360 likes | 504 Views
A Private Story. Cost of time in Pharma Research and Discovery. $150/Sec For a Block Buster Project. Imagine a Scientist. Who wants 25 servers. Now!!!. To crunch some numbers!. IT Dept. Try 3 Months!!!. “You want it when?”. He finds a friendly IT Guy.
E N D
A Private Story... Cost of time in Pharma Research and Discovery $150/Sec For a Block Buster Project
Who wants 25 servers... Now!!! To crunch some numbers!
IT Dept.... Try 3 Months!!! “You want it when?”
He finds a friendly IT Guy Who’s being playing in the Clouds!
So he built 25 virtual servers ... ...in about an hour
He loaded up the data! And started the crunching
The processing completed... And the scientist was happy!
The Cost? ? $89
The Benefits of the CloudsorAvoiding The Cloud Trap! Adrian Seccombe
F I R S T C L A S S I F Y Y O U R D A T A !!! Determine what rules MUST apply to it. Must it only exist in specific trust levels? For example can it leave Europe? Does it have to stay in Safe Harbours? Must it stay in Europe? ? Then decide to which type of Cloud you want to move We need a universal data classification model that is simple (cf G8 TLP) We need a recognised trust level standard for all aspects of computing We need standardised meta data that signals to “cloud security” the data’s security needs
To Cloud or Not to Cloud? Traditional Clouds
<<<< Same old TraditionalApproach For all Clouds are not equal... Fully automated System Redundancy Manual System Recovery Fully automated Data Backup and Recovery Tapes sent by Truck Data Backup and Recovery variable risk Fully automated Data Redundancy Self owned Disk Storage Data Redundancy ...sometimes Fully automated Disaster Recovery Warmish Back up Data Centre For Disaster Recovery Significant switching impact And testing costs Full on Clouds this way >>>>>
Cloud Layers Outcome / Value Last! Process 3rd Orchestration Security and IdAM Software A b s t r a c t I o n o c c u r s h e r e ! 2nd Platform 1st Infrastructure
Cloud Patterns External Internal
Cloud Patterns Proprietary Open
Cloud Patterns External Internal Proprietary Open
Cloud Patterns To get through here You need theC O A Deperimeterised Perimeterised
Cloud Patterns External Deperimeterised Internal Perimeterised Proprietary Open
Cloud Patterns External Deperimeterised Internal Perimeterised Proprietary Open We need inter cloud “IPI” standards... especially those that enable Collaboration.
Cloud Patterns External Deperimeterised Internal Perimeterised Proprietary Open Recognise that some interfaces will be easier to enable than others!.
Cloud Patterns External Deperimeterised Internal Perimeterised Proprietary Open
...and ”then” ensure the controls you require are available in the Clouds... ...Oops!!!You mean “Cloud Security Central”doesn’t exist?
Cloud Layers Outcome / Value Last! Process 3rd Orchestration Security and IdAM Software A b s t r a c t I o n o c c u r s h e r e ! 2nd Platform 1st Infrastructure Cloud Maturity Scale
We haven’t even identified all the needs yet. Bread Crumb DetectorBread Crumb HooverCloud Identity Services and their ProvidersWhat about Trust Levels?
Proposed Individual Trust Levels Trust Intent Impact Trust Level Authentication Physical Level Label Activity World equiv T0 Stay None Anonymous None - Unidentified T1 Self Insignificant Self Asserted None Pseudonym Assertion* T2 Proof Minor Document Verified Authenticated: Proof of Abode of Identity Name, Address, Age Electricity Bill T3 T2+ Ability Major Legally/ Financially Authenticate Credit Credit Card to Commit Verified Worthiness and / Pay Payment Method Pay Ability to Pay Varied Single use Authenticate Credit Financially Worthiness and Single Cash Verified Use Payment Method T4 T2+ Material Government Government Passport Gov Id Verified T5 Protect Catastrophic Military Grade Positive Vetting Security Lives Clearance