A Break in the Clouds: Towards a Cloud Definition L.M. Vaquero, L. Rodero-Merino, J. Cáceres, M. Lindner. ACM Computer Communication Reviews. 2009 http://reservoir.cs.ucl.ac.uk/twiki/pub/Reservoir/PublicationsPage/CloudDefinitionPaper.pdf
Security Solutions - Require industry-leading technology, products, partnerships and services. We reduce complexity, risk, and cost by combining expert knowledge, proven methodologies and global resources to achieve better business outcomes Security Innovation- Leader in financial interchange and critical infrastructure security, policy management, encryption, Key Management, and risk mitigation Global Scale & Reach - Ability to provide low-cost/high-quality solution delivery offerings across the world Flexible Technology - The industry’s broadest portfolio of products, services and solutions Collaborative Expertise - Talented people with deep security knowledge and decades of technical experience HP Security solutions include HP products, selected partner products and HP services. These product offerings extend the value of your enterprise and enable business outcomes for your business. Examples include continuity of your manufacturing, your insurance and banking business operations, and being able pass your SOX or GLBA or PCI audits for compliance. Protect resources: - HP has multiple OS platforms with the highest level of certification providing maximum pro-active protection - HP Software’s Configuration and patch management provide continuous protection in changing environment - Enterprise Log Management collects and monitors the IT infrastructure for security issues and provides forensic evidence in the case of problems Protect data - Encryption of critical data at rest, in use or in motion increases protection - Examples of data protection include encryption in HP-UX, HP StorageWorks LT-O4 Tape, and use of our HP Compliance Log Warehouse product for proactive security management (to alert on data issues), and our linkage to selected partners This capability extends from servers to desktops and printers, with focused Key Management Provide validation - Validation at necessary audit points enables audit trails for compliance to industry regulations - Example : HP Compliance Log Warehouse provides compliance reports for a wide range of regulatory requirements, SOX, GLBA, HIPAA, PCI - Future integration of encryption and Key Management across an organization will provide end-to-end protection These technologies and the HP Services Information Security Service Management methodology based on industry standards are used to deliver a solution that includes HP Products, Partner products and incorporates a customer’s people and process needs into a complete solution. Protecting the security of your gear and your data should be as simple as using an ATM card. Basic principles HP learned a long time ago in protecting PINS and information about money moving through networks, now protect your health data, your systems and your future. Choose the right solution from HP’s broad portfolio—from desktop to data center With HP’s proven innovation: Protect your resources Protect all your data Provide validation and stay compliant
HP is uniquely positioned to deliver Cloud Assure due to our experience and success delivering SaaS. We have learned quite a few lessons as a SaaS provider over 9 years to more than 700 customers around the correct practices to ensure our customer’s experience, that are reflected in our architecture, application, and processes. Our Cloud Assure offering leverages HP’s industry-leading portfolio covering security, performance, and availability while delivering on the industry’s leading SLAs for SaaS. HP SaaS has also developed a unique expertise as well in providing guidance to our customers to ensure their end-user’s experience, with a special expertise around web applications built over more then a decade.
1 Favorite
Claude Florin, Innovation marketing manager at Hewlett-Packard, favorited this 2 months ago
Securing Cloud Services John Rhoton Distinguished Technologist HP EDS CTO Office June 2009
Overview of Cloud
Security benefits
Security challenges
HP Solutions
Agenda
Overview of Cloud
Security benefits
Security challenges
HP Solutions
Agenda
So, What is Cloud Computing?
The 451 Group: “The cloud is IT as a Service, delivered by IT resources that are independent of location”
Gartner: “Cloud computing is a style of computing where massively scalable IT-related capabilities are provided ‘as a service’ across the Internet to multiple external customers”
Forrester: “A pool of abstracted, highly scalable, and managed infrastructure capable of hosting end-customer applications and billed by consumption”
Wikipedia: “A style of computing in which dynamically scalable and often virtualized resources are provided as a service over the Internet. Users need not have knowledge of, expertise in, or control over the technology infrastructure "in the cloud" that supports them. ”
“ A large pool of easily usable and accessible virtualized resources (such as hardware, development platforms and/or services). These resources can be dynamically reconfigured to adjust to a variable load (scale), allowing also for an optimum resource utilization. This pool of re-sources is typically exploited by a pay-per-use model in which guarantees are offered by the Infrastructure Provider by means of customized SLAs.” Vaquero, Rodero-Merino, Caceres, Lindner
2938: The Value of Cloud in the Business Technology Ecosystem
Enterprise Class Global class On-premise Hybrid/off-premise 100s -1000s of nodes 10,000+ nodes Proprietary Commodity HW resiliency SW resiliency Max performance Max efficiency Silo’ed Resources Shared Resources Cost-Center Clusters Grids/Cloud Value/ Revenue-Center Static Elastic Shared storage Replicated storage Facility costs Power Usage Efficiency
Market context A service-centric perspective sheds light on all value chain constituents S S S External services In-house services Cloud services Massive scale-out infrastructure Global-class software Enterprise-class software Dedicated and shared infrastructure Enterprise-class software Dedicated and shared infrastructure
2938: The Value of Cloud in the Business Technology Ecosystem
Business users Cloud service provider Hosted / outsourced service provider IT organization internal service provider Business outcome
Cloud Model Integration Operation Governance Hardware Computation Storage Memory Colocation Real Estate Cooling Power Bandwidth Virtualisation Provisioning Billing Virtualisation Platform Programming Language Development Environment APIs Application CRM UC Email ....... .......
Benefit from economies of scale and experience curve
Predictability of spend
Avoids cost of over-provisioning
Reduction in up-front investment
Risk reduction
Offload risk or running the data-centre, data protection, and disaster recovery
Reduces risk of under-provisioning
Focus on core competency
Reduce effort and administration related to IT
Automatic service evolution
Flexibility
Roll-out new services, retire old
Scale up and down as needed; quickly
Faster time to market: Lower barriers to innovation
Access from any place, any device, any time
Overview of Cloud
Security benefits
Security challenges
HP Solutions
Agenda
Security Benefits and Opportunities
Cloud providers undergo rigorous audits
Isolation of customer and employee data
Disaster Recovery extensions
Centralised monitoring
Forensic readiness
Password assurance testing
Pre-hardened builds
Security testing
Obfuscation of physical infrastructure
June 19, 2009
Overview of Cloud
Security benefits
Security challenges
HP Solutions
Agenda
Challenges
Governance
Compliance
Data Privacy
Service Availability
Vendor Lock-in
Latency
Identity Management
Lock-in
Rogue Clouds
June 19, 2009
Governance June 19, 2009
Compliance
Sarbanes Oxley
HIPAA
FDA
Basel II
PCI
FISMA
GLBA
OSHA
ISO 27002
June 19, 2009
Data Privacy June 19, 2009
Resilience
Service Availability
Integration risks
Business Continuity
Latency
Fault Tolerance
June 19, 2009
Identity Management
Authentication
Authorisation
Access rights
Federation
Interoperability
Standards
XACML, SAML
Rapid provisioning
Immediate de-provisioning
Identity theft
June 19, 2009
Cloud Computing: Models Enterprise Data Storage Service Office Apps On Demand CPUs Printing Service Cloud Provider #1 Cloud Provider #2 Internal Cloud CRM Service … Service 3 Backup Service ILM Service Service Service Service Business Apps/Service Employee User … … … The Internet
Identity in the Cloud: Enterprise Case Enterprise Data Storage Service Office Apps On Demand CPUs Printing Service Cloud Provider #1 Cloud Provider #2 Internal Cloud CRM Service … Service 3 Backup Service ILM Service Service Service Service Business Apps/Service Employee … … … The Internet Identity & Credentials Identity & Credentials Identity & Credentials Identity & Credentials Identity & Credentials Identity & Credentials Identity & Credentials Authentication Authorization Audit Authentication Authorization Audit Authentication Authorization Audit Authentication Authorization Audit User Account Provisioning/ De-provisioning User Account Provisioning/ De-provisioning User Account Provisioning/ De-provisioning User Account Provisioning/ De-provisioning PII Data & Confidential Information PII Data & Confidential Information PII Data & Confidential Information PII Data & Confidential Information IAM Capabilities and Services Can be Outsourced in The Cloud …
Lock-in
IaaS
Standard Hardware, Software
Low Risk
PaaS
Programming Language,
APIs
Data Extraction
SaaS
Data Extraction
Functionality, User retraining
Assess Vendor viability
June 19, 2009
Rogue Clouds
Shadow IT may circumvent Central IT
Suboptimal Resource allocation
Disregard Compliance
Compromise Information Security
June 19, 2009
Cloud Security Activity and Standards
Cloud Security Alliance
ENISA (European Network and Information Security Agency)
Cloud Risk Assessment
Open Group
Jericho Forum
SAS 70
NIST Special Publication 853
FIPS 199/200
June 19, 2009
Overview of Cloud
Security benefits
Security challenges
HP Solutions
Agenda
An infrastructure utility underpins both dedicated and “as a service” applications Business outcomes Technology-enabled services Internally hosted
2938: The Value of Cloud in the Business Technology Ecosystem
Externally hosted Infrastructure as a service Business outcome Cloud Infrastructure Utility Enterprise Infrastructure Utility Enterprise-class applications Global-class cloud services
HP delivers on the Business Technology Ecosystem A sampling of HP product and services Business outcomes Technology-enabled services
2938: The Value of Cloud in the Business Technology Ecosystem
Business outcome Externally hosted Infrastructure as a service Infrastructure Utility homogeneous, centralized design Infrastructure Utility heterogeneous, distributed design Enterprise-class applications Global-class cloud services EDS Application Services Performance / Quality Center Security Center Service Manager Catalog Business Service Automation Insight Orchestration Business Service Management Proliant / Integrity ProCurve Storage Works Insight Dynamics - VSE Proliant BL2x220c StorageWorks ExDS9100 Portable Optimized Datacenter Snapfish, BookPrep, MagCloud Business Availability Center Quality and Security Centers Cloud Assure Concierge Services Project & Portfolio Management
HP delivers value across the business technology ecosystem Jun 19, 2009 We build it Leading data center design company We power it With leading servers, storage and networking We design it Expertise in application architecture & frameworks We automate it With virtualization and management software We secure it Through HP Secure Advantage program We support it With tens of thousands of IT professionals We govern it HP wrote the books on service management We measure it HP can measure the fiscal impact of services We deliver it Through purchased, financed, outsourced, cloud
2938: The Value of Cloud in the Business Technology Ecosystem
HP Secure Advantage: Making security a business enabler June 19, 2009 Business Outcomes People and process The secure end-to-end business advantage
3296 HP Secure Advantage
Products –– Partners –– Solutions Protect resources Protect data Provide validation Technology
Reduce Cost
Virtualized
Efficient
Pre-packaged
Scalable
HP provides low-cost/high-quality solution delivery combining expert knowledge and security products from the desktop to the data center using proven methodologies with global resources. Reduce Complexity Standardized • Integrated • Consulting • Managed • In/Outsourced • Pre-integrated solutions with major security players , & the HP Secure Advantage portfolio, along with the flexibility to leverage services globally to consult, deploy or manage these solutions, reduces complexity for our customers. Reduce Risk HP uses its internal best practices, developed in HP Labs and HP Services to create and commercialize security solutions and services for customers across the world.
HP Secure Advantage services portfolio Enablement to Management services from Desktop to Datacenter. Endpoint Security Network Security Data Center Security Security Operations Business Continuity & Recovery Risk Management & Compliance Infrastructure Security Governance, Risk & Compliance Mgmt Data Protection & Privacy Mgmt Identity & Access Management Identity & Access Mgmt Data Security Content Security Application Security
3296 HP Secure Advantage
Provide validation Protect data Governance, Risk & Compliance Management Infrastructure Security Identity & Access Management Data Protection & Privacy Management Protect resources
HP Secure Advantage- Product Portfolio -1
3296 HP Secure Advantage
Categories Domains HP Secure Advantage Products Infrastructure Security Network Security HP ProCurve Network Access Control HP ProCurve Network Immunity Manager HP ProCurve ONE network security solutions Endpoint Security HP ProtectTools HP Business Service Automation - Client Automation Center HP Secure Document Advantage Family Data Center Security HP Insight Dynamics - VSE HP NetTop HP-UX 11i (CC EAL4+, HIDS) HP Linux (CC EAL4+) HP OpenVMS HP NonStop Safeguard HP Neoview Security Data Protection & Privacy Management Data Security HP Secure Key Manager HP Atalla Key Block, NSP HP ProtectTools Drive Encryption HP Storage Media Encryption Fabric Switch HP XP Disk Array Encryption HP LTO-4 Tape Encryption HP Data Protector HP-UX EVFS HP NonStop Volume Level Encryption HP Medical Archive Solution Content Security HP BladeSystem content security solutions Application Security HP Application Security Center
HP Secure Advantage – Product Portfolio - 2
3296 HP Secure Advantage
Categories Domains HP Secure Advantage Products Governance Risk & Compliance Mgmt Risk Management & Compliance HP Compliance Log Warehouse HP TRIM (e-Discovery) HP Integrated Archival Platform (ILM/archiving for Email, Database, File) HP Business Service Automation - Data Center Automation Center (Server Automation, Network Automation) HP Medical Archive Solution HP Dragon HP Application Security Center Security Operations HP Business Service Automation - Data Center Automation Center (Server Automation, Network Automation, Live Network, Release Control) and Client Automation Center HP IT Service Management (Asset Manager, Decision Center etc) HP UCMDB, DDM HP Proliant Essentials Vulnerability & Patch Management Pack HP Systems Insight Manager HP Compliance Log Warehouse Business Continuity& Recovery HP Business Service Management Identity & Access Management Identity & Access Management HP ProCurve Identity Driven Manager HP Icewall HP-UX, Linux, NonStop etc
0 comments
Post a comment