Cloud Industry Forum
The Cloud Industry Forum (often known as CIF) has launched a Code of Practice for cloud service providers. There have been a number of concerns with regard to cloud computer services including security, data protection and ability to transfer the service at the end of the contract. The Code of Practice has been promulgated in answer to some of those concerns.
The Code's enforceability is based on annual self certification, plus spot checks to ensure compliance. There are three pillars to the Code:
- The first, and most important, is to ensure a reasonable and consistent level of transparency about businesses and their operation and practices. Specified types of information must be disclosed, divided into information for public disclosure and information which must be disclosed in connection with proposals/contracts. Included within the second category are matters such as termination terms, customer migration paths at contract termination and service continuity.
- The second pillar is "capability" by which is meant the ability of an organisation to perform essential management functions as demonstrated by having in place auditable documented management systems. The areas for such systems include management of information security, service continuity, service levels and software licences.
- The third pillar is "accountability". The CIF will revoke the certification of any organisation deemed not to be complying with the Code.
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.



