the Event

The U.S. government spends billions of dollars each year on computer hardware, software and file servers that may no longer be necessary. Currently, the public sector makes relatively little use of cloud computing, even though studies suggest substantial government savings from a migration to more Internet-based computing with shared resources.

On July 21, the Center for Technology Innovation at Brookings hosted a policy forum on steps to enhance public sector adoption of cloud computing innovations. Brookings Vice President Darrell West moderated a panel of experts, including David McClure of the General Services Administration, Dawn Leaf of the National Institute for Standards and Technology, and Katie Ratte of the Federal Trade Commission. West released a paper detailing the policy changes required to improve the efficiency and effectiveness of federal computing.

Audio

Transcript

Event Materials

     
 
 




t

Privacy and Security in the Cloud Computing Age


Event Information

October 26, 2010
10:00 AM - 11:30 AM EDT

Falk Auditorium
The Brookings Institution
1775 Massachusetts Ave., NW
Washington, DC

Register for the Event

Although research suggests that considerable efficiencies can be gained from cloud computing technology, concerns over privacy and security continue to deter government and private-sector firms from migrating to the cloud. By its very nature, storing information or accessing services through remote providers would seem to raise the level of privacy and security risks. But is such apprehension warranted? What are the real security threats posed to individuals, business and government by cloud computing technologies? Do the cost-saving benefits outweigh the dangers?

On October 26, the Brookings Institution hosted a policy forum on the privacy and security challenges raised by cloud computing. Governance Studies Director Darrell West moderated a panel of technology industry experts examining how cloud computing systems can generate innovation and cost savings without sacrificing privacy and security. West will also present findings from his forthcoming paper “Privacy, Security, and Innovation in Cloud Computing.”

After the program, panelists took audience questions.

Transcript

Event Materials

     
 
 




t

Privacy and Security in Cloud Computing


Executive Summary

Cloud computing can mean different things to different people, and obviously the privacy and security concerns will differ between a consumer using a public cloud application, a medium-sized enterprise using a customized suite of business applications on a cloud platform, and a government agency with a private cloud for internal database sharing (Whitten, 2010). The shift of each category of user to cloud systems brings a different package of benefits and risks.

What remains constant, though, is the tangible and intangible value that the user seeks to protect. For an individual, the value at risk can range from loss of civil liberties to the contents of bank accounts. For a business, the value runs from core trade secrets to continuity of business operations and public reputation. Much of this is hard to estimate and translate into standard metrics of value (Lev, 2003) The task in this transition is to compare the opportunities of cloud adoption with the risks. The benefits of cloud have been discussed elsewhere, to the individual to the enterprise, and to the government (West, 2010a, 2010b).

This document explores how to think about privacy and security on the cloud. It is not intended to be a catalog of cloud threats (see ENISA (2009) for an example of rigorous exploration of the risks of cloud adoption to specific groups). We frame the set of concerns for the cloud and highlight what is new and what is not. We analyze a set of policy issues that represent systematic concerns deserving the attention of policy-makers. We argue that the weak link in security generally is the human factor and surrounding institutions and incentives matter more than the platform itself. As long as we learn the lessons of past breakdowns, cloud computing has the potential to generate innovation without sacrificing privacy and security (Amoroso, 2006; Benioff, 2009).

Downloads

Image Source: Jupiterimages
     
 
 




t

The Terms They Are A-Changin'...: Watching Cloud Computing Contracts Take Shape


EXECUTIVE SUMMARY

Many web services are examples of cloud computing, from storage and backup sites such as Flickr and Dropbox to online business productivity services such as Google Docs and Salesforce.com. Cloud computing offers a potentially attractive solution to customers keen to acquire computing infrastructure without large up-front investment, particularly in cases where their demand may be variable and unpredictable, as a means of achieving financial savings, productivity improvements and the wider flexibility that accompanies Internet-hosting of data and applications.

The greater flexibility of a cloud computing service as compared with a traditional outsourcing contract may be offset by reduced certainty for the customer in terms of the location of data placed into the cloud and the legal foundations of any contract with the provider. There may be unforeseen costs and risks hidden in the terms and conditions of such services.

This document reports on a detailed survey and analysis of the terms and conditions offered by cloud computing providers.

The survey formed part of the Cloud Legal Project at the Centre for Commercial Law Studies (CCLS), within the School of Law at Queen Mary, University of London, UK. Funded by a donation from Microsoft, but academically independent, the project is examining a wide range of legal and regulatory issues arising from cloud computing. The project's survey of 31 cloud computing contracts from 27 different providers, based on their standard terms of service as offered to customers in the E.U. and U.K., found that many include clauses that could have a significant impact, often negative, on the rights and interests of customers. The ease and convenience with which cloud computing arrangements can be set up may lull customers into overlooking the significant issues that can arise when key data and processes are entrusted to cloud service providers. The main lesson to be drawn from the Cloud Legal Project’s survey is that customers should review the terms and conditions of a cloud service carefully before signing up to it.

The survey found that some contracts, for instance, have clauses disclaiming responsibility for keeping the user’s data secure or intact. Others reserve the right to terminate accounts for apparent lack of use (potentially important if they are used for occasional backup or disaster recovery purposes), for violation of the provider’s Acceptable Use Policy, or indeed for any or no reason at all. Furthermore, whilst some providers promise only to hand over customer data if served with a court order, others state that they will do so on much wider grounds, including it simply being in their own business interests to disclose the data. Cloud providers also often exclude liability for loss of data, or strictly limit the damages that can be claimed against them – damages that might otherwise be substantial if a failure brought down an e-commerce web site.

Although in some U.S. states, in E.U. countries and in various other jurisdictions the validity of such terms may be challenged under consumer protection laws, users of cloud services may face practical obstacles to bringing a claim for data loss or privacy breach against a provider that seems local online but is, in fact, based in another continent. Indeed, service providers usually claim that their contracts are subject to the laws of the place where they have their main place of business. In many cases this is a US state, with a stipulation that any dispute must be heard in the provider’s local courts, regardless of the customer’s location.

Perhaps the most disconcerting discovery of the Cloud Legal Project’s survey was that many providers claimed to be able to amend their contracts unilaterally, simply by posting an updated version on the web. In effect, customers are put on notice to download lengthy and complex contracts, on a regular basis, and to compare them against their own copies of earlier versions to look for changes.

The cloud computing market is still developing rapidly, and potential cloud customers should be aware that there may be a mismatch between their expectations and the reality of cloud providers' service terms, and be alive to the possibility of unexpected changes to the terms.

Downloads

Authors

  • Simon Bradshaw
  • Christopher Millard
  • Ian Walden
Image Source: Natalie Racioppa
     
 
 




t

Technology and the Federal Government: Recommendations for the Innovation Advisory Board


Our former Brookings colleague Rebecca Blank, now at the Commerce Department, is today leading the first meeting of the Obama Administration’s Innovation Advisory Board, looking at the innovative capacity and economic competitiveness of the United States.

I applaud the effort.  Nothing is more important to America’s longterm competitiveness than emphasizing innovation.  As the council looks to the private sector and global markets, I urge it to examine how the U.S. government can lead innovation and contribute to economic growth.  The best place to look is new and emerging digital technologies that can make government more accessible, accountable, responsive and efficient for the people who use government services every day.

Here are some of the recommendations I made in a recent paper I wrote with colleagues here at Brookings as part of our “Growth Through Innovation” initiative:

  • Save money and gain efficiency by moving federal IT functions “to the cloud,” i.e., using advances in cloud computing to put software, hardware, services and data storage through remote file servers.

  • Continue to prioritize the Obama administration’s existing efforts to put unparalleled amounts of data online at Data.gov and other federal sites, making it easier and cheaper for citizens and businesses to access the information they need.

  • Use social media networks to deliver information to the public and to solicit feedback to improve government performance.

  • Integrate ideas and operations with state and local organizations, where much of government innovation is taking place today. 

  • Apply the methods of private-sector business planning to the public sector to produce region-specific business plans that are low cost and high impact.

These improvements in government services innovations in the digital age can help spur innovation and support a robust business climate.  And, as a sorely needed side benefit, they can also serve to eliminate some of the current distrust and even contempt for government that has brought public approval of the performance of the federal government to near historic lows.  



Authors

Image Source: © Mario Anzuoni / Reuters
     
 
 




t

Evaluating the Cloud Computing Act of 2011


Event Information

June 16, 2011
12:00 PM - 1:30 PM EDT

Room SVC-209
U.S. Capitol Visitor's Center
U.S. Capitol
Washington, DC

While research suggests that considerable efficiencies can be gained from cloud computing technology, concerns over privacy and security continue to deter governments and private-sector firms from migrating to the cloud. Senator Amy Klobuchar (D-Minn.) has advanced discussion of the “Cloud Computing Act of 2011,” draft legislation that would address these challenges by encouraging the U.S. government to negotiate with other countries to establish consistent laws related to online security and cloud computing. The bill also creates new enforcement tools for investigating and prosecuting those who violate online privacy and security laws.

On June 16, the Brookings Institution hosted a forum on the policy proposals in the Cloud Computing Act of 2011. Discussion included an overview of the international policy implications as governments and firms adjust to a coherent legal framework, changes and innovations in public procurement, and challenges for private industry as it balances consumer needs and compliance with these proposed cloud computing safeguards.

After the program, panelists took audience questions.

Transcript

Event Materials