CloudAuditA6 Working Group Call<br />February 12, 2010<br />
Agenda<br />Introducing CloudAudit & A6 Branding<br />Overview & Working Group Goals (5 Mins)<br />Introduction of the cor...
Introducing CloudAudit<br />A6 – The Automated Audit, Assertion, Assessment, & Assurance API<br />
Branding/Home/Coverage	<br />Moving to the CloudAudit brand, keeping A6 as a “byline” – Easier to find and understand<br /...
Overview of CloudAudit<br />A Brief Review Of the Effort<br />
CloudAudit (A6) Overview<br />A6 is the geeky byline for the working group of CloudAudit and stands for:Automated Audit, A...
CloudAudit Overview (Continued)<br />The goal is to utilize security automation capabilities with existing tools/protocols...
CloudAudit Core Team<br />Initial Core Team To Drive Development Of Specifications & Requirements <br />
Motivated Interested Parties* ;)<br />*Does not denote any contractual arrangement or corporate commitment <br />
Specifications & Requirements Discussion <br />Discussing the model and moving forward…<br />
Let’s Revisit OCCI<br />A Practical Reference<br />
5,000-foot Look at OCCI<br />GET http://abc.com/uid123foobar/<br />*<br />Provider<br />Instance<br />*<br />HTTP LINK hea...
REQUEST<br />Eye-level Look at OCCI<br />&gt; GET /us-east/webapp/vm01 HTTP/1.1 <br />&gt; User-Agent: occi-client/1.0 (li...
An Simpler CloudAudit Example<br />http://www.cloudaudit.net/.well-known/cloudaudit/com/rackspace/<br />
Which Can Present Things Like…<br />
An Simpler CloudAudit Example<br />http://www.cloudaudit.net/.well-known/cloudaudit/com/rackspace/<br />
Or Element Audit/Assurance Such As:<br />http://www.cloudaudit.net/.well-known/cloudaudit/com/rackspace/com.csc.cloudtrust...
So Now the Fun Begins…<br />We need to build the foundational set of requirements and specifications that define elements ...
Contact Info<br />Chris Hoff<br />hoffc@cisco.com | choff@packetfilter.com<br />+1.978.631.0302<br />@beaker<br />Skype: i...
Upcoming SlideShare
Loading in...5
×

CloudAudit/A6 - 2/12/10 Call

11,310

Published on

Slides from the CloudAudit/A6 Working group call on 2/12/10. The goal of CloudAudit is to provide a common interface that allows Cloud providers to automate the Audit, Assertion, Assessment, and Assurance (A6) of their environments and allow authorized consumers of their services to do likewise via an open, extensible and secure API. CloudAudit is a volunteer cross-industry effort from the best minds and talent in Cloud, networking, security, audit, assurance and architecture backgrounds

Published in: Technology
0 Comments
0 Likes
Statistics
Notes
  • Be the first to comment

  • Be the first to like this

No Downloads
Views
Total Views
11,310
On Slideshare
0
From Embeds
0
Number of Embeds
6
Actions
Shares
0
Downloads
95
Comments
0
Likes
0
Embeds 0
No embeds

No notes for slide

CloudAudit/A6 - 2/12/10 Call

  1. 1. CloudAuditA6 Working Group Call<br />February 12, 2010<br />
  2. 2. Agenda<br />Introducing CloudAudit & A6 Branding<br />Overview & Working Group Goals (5 Mins)<br />Introduction of the core team (5 Mins)<br />Specification/Requirements Discussion (35 Mins)<br />SafeMashups - Brokering Trust in Clouds (15 Mins)<br />
  3. 3. Introducing CloudAudit<br />A6 – The Automated Audit, Assertion, Assessment, & Assurance API<br />
  4. 4. Branding/Home/Coverage <br />Moving to the CloudAudit brand, keeping A6 as a “byline” – Easier to find and understand<br />Going to 99designs.com for logo development<br />Migrate Google Groups Members from A6WG to CloudAudit<br />Call http://www.CloudAudit.org home<br />Add Wiki/Blog/Code Repository<br />Plan for official “launch” shortly<br />
  5. 5. Overview of CloudAudit<br />A Brief Review Of the Effort<br />
  6. 6. CloudAudit (A6) Overview<br />A6 is the geeky byline for the working group of CloudAudit and stands for:Automated Audit, Assertion, Assessment, and Assurance API<br />The goal of CloudAudit is to provide a common interface that allows Cloud providers to automate the Audit, Assertion, Assessment, and Assurance of their environments and allow authorized consumers of their services to do likewise via an open, extensible and secure API. <br />
  7. 7. CloudAudit Overview (Continued)<br />The goal is to utilize security automation capabilities with existing tools/protocols/frameworks via a standard, open and extensible set of interfaces<br />Keep it simple, lightweight and easy to implement; offer primitive definitions & language structure using HTTP(S) first at a very basic level (firewall=true or SAS70=false)<br />Allow for extension and elaboration by providers and choice of trusted assertion validation sources, checklist definitions, etc.<br />Encourage adoption by driving client usage; providers opt-in. Null returns could be considered “non-validated” or “non-asserted”<br />Do not require adoption of other platform-specific APIs<br />Provide interfaces to Cloud naming and registry services<br />
  8. 8. CloudAudit Core Team<br />Initial Core Team To Drive Development Of Specifications & Requirements <br />
  9. 9. Motivated Interested Parties* ;)<br />*Does not denote any contractual arrangement or corporate commitment <br />
  10. 10. Specifications & Requirements Discussion <br />Discussing the model and moving forward…<br />
  11. 11. Let’s Revisit OCCI<br />A Practical Reference<br />
  12. 12. 5,000-foot Look at OCCI<br />GET http://abc.com/uid123foobar/<br />*<br />Provider<br />Instance<br />*<br />HTTP LINK header<br />Compute<br />*<br />Storage<br />*<br />Links<br />Network<br />*<br />Operations<br />*<br />Attributes<br />OCCI<br />Atom-like categories<br />
  13. 13. REQUEST<br />Eye-level Look at OCCI<br />&gt; GET /us-east/webapp/vm01 HTTP/1.1 <br />&gt; User-Agent: occi-client/1.0 (linux) libcurl/7.19.4 OCCI/1.0 <br />&gt; Host: cloud.example.com<br />&gt; Accept: */* <br />&gt; <br />&lt; HTTP/1.1 200 OK <br />&lt; Date: Sat, 10 Oct 2009 12:56:51 GMT <br />&lt; Content-Type: application/ovf<br />&lt; Link: &lt;/us-east/webapp/vm01;start&gt;; <br />&lt; rel=&quot;http://purl.org/occi/action/start&quot;; <br />&lt; title=&quot;Start&quot; <br />&lt; Link: &lt;/us-east/webapp/build.pdf&gt;; <br />&lt; rel=&quot;related&quot;; <br />&lt; title=&quot;Documentation&quot;; <br />&lt; type=&quot;application/pdf&quot; <br />&lt; Category: compute; <br />&lt; label=&quot;Compute Resource”; <br />&lt; scheme=&quot;http://purl.org/occi/kind/&quot; <br />&lt; Server: occi-server/1.0 (linux) OCCI/1.0 <br />&lt; Connection: close <br />&lt; <br />&lt; &lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt; <br />&lt; &lt;Envelope xmlns:xsi=&quot;http://www.w3.org/2001/XMLSchema-instance&quot; <br />&lt; xmlns:ovf=&quot;http://schemas.dmtf.org/ovf/envelope/1&quot; <br />&lt; xmlns=&quot;http://schemas.dmtf.org/ovf/envelope/1&quot; <br />&lt; xml:lang=&quot;en-US”<br />&lt; ...<br />Get the resource,<br />in whatever format<br />RESPONSE<br />It’s in OVF<br />format<br />You can “start” it<br />Related “documentation”<br />It’s a “compute” resource<br />The OVF payload<br />
  14. 14. An Simpler CloudAudit Example<br />http://www.cloudaudit.net/.well-known/cloudaudit/com/rackspace/<br />
  15. 15. Which Can Present Things Like…<br />
  16. 16. An Simpler CloudAudit Example<br />http://www.cloudaudit.net/.well-known/cloudaudit/com/rackspace/<br />
  17. 17. Or Element Audit/Assurance Such As:<br />http://www.cloudaudit.net/.well-known/cloudaudit/com/rackspace/com.csc.cloudtrust.xml<br />
  18. 18. So Now the Fun Begins…<br />We need to build the foundational set of requirements and specifications that define elements of interest for v1.0 of the CloudAudit Protocol<br />How will the exposed API be consumed?<br />How will the resultant responses be cross-referenced to things like compliance frameworks that have specific requirements?<br />What are the A6 requirements for third party trust brokers and should worry about this now?<br />We should be able to get to a roughed out work product relatively quickly given the Cloud service consumer-driven requirements<br />
  19. 19. Contact Info<br />Chris Hoff<br />hoffc@cisco.com | choff@packetfilter.com<br />+1.978.631.0302<br />@beaker<br />Skype: infosecenigma<br />Google Group<br />http://groups.google.com/group/A6WG<br />Website<br />http://www.CloudAudit.org<br />
  1. A particular slide catching your eye?

    Clipping is a handy way to collect important slides you want to go back to later.

×