As with most technological advances, regulators are typically in a “catchup” mode to identify policy, governance, and law . Cloud computing presents an extension of problems heretofore experienced with the Internet. As mentioned, legal decisions will ultimately determine who “owns” the responsibility for securing information shared within clouds . To ensure that such decisions are informed and appropriate for the cloud computing environment,the industry itself should establish coherent and effective policy and governance to identify and implement proper security methods. To facilitate such policy and governance’s emergence, the US