Information Security &
                       Cloud Computing
                                         Dr Paul Miller
                                     The Cloud of Data
                                paul.miller@cloudofdata.com




cloudofdata.com
Topics
           Cloud Stack redux

           Some (quick!) ‘truths’ about the Cloud

           Information Security?




cloudofdata.com
‘The Cloud’ lumps different
                    concepts/capabilities together
  The Cloud Stack




cloudofdata.com              www.flickr.com/photos/wonderlane/3089163372/
“convenient, on-demand network access to a shared pool of
            configurable computing resources...”




cloudofdata.com                                            csrc.nist.gov/groups/SNS/cloud-computing/
Traditional 3 layer model - there are plenty of others!
                  all ‘Cloud’… but DIFFERENT!


                  Software/Application [as a Service]
                               (SaaS)



                        Platform [as a Service]
                                (PaaS)



                     Infrastructure [as a Service]
                                 (IaaS)




cloudofdata.com
outsource raw infrastructure - avoid
                                       significant CapEx
                                       scale to meet demand - Eli Lilly, payroll
                                       SaaS private/ hybrid
                                       public/

                                       PaaS

                         Infrastructure as a Service (IaaS)

                  computers (Amazon EC2, Rackspace, GoGrid...)
                  storage (Amazon S3, MobileMe, Google Drive...)
                             Elasticity (Rightscale…)
                    Bandwidth (Limelight, Amazon CloudFront…)
                                     Electricity
                                      Cooling
                                         etc.


cloudofdata.com
‘does heavy lifting’
                                 concentrate on your app’s USP

                                least developed but most potential?
                             SaaS


                  Platform as a Service (PaaS)

                     Salesforce force.com
                     Apprenda SaaSGrid
                      Google App Engine
                       Microsoft Azure
                            Appistry
                         Talis Platform


                             IaaS


cloudofdata.com
light weight applications, delivered over Web
                        mostly low-end disruptors for now...


                  Software as a Service (SaaS)

                     Google Apps, Zoho
                   Acrobat.com, iWork.com
                     Kashflow, FreeAgent
                       WordPress.com
                         MobileMe
                       Salesforce.com


                             PaaS

                             IaaS


cloudofdata.com
Some more true than others!




                   Some ‘Truths’ about the Cloud
 cloudofdata.com                      www.flickr.com/photos/dpicker/2255136085/
Microsoft Data Centre, Dublin              Cisco, VMware et al pushing
                                           on-premise

                                           G-Cloud, here and in USA...




       It’s All Off-Premise




 cloudofdata.com                www.datacenterknowledge.com/wp-content/uploads/2009/09/aerial-1000.jpg
For elastic or periodic jobs.
                   Less clear-cut for ‘normal’ load




      It’s Cheap




cloudofdata.com            www.flickr.com/photos/esdrascalderan/357434020/
Probably… but Simon Wardley




      It’s Green



                            http://tr.im/greenclouds

cloudofdata.com             www.flickr.com/photos/venteco/2851026377/
Numbers don’t add up...




                  It’s Not Reliable
cloudofdata.com          www.flickr.com/photos/raver_mikey/2300514593/
And your data centre ?




      It’s Not Secure




cloudofdata.com          www.flickr.com/photos/8323834@N07/500995147/
PATRIOT Act and data territoriality are real… but manageable



       USA will read my data




 cloudofdata.com                                   www.flickr.com/photos/whitehouse/3484013571/
And Rackspace,
                           and Microsoft,
                           and Sun, and HP,
    It’s Amazon            and Google, and...




cloudofdata.com   www.flickr.com/photos/lucasartoni/2967023166/
Amazon      Rackspace     Joyent   GoGrid             OpSource                  FlexiScale



   3,000
Guy Rosen has
begun tracking
trends, using
QuantCast’s top
   2,250

500,000 sites

   1,500




    750




      0
           July            September      November     January                     March                         May



 cloudofdata.com                                              www.jackofallclouds.com/2010/05/state-of-the-cloud-may-2010/
With thanks to Simon Wardley




                   “It’s like computers on the
                   Internet, innit?”
 cloudofdata.com                      www.flickr.com/photos/fimbrethil/2642775023/
What are you securing…
and Why?

5 broad areas...




                         Security
 cloudofdata.com
Secure Physical Infrastructure
cloudofdata.com                       www.flickr.com/photos/treborrenrut/4481585336/
Secure the Network
cloudofdata.com
Secure Applications
cloudofdata.com
Secure Data
cloudofdata.com
Secure People
cloudofdata.com
Conclusion
cloudofdata.com
it can be!

             what matters?

             security costs time, money and effort

             identify appropriate levels of security…

             always remember that people will be people.




cloudofdata.com
cloud of data




  Thank you                                                                                                       Download this presentation
                                                                                                                  slideshare.net/cloudofdata


  Dr Paul Miller
  The Cloud of Data
  paul.miller@cloudofdata.com
                                                                                                                                          Made on a
  skype: cloudofdata
                                                                                                                                          Mac
  phone: +44 7769 740083

                                Except where otherwise noted, this work is licensed under the Creative Commons Attribution Licence.
                                      To view a copy of this licence, visit creativecommons.org/licenses/by/2.0/uk/ or send a letter to
cloudofdata.com                             Creative Commons, 171 Second St, San Francisco, CA 94105, United States of America
Information Security and Cloud Computing

Information Security and Cloud Computing

  • 1.
    Information Security & Cloud Computing Dr Paul Miller The Cloud of Data paul.miller@cloudofdata.com cloudofdata.com
  • 2.
    Topics Cloud Stack redux Some (quick!) ‘truths’ about the Cloud Information Security? cloudofdata.com
  • 3.
    ‘The Cloud’ lumpsdifferent concepts/capabilities together The Cloud Stack cloudofdata.com www.flickr.com/photos/wonderlane/3089163372/
  • 4.
    “convenient, on-demand networkaccess to a shared pool of configurable computing resources...” cloudofdata.com csrc.nist.gov/groups/SNS/cloud-computing/
  • 5.
    Traditional 3 layermodel - there are plenty of others! all ‘Cloud’… but DIFFERENT! Software/Application [as a Service] (SaaS) Platform [as a Service] (PaaS) Infrastructure [as a Service] (IaaS) cloudofdata.com
  • 6.
    outsource raw infrastructure- avoid significant CapEx scale to meet demand - Eli Lilly, payroll SaaS private/ hybrid public/ PaaS Infrastructure as a Service (IaaS) computers (Amazon EC2, Rackspace, GoGrid...) storage (Amazon S3, MobileMe, Google Drive...) Elasticity (Rightscale…) Bandwidth (Limelight, Amazon CloudFront…) Electricity Cooling etc. cloudofdata.com
  • 7.
    ‘does heavy lifting’ concentrate on your app’s USP least developed but most potential? SaaS Platform as a Service (PaaS) Salesforce force.com Apprenda SaaSGrid Google App Engine Microsoft Azure Appistry Talis Platform IaaS cloudofdata.com
  • 8.
    light weight applications,delivered over Web mostly low-end disruptors for now... Software as a Service (SaaS) Google Apps, Zoho Acrobat.com, iWork.com Kashflow, FreeAgent WordPress.com MobileMe Salesforce.com PaaS IaaS cloudofdata.com
  • 9.
    Some more truethan others! Some ‘Truths’ about the Cloud cloudofdata.com www.flickr.com/photos/dpicker/2255136085/
  • 10.
    Microsoft Data Centre,Dublin Cisco, VMware et al pushing on-premise G-Cloud, here and in USA... It’s All Off-Premise cloudofdata.com www.datacenterknowledge.com/wp-content/uploads/2009/09/aerial-1000.jpg
  • 11.
    For elastic orperiodic jobs. Less clear-cut for ‘normal’ load It’s Cheap cloudofdata.com www.flickr.com/photos/esdrascalderan/357434020/
  • 12.
    Probably… but SimonWardley It’s Green http://tr.im/greenclouds cloudofdata.com www.flickr.com/photos/venteco/2851026377/
  • 13.
    Numbers don’t addup... It’s Not Reliable cloudofdata.com www.flickr.com/photos/raver_mikey/2300514593/
  • 14.
    And your datacentre ? It’s Not Secure cloudofdata.com www.flickr.com/photos/8323834@N07/500995147/
  • 15.
    PATRIOT Act anddata territoriality are real… but manageable USA will read my data cloudofdata.com www.flickr.com/photos/whitehouse/3484013571/
  • 16.
    And Rackspace, and Microsoft, and Sun, and HP, It’s Amazon and Google, and... cloudofdata.com www.flickr.com/photos/lucasartoni/2967023166/
  • 17.
    Amazon Rackspace Joyent GoGrid OpSource FlexiScale 3,000 Guy Rosen has begun tracking trends, using QuantCast’s top 2,250 500,000 sites 1,500 750 0 July September November January March May cloudofdata.com www.jackofallclouds.com/2010/05/state-of-the-cloud-may-2010/
  • 18.
    With thanks toSimon Wardley “It’s like computers on the Internet, innit?” cloudofdata.com www.flickr.com/photos/fimbrethil/2642775023/
  • 19.
    What are yousecuring… and Why? 5 broad areas... Security cloudofdata.com
  • 20.
    Secure Physical Infrastructure cloudofdata.com www.flickr.com/photos/treborrenrut/4481585336/
  • 21.
  • 22.
  • 23.
  • 24.
  • 25.
  • 26.
    it can be! what matters? security costs time, money and effort identify appropriate levels of security… always remember that people will be people. cloudofdata.com
  • 27.
    cloud of data Thank you Download this presentation slideshare.net/cloudofdata Dr Paul Miller The Cloud of Data paul.miller@cloudofdata.com Made on a skype: cloudofdata Mac phone: +44 7769 740083 Except where otherwise noted, this work is licensed under the Creative Commons Attribution Licence. To view a copy of this licence, visit creativecommons.org/licenses/by/2.0/uk/ or send a letter to cloudofdata.com Creative Commons, 171 Second St, San Francisco, CA 94105, United States of America