490 likes | 803 Views
Cloud Computing. Steven C. Markey , MSIS, PMP, CISSP, CIPP, CISM, CISA, STS-EV, CCSK Principal , nControl, LLC Adjunct Professor, Philadelphia University. Cloud Computing. Why should you care?. Cloud Computing Trends. Source: Open Group. Cloud Computing. Presentation Overview
E N D
Cloud Computing Steven C. Markey, MSIS, PMP, CISSP, CIPP, CISM, CISA, STS-EV, CCSK Principal, nControl, LLC Adjunct Professor, Philadelphia University
Cloud Computing Why should you care?
Cloud Computing Trends Source: Open Group
Cloud Computing • Presentation Overview • What is it? • Business Case • Cost Benefit Analysis (CBA) • Cloud Strategy/Roadmap • Risk & Cloud
Cloud Computing • What is it? • Re-Branded IT Business Model • Application Service Provider (ASP) • IT Outsourcing (ITO) • Formal Characteristics • Resource Pooling • Rapid Elasticity • Confusion • Hosting • Virtualization • Service Provider
Service Delivery Models Source: Swain Techs
Responsibility Source: Matthew Gardiner, Computer Associates
Private Cloud • Dedicated Clouds • Usually Hosted Internally • Use Chargeback/Shared Services Model • External Private Clouds Exist • Technology is Discussed Later
Technical Feasibility • How is this possible? • Moore’s Law • Ubiquity of Bandwidth & Internet Connectivity • Commoditization of Computing • Virtualization
Type I Hypervisor Source: Virtuatopia
Type II Hypervisor Source: Virtuatopia
Amazon Web Services (AWS) Hypervisor Build Source: Amazon
Citrix Xen Source: VMware
VMware ESX/i Source: VMware
Microsoft Hyper-V Source: Microsoft
IaaS/Private Cloud Outside World Compute Controller Storage/ Volume Controller Management Network (Using APIs) Management and Orchestration VM VM VM VM VM VM VM VM Management and Orchestration Hypervisor Hypervisor Hypervisor Hypervisor Compute Pool Storage Pool Source: Securosis
Cloud Computing • Business Case • Time-to-Market • Operating Expense vs. Capital Expense • Allows for Focus on Core Competency • Elasticity
Cloud Computing • Business Case • Time-to-Market • Global Presence • Focus on Core Competency • Elasticity
Cloud Computing • Business Case • Time-to-Market • You can have brilliant ideas, but if you can not get them across, your ideas will not get you anywhere - Lee Iacocca • Enhanced Responsiveness to Market/Customers
Cloud Computing • Business Case • Global Presence • Barriers to Entry - No More • Multiple Provider Data Centers – Appease Jurisdictions
Cloud Computing • Business Case • Focus on Core Competency • Business Can Focus • Providers Can Focus
Cloud Computing • Business Case • Elasticity
Cloud Computing • CBA • Total Cost of Ownership (TCO) • Return on Investment (ROI) • Controlling Costs • Operating Expense vs. Capital Expense
Cloud Computing • CBA • TCO • Traded for Control/Customization • SaaS Has Lowest TCO • IaaS Has Highest TCO
Cloud Computing • CBA • ROI • Varies, Difficult to Quantify • Whatever the Board/CxO Wants
Cloud Computing • CBA • Controlling Costs • Costs Become Variable versus Fixed • Usually Lower than Fixed • Difficult to Gauge at First
Cloud Computing • CBA • Operating Expense versus Capital Expense • Reduced Up-Front Expenses • Computing Costs are Spread-Out
Cloud Computing Cloud Strategy/Roadmap
Risk & Cloud • The Cloud is Perceived as Risky Business • Lack of Control • Regulatory Compliance • Hacks, Outages, Disasters….Oh My! Source: Youtube
Cloud Governance • The Cloud is Maturing • Security Guidance • CSA Guide v2.1 • ENISA Cloud Computing Risk Assessment • NIST SP 800-144 Guidelines Security/Privacy for a Public Cloud
Cloud Security Alliance (CSA) Guide • CSA Guide v2.1 Domains • Governance & Enterprise Risk • Legal and Electronic Discovery • Information Lifecycle Management • Portability & Interoperability • Traditional Security, BCM/DR • Data Center Operations • Incident Response • Application Security • Encryption & Key Management • Identity and Access Management • Virtualization
ENISA Risk Assessment • ENISA Information Assurance Requirements • Personnel Security • Supply-Chain Assurance • Operational Security • Identity and Access Management • Asset Management • Data and Service Portability • Business Continuity Management • Physical Security • Environmental Controls • Legal Requirements
NIST SP 800-144 • NIST SP 800-144 Domains • Governance • Compliance • Trust • Architecture • Identity and Access Management • Software Isolation • Data Protection • Availability • Incident Response
Vendors Are Getting It (Cont) • They Are Drinking the GRC/InfoSec • Security Practices • http://media.amazonwebservices.com/pdf/AWS_Security_Whitepaper.pdf • http://static.googleusercontent.com/external_content/untrusted_dlcp/www.google.com/en/us/a/help/intl/en/admins/pdf/ds_gsa_apps_whitepaper_0207.pdf • http://www.microsoft.com/windowsazure/whitepapers/
Vendors Are Getting It (Cont) • They Are Drinking the GRC/InfoSec • Virtual Private Cloud (VPC) Source: Amazon
AWS Firewall Source: Amazon
Mapping Traditional Defenses to the Cloud No change Input Validation, Sanitization, Fuzzing Scoping Issues, Application-level DoS protection Subdomain scope, Application request throttling Authentication, Authorization, Audit ADFSv2, WLID, ACS, MDS Storage ACLs Shared-Access Signatures Certificate Services WACS via Azure Development Portal IPC Internal Endpoints Source: Microsoft
Defenses Inherited by Azure Tenants Spoofing Tampering & Disclosure Denial of Service Elevation of Privilege VLANs Top of Rack Switches Custom packet filtering VM switch hardening Certificate Services Shared-Access Signatures HTTPS Sidechannel protections Load-balanced Infrastructure Network bandwidth throttling DDoS protection on Storage nodes Configurable scale-out Partial Trust Runtime Hypervisor custom sandboxing Virtual Service Accounts Repudiation Monitoring / Diagnostics Service Source: Microsoft
Questions? • Contact • Email: markeys@philau.edu, steve@ncontrol-llc.com • Twitter: markes1