SlideShare uma empresa Scribd logo
1 de 18
Baixar para ler offline
Latest in Cloud
Computing Standards
Eric A. Hibbard, CISSP, ISSAP, ISSEP, ISSMP, CISA, SCSE
CTO Security & Privacy
Hitachi Data systems

                                                          1
Standards Alphabet Soup
 •   CSA = Cloud Security Alliance
 •   DMTF = Distributed Management Task Force
 •   ENISA = European Network and Information Security Agency
 •   ETSI = European Telecommunications Standards Institute
 •   IEC = International Electrotechnical Commission
 •   IEEE = Institute of Electrical and Electronics Engineers
 •   INCITS = International Committee for Information Technology
     Standards
 •   ISO = International Organization for Standardization
 •   ITU-T = International Telecommunication Union – Telecom
 •   NIST = National Institute for Standards and Technology
 •   OASIS = Organization for the Advancement of Structured
     Information Standards
 •   SNIA = Storage Networking Industry Association
 •   TCG = Trusted Computing Group                                 2
Sample Cloud SDO Relationships
                                                      CT-CC
                                     ITU-T
  CSA

                    ISO/IEC                          ISO/IEC
 ENISA                SC27                             SC38



  TCG
                    INCITS/                         INCITS/
                      CS1                           DAPS38

             IEEE
                              NIST           SNIA        DMTF
                                                                3
  Formal
  Informal
Standards & Glaciers…Similar Pace




                                    4
Cloud Computing…


cloud computing: paradigm for enabling [ubiquitous,
convenient, on-demand] network access to a shared
pool of configurable cloud resources (3.2.4) accessed
through services (3.1.8), that can be [rapidly]
provisioned and released [with minimal management
effort or service provider interaction.]
                           SOURCE: ISO/IEC 2ndCD 17788


                                                         5
ISO/IEC JTC 1/SC 38
 • SC38 = Information Technology – Distributed Application Platforms &
          Services

 • ISO/IEC 17788 (Cloud computing – Vocabulary and overview)
   •   Collaborative Team (CT) with ITU-T/SG13 to develop common text
   •   Defines key cloud terminology and provides an overview of cloud computing
   •   Intended to be a foundation document for cloud computing
   •   Stage: 2nd Committee Draft (CD)
 • ISO/IEC 17789 (Reference architecture)
   • Collaborative Team (CT) with ITU-T/SG13 to develop common text
   • Covers general concepts and characteristics of cloud computing, the
     components/functions and roles and their capabilities and inter-relationships
   • Focused on the requirements of ―what Cloud services provide, not ―how to
     design solutions and implementations
   • Stage: Working Draft (CD)                                                       6
 • Under Consideration:
   • Service Delivery Principles and Service Level Agreements
ITU-T/Study Group 13 (SG13)
 • Future networks including cloud computing, mobile and next-
   generation networks

 • Y.ccdef – Cloud computing definition and vocabulary
 • Y.cceco – Cloud computing: ecosystem, use cases and general
   requirements
 • Y.Cloud-SIDE-Reqts – High level requirements and capabilities for cloud
   enabled service environment
 • Y.ccic – Framework of inter-cloud for network and infrastructure
 • Y.ccinfra – Cloud computing infrastructure requirements
 • Y.ccra – Cloud computing reference architecture
 • Y.e2eccrmr – End-to-end cloud computing resources management
   requirements
 • Y.VNC – Resource control and management for virtual networks for cloud
                                                                             7
   services (VNCs)
ITU-T/Study Group 17 (SG17)
 • Security

 • X.ccsec – High-level security framework for cloud computing
 • X.goscc – Guidelines of operational security for cloud computing
 • X.sfcse – Security functional requirements for Software as a
   Service (SaaS) application environment
 • X.idmcc – Requirement of IdM in cloud computing




                                                                      8
ISO/IEC JTC 1/SC27
• SC27 = Information Technology – Security techniques

• ISO/IEC 27017 (Code of practice for information security controls for
  cloud computing services based on ISO/IEC 27002)
  • Additional implementation guidance for relevant information security
    controls specified in ISO/IEC 27002; and
  • Additional controls and implementation guidance that specifically relate to
    cloud computing services.
  • Technical Report => International Standard
  • Stage: 4th Working Draft (WD)
• ISO/IEC 27018 (Code of practice for data protection controls for public
  cloud computing services)
   • Applies to organizations providing public cloud computing services
     that act as PII processors (possibly PII controllers)
   • Establishes commonly accepted control objectives, controls and
     guidelines for implementing controls to protect                              9
  • Stage: 2nd Working Draft (WD)
ISO/IEC JTC 1/SC27 (cont.)
 • ISO/IEC 27040 (Storage security)
   • Overview of storage security concepts and related definitions
   • Guidance on the threat, design and control aspects associated with typical
     storage scenarios and storage technology areas
   • Limited coverage for cloud storage (e.g., CDMI)
   • Stage: 2nd Committee Draft (CD)


 • Numerous other security standards that are potentially relevant!




                                                                                  10
Standards Setting Organizations
(SSO) & Industry Associations


                                  11
NIST – Information Technology Laboratory
 • Special Publication 800-144, Guidelines on Security and Privacy in Public
   Cloud Computing
 • Special Publication 800-145, The NIST Definition of Cloud Computing
 • Special Publication 800-146, Cloud Computing Synopsis and
   Recommendations
 • Special Publication 500-291, NIST Cloud Computing Standards Roadmap
 • Special Publication 500-292, NIST Cloud Computing Reference
   Architecture
 • Special Publication 500-293, (Draft). US Government Cloud Computing
   Technology.
 • Interagency Report 7904, (Draft) Trusted Geolocation in the Cloud: Proof
   of Concept Implementation


                                                                               12
Cloud Security Alliance (CSA)
 • Security Guidance for Critical Areas of Focus in Cloud
   Computing
 • Open Certification Framework
 • Cloud Controls Matrix (CCM)
 • Trusted Cloud Initiative (TCI) Reference Architecture Model
 • Top Threats to Cloud Computing
 • Security as a Service (SecaaS) Implementation Guidance




                                                                 13
OASIS
• Cloud Application Management for Platforms (CAMP)
•  Identity in the Cloud (IDCloud)
• Symptoms Automation Framework (SAF)
• Topology and Orchestration Specification for Cloud
  Applications (TOSCA)
• Cloud Authorization (CloudAuthZ)
• Public Administration Cloud Requirements (PACR)




                                                       14
Other Cloud Activities of SSOs & IAs
 • IEEE Standards Association (IEEE-SA)
    • P2301 - Guide for Cloud Portability and Interoperability Profiles
      (CPIP)
    • P2302 - Standard for Intercloud Interoperability and Federation
      (SIIF)
 • Internet Engineering Task Force (IETF)
    • RFC 6208 – Cloud Data Management Interface (CDMI) Media Types
    • Huge number of RFCs that enable the cloud.
 • Trusted Computing Group (TCG)
    • Trusted Multi-Tenant Infrastructure (TMI) Use Cases
    • Trusted Multi-tenant Infrastructure (TMI) Specification [Goal]
 • Storage Network Industry Association (SNIA)
    • Cloud Data Management Interface (CDMI) specification
    • ISO/IEC 17826: 2012, Information technology -- Cloud Data
                                                                          15
      Management Interface (CDMI) [CDMI v1.0.2]
Other Cloud Activities of SSOs & IAs
 • The Open Group
   • Service-oriented Cloud Computing Infrastructure (SOCCI) Framework
   • Cloud Computing Reference Architecture (CCRA)
 • Distributed Management Task Force (DMTF)
   • DSP0243 Open Virtualization Format (OVF)
   • ISO/IEC 17203:2011, Information technology -- Open Virtualization
     Format (OVF) specification
   • DSP0263 Cloud Infrastructure Management Interface (CIMI) Model
     and REST Interface over HTTP Specification
   • DSP0264 CIMI-CIM Specification




                                                                         16
Final Thoughts
 • A significant number of the cloud computing standards and
   specifications are still in draft form

 • There are many organization operating in this space, but it does
   appear there are conscious efforts to avoid duplication and
   contradiction

 • It is unlikely that a single, all-encompassing standard (or source
   for standards) will emerge for cloud




                                                                        17
eric.hibbard@hds.com




THANK YOU                  18

Mais conteúdo relacionado

Mais procurados

4.cloud Deployment models
4.cloud Deployment models4.cloud Deployment models
4.cloud Deployment modelsDrRajapraveen
 
IT Geek Week 2016 - Introduction To Cloud Computing
IT Geek Week 2016 - Introduction To Cloud ComputingIT Geek Week 2016 - Introduction To Cloud Computing
IT Geek Week 2016 - Introduction To Cloud ComputingHaim Ateya
 
Cloud deployment models
Cloud deployment modelsCloud deployment models
Cloud deployment modelsAshok Kumar
 
Cloud Computing - Introduction
Cloud Computing - IntroductionCloud Computing - Introduction
Cloud Computing - IntroductionRupesh Mishra
 
Cloud computing reference architecture from nist and ibm
Cloud computing reference architecture from nist and ibmCloud computing reference architecture from nist and ibm
Cloud computing reference architecture from nist and ibmRichard Kuo
 
Chap 5 software as a service (saass)
Chap 5 software as a service (saass)Chap 5 software as a service (saass)
Chap 5 software as a service (saass)Raj Sarode
 
Cloud Computing Standards and Use Cases (Robert Grossman) 09-v8p
Cloud Computing Standards and Use Cases (Robert Grossman) 09-v8pCloud Computing Standards and Use Cases (Robert Grossman) 09-v8p
Cloud Computing Standards and Use Cases (Robert Grossman) 09-v8pRobert Grossman
 
Cloud computing and data security
Cloud computing and data securityCloud computing and data security
Cloud computing and data securityMohammed Fazuluddin
 
Third party cloud services cloud computing
Third party cloud services cloud computingThird party cloud services cloud computing
Third party cloud services cloud computingSohailAliMalik
 
Cloud computing security and privacy
Cloud computing security and privacyCloud computing security and privacy
Cloud computing security and privacyAdeel Javaid
 
Chap 1 introduction to cloud computing
Chap 1 introduction to cloud computingChap 1 introduction to cloud computing
Chap 1 introduction to cloud computingRaj Sarode
 
Cloud Computing Use Cases Whitepaper 3 0
Cloud Computing Use Cases Whitepaper 3 0Cloud Computing Use Cases Whitepaper 3 0
Cloud Computing Use Cases Whitepaper 3 0Jason Reed
 
Security in cloud computing
Security in cloud computingSecurity in cloud computing
Security in cloud computingveena venugopal
 
Cloud Deployment Models
Cloud Deployment ModelsCloud Deployment Models
Cloud Deployment ModelsStanton Jones
 

Mais procurados (18)

Ccl basics
Ccl basicsCcl basics
Ccl basics
 
4.cloud Deployment models
4.cloud Deployment models4.cloud Deployment models
4.cloud Deployment models
 
IT Geek Week 2016 - Introduction To Cloud Computing
IT Geek Week 2016 - Introduction To Cloud ComputingIT Geek Week 2016 - Introduction To Cloud Computing
IT Geek Week 2016 - Introduction To Cloud Computing
 
Cloud deployment models
Cloud deployment modelsCloud deployment models
Cloud deployment models
 
Cloud Computing - Introduction
Cloud Computing - IntroductionCloud Computing - Introduction
Cloud Computing - Introduction
 
Cloud computing reference architecture from nist and ibm
Cloud computing reference architecture from nist and ibmCloud computing reference architecture from nist and ibm
Cloud computing reference architecture from nist and ibm
 
Chap 5 software as a service (saass)
Chap 5 software as a service (saass)Chap 5 software as a service (saass)
Chap 5 software as a service (saass)
 
Cloud Computing Standards and Use Cases (Robert Grossman) 09-v8p
Cloud Computing Standards and Use Cases (Robert Grossman) 09-v8pCloud Computing Standards and Use Cases (Robert Grossman) 09-v8p
Cloud Computing Standards and Use Cases (Robert Grossman) 09-v8p
 
Cloud computing and data security
Cloud computing and data securityCloud computing and data security
Cloud computing and data security
 
Presentation on Top Cloud Computing Technologies
Presentation on Top Cloud Computing TechnologiesPresentation on Top Cloud Computing Technologies
Presentation on Top Cloud Computing Technologies
 
Third party cloud services cloud computing
Third party cloud services cloud computingThird party cloud services cloud computing
Third party cloud services cloud computing
 
Cloud computing security and privacy
Cloud computing security and privacyCloud computing security and privacy
Cloud computing security and privacy
 
Chap 1 introduction to cloud computing
Chap 1 introduction to cloud computingChap 1 introduction to cloud computing
Chap 1 introduction to cloud computing
 
Cloud Computing Use Cases Whitepaper 3 0
Cloud Computing Use Cases Whitepaper 3 0Cloud Computing Use Cases Whitepaper 3 0
Cloud Computing Use Cases Whitepaper 3 0
 
Ppt cloud deployment
Ppt cloud deploymentPpt cloud deployment
Ppt cloud deployment
 
Security in cloud computing
Security in cloud computingSecurity in cloud computing
Security in cloud computing
 
Cloud Encryption
Cloud EncryptionCloud Encryption
Cloud Encryption
 
Cloud Deployment Models
Cloud Deployment ModelsCloud Deployment Models
Cloud Deployment Models
 

Destaque

OGF Cloud Standards: Current status and ongoing interoperability efforts wi...
OGF Cloud Standards: Current status and ongoing interoperability efforts wi...OGF Cloud Standards: Current status and ongoing interoperability efforts wi...
OGF Cloud Standards: Current status and ongoing interoperability efforts wi...Florian Feldhaus
 
Cloud Computing and Distance Education
Cloud Computing and Distance EducationCloud Computing and Distance Education
Cloud Computing and Distance EducationRoryMcGreal
 
ISO 9000
ISO 9000ISO 9000
ISO 900017somya
 
Cloud Standards and Virtualization
Cloud Standards and VirtualizationCloud Standards and Virtualization
Cloud Standards and VirtualizationPeter Tröger
 
Cloud Standards in the Real World: Cloud Standards Testing for Developers
Cloud Standards in the Real World: Cloud Standards Testing for DevelopersCloud Standards in the Real World: Cloud Standards Testing for Developers
Cloud Standards in the Real World: Cloud Standards Testing for DevelopersAlan Sill
 
WCIT12 myth busting presentation
WCIT12 myth busting presentationWCIT12 myth busting presentation
WCIT12 myth busting presentationITU
 
The state of the internet
The state of the internetThe state of the internet
The state of the internetMateo Budinich
 
OGF standards for cloud computing
OGF standards for cloud computingOGF standards for cloud computing
OGF standards for cloud computingAlan Sill
 
Open Cloud Computing Interface Presentation
Open Cloud Computing Interface PresentationOpen Cloud Computing Interface Presentation
Open Cloud Computing Interface PresentationIntel Corporation
 
Cloud Computing and Open Source
Cloud Computing and Open SourceCloud Computing and Open Source
Cloud Computing and Open SourceJohn Willis
 
Peter Mell Cloud Standards 20090915
Peter Mell Cloud Standards 20090915Peter Mell Cloud Standards 20090915
Peter Mell Cloud Standards 20090915GovCloud Network
 
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30This account is closed
 
Cloud Standards: EnablingInteroperability.and.package.delivery
Cloud Standards: EnablingInteroperability.and.package.deliveryCloud Standards: EnablingInteroperability.and.package.delivery
Cloud Standards: EnablingInteroperability.and.package.deliveryAbiquo, Inc.
 
ITU-T Perspectives on the Standards-Based Security Landscape (SG 17 Main Focus)
ITU-T Perspectives on the Standards-Based Security Landscape  (SG 17 Main Focus)ITU-T Perspectives on the Standards-Based Security Landscape  (SG 17 Main Focus)
ITU-T Perspectives on the Standards-Based Security Landscape (SG 17 Main Focus)Abbie Barbir
 
Latest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and PrivacyLatest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and PrivacyCloud Standards Customer Council
 

Destaque (20)

OGF Cloud Standards: Current status and ongoing interoperability efforts wi...
OGF Cloud Standards: Current status and ongoing interoperability efforts wi...OGF Cloud Standards: Current status and ongoing interoperability efforts wi...
OGF Cloud Standards: Current status and ongoing interoperability efforts wi...
 
Cloud Computing and Distance Education
Cloud Computing and Distance EducationCloud Computing and Distance Education
Cloud Computing and Distance Education
 
ISO 27001
ISO 27001ISO 27001
ISO 27001
 
ISO 9000
ISO 9000ISO 9000
ISO 9000
 
Cloud Standards and Virtualization
Cloud Standards and VirtualizationCloud Standards and Virtualization
Cloud Standards and Virtualization
 
Cloud Standards in the Real World: Cloud Standards Testing for Developers
Cloud Standards in the Real World: Cloud Standards Testing for DevelopersCloud Standards in the Real World: Cloud Standards Testing for Developers
Cloud Standards in the Real World: Cloud Standards Testing for Developers
 
Nuevos retos CIO
Nuevos retos CIONuevos retos CIO
Nuevos retos CIO
 
WCIT12 myth busting presentation
WCIT12 myth busting presentationWCIT12 myth busting presentation
WCIT12 myth busting presentation
 
The state of the internet
The state of the internetThe state of the internet
The state of the internet
 
OGF standards for cloud computing
OGF standards for cloud computingOGF standards for cloud computing
OGF standards for cloud computing
 
Open Cloud Computing Interface Presentation
Open Cloud Computing Interface PresentationOpen Cloud Computing Interface Presentation
Open Cloud Computing Interface Presentation
 
Cloud Services & the Development of ISO/IEC 27018
Cloud Services & the Development of ISO/IEC 27018Cloud Services & the Development of ISO/IEC 27018
Cloud Services & the Development of ISO/IEC 27018
 
Cloud Computing and Open Source
Cloud Computing and Open SourceCloud Computing and Open Source
Cloud Computing and Open Source
 
Peter Mell Cloud Standards 20090915
Peter Mell Cloud Standards 20090915Peter Mell Cloud Standards 20090915
Peter Mell Cloud Standards 20090915
 
Security in the cloud
Security in the cloudSecurity in the cloud
Security in the cloud
 
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30
 
Cloud Standards: EnablingInteroperability.and.package.delivery
Cloud Standards: EnablingInteroperability.and.package.deliveryCloud Standards: EnablingInteroperability.and.package.delivery
Cloud Standards: EnablingInteroperability.and.package.delivery
 
ITU-T Perspectives on the Standards-Based Security Landscape (SG 17 Main Focus)
ITU-T Perspectives on the Standards-Based Security Landscape  (SG 17 Main Focus)ITU-T Perspectives on the Standards-Based Security Landscape  (SG 17 Main Focus)
ITU-T Perspectives on the Standards-Based Security Landscape (SG 17 Main Focus)
 
Latest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and PrivacyLatest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and Privacy
 
Cloud computing protocol
Cloud computing protocolCloud computing protocol
Cloud computing protocol
 

Semelhante a Latest Cloud Computing Standards Update

The cloud landscape nad 2012
The cloud landscape   nad 2012The cloud landscape   nad 2012
The cloud landscape nad 2012David Terrar
 
Cloud computing standards and protocols r.nabati
Cloud computing standards and protocols r.nabatiCloud computing standards and protocols r.nabati
Cloud computing standards and protocols r.nabatinabati
 
CompTIA Cloud+ Objectives
CompTIA Cloud+ Objectives CompTIA Cloud+ Objectives
CompTIA Cloud+ Objectives sombat nirund
 
CCNA4 Verson6 Chapter7
CCNA4 Verson6 Chapter7CCNA4 Verson6 Chapter7
CCNA4 Verson6 Chapter7Chaing Ravuth
 
MPLS/SDN 2013 Intercloud Standardization and Testbeds - Sill
MPLS/SDN 2013 Intercloud Standardization and Testbeds - SillMPLS/SDN 2013 Intercloud Standardization and Testbeds - Sill
MPLS/SDN 2013 Intercloud Standardization and Testbeds - SillAlan Sill
 
CCNA (R & S) Module 02 - Connecting Networks - Chapter 7
CCNA (R & S) Module 02 - Connecting Networks - Chapter 7CCNA (R & S) Module 02 - Connecting Networks - Chapter 7
CCNA (R & S) Module 02 - Connecting Networks - Chapter 7Waqas Ahmed Nawaz
 
Necos keynote UFRN Telecomday
Necos keynote UFRN TelecomdayNecos keynote UFRN Telecomday
Necos keynote UFRN TelecomdayAugusto Neto
 
Grid and Cloud Computing Lecture-2a.pptx
Grid and Cloud Computing Lecture-2a.pptxGrid and Cloud Computing Lecture-2a.pptx
Grid and Cloud Computing Lecture-2a.pptxDrAdeelAkram2
 
Cisco connect winnipeg 2018 gain insight and programmability with cisco dc ...
Cisco connect winnipeg 2018   gain insight and programmability with cisco dc ...Cisco connect winnipeg 2018   gain insight and programmability with cisco dc ...
Cisco connect winnipeg 2018 gain insight and programmability with cisco dc ...Cisco Canada
 
Experiences evaluating cloud services and products
Experiences evaluating cloud services and productsExperiences evaluating cloud services and products
Experiences evaluating cloud services and productsJavier Tallón
 
Data Center of the Future v1.0.pptx
Data Center of the Future v1.0.pptxData Center of the Future v1.0.pptx
Data Center of the Future v1.0.pptxjuergenJaeckel
 
How Cloud Computing will change how you and your team will run IT
How Cloud Computing will change how you and your team will run ITHow Cloud Computing will change how you and your team will run IT
How Cloud Computing will change how you and your team will run ITPeter HJ van Eijk
 
Nist cloud computing-standardsispab-dec2008p-mell-090508165235-phpapp01
Nist cloud computing-standardsispab-dec2008p-mell-090508165235-phpapp01Nist cloud computing-standardsispab-dec2008p-mell-090508165235-phpapp01
Nist cloud computing-standardsispab-dec2008p-mell-090508165235-phpapp01sengura
 
Overview of Cloud Computing
Overview of Cloud ComputingOverview of Cloud Computing
Overview of Cloud ComputingPeter R. Egli
 
Cloud and grid computing by Leen Blom, Centric
Cloud and grid computing by Leen Blom, CentricCloud and grid computing by Leen Blom, Centric
Cloud and grid computing by Leen Blom, CentricCentric
 
Cloud and Grid Computing
Cloud and Grid ComputingCloud and Grid Computing
Cloud and Grid ComputingLeen Blom
 
NECOS Industrial Workshop Technical highlights by Prof. Alex Galis (Universit...
NECOS Industrial Workshop Technical highlights by Prof. Alex Galis (Universit...NECOS Industrial Workshop Technical highlights by Prof. Alex Galis (Universit...
NECOS Industrial Workshop Technical highlights by Prof. Alex Galis (Universit...Christian Esteve Rothenberg
 
Hope, fear, and the data center time machine
Hope, fear, and the data center time machineHope, fear, and the data center time machine
Hope, fear, and the data center time machineCisco Canada
 

Semelhante a Latest Cloud Computing Standards Update (20)

David Terrar the cloud landscape
David Terrar the cloud landscapeDavid Terrar the cloud landscape
David Terrar the cloud landscape
 
The cloud landscape nad 2012
The cloud landscape   nad 2012The cloud landscape   nad 2012
The cloud landscape nad 2012
 
Cloud computing standards and protocols r.nabati
Cloud computing standards and protocols r.nabatiCloud computing standards and protocols r.nabati
Cloud computing standards and protocols r.nabati
 
CompTIA Cloud+ Objectives
CompTIA Cloud+ Objectives CompTIA Cloud+ Objectives
CompTIA Cloud+ Objectives
 
CCNA4 Verson6 Chapter7
CCNA4 Verson6 Chapter7CCNA4 Verson6 Chapter7
CCNA4 Verson6 Chapter7
 
MPLS/SDN 2013 Intercloud Standardization and Testbeds - Sill
MPLS/SDN 2013 Intercloud Standardization and Testbeds - SillMPLS/SDN 2013 Intercloud Standardization and Testbeds - Sill
MPLS/SDN 2013 Intercloud Standardization and Testbeds - Sill
 
CCNA (R & S) Module 02 - Connecting Networks - Chapter 7
CCNA (R & S) Module 02 - Connecting Networks - Chapter 7CCNA (R & S) Module 02 - Connecting Networks - Chapter 7
CCNA (R & S) Module 02 - Connecting Networks - Chapter 7
 
Necos keynote UFRN Telecomday
Necos keynote UFRN TelecomdayNecos keynote UFRN Telecomday
Necos keynote UFRN Telecomday
 
Grid and Cloud Computing Lecture-2a.pptx
Grid and Cloud Computing Lecture-2a.pptxGrid and Cloud Computing Lecture-2a.pptx
Grid and Cloud Computing Lecture-2a.pptx
 
Cisco connect winnipeg 2018 gain insight and programmability with cisco dc ...
Cisco connect winnipeg 2018   gain insight and programmability with cisco dc ...Cisco connect winnipeg 2018   gain insight and programmability with cisco dc ...
Cisco connect winnipeg 2018 gain insight and programmability with cisco dc ...
 
Cloud - Fundamentals
Cloud - FundamentalsCloud - Fundamentals
Cloud - Fundamentals
 
Experiences evaluating cloud services and products
Experiences evaluating cloud services and productsExperiences evaluating cloud services and products
Experiences evaluating cloud services and products
 
Data Center of the Future v1.0.pptx
Data Center of the Future v1.0.pptxData Center of the Future v1.0.pptx
Data Center of the Future v1.0.pptx
 
How Cloud Computing will change how you and your team will run IT
How Cloud Computing will change how you and your team will run ITHow Cloud Computing will change how you and your team will run IT
How Cloud Computing will change how you and your team will run IT
 
Nist cloud computing-standardsispab-dec2008p-mell-090508165235-phpapp01
Nist cloud computing-standardsispab-dec2008p-mell-090508165235-phpapp01Nist cloud computing-standardsispab-dec2008p-mell-090508165235-phpapp01
Nist cloud computing-standardsispab-dec2008p-mell-090508165235-phpapp01
 
Overview of Cloud Computing
Overview of Cloud ComputingOverview of Cloud Computing
Overview of Cloud Computing
 
Cloud and grid computing by Leen Blom, Centric
Cloud and grid computing by Leen Blom, CentricCloud and grid computing by Leen Blom, Centric
Cloud and grid computing by Leen Blom, Centric
 
Cloud and Grid Computing
Cloud and Grid ComputingCloud and Grid Computing
Cloud and Grid Computing
 
NECOS Industrial Workshop Technical highlights by Prof. Alex Galis (Universit...
NECOS Industrial Workshop Technical highlights by Prof. Alex Galis (Universit...NECOS Industrial Workshop Technical highlights by Prof. Alex Galis (Universit...
NECOS Industrial Workshop Technical highlights by Prof. Alex Galis (Universit...
 
Hope, fear, and the data center time machine
Hope, fear, and the data center time machineHope, fear, and the data center time machine
Hope, fear, and the data center time machine
 

Mais de CA API Management

Api architectures for the modern enterprise
Api architectures for the modern enterpriseApi architectures for the modern enterprise
Api architectures for the modern enterpriseCA API Management
 
Mastering Digital Channels with APIs
Mastering Digital Channels with APIsMastering Digital Channels with APIs
Mastering Digital Channels with APIsCA API Management
 
Takeaways from API Security Breaches Webinar
Takeaways from API Security Breaches WebinarTakeaways from API Security Breaches Webinar
Takeaways from API Security Breaches WebinarCA API Management
 
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...CA API Management
 
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...CA API Management
 
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...CA API Management
 
API Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your DataAPI Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your DataCA API Management
 
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...CA API Management
 
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...CA API Management
 
Enabling the Multi-Device Universe
Enabling the Multi-Device UniverseEnabling the Multi-Device Universe
Enabling the Multi-Device UniverseCA API Management
 
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...CA API Management
 
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...CA API Management
 
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...CA API Management
 
Adapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & WinAdapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & WinCA API Management
 
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...CA API Management
 
5 steps end to end security consumer apps
5 steps end to end security consumer apps5 steps end to end security consumer apps
5 steps end to end security consumer appsCA API Management
 
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...CA API Management
 
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...CA API Management
 
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...CA API Management
 
Using APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail ExperienceUsing APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail ExperienceCA API Management
 

Mais de CA API Management (20)

Api architectures for the modern enterprise
Api architectures for the modern enterpriseApi architectures for the modern enterprise
Api architectures for the modern enterprise
 
Mastering Digital Channels with APIs
Mastering Digital Channels with APIsMastering Digital Channels with APIs
Mastering Digital Channels with APIs
 
Takeaways from API Security Breaches Webinar
Takeaways from API Security Breaches WebinarTakeaways from API Security Breaches Webinar
Takeaways from API Security Breaches Webinar
 
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
 
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
 
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
 
API Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your DataAPI Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your Data
 
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
 
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
 
Enabling the Multi-Device Universe
Enabling the Multi-Device UniverseEnabling the Multi-Device Universe
Enabling the Multi-Device Universe
 
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
 
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
 
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
 
Adapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & WinAdapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & Win
 
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
 
5 steps end to end security consumer apps
5 steps end to end security consumer apps5 steps end to end security consumer apps
5 steps end to end security consumer apps
 
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
 
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
 
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
 
Using APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail ExperienceUsing APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail Experience
 

Latest Cloud Computing Standards Update

  • 1. Latest in Cloud Computing Standards Eric A. Hibbard, CISSP, ISSAP, ISSEP, ISSMP, CISA, SCSE CTO Security & Privacy Hitachi Data systems 1
  • 2. Standards Alphabet Soup • CSA = Cloud Security Alliance • DMTF = Distributed Management Task Force • ENISA = European Network and Information Security Agency • ETSI = European Telecommunications Standards Institute • IEC = International Electrotechnical Commission • IEEE = Institute of Electrical and Electronics Engineers • INCITS = International Committee for Information Technology Standards • ISO = International Organization for Standardization • ITU-T = International Telecommunication Union – Telecom • NIST = National Institute for Standards and Technology • OASIS = Organization for the Advancement of Structured Information Standards • SNIA = Storage Networking Industry Association • TCG = Trusted Computing Group 2
  • 3. Sample Cloud SDO Relationships CT-CC ITU-T CSA ISO/IEC ISO/IEC ENISA SC27 SC38 TCG INCITS/ INCITS/ CS1 DAPS38 IEEE NIST SNIA DMTF 3 Formal Informal
  • 5. Cloud Computing… cloud computing: paradigm for enabling [ubiquitous, convenient, on-demand] network access to a shared pool of configurable cloud resources (3.2.4) accessed through services (3.1.8), that can be [rapidly] provisioned and released [with minimal management effort or service provider interaction.] SOURCE: ISO/IEC 2ndCD 17788 5
  • 6. ISO/IEC JTC 1/SC 38 • SC38 = Information Technology – Distributed Application Platforms & Services • ISO/IEC 17788 (Cloud computing – Vocabulary and overview) • Collaborative Team (CT) with ITU-T/SG13 to develop common text • Defines key cloud terminology and provides an overview of cloud computing • Intended to be a foundation document for cloud computing • Stage: 2nd Committee Draft (CD) • ISO/IEC 17789 (Reference architecture) • Collaborative Team (CT) with ITU-T/SG13 to develop common text • Covers general concepts and characteristics of cloud computing, the components/functions and roles and their capabilities and inter-relationships • Focused on the requirements of ―what Cloud services provide, not ―how to design solutions and implementations • Stage: Working Draft (CD) 6 • Under Consideration: • Service Delivery Principles and Service Level Agreements
  • 7. ITU-T/Study Group 13 (SG13) • Future networks including cloud computing, mobile and next- generation networks • Y.ccdef – Cloud computing definition and vocabulary • Y.cceco – Cloud computing: ecosystem, use cases and general requirements • Y.Cloud-SIDE-Reqts – High level requirements and capabilities for cloud enabled service environment • Y.ccic – Framework of inter-cloud for network and infrastructure • Y.ccinfra – Cloud computing infrastructure requirements • Y.ccra – Cloud computing reference architecture • Y.e2eccrmr – End-to-end cloud computing resources management requirements • Y.VNC – Resource control and management for virtual networks for cloud 7 services (VNCs)
  • 8. ITU-T/Study Group 17 (SG17) • Security • X.ccsec – High-level security framework for cloud computing • X.goscc – Guidelines of operational security for cloud computing • X.sfcse – Security functional requirements for Software as a Service (SaaS) application environment • X.idmcc – Requirement of IdM in cloud computing 8
  • 9. ISO/IEC JTC 1/SC27 • SC27 = Information Technology – Security techniques • ISO/IEC 27017 (Code of practice for information security controls for cloud computing services based on ISO/IEC 27002) • Additional implementation guidance for relevant information security controls specified in ISO/IEC 27002; and • Additional controls and implementation guidance that specifically relate to cloud computing services. • Technical Report => International Standard • Stage: 4th Working Draft (WD) • ISO/IEC 27018 (Code of practice for data protection controls for public cloud computing services) • Applies to organizations providing public cloud computing services that act as PII processors (possibly PII controllers) • Establishes commonly accepted control objectives, controls and guidelines for implementing controls to protect 9 • Stage: 2nd Working Draft (WD)
  • 10. ISO/IEC JTC 1/SC27 (cont.) • ISO/IEC 27040 (Storage security) • Overview of storage security concepts and related definitions • Guidance on the threat, design and control aspects associated with typical storage scenarios and storage technology areas • Limited coverage for cloud storage (e.g., CDMI) • Stage: 2nd Committee Draft (CD) • Numerous other security standards that are potentially relevant! 10
  • 11. Standards Setting Organizations (SSO) & Industry Associations 11
  • 12. NIST – Information Technology Laboratory • Special Publication 800-144, Guidelines on Security and Privacy in Public Cloud Computing • Special Publication 800-145, The NIST Definition of Cloud Computing • Special Publication 800-146, Cloud Computing Synopsis and Recommendations • Special Publication 500-291, NIST Cloud Computing Standards Roadmap • Special Publication 500-292, NIST Cloud Computing Reference Architecture • Special Publication 500-293, (Draft). US Government Cloud Computing Technology. • Interagency Report 7904, (Draft) Trusted Geolocation in the Cloud: Proof of Concept Implementation 12
  • 13. Cloud Security Alliance (CSA) • Security Guidance for Critical Areas of Focus in Cloud Computing • Open Certification Framework • Cloud Controls Matrix (CCM) • Trusted Cloud Initiative (TCI) Reference Architecture Model • Top Threats to Cloud Computing • Security as a Service (SecaaS) Implementation Guidance 13
  • 14. OASIS • Cloud Application Management for Platforms (CAMP) • Identity in the Cloud (IDCloud) • Symptoms Automation Framework (SAF) • Topology and Orchestration Specification for Cloud Applications (TOSCA) • Cloud Authorization (CloudAuthZ) • Public Administration Cloud Requirements (PACR) 14
  • 15. Other Cloud Activities of SSOs & IAs • IEEE Standards Association (IEEE-SA) • P2301 - Guide for Cloud Portability and Interoperability Profiles (CPIP) • P2302 - Standard for Intercloud Interoperability and Federation (SIIF) • Internet Engineering Task Force (IETF) • RFC 6208 – Cloud Data Management Interface (CDMI) Media Types • Huge number of RFCs that enable the cloud. • Trusted Computing Group (TCG) • Trusted Multi-Tenant Infrastructure (TMI) Use Cases • Trusted Multi-tenant Infrastructure (TMI) Specification [Goal] • Storage Network Industry Association (SNIA) • Cloud Data Management Interface (CDMI) specification • ISO/IEC 17826: 2012, Information technology -- Cloud Data 15 Management Interface (CDMI) [CDMI v1.0.2]
  • 16. Other Cloud Activities of SSOs & IAs • The Open Group • Service-oriented Cloud Computing Infrastructure (SOCCI) Framework • Cloud Computing Reference Architecture (CCRA) • Distributed Management Task Force (DMTF) • DSP0243 Open Virtualization Format (OVF) • ISO/IEC 17203:2011, Information technology -- Open Virtualization Format (OVF) specification • DSP0263 Cloud Infrastructure Management Interface (CIMI) Model and REST Interface over HTTP Specification • DSP0264 CIMI-CIM Specification 16
  • 17. Final Thoughts • A significant number of the cloud computing standards and specifications are still in draft form • There are many organization operating in this space, but it does appear there are conscious efforts to avoid duplication and contradiction • It is unlikely that a single, all-encompassing standard (or source for standards) will emerge for cloud 17