Enterprise Strategy Group: Building a Private Online File Sharing Cloud with EMC Isilon

Uploaded on

This ESG white paper describes the risks posed by consumer-oriented file sharing services and compares public, hybrid, and private online file sharing alternatives. The report identifies key …

This ESG white paper describes the risks posed by consumer-oriented file sharing services and compares public, hybrid, and private online file sharing alternatives. The report identifies key considerations to select a storage system for private cloud file sharing and how on-premise EMC Isilon NAS solutions meet the online file sharing challenge.

More in: Technology
  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
    Be the first to comment
    Be the first to like this
No Downloads


Total Views
On Slideshare
From Embeds
Number of Embeds



Embeds 0

No embeds

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

    No notes for slide


  • 1. WhitePaperBuilding a Private Online File SharingCloud with EMC IsilonBy Terri McClure, Senior AnalystJanuary 2013This ESG White Paper was commissioned by EMC Isilonand is distributed under license from ESG.© 2013 by The Enterprise Strategy Group, Inc. All Rights Reserved.
  • 2. White Paper: Building a Private Online File Sharing Cloud with EMC Isilon 2Contents Why You Need to Focus on Files Now .......................................................................................................... 3 Warning: Your File Data has Left the Building .......................................................................................................... 3 The Imperative to Take Action ................................................................................................................................. 4 File Server Consolidation in a Mobile World ................................................................................................ 4 Public, Hybrid, and Private Cloud Models for Online File Sharing ............................................................... 5 Comparing Public, Hybrid, and Private Clouds for Online File Sharing ........................................................ 6 Public Cloud File Sharing .......................................................................................................................................... 6 Hybrid Cloud ............................................................................................................................................................. 7 Private Cloud ............................................................................................................................................................ 7 Storage System Considerations for Private Cloud File Sharing ................................................................................ 8 How EMC Isilon Meets the OFS Challenge ................................................................................................... 9 The Bigger Truth ......................................................................................................................................... 11All trademark names are property of their respective companies. Information contained in this publication has been obtained by sources TheEnterprise Strategy Group (ESG) considers to be reliable but is not warranted by ESG. This publication may contain opinions of ESG, which aresubject to change from time to time. This publication is copyrighted by The Enterprise Strategy Group, Inc. Any reproduction or redistribution ofthis publication, in whole or in part, whether in hard-copy format, electronically, or otherwise to persons not authorized to receive it, without theexpress consent of The Enterprise Strategy Group, Inc., is in violation of U.S. copyright law and will be subject to an action for civil damages and,if applicable, criminal prosecution. Should you have any questions, please contact ESG Client Relations at 508.482.0188. © 2013 by The Enterprise Strategy Group, Inc. All Rights Reserved.
  • 3. White Paper: Building a Private Online File Sharing Cloud with EMC Isilon 3Why You Need to Focus on Files NowFile data has been the neglected afterthought of the IT organization. IT managers typically spend their time dealingwith business applications and associated data—data which is typically stored on internal disks, DAS or SAN. That isbecause these business applications keep the lights on, making sure the bills get paid, orders get shipped, andinvoices are tracked, while file data is typically associated with individuals or line of business applications. IT is ofteninvolved in some level of decision making and support when it comes to how that data will be stored and managed,but often times, responsibility for file sharing and support is decentralized.That’s why, until recently, primary storage for file data today can be found in three places;  In the data center, either on specialty NAS systems, or Windows or Linux servers  Scattered across departmental specialty NAS systems, or Windows or Linux servers  On employees’ PCs and laptopsBut with the influx of consumer devices such as tablets and smartphones into the enterprise, IT needs to pay muchmore attention to file data. These devices are why there is now a fourth place that files can be found: in consumerfile sharing services.Warning: Your File Data has Left the BuildingUsers are storing business files in personal file sharing accounts in order to access them from multiple mobiledevices, such as their tablets and smartphones as well as their business devices such as PCs, Macs, or laptops. Infact, ESG recently conducted research into IT’s perception of just how widespread the problem, often called rogueapplication use or shadow IT, is, and we found it to be very widespread. A whopping 70% of the IT managerssurveyed by ESG know or believe that users have business data in their own personal file sharing accounts (seeFigure 1).1 Figure 1. Use of Non-Corporate Approved Online File Sharing Solutions Regardless of whether or not your company has a corporate account, do you know if end- users in your organization are using non-IT approved Online File Sharing and Collaboration solutions? (Percent of respondents, N=499) Dont know, 1% No, I do not believe that end-users are Yes, I know that end- using their own users are using their individual accounts own individual that are not endorsed accounts that are not by IT, 28% endorsed by IT, 36% Perhaps, I suspect that end-users are using their own individual accounts that are not endorsed by IT, but cant be sure, 34% Source: Enterprise Strategy Group, 2013.1 Source: ESG Research Report, Corporate Online File Sharing and Collaboration Market Trends, November 2012. All other ESG research chartsand references in this white paper are taken from this research report, unless otherwise noted. © 2013 by The Enterprise Strategy Group, Inc. All Rights Reserved.
  • 4. White Paper: Building a Private Online File Sharing Cloud with EMC Isilon 4IT managers have been trying to keep data under control by discouraging or even setting formal policies against useof personal file sharing accounts for business data—but more than a third, or 36%, of the companies with formalpolicies against use of personal accounts report that they know employees are using personal accounts, and 21% ofthose with policies in place suspect rogue usage. The news is worse for companies that don’t have formal policesand just discourage use of personal accounts: Thirty five percent know about and 51% suspect rogue usage. Mindyou, these numbers are likely low, since some IT managers are probably reticent to admit even in a blind surveythat they know or suspect that employees are using personal accounts despite policies and discouragement.The Imperative to Take ActionThe danger of these personal accounts is the threat of data leakage, opening the network to external threats, andthe lack of IT control and visibility into the sharing environment. When an employee stores data in a personal filesharing account, IT has no visibility into what data is stored there and what devices it may be shared on. And thereis no audit trail of who else has access to the data. But perhaps most disturbing is the fact that if the employeeleaves the company, the data in the online file sharing account more or less “leaves” with that person. It is in theirpersonal account in a cloud service, and probably synced to their laptop, desktop, or cached on a tablet. IT has novisibility as to what data left with the employee.Granted, the threat of data loss has always been a challenge for IT, but it has always been a conscious decision byan employee to take data, either by copying it onto a USB stick or a CD. With personal file sharing accounts, thethreat is heightened: Data leakage becomes the default behavior—it just happens. And since the data could be onmultiple devices that are accessed by multiple people, there is no accountability whatsoever.At this point, it is not a question of whether there will be a major data loss event associated with the use ofpersonal file sharing accounts, it is a matter of when. That is why IT needs to act sooner rather than later to build afile sharing environment that supports the mobility requirements of the modern enterprise without compromisingcorporate security by opening the network to outside threats. End-users are doing it without IT—it is time for IT tochange the equation and get back in control of corporate data.File Server Consolidation in a Mobile WorldBecause of the decentralized nature of file data, there are big challenges associated with gaining control of the filesharing environment. A common byproduct of both the cloud and consumerization movements is ademocratization of the decision making process around technology use. IT can no longer dictate what technology isused across the enterprise, and employees and departments can quickly find alternatives to the solutions providedby corporate IT. In a decentralized file sharing environment, the challenge is magnified: Departments have alreadyhad some level of autonomy in decision making. That is why it is important for IT to take a well-planned approachto solving the mobile file sharing challenge, including steps to:  Team with the business unit to evaluate solutions that meet individual needs. With the broad availability and easy-to-deploy nature of alternative file sharing services, the old command and control approach is just not going to work. The business unit knows what functionality is required—how much project management and workflow functionality may be required, how strict the controls and auditability of the sharing environments needs to be.  Pay lots of attention to end-user ease of use... There are almost no barriers or switching costs for the employees to use or keep using alternative file sharing solutions. As important as administrative functionality and controls are, end-user ease of use is just as, if not more, important. If the solution you provide is not as easy to use as the consumer solutions, you will have challenges with adoption.  …and training. Many business-focused services have richer functionality and are much better suited for collaborative environments than consumer solutions, but the very nature of the richer functionality makes them a little more complex to use. Many solutions now do a nice job of balancing functionality and ease of use, but they are still not “Dropbox simple” and that is what consumers are used to. Once end-users are trained on the new and richer functionality and understand the productivity benefits, they often see the © 2013 by The Enterprise Strategy Group, Inc. All Rights Reserved.
  • 5. White Paper: Building a Private Online File Sharing Cloud with EMC Isilon 5 light and embrace it. ESG has heard time and again as users train on business solutions “at first I didn’t like it because it wasn’t as easy and intuitive as Dropbox, but once I used it and realized how much more I could do, I loved it.”  Leverage the viral effect. That is how the consumer solutions got into your enterprise, and that is how you will get them out. Once users are on board, trained, and productive, make sure everyone knows it. Publish best practices and productivity success stories. Make sure everyone knows the benefits of using the advanced features you just introduced that are lacking in their personal consumer solutions—for example, how much easier life can be when working on projects and managing files using the full text search, embedded comment threads, shared version tracking, and file locking features you have in the new solution.  Understand that one solution may not meet all needs. Some teams have a need for tracking IP while others may need to lock down documents in deal rooms, and other teams may just have requirements for basic sharing of files across multiple devices. There is no one-size-fits-all solution—often, the greater the security functionality, the greater the cost and the administrative burden (for both IT and the end-user). That complexity could easily turn off those end-users that just need basic file sharing across devices and drive them back toward using personal accounts. The most cost-effective and stickiest way to meet the mobile file sharing dilemma is to build a service catalog that has tiers of solutions—some simple and basic, some complex yet very secure.  If building a private cloud, ensure your storage infrastructure can be quickly and easily scaled. The online file sharing area is one place where IT needs to be especially cautious about injecting any friction into the business process. If it takes too long to add capacity or if it is too painful to add collaborators or clients, it is much too easy for a group or department to go to a service provider. Additionally, with centralization of departmental file servers and consolidation of capacity that used to be on desktop and laptop hard drives, capacity planning and growth will be less predictable and likely faster than IT teams have experienced in the past. Therefore, the infrastructure you build on is critical to your success.Public, Hybrid, and Private Cloud Models for Online File SharingPublic and hybrid cloud solutions for online file sharing are similar in many ways, while pure, private file sharingcloud deployments have significantly different requirements (see Table 1). The differences between public, private,and hybrid are simply where pieces of the infrastructure, such as the servers and storage capacity, are housed, andwho owns and controls those pieces. In a public cloud scenario, all equipment is owned and controlled by theservice provider. In a hybrid cloud scenario, the customer organization keeps some pieces on-premises. Forexample, an organization may keep its encryption keys on a local server, separate from the encrypted files stored inthe cloud. And in a private scenario, the equipment is owned and controlled by the client, while the application maybe owned and controlled by the service provider or the client. © 2013 by The Enterprise Strategy Group, Inc. All Rights Reserved.
  • 6. White Paper: Building a Private Online File Sharing Cloud with EMC Isilon 6 Table 1. Public, Hybrid, and Private Cloud for Online File Sharing Comparison Characteristics Public Cloud Hybrid Cloud Private Cloud Hosted by service Hosted by service Application hosting On-premises provider provider Controlled by service Controlled by service May be controlled by the Application control provider * provider * client or a service provider* Client owns, runs, and maintains some Service provider owns, equipment; service Client owns, runs, and Equipment ownership runs, and maintains all provider owns, runs, and maintains all equipment equipment maintains some equipment Client licenses software on Client licenses software Typical licensing plan a per-seat, subscription on a per-seat, Multiple models available basis subscription basis * Client may control some limited configuration settings and controls user administration functions Source: Enterprise Strategy Group, 2013.Comparing Public, Hybrid, and Private Clouds for Online File SharingWhen evaluating a full public cloud implementation, a private cloud, or a hybrid cloud implementation, ITprofessionals should consider the following advantages and disadvantages of each approach. There are tradeoffs inperformance, administration, and equipment overhead with each approach, as well as security considerations.Public Cloud File SharingIn a public cloud deployment, the service provider is responsible for all equipment procurement, maintenance, andadministration, as well as application administration and data protection. The client (or enterprise) is responsiblefor user and account administration.Advantages of public cloud file sharing:  Service provider absorbs almost all associated costs (i.e., real estate, staffing, hardware maintenance, software patching, etc.); service provider’s fees take advantage of economies of scale  Service provider is responsible for data availability, file backup and disaster recovery  Configuration and implementation are relatively simpleDisadvantages of public cloud file sharing:  Customer organization is dependent on service provider for file security  Performance may be degraded as users wait for files to upload or download  File sizes may be limited by the cloud service provider’s terms  Customer organization is dependent on service provider for rapid response to unanticipated outagesThere can be significant costs savings achieved on both the capex and opex fronts leveraging the economies of scalethat an online file sharing service can provide. The tradeoff is a lack of control over the infrastructure. Customerorganizations are entirely dependent on the service provider when it comes to maintaining data availability orresponding quickly to unplanned outages. Customer organizations should asses the service provider’s dataavailability, business continuity and disaster recovery practices to ensure their needs will be met. © 2013 by The Enterprise Strategy Group, Inc. All Rights Reserved.
  • 7. White Paper: Building a Private Online File Sharing Cloud with EMC Isilon 7Hybrid CloudIn a hybrid deployment, the service provider is responsible for some equipment procurement, while the client alsoprocures in-house components. Both share some management burden for the equipment (though the serviceprovider typically absorbs the brunt of the work). Application maintenance and administration falls to the serviceprovider, while user and account administration falls to the enterprise.Advantages of hybrid cloud file sharing:  Latency problems may be mitigated with local cache  With sufficient local capacity, enterprise is typically not limited in file sizes  Enterprise may maintain key security controls locally  Enterprises may control what data can go to the cloud and what data stays behind the firewall  Customer organization may rely on service provider for file-based back-up and disaster recovery relating to the set of files stored in the cloudDisadvantages of hybrid cloud file sharing:  Customer organization absorbs a portion of the associated costs  Configuration and implementation is more complex to deploy and maintain  Synchronization and data integrity problems may arise as applications access files from both locationsThe added complexity of a hybrid cloud solution should not be underestimated, but can be eased somewhat bycloud storage service providers who integrate tools (such as Active Directory to replicate permissions) and provide acommon control plane for setting policies across the on-premises and in-cloud environments.Private CloudIn a private cloud, the enterprise is responsible for most if not all equipment procurement, operation, andmaintenance. The application may be delivered as a service in which the service provider has some compute cyclesin the cloud that run the application (commonly referred to as the control plane) in the cloud, while all dataremains in-house. In this case, the software is often licensed under a subscription model by seats, and the serviceprovider maintains and administers the application while the enterprise handles user and account administration.The alternative model is one in which the software is licensed on an annual basis in an enterprise software model,and deployed in the data center. In this case, the enterprise handles all software maintenance and administrationas well as user administration.Advantages of private cloud file sharing:  Local file sharing eliminates latency concerns associated with leveraging public cloud  Enterprise is typically not limited in file sizes  Enterprise maintains key security controls locally, can integrate with in-house security processes (i.e., key management, etc.)  Data stays behind the firewall  Enterprise controls and is accountable for data protection policies and proceduresDisadvantages of private cloud file sharing:  Customer organization absorbs all the associated costs  Configuration and implementation is more complex to deploy and maintain © 2013 by The Enterprise Strategy Group, Inc. All Rights Reserved.
  • 8. White Paper: Building a Private Online File Sharing Cloud with EMC Isilon 8There is one more caveat when deploying a private file sharing cloud. The underlying storage infrastructure plays astarring role—it has a direct impact on the user experience, and therefore it must be carefully planned out.Storage System Considerations for Private Cloud File SharingAccording to ESG research, the growth and management of unstructured data is already the biggest storagechallenge facing IT today (see Figure 2).2 Bringing all the file data associated with departmental servers and onlinefile sharing into the data center will certainly magnify the problem. Of course, file server consolidation can helpreduce costs by simply reducing the number of file sharing systems (Windows and Linux file servers as well asspecialty NAS systems) deployed in general and getting better utilization—but if you are bringing all this endpointdata into the data center, it is important that the backend storage platform is the right one for the job or the effortto get back control over your file data could backfire. Figure 2. Top Ten Biggest Storage Challenges In general, what would you say are your organization’s biggest challenges in terms of its storage environment? Which would you characterize as the primary storage challenge for your organization? (Percent of respondents, N=418) Rapid growth and management of unstructured data 15% 40% Data protection (e.g., backup/recovery, etc.) 11% 39% Hardware costs 10% 39% Running out of physical space 7% 25% Primary storage Need to support growing virtual server environments 5% 25% challenge Data migration 4% All storage 25% challenges Staff costs 5% 20% Management, optimization & automation of data 5% placement 19% Lack of skilled staff resources 6% 19% Discovery, analysis and reporting of storage usage 5% 17% 0% 10% 20% 30% 40% 50% Source: Enterprise Strategy Group, 2013.One of the biggest challenges with the overall storage environment in recent years has been the time it takes torespond to requests to provision users or capacity. With the ubiquity of online file sharing solutions, departmentsare not going to wait for IT to provision more storage to launch a new project or bring new collaborators into anexisting project. They will just go subscribe to a service. So having a fast time to provision is a key factor in choosinga storage system.The next issue is availability. PC and laptop users in a sync and share environment may not notice an outage,because most solutions sync all the data on the local device and private cloud. But more and more end-users areaccessing data from mobile devices (i.e., smartphones and tablets) especially your executive staff. OFS solutions donot sync all the files on these devices because there just isn’t enough capacity on the mobile devices to do that;2 Source: ESG Research Report, 2012 Storage Market Survey, November 2012. © 2013 by The Enterprise Strategy Group, Inc. All Rights Reserved.
  • 9. White Paper: Building a Private Online File Sharing Cloud with EMC Isilon 9these devices depend on the data being available 24 x 7, therefore the storage system must be available 24 x 7 x365, even during upgrades, lease rollovers, or site outages. Remember: These are all the files related to user homedirectories and group projects, so if employees can’t get to them, they can’t work.These first two points address those parts of the storage experience that affect the end-users, and since end-userscan switch so easily, they are the top two criteria. But peripherally related to the user experience are performanceand capacity. Of course when sharing files over the internet, performance will vary based on connectivity. But ITneeds to be very aware that the constant syncing of files with desktop and laptop clients and the increasedfrequency of access from mobile devices will put greater demand on the file storage infrastructure. That createsthree areas where special attention needs to be paid to the storage infrastructure—first, it must scale throughputwith capacity (scale-out) so that bandwidth does not create a bottleneck. Second, it must load balance and tuneitself in an automated manner because storage administrators can’t be in reactive performance tuning and loadbalancing mode as that would take too many administrative cycles to keep up. And third, it must scale to supportthe higher capacity demands associated with a file server consolidation effort combined with the consolidation ofendpoint device capacity. Additionally—and policies will vary largely by company—many companies are allowingemployees to partition off a part of the online file sharing service for personal data in order to encourage adoptionof the business-sanctioned file sharing solution. That means providing capacity for personal photo and multimediafiles. The trade-off of managing extra capacity for getting corporate data back in-house is worth it to manyorganizations.Then we have the considerations that do not directly impact the end-user experience, but will significantly impactIT. Having a system that scales performance with capacity, scales to massive capacity, and provides automatedtuning and load balancing will reduce the footprint (by requiring fewer systems), help increase utilization (byconsolidating on a single shared resource and eliminating storage stovepipes) and reduce the administrativeburden (by requiring fewer systems and implementing automation). In addition, there is still more efficiency thatcan be gained through tiering.The bulk of our employees are digital pack rats, and the bulk of their files are stored because they don’t want orneed to delete them or they feel that someday down the road they may need them. Storage administratorscertainly don’t know what files can or should be deleted from these accounts, so they cannot take action. Thatmeans these systems are storing lots of stagnant data. While the system needs to support new performancedemands for some data, policies are required to facilitate tiering to cost-effective storage as use of files becomesstale. Having these policies in place with a tiered storage system that has a dense, low performance, and lessexpensive storage tier is critical to supporting online file sharing environments efficiently. You may have tens,hundreds, thousands, or tens of thousands of users that need some files fast, likely all of them at the start of theday, and those require your high-performance storage. The rest does not, and that is the bulk of your data—sotiering can help reduce the footprint and overall cost of the hardware infrastructure.How EMC Isilon Meets the OFS ChallengeEMC’s Isilon offering is largely recognized as the “father of scale-out storage.” It pioneered the concept ofcommercially viable scale-out storage appliances that are easy to use and applicable to enterprise business usecases.Because of its scale-out nature, the EMC Isilon platform can scale performance with capacity. As new nodes areadded, they are absorbed into the platform, which automatically load balances and tunes, so storage admins do nothave to spend their time creating LUNs, allocating storage, and then migrating data—it just happens. And it alsosupports tiering with Smartpools, so newer, active data can be on higher performance nodes while older, staticdata can be stored on dense and efficient nodes. And it scales to tens of PBs of capacity (144 nodes) that are allmanaged within a single namespace. This all combines to make EMC Isilon an ideal platform for consolidation.Regarding time to provision new capacity, EMC Isilon’s scale-out nature gives it granular scale—nodes can be addedas required, for just-in-time scalability, while the push-button provisioning brings capacity online quickly. And it is a © 2013 by The Enterprise Strategy Group, Inc. All Rights Reserved.
  • 10. White Paper: Building a Private Online File Sharing Cloud with EMC Isilon 10high-availability system that can withstand up to four drive or node failures and offers remote replication so it canbe set up to even withstand a site failure.Supporting a private cloud for online file sharing and collaboration is a two headed monster—both the end-userexperience and the administrative experience must be addressed, or end-users will just use their own privateaccounts. EMC Isilon’s strong commitment to designing for performance, scale, time to scale, and availability makeit a well suited platform for supporting a private corporate online file sharing initiative and ensuring the end-userexperience can be a good one. And it ensures the storage administrative end of the equation with a scalable,automated, efficient platform for consolidation. © 2013 by The Enterprise Strategy Group, Inc. All Rights Reserved.
  • 11. White Paper: Building a Private Online File Sharing Cloud with EMC Isilon 11The Bigger TruthIt is time to start paying closer attention to your file data. You may not depend on file data to keep the lights on,but your employees depend on it to get their day to day work done. Not only that, but for many companies, theircore intellectual property is file-based departmental data—i.e., engineering design files, contracts, graphics,blueprints, formulas, or just conceptual documents that have yet to progress to design phase but could holdtremendous value for the company over time. Do you really want that data in someone’s personal file sharingaccount? To be easily accessible to an employee that is no longer with the company? Do you want to expose yourcorporate network to untrusted cloud-based applications? That is what is happening today. It is time to payattention and get control over file data by providing a corporately sanctioned solution that supports yourrequirements for security and control of data. You can accomplish that by building your own file sharing cloud—butit needs to be built on the right infrastructure.Facing accelerated data growth driven by file server consolidation efforts and the need to support mobile users,scale-out platforms, such as those offered by EMC Isilon, are a necessity. You just can’t do this with a traditionalstorage approach. © 2013 by The Enterprise Strategy Group, Inc. All Rights Reserved.
  • 12. 20 Asylum Street | Milford, MA 01757 | Tel: 508.482.0188 Fax: 508.482.0218 | www.esg-global.com