SlideShare uma empresa Scribd logo
1 de 26
Manju Srinivas
/@manjusrinivas
What are we discussing today?
◊ Introduction to Cloud Computing
◊ Security and Compliance
◊ Evaluating Cloud computing
◊ Business Cases
◊ Amazon Web Service (AWS) Lab
Introduction to
Cloud Computing
What’s this Cloud computing?
“Cloud computing is a model for enabling ubiquitous,
convenient, on-demand network access to a shared pool of
configurable computing resources (networks, servers, storage,
applications, services…) that can be rapidly provisioned
and released with minimal management effort or service
provider interaction.”
- NIST Special Publication
Private Cloud
Public /
External
On-Premises / Internal Off-Premises / External
Hybrid
Community
Deployment Models
Service Models & Cloud Vendors
Software as a Service
(SaaS)
Infrastructure as a
Service (IaaS)
Platform as a Service
(PaaS)
Why are customers adopting cloud computing?
 Variable expense Replace capital expenditure with variable expense
 Economies of scale Lower variable expense than companies can achieve
themselves
 Elastic capacity No need to guess capacity requirements and over-
provision
 Speed and agility Infrastructure in minutes, not weeks and months!
 Focus on business Not undifferentiated heavy IT lifting
 Global Reach Go global in minutes and reach global audience
Benefits & Limitations
* Cost (pay per use, reduced hosting cost…)
* Automated (updates, backups…)
* Flexibility (On demand, scalable…)
* Multi tenant (shared resources, green comp)
* Mobility (Access from any Web device)
* Security
* Location of data
* Compliance and Privacy (regulations…)
* Internet Dependency / Speed
* Service Levels
* Migration / Vendor Lock-in
Security & Compliance
Cloud Architecture Example
What should be secured in Cloud?
• All the components in
the Cloud – Network,
Storage, Database,
Operating System,
virtualization, load
balancing –
everything should be
secured.
• Cloud computing
security is no
different than regular
security.
Security Risks and Mitigations
Risk
• Data loss / leakage
• Shared technology /
vulnerabilities
• Insecure application
interfaces
• Malicious insiders
• Unknown risk profile /
accounts
• Account, service and
traffic hijacking
Mitigation
• Strong Authentication,
auditing etc.
• Operations procedure,
security practices etc.
• Secured design
(Firewalls…)
• Staff vetting
• Validation of
credentials, active
monitoring of traffic
Compliance
• Numerous regulations pertain to storage and use of
data - PCI DSS, HIPAA and Sarbanes–Oxley (SOX) Act
• Business continuity and data recovery
• Logs and audit trails
• Data or Datacenter location jurisdiction
• Legal and contractual issues
Evaluating
Cloud Computing (Service) Provider
Evaluating Cloud Computing Implementation
Cost
Benefits
Business
SLA
Business Cases
Service
Supplier
Evaluation
Things to check/ask before implementing
• How good is the security of Cloud DC?
• How much will I save? (CapEx, Software licensing…)
• Time to build new system
• Maintenance strategies (outages, patches…)
• Latency comparison between Cloud and own DC
• Comparative study of various cloud providers
• Demand for trial period
• Compliance (ISO standards etc.)
• Service Levels (Uptime, time to resolution…)
Cloud Provider – Tenant Responsibility Matrix
SaaS PaaS IaaS Data Center
Data Provider Tenant Tenant Tenant
Application Provider Tenant Tenant Tenant
OS Provider Provider Tenant Tenant
Virtualization Provider Provider Provider Tenant / NA
Network Provider Provider Provider Tenant
Physical Provider Provider Provider Tenant
Business Case Studies
Business Case #1 on Elasticity – Amazon.com
Contd…
Contd…
Contd…
Contd…
Provisioned capacity Real capacity
Time for AWS Hands-on
Cloud Computing Overview

Mais conteúdo relacionado

Mais procurados

IT Series: Cloud Computing Done Right CISOA 2011
IT Series: Cloud Computing Done Right CISOA 2011IT Series: Cloud Computing Done Right CISOA 2011
IT Series: Cloud Computing Done Right CISOA 2011Donald E. Hester
 
Health Data Management - Clear Data - 5 reasons hospital CIOs are extending t...
Health Data Management - Clear Data - 5 reasons hospital CIOs are extending t...Health Data Management - Clear Data - 5 reasons hospital CIOs are extending t...
Health Data Management - Clear Data - 5 reasons hospital CIOs are extending t...Dez Blanchfield
 
Saas & DBaas
Saas & DBaasSaas & DBaas
Saas & DBaasalkuzaee
 
Introduction to Infrastructure as a Service (IaaS)
Introduction to Infrastructure as a Service (IaaS)Introduction to Infrastructure as a Service (IaaS)
Introduction to Infrastructure as a Service (IaaS)rgtechnologies
 
Webinar: Cut Disaster Recovery Expenses – Improve Recovery Times
Webinar: Cut Disaster Recovery Expenses – Improve Recovery TimesWebinar: Cut Disaster Recovery Expenses – Improve Recovery Times
Webinar: Cut Disaster Recovery Expenses – Improve Recovery TimesStorage Switzerland
 
Managed Services Cloud Computing
Managed Services Cloud Computing Managed Services Cloud Computing
Managed Services Cloud Computing dcVAST
 
An overview of cloud storage providers
An overview of cloud storage providersAn overview of cloud storage providers
An overview of cloud storage providersRonit Sharma
 
Cloud computing concept & design
Cloud computing concept & designCloud computing concept & design
Cloud computing concept & designSandipan Samaddar
 
2nd Anniversary Datacomm Cloud Business- Azure Stack
2nd Anniversary Datacomm Cloud Business- Azure Stack2nd Anniversary Datacomm Cloud Business- Azure Stack
2nd Anniversary Datacomm Cloud Business- Azure StackPT Datacomm Diangraha
 
Extensibility: The Key To Managing Your Entire Cloud Portfolio
Extensibility: The Key To Managing Your Entire Cloud PortfolioExtensibility: The Key To Managing Your Entire Cloud Portfolio
Extensibility: The Key To Managing Your Entire Cloud PortfolioDell World
 

Mais procurados (18)

IT Series: Cloud Computing Done Right CISOA 2011
IT Series: Cloud Computing Done Right CISOA 2011IT Series: Cloud Computing Done Right CISOA 2011
IT Series: Cloud Computing Done Right CISOA 2011
 
Health Data Management - Clear Data - 5 reasons hospital CIOs are extending t...
Health Data Management - Clear Data - 5 reasons hospital CIOs are extending t...Health Data Management - Clear Data - 5 reasons hospital CIOs are extending t...
Health Data Management - Clear Data - 5 reasons hospital CIOs are extending t...
 
Saas & DBaas
Saas & DBaasSaas & DBaas
Saas & DBaas
 
Infrastructure as a Service
Infrastructure as a ServiceInfrastructure as a Service
Infrastructure as a Service
 
Introduction to Infrastructure as a Service (IaaS)
Introduction to Infrastructure as a Service (IaaS)Introduction to Infrastructure as a Service (IaaS)
Introduction to Infrastructure as a Service (IaaS)
 
Info sheet-Cloud
Info sheet-CloudInfo sheet-Cloud
Info sheet-Cloud
 
Core Concept: Software Defined Everything
Core Concept: Software Defined EverythingCore Concept: Software Defined Everything
Core Concept: Software Defined Everything
 
Ms.azure in detail
Ms.azure in detailMs.azure in detail
Ms.azure in detail
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
Webinar: Cut Disaster Recovery Expenses – Improve Recovery Times
Webinar: Cut Disaster Recovery Expenses – Improve Recovery TimesWebinar: Cut Disaster Recovery Expenses – Improve Recovery Times
Webinar: Cut Disaster Recovery Expenses – Improve Recovery Times
 
Dave's Cloud
Dave's CloudDave's Cloud
Dave's Cloud
 
Managed Services Cloud Computing
Managed Services Cloud Computing Managed Services Cloud Computing
Managed Services Cloud Computing
 
An overview of cloud storage providers
An overview of cloud storage providersAn overview of cloud storage providers
An overview of cloud storage providers
 
Cloud computing concept & design
Cloud computing concept & designCloud computing concept & design
Cloud computing concept & design
 
2nd Anniversary Datacomm Cloud Business- Azure Stack
2nd Anniversary Datacomm Cloud Business- Azure Stack2nd Anniversary Datacomm Cloud Business- Azure Stack
2nd Anniversary Datacomm Cloud Business- Azure Stack
 
Virtualize
VirtualizeVirtualize
Virtualize
 
IT Resilience Use Case
IT Resilience Use CaseIT Resilience Use Case
IT Resilience Use Case
 
Extensibility: The Key To Managing Your Entire Cloud Portfolio
Extensibility: The Key To Managing Your Entire Cloud PortfolioExtensibility: The Key To Managing Your Entire Cloud Portfolio
Extensibility: The Key To Managing Your Entire Cloud Portfolio
 

Semelhante a Cloud Computing Overview

Financial impact of Cloud Computing
Financial impact of Cloud ComputingFinancial impact of Cloud Computing
Financial impact of Cloud Computingkrisbliesner
 
NIST Cybersecurity Framework (CSF) on the Public Cloud
NIST Cybersecurity Framework (CSF) on the Public CloudNIST Cybersecurity Framework (CSF) on the Public Cloud
NIST Cybersecurity Framework (CSF) on the Public CloudCloudHesive
 
Winning Governance Strategies for the Technology Disruptions of our Time
Winning Governance Strategies for the Technology Disruptions of our TimeWinning Governance Strategies for the Technology Disruptions of our Time
Winning Governance Strategies for the Technology Disruptions of our TimeCloudHesive
 
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...EuroCloud
 
Evaluating the Cloud
Evaluating the CloudEvaluating the Cloud
Evaluating the CloudSociusPartner
 
Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012Agora Group
 
Cloud strategy briefing 101
Cloud strategy briefing 101 Cloud strategy briefing 101
Cloud strategy briefing 101 Predrag Mitrovic
 
cloud services and providers
cloud services and providerscloud services and providers
cloud services and providersKalai Selvi
 
Plenary_three_Cloud_computing_-_is_social_housing_ready_for_it_-_Phil_Copperw...
Plenary_three_Cloud_computing_-_is_social_housing_ready_for_it_-_Phil_Copperw...Plenary_three_Cloud_computing_-_is_social_housing_ready_for_it_-_Phil_Copperw...
Plenary_three_Cloud_computing_-_is_social_housing_ready_for_it_-_Phil_Copperw...Phil Copperwheat
 
Cloud Computing for Small & Medium Businesses
Cloud Computing for Small & Medium BusinessesCloud Computing for Small & Medium Businesses
Cloud Computing for Small & Medium BusinessesAl Sabawi
 
Security & Compliance in the Cloud [2019]
Security & Compliance in the Cloud [2019]Security & Compliance in the Cloud [2019]
Security & Compliance in the Cloud [2019]Tudor Damian
 
AWS April Webianr Series - How Willbros Builds Securely in AWS with Trend Micro
AWS April Webianr Series - How Willbros Builds Securely in AWS with Trend MicroAWS April Webianr Series - How Willbros Builds Securely in AWS with Trend Micro
AWS April Webianr Series - How Willbros Builds Securely in AWS with Trend MicroAmazon Web Services
 
SaaS & DBaas
SaaS & DBaasSaaS & DBaas
SaaS & DBaasalkuzaee
 
ShareResponsibilityModel.pptx
ShareResponsibilityModel.pptxShareResponsibilityModel.pptx
ShareResponsibilityModel.pptxBabatundeAbioye2
 

Semelhante a Cloud Computing Overview (20)

Financial impact of Cloud Computing
Financial impact of Cloud ComputingFinancial impact of Cloud Computing
Financial impact of Cloud Computing
 
Boot camp - Migration to AWS
Boot camp - Migration to AWSBoot camp - Migration to AWS
Boot camp - Migration to AWS
 
NIST Cybersecurity Framework (CSF) on the Public Cloud
NIST Cybersecurity Framework (CSF) on the Public CloudNIST Cybersecurity Framework (CSF) on the Public Cloud
NIST Cybersecurity Framework (CSF) on the Public Cloud
 
Winning Governance Strategies for the Technology Disruptions of our Time
Winning Governance Strategies for the Technology Disruptions of our TimeWinning Governance Strategies for the Technology Disruptions of our Time
Winning Governance Strategies for the Technology Disruptions of our Time
 
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...
 
Logicalis Cloud Briefing
Logicalis Cloud BriefingLogicalis Cloud Briefing
Logicalis Cloud Briefing
 
Architecting SaaS
Architecting SaaSArchitecting SaaS
Architecting SaaS
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
Evaluating the Cloud
Evaluating the CloudEvaluating the Cloud
Evaluating the Cloud
 
What is cloud
What is cloudWhat is cloud
What is cloud
 
Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012
 
Cloud strategy briefing 101
Cloud strategy briefing 101 Cloud strategy briefing 101
Cloud strategy briefing 101
 
cloud services and providers
cloud services and providerscloud services and providers
cloud services and providers
 
Plenary_three_Cloud_computing_-_is_social_housing_ready_for_it_-_Phil_Copperw...
Plenary_three_Cloud_computing_-_is_social_housing_ready_for_it_-_Phil_Copperw...Plenary_three_Cloud_computing_-_is_social_housing_ready_for_it_-_Phil_Copperw...
Plenary_three_Cloud_computing_-_is_social_housing_ready_for_it_-_Phil_Copperw...
 
Cloud services and it security
Cloud services and it securityCloud services and it security
Cloud services and it security
 
Cloud Computing for Small & Medium Businesses
Cloud Computing for Small & Medium BusinessesCloud Computing for Small & Medium Businesses
Cloud Computing for Small & Medium Businesses
 
Security & Compliance in the Cloud [2019]
Security & Compliance in the Cloud [2019]Security & Compliance in the Cloud [2019]
Security & Compliance in the Cloud [2019]
 
AWS April Webianr Series - How Willbros Builds Securely in AWS with Trend Micro
AWS April Webianr Series - How Willbros Builds Securely in AWS with Trend MicroAWS April Webianr Series - How Willbros Builds Securely in AWS with Trend Micro
AWS April Webianr Series - How Willbros Builds Securely in AWS with Trend Micro
 
SaaS & DBaas
SaaS & DBaasSaaS & DBaas
SaaS & DBaas
 
ShareResponsibilityModel.pptx
ShareResponsibilityModel.pptxShareResponsibilityModel.pptx
ShareResponsibilityModel.pptx
 

Último

From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESmohitsingh558521
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxBkGupta21
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 

Último (20)

From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptx
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 

Cloud Computing Overview

  • 2. What are we discussing today? ◊ Introduction to Cloud Computing ◊ Security and Compliance ◊ Evaluating Cloud computing ◊ Business Cases ◊ Amazon Web Service (AWS) Lab
  • 4. What’s this Cloud computing? “Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (networks, servers, storage, applications, services…) that can be rapidly provisioned and released with minimal management effort or service provider interaction.” - NIST Special Publication
  • 5.
  • 6. Private Cloud Public / External On-Premises / Internal Off-Premises / External Hybrid Community Deployment Models
  • 7. Service Models & Cloud Vendors Software as a Service (SaaS) Infrastructure as a Service (IaaS) Platform as a Service (PaaS)
  • 8. Why are customers adopting cloud computing?  Variable expense Replace capital expenditure with variable expense  Economies of scale Lower variable expense than companies can achieve themselves  Elastic capacity No need to guess capacity requirements and over- provision  Speed and agility Infrastructure in minutes, not weeks and months!  Focus on business Not undifferentiated heavy IT lifting  Global Reach Go global in minutes and reach global audience
  • 9. Benefits & Limitations * Cost (pay per use, reduced hosting cost…) * Automated (updates, backups…) * Flexibility (On demand, scalable…) * Multi tenant (shared resources, green comp) * Mobility (Access from any Web device) * Security * Location of data * Compliance and Privacy (regulations…) * Internet Dependency / Speed * Service Levels * Migration / Vendor Lock-in
  • 12. What should be secured in Cloud? • All the components in the Cloud – Network, Storage, Database, Operating System, virtualization, load balancing – everything should be secured. • Cloud computing security is no different than regular security.
  • 13. Security Risks and Mitigations Risk • Data loss / leakage • Shared technology / vulnerabilities • Insecure application interfaces • Malicious insiders • Unknown risk profile / accounts • Account, service and traffic hijacking Mitigation • Strong Authentication, auditing etc. • Operations procedure, security practices etc. • Secured design (Firewalls…) • Staff vetting • Validation of credentials, active monitoring of traffic
  • 14. Compliance • Numerous regulations pertain to storage and use of data - PCI DSS, HIPAA and Sarbanes–Oxley (SOX) Act • Business continuity and data recovery • Logs and audit trails • Data or Datacenter location jurisdiction • Legal and contractual issues
  • 16. Evaluating Cloud Computing Implementation Cost Benefits Business SLA Business Cases Service Supplier Evaluation
  • 17. Things to check/ask before implementing • How good is the security of Cloud DC? • How much will I save? (CapEx, Software licensing…) • Time to build new system • Maintenance strategies (outages, patches…) • Latency comparison between Cloud and own DC • Comparative study of various cloud providers • Demand for trial period • Compliance (ISO standards etc.) • Service Levels (Uptime, time to resolution…)
  • 18. Cloud Provider – Tenant Responsibility Matrix SaaS PaaS IaaS Data Center Data Provider Tenant Tenant Tenant Application Provider Tenant Tenant Tenant OS Provider Provider Tenant Tenant Virtualization Provider Provider Provider Tenant / NA Network Provider Provider Provider Tenant Physical Provider Provider Provider Tenant
  • 20. Business Case #1 on Elasticity – Amazon.com
  • 25. Time for AWS Hands-on

Notas do Editor

  1. Broad network access: Cloud Capabilities are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms such as mobile phones, laptops and PDAs.Measured service: Cloud computing resource usage can be measured, controlled, and reported providing transparency for both the provider and consumer of the utilised service. Cloud computing services use a metering capability which enables to control and optimise resource use. This implies that just like air time, electricity or municipality water IT services are charged per usage metrics – pay per use. The more you utilise the higher the bill. Just as utility companies sell power to subscribers, and telephone companies sell voice and data services, IT services such as network security management, data center hosting or even departmental billing can now be easily delivered as a contractual service.On demand self services: computer services such as email, applications, network or server service can be provided without requiring human interaction with each service provider. Cloud service providers providing on demand self services include Amazon Web Services (AWS), Microsoft, Google, IBM and Salesforce.com. New York Times and NASDAQ are examples of companies using AWS (NIST). Gartner describes this characteristic as service based Rapid elasticity: Cloud services can be rapidly and elastically provisioned, in some cases automatically, to quickly scale out and rapidly released to quickly scale in. To the consumer, the capabilities available for provisioning often appear to be unlimited and can be purchased in any quantity at any timeResource pooling: The provider’s computing resources are pooled together to serve multiple consumers using multiple-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand. The resources include among others storage, processing, memory, network bandwidth, virtual machines and email services. The pooling together of the resource builds economies of scale (Gartner).
  2. Salesforce.com has become the poster child of software as a service Customer Relationship Management (CRM) software solutions. Now the technology pioneer continues a push into the platform as a service (PaaS) market with its Force.com application platform.NetSuite delivers software as a service (SaaS) enterprise-wide business applications, including full-featured financials and accounting, Customer Relationship Management (CRM), inventory, and e-commerce software—all in a fully integration application.Oracle's on demand CRM software allows customers flexibility in how to deploy tehir CRM software based on their specific needs and budget requirements. Hosted and Managed Applications and Software-as-a-Service (SaaS) deployment models are all available.Enterprise Resource Planning (ERP) giant SAP is assertively pushing into the software as a service CRM and ERP markets with its Business ByDesign solution. The on-demand ERP system is showing strong global adoption from both customers and partners.=====================Google has made a name for itself with its Google Apps suite of business and consumer cloud applications and its Google App Engine, the developer platform that lets users build and host Web apps in the cloud in an effortless fashion.Microsoft's cloud platform, Windows Azure, is a little more than a year old and is still gathering momentum. Azure has blossomed into more than just a development play—it's a full-fledged cloud services operating system that also offers service hosting and service management.Flexiant's public cloud platform, FlexiScale, has made the company one of Europe's premier cloud players and an up-and-comer in the U.S. The platform is aimed at SMEs and startups looking to offer streaming video, social networking, IPTV, VoIP or SaaS.GridGain's open-source cloud application platform helps developers build scalable applications that can work natively on managed infrastructure, from a Google Android device to large grids and clouds. The software supports major OSes and provides native support for Java and Scala.=================Amazon Web Services has become the one to beat in the cloud game, and Amazon EC2, its compute capacity play, set the standard for spinning up and taking down cloud capacity quickly and affordably with a pay-as-you-go model.GoGrid prides itself on being the biggest pure-play Infrastructure-as- a-Service company in the world. Its infrastructure lets businesses deploy and manage apps in the cloud platform within minutes and with a flexibility that separates it from the Johnny-comelatelies.While formally known as Rackspace Hosting, Rackspace Cloud is taking over. And with Rackspace's Cloud Servers infrastructure play, the top cloud dog of Texas is rivaling the major players with its select-asize, customizable IaaS backed by Rackspace's own "fanatical support."Late last year, Savvis launched Savvis Symphony, its suite of enterprise-focused cloud solutions to let businesses break free from IT infrastructure. Savvis says its cloud infrastructure can reduce capital expense, improve service levels and keep enterprises at the forefront of cloud innovation.
  3. Payment Card Industry Data Security Standard - PCI DSSHealth Insurance Portability and accountability Act - HIPAA