• Share
  • Email
  • Embed
  • Like
  • Save
  • Private Content
CloudAudit/A6 - 2/12/10 Call
 

CloudAudit/A6 - 2/12/10 Call

on

  • 11,376 views

Slides from the CloudAudit/A6 Working group call on 2/12/10. The goal of CloudAudit is to provide a common interface that allows Cloud providers to automate the Audit, Assertion, Assessment, and ...

Slides from the CloudAudit/A6 Working group call on 2/12/10. The goal of CloudAudit is to provide a common interface that allows Cloud providers to automate the Audit, Assertion, Assessment, and Assurance (A6) of their environments and allow authorized consumers of their services to do likewise via an open, extensible and secure API. CloudAudit is a volunteer cross-industry effort from the best minds and talent in Cloud, networking, security, audit, assurance and architecture backgrounds

Statistics

Views

Total Views
11,376
Views on SlideShare
3,868
Embed Views
7,508

Actions

Likes
0
Downloads
87
Comments
0

18 Embeds 7,508

https://cloudsecurityalliance.org 5279
http://cloudaudit.org 979
http://www.rationalsurvivability.com 680
http://www.cloudaudit.org 496
http://www.cloudaudit.com 24
http://cloudaudit.com 19
http://www.slideshare.net 8
http://translate.googleusercontent.com 6
http://www.securitybloggers.net 5
https://translate.googleusercontent.com 3
http://www.jkwebco.com 2
http://www.onlydoo.com 1
file:// 1
http://webcache.googleusercontent.com 1
http://www.cloudaudit.org. 1
http://cloudaudit.org. 1
http://www.google.com 1
http://www.cloudsecurityalliance.org 1
More...

Accessibility

Categories

Upload Details

Uploaded via as Microsoft PowerPoint

Usage Rights

© All Rights Reserved

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

Cancel
  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
    Processing…
Post Comment
Edit your comment

    CloudAudit/A6 - 2/12/10 Call CloudAudit/A6 - 2/12/10 Call Presentation Transcript

    • CloudAuditA6 Working Group Call
      February 12, 2010
    • Agenda
      Introducing CloudAudit & A6 Branding
      Overview & Working Group Goals (5 Mins)
      Introduction of the core team (5 Mins)
      Specification/Requirements Discussion (35 Mins)
      SafeMashups - Brokering Trust in Clouds (15 Mins)
    • Introducing CloudAudit
      A6 – The Automated Audit, Assertion, Assessment, & Assurance API
    • Branding/Home/Coverage
      Moving to the CloudAudit brand, keeping A6 as a “byline” – Easier to find and understand
      Going to 99designs.com for logo development
      Migrate Google Groups Members from A6WG to CloudAudit
      Call http://www.CloudAudit.org home
      Add Wiki/Blog/Code Repository
      Plan for official “launch” shortly
    • Overview of CloudAudit
      A Brief Review Of the Effort
    • CloudAudit (A6) Overview
      A6 is the geeky byline for the working group of CloudAudit and stands for:Automated Audit, Assertion, Assessment, and Assurance API
      The goal of CloudAudit is to provide a common interface that allows Cloud providers to automate the Audit, Assertion, Assessment, and Assurance of their environments and allow authorized consumers of their services to do likewise via an open, extensible and secure API.
    • CloudAudit Overview (Continued)
      The goal is to utilize security automation capabilities with existing tools/protocols/frameworks via a standard, open and extensible set of interfaces
      Keep it simple, lightweight and easy to implement; offer primitive definitions & language structure using HTTP(S) first at a very basic level (firewall=true or SAS70=false)
      Allow for extension and elaboration by providers and choice of trusted assertion validation sources, checklist definitions, etc.
      Encourage adoption by driving client usage; providers opt-in. Null returns could be considered “non-validated” or “non-asserted”
      Do not require adoption of other platform-specific APIs
      Provide interfaces to Cloud naming and registry services
    • CloudAudit Core Team
      Initial Core Team To Drive Development Of Specifications & Requirements
    • Motivated Interested Parties* ;)
      *Does not denote any contractual arrangement or corporate commitment
    • Specifications & Requirements Discussion
      Discussing the model and moving forward…
    • Let’s Revisit OCCI
      A Practical Reference
    • 5,000-foot Look at OCCI
      GET http://abc.com/uid123foobar/
      *
      Provider
      Instance
      *
      HTTP LINK header
      Compute
      *
      Storage
      *
      Links
      Network
      *
      Operations
      *
      Attributes
      OCCI
      Atom-like categories
    • REQUEST
      Eye-level Look at OCCI
      > GET /us-east/webapp/vm01 HTTP/1.1
      > User-Agent: occi-client/1.0 (linux) libcurl/7.19.4 OCCI/1.0
      > Host: cloud.example.com
      > Accept: */*
      >
      < HTTP/1.1 200 OK
      < Date: Sat, 10 Oct 2009 12:56:51 GMT
      < Content-Type: application/ovf
      < Link: </us-east/webapp/vm01;start>;
      < rel="http://purl.org/occi/action/start";
      < title="Start"
      < Link: </us-east/webapp/build.pdf>;
      < rel="related";
      < title="Documentation";
      < type="application/pdf"
      < Category: compute;
      < label="Compute Resource”;
      < scheme="http://purl.org/occi/kind/"
      < Server: occi-server/1.0 (linux) OCCI/1.0
      < Connection: close
      <
      < <?xml version="1.0" encoding="UTF-8"?>
      < <Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
      < xmlns:ovf="http://schemas.dmtf.org/ovf/envelope/1"
      < xmlns="http://schemas.dmtf.org/ovf/envelope/1"
      < xml:lang="en-US”
      < ...
      Get the resource,
      in whatever format
      RESPONSE
      It’s in OVF
      format
      You can “start” it
      Related “documentation”
      It’s a “compute” resource
      The OVF payload
    • An Simpler CloudAudit Example
      http://www.cloudaudit.net/.well-known/cloudaudit/com/rackspace/
    • Which Can Present Things Like…
    • An Simpler CloudAudit Example
      http://www.cloudaudit.net/.well-known/cloudaudit/com/rackspace/
    • Or Element Audit/Assurance Such As:
      http://www.cloudaudit.net/.well-known/cloudaudit/com/rackspace/com.csc.cloudtrust.xml
    • So Now the Fun Begins…
      We need to build the foundational set of requirements and specifications that define elements of interest for v1.0 of the CloudAudit Protocol
      How will the exposed API be consumed?
      How will the resultant responses be cross-referenced to things like compliance frameworks that have specific requirements?
      What are the A6 requirements for third party trust brokers and should worry about this now?
      We should be able to get to a roughed out work product relatively quickly given the Cloud service consumer-driven requirements
    • Contact Info
      Chris Hoff
      hoffc@cisco.com | choff@packetfilter.com
      +1.978.631.0302
      @beaker
      Skype: infosecenigma
      Google Group
      http://groups.google.com/group/A6WG
      Website
      http://www.CloudAudit.org