Ncontrol Grid Cloud Drexel

You might also like

Download as ppt, pdf, or txt
Download as ppt, pdf, or txt
You are on page 1of 18

Steve Markey, PMP, CISSP, CIPP, CISM, CISA

Founder/Principal, nControl
 Grid/Cloud Computing
 Grid Computing Leverages Excess Capacity on Various

Servers for a Supercomputer


 Clusters
 Can be heterogeneous, geographically separated hardware.
 Virtual Machines
 Cloud Computing Presents On-Demand Applications
 Data and Software Reside on a Remote Server
 Access via Browser/Thin-client or Mobile Client
 Grid/Cloud Service Delivery Models
 Infrastructure as a Service (IaaS)
 Compute (Amazon Elastic Compute Cloud (EC2))
 Storage (Amazon Simple Storage Service (S3))
 Grid (Sun Cloud)
 Platform as a Service (PaaS)
 Force.com
 Intuit QuickBase
 Microsoft Azure
 Software as a Service (SaaS)
 Salesforce
 Google Apps & Docs
 Zoho
 Cloud Deployment Modalities
 Public
 Amazon S3 & EC2
 Salesforce
 Google Apps & Docs
 Zoho
 Private
 Cloud Implementations Hosted Internally
 Shared Services/Charge-back Model
 Managed
 mySAP, Microsoft CRM/Project/SharePoint
 Hybrid
 Dedicated Servers Over Private Lines
 Data Center
 Reduce Need for Rack Space, Hardware & Server Software
 Client Software
 Reduce Need for Client Software
 Derivative of Terminal/Mainframe Era
 Security
 Privacy
 Operations
 Security
 Controls
 Logical
 Physical
 Standards/Certification
 Public/Private Sector
 Industry
 Heterogeneous Platforms
 Windows/Linux/UNIX/Android/MacOS X
 Palm/BlackBerry/OS X
 Privacy
 Data
 Ownership
 Flows
 Incident Response
 Data Breach Notification
 Operations
 Single-Point-of-Failure
 “Steve the Internet is down…I am going home…”
 Peripherals
 How do I print?
 Vendor Over-Commitment
 Bandwidth
 Storage Scalability
 Data Recovery
 Vendor Portability/Interoperability
 Open Standards
 Groups/Associations
 Cloud Security Alliance (CSA)
 CSA Guide
 Domains: Cloud Architecture, Governance & ERM, Legal, Electronic
Discovery, Compliance & Audit, Information Lifecycle Management,
Portability & Interoperability, Physical Security & BC/DR, Data Center
Operations, Incident Response & Notification, Application Security,
Encryption & Key Management, Identity & Access Management,
Storage, Virtualization.
 ISACA
 OWASP
 Adoption
 Standardization
 Let Requirements Dictate Adoption
 Remote Access
 Sales & Marketing
 Non-Proprietary, Public Data
 Embrace Grid/Cloud Computing Iteratively
 Non-essential to Essential
 Non-Proprietary to Proprietary
 Public to Confidential
 Data Center then Client Software
 For Once; Let Vendors Dictate
 Worldwide Adoption is Inevitable
 EHR/PHR
 Collaboration/Email/Portals
 Document Management
 Process/Project Management
 For Proprietary Applications/Systems
 Deploy Internally-Built Apps Before Embracing IaaS/PaaS
 Walk Before You Run
 Embrace Private or Hybrid Clouds Before Public Clouds
 Especially for Confidential Data
 Peripherals
 Use Virtual Print Server
 Ex. ThinPrint
 Security
 Best of Breed Standards
 FISMA/NIST
 ISO
 HHS/CCHIT/HITRUST
 Privacy
 Parse Logical Instances

 Group Systems Based on Privacy/Security Reqs


 Industry
 Function
 Geographic Area
 Operations
 Single-Point-of-Failure
 Cached File Drives
 Egnyte Local Cloud
 Most Organizations Have Redundant DataCom
 How about your service providers/vendors?
 Best of Breed Standards
 FISMA/NIST
 ISO
 HHS/CCHIT/HITRUST
 SAS-70 Type II
 IaaS
 Deploy applications in run-time in a way that is abstracted from the
machine image.
 PaaS
 Use careful application development techniques to minimize
potential lock-in with the vendor.
 SaaS
 Perform data extraction processes and backup data independent of
the vendor.

 CSA: http://www.cloudsecurityalliance.org/
 http://www.cloudsecurityalliance.org/guidance/csaguide.pdf
 Twitter
 Uses Google Docs, and an employee using a weak password
led to a Data Breach of their online data.
 Lessons
 Password Standards
 Segregation of Duties

 City of L.A.
 Announced plans to move all e-mail and records retention
processes for city-based services onto the grid (Google).
 Lessons
 Privacy/Compliance
 Project Management/Change Management/Vendor Management
 ?

You might also like