Cloud Computing NATIONAL SECURITY ENERGY & ENVIRONMENT HEALTH CYBERSECURITY. SAIC. All rights reserved.
|
|
|
- Daniella Townsend
- 10 years ago
- Views:
Transcription
1 Cloud Computing James Fanning, Ph.D. Chief Engineer and VP Enterprise and Mission Solutions Business Unit Science Applications International Corporation 07 DEC 2011 NATIONAL SECURITY ENERGY & ENVIRONMENT HEALTH CYBERSECURITY
2 Introduction Cloud-First strategy, part of the federal 25-point IT plan and motivations Important role of NIST Definitions Reference architecture Federal Information Security Management Act (FISMA) Standards Acceleration to Jumpstart Adoption of Cloud Computing (SAJACC) Business use cases (BUCs) Why, when, and where does it make good business sense to migrate to a cloud? Cross-cutting business use cases What business functions make sense? Role of GSA infrastructure-as-a-service (IAAS) and -as-a-service (EAAS) Late-breaking news from the Cloud PMO - GSA NIST = National Institute of Standards and Technology GSA = General Services Administration PMO = Project Management Office 2
3
4 What Is the Cloud and Where Is It Useful? Business Week The Wall Street Journal Economist.com Gartner WashingtonPost.com FT.com Washington Technology TechWorld The Seattle Times The New York Times PDFzone >>> Information Week National Public Radio WIRED Technology Review 4
5 Federal Government Drivers and Trends: 25-Point Plan, Including Cloud-First Strategy (Dec. 9, 2010) >> Feb 8, 2011 PART I: ACHIEVING OPERATIONAL EFFICIENCY A. Apply Light Technology "and Shared Solutions 1.Complete detailed implementation plans to consolidate at least 800 data centers by Create a government-wide marketplace for data center availability 3.Shift to a Cloud First policy 4.Stand-up contract vehicles for secure IaaS solutions 5.Stand-up contract vehicles for commodity services 6.Develop a strategy for shared services PART II: EFFECTIVELY MANAGING LARGE- SCALE IT PROGRAMS. Cloud First Strategy Begins immediately with three (3) parts: Use commercial cloud technologies where feasible Launch private government clouds Utilize regional clouds with state and local governments Default to cloud-based solutions 3.1 Publish cloud strategy Federal CIO will publish a strategy to accelerate the safe and secure adoption NIST will facilitate and lead the development of standards 3.2 Jump-start the migration to cloud technologies required to identify three must move services and create a project plan for migrating each of them to cloud solutions and retiring the associated legacy systems. Of the three, at least one of the services must fully migrate to a cloud solution within 12 months and the remaining two within 18 months. 5 NIST = National Institute of Standards and Technology CIO = Chief Information Officer
6 IT Memorandum Examples 6
7 The Spending Motivation Source: Federal Cloud Computing Strategy, FEB2011, Appendix 1: Potential spending on cloud computing by agency. Agency estimates reported to the Office of Management and Budget (OMB). 7
8 The Utilization Motivation Distributed Component-Orientation Virtualized Layer-Orientation Automated Service-Orientation POWER: Computers typically require 70% of their total power requirements to run at just 15% utilization. Source: Gartner Group, Cost of Traditional Data Centers (2009), and Data Center Efficiency (2010). 8
9 Primary Activities Within the Federal Cloud Project Management Office (PMO) Apps.gov FedRAMP Federal Data Center Consolidation Initiative Infrastructureas-a-Service (Development) Softwareas-a-Service ( ) Platformas-a-Service (Geospatial) FDCCI First federal storefront offering commoditized cloud services Authorize once, use many approach to security for cloud service providers Assist agencies to consolidate at least 800 data centers by Fiscal Year 2015 Commodity computing resources - GSA BPAs, DISA RACE Cloud to be made available (Awards now spring of 2012 ) Federal Geographic Data Committee (FGDC) and GSA GeoCloud Sandbox Initiative FedRAMP (Federal Risk and Authorization Management Program) is a trademark of the United States General Services Administration in the U.S. and/or other countries. 9 Business Use Cases Addressed Here GSA = General Services Administration, BPAs = blanket purchase agreements, DISA = Defense Information Systems Agency Rapid Access Computing Environment
10 Reinforcing the Federal Strategic Decision Regarding Cloud Computing Federal Cloud Computing Strategy called out the important role of NIST in promoting standards and security measures for cloud computing: Cloud definitions and guidance. Special Publication (SP) series include [ SP 500 series for Information Technology SP 800 series Computer Security Computer security-related Federal Information Processing Standards (FIPS) Industry/government working groups/committees established for: FedRAMP (Federal Risk Assessment Management Program) for cross-agency C&A with utilization of NIST SP (and others) as a tech basis under Federal Information Security Management Act (FISMA) SAJACC (Standards Acceleration to Jumpstart Adoption of Cloud Computing) Reference architecture definition Business use cases definition NIST = National Institute of Standards and Technology FedRAMP is a trademark of the United States General Services Administration in the U.S. and/or other countries. 10
11 NIST Special Publication Cloud Examples (as of November 2011) SP aimed at accelerating the cloud computing adoption by federal agencies: NIST SP , Cloud Computing Standards Roadmap (10 AUG 2011) NIST SP , Cloud Computing Reference Architecture (08 SEP 2011) NIST SP , US Government Cloud Computing Technology Roadmap (~NOV 2011) Volume I, High-Priority requirements to Further USG Agency Cloud Computing Adoption (Draft) Volume II, Useful Information for Cloud Adopters (Draft) Volume III, Technical Considerations for USG Cloud Computing Deployment Decisions (Draft) NIST SP A, Guide for Assessing the Security Controls in Federal Information Systems and Organizations (29 JUN 2010) NIST SP , Information Security Continuous Monitoring for Federal Information Systems and Organizations (SEP 2011) NIST SP , Guidelines on Security and Privacy in Public Cloud Computing (Draft, JAN 2011) NIST SP , The NIST Definition of Cloud Computing (SEP 2011) NIST SP , Cloud Computing Synopsis and Recommendations (Draft, MAY 2011) NIST = National Institute of Standards and Technology SP = special publication 11
12 Cloud Computing Reference Architecture (SP SEP 2011 ) Source: 12
13 Federal Information Security Management Act (FISMA) Comprehensive framework to protect government information, operations and assets against natural or manmade threats Many federal agencies stipulate FISMA certification as a requirement for their IT solutions Certification and accreditation are confirmed by the General Services Administration Consolidates many security requirements and guidance into an overall framework) SC information system = {(confidentiality, impact), (integrity, impact), (availability, impact)} Security category LOW limited MODERATE serious HIGH catastrophic Requires executive agencies within the federal government to Plan, assign, review, authorize FISMA has three main sections: Reporting requirement Independent evaluation Corrective action plan SP A SP SP SP A Security Control Monitoring System Authorization Security Control Assessment FIPS 199 SP SP Security Categorization Security Control Implementation FIPS 200 SP SP SP SP Security Control Selection Security Control Supplement Security Control Documentation 13 FIPS = Federal Information Processing Standard SP = special publication
14 Cloud Security Concerns (NIST Working List 02NOV11) NIST_Security_Requirements_for_US_Government_Cloud.pdf 1. Potential Loss of Control/Ownership of Data 2. Data Integration, Privacy Enforcement, Data Encryption 3. Security Concerns are Identified Threats - CSA's Top Threats (7) 4. Data Remanence after de-provisioning 5. Multi Tenant Data Isolation 6. Data Location Requirements (within national borders) 7. Hypervisor Security 8. Audit Data Integrity Protection 9. Ensuring Verification of Subscriber policies (including regulatory needs) through Provider controls 10. Certification/Accreditation Requirements for a given Cloud Service Source: CSA = Cloud Security Alliance NIST = National Institute of Standards and Technology 14
15 NIST 3-Part Cloud Definition (SP SEP 2011) Service Models e.g. = for example 15 Software-as-a-service is access to virtualized applications via thin clients (e.g., Web browser) Platform-as-a-service is access to programming environments and tools Infrastructure-as-a-service is access to an operating environment (e.g., servers, storage, network) Deployment Models Cloud infrastructure operated solely for a single organization; can be third party; onor off-premises Cloud infrastructure shared by multiple organizations with similar mission or interest; can be third party; on-or off-premises Cloud infrastructure is property of the cloud provider and open to everyone Combination of two or more deployment types; enabling portability and cloud bursting Essential Characteristics On-demand self-service Broad network access Resource pooling Rapid elasticity (scale up/down) Measured service
16 Cost Tradeoffs Between Cost and Security for the Cloud Deployment Models Hybrid Private Community Public Risk 16
17 IaaS, PaaS, SaaS Stack Ownership Infrastructure As a Service (IaaS) Platform As a Service (PaaS) Software As a Service (SaaS) Business Business Business Applications Applications Applications Cloud Consumer Runtimes Security & Integration Runtimes Security and Integration Runtimes Security and Integration Databases Databases Databases Servers Servers Servers Virtualization Virtualization Virtualization Cloud Provider Server Hardware Server Hardware Server Hardware Storage Storage Storage Networking Networking Networking 17
18 IaaS, PaaS, SaaS Vendor Examples Service Model Government <<<<<< Commercial <<<<<< Software as a service (SaaS) GSA Apps.Gov Google Apps PayPal ZOHO work online Salesforce Platform as a service (PaaS) Infrastructure as a service (IaaS) Federal Geographic Data Committee (FGDC) & GSA GeoCloud Sandbox Initiative DISA RACE Flexible Payments Service TM (FPS) amazon web services Simple Storage Service (S3) Elastic Compute Cloud (EC2). force.com GoGrid Windows Azure YAHOO! DEVELOPER NETWORK Google App Engine 18 GSA = General Services Administration DISA RACE = Defense Information Systems Agency Rapid Access Computing Environment, Trademark attributions on slide 35
19 For instance, AWS Recent News September 15, 2011, Amazon company statement Amazon Web Services (AWS ) hosted storage and computing products have achieved FISMA Moderate certification Amazon Web Services now has PCI DSS Level 1 credit card standards, FIPS 140-2, ISO international security standard, and SAS-70 type II auditing standard certifications, and the HIPAA health data privacy act The configurations and controls required by FISMA Moderate are extensive, according to Amazon, and include third-party audits and process documentation Public-sector customers including Recovery.gov, Treasury.gov and the Federal Register are using the Amazon Elastic Compute Cloud for flexible computing power The company has established a partitioned AWS GovCloud specifically for government customers 19 Can handle data subject to International Traffic in Arms Regulations (ITAR) AWS GovCloud is physically and logically accessible by U.S. persons only Procure cloud computing services from AWS at the FISMA Moderate level using the GSA IaaS BPA (blanket purchase agreement) FISMA = Federal Information Security Management Act PCI DSS = Payment Card Industry Data Security Standard FIPS Federal Information Processing Standard SAS-70 = Statement on Auditing Standards No. 70 HIPAA = Health Insurance Portability and Accountability Act GSA IaaS = General Services Administration Infrastructure as a service ISO is a registered trademark of the International Organization for Standardization in the U.S. and/or other countries. AWS is a registered trademark of Amazon Technologies, Inc. in the U.S. and/or other countries.
20 Cloud Broker Example Application & Services enstratus Right Scale Cloud Enterprise Management Layer amazon web services DATALINE ServerVault terremark NASA NEBULA Cloud Delivery Layer CLOUD SWITCH CITRIX Eucalyptus Systems, Inc. Xen EMC vcloud Express vmware Cloud Framework & Application Interface Layer Virtualization Layer CISCO BROCADE EMC DELL Sun DELL Sun Data Center Components 20 Trademark attributions on slide 35
21 Why Government Is Turning to the Cloud? Agility, speed, and flexibility Rapid deployment and change management (Minutes vs. months to provision IT resources) Adaptable to changing/unpredictable business needs Ideal for cyclical or episodic circumstances User self-service capabilities possible Financial benefits Cost savings vs. legacy (some perceived, some real) Pay-as-you-go model reduces financial risk and exposure Move from capital expense (CapEx) to operating expense (OpEx) A natural for green IT and data center consolidation mandates 21
22 Why Government Is Turning to the Cloud? Simplicity and convenience Easy, on-demand procurement of cloud services promised Encourages use of standardized resources/applications Easy mobile access to applications globally New capabilities New integrated solutions not feasible before Most security risks well mitigated and being addressed by FedRAMP New citizen services opportunities facilitated by wide cloud adoption FedRAMP is a trademark of the United States General Services Administration in the U.S. and/or other countries. 22
23 Mission Areas for Government Business Use Cases Large egovernment, public, information dissemination mission, and those subject to flash crowds should be among the first adopters (with minimal security risk) A cyclical and seasonal set of requirements (for example, census, IRS, NOAA, DOE, agriculture) Large databases and statistical responsibility requiring large-scale scientific and technical computing resources (largely to be on standby) IRS = Internal Revenue Service NOAA = National Oceanic and Atmospheric Administration DOE = Department of Energy 23
24 Mission Areas for Government Business Use Cases Episodic requirements which can benefit from rapid, on-demand cloud provisioning Emergency management per the Federal Response Plan with 28 agencies and FEMA International support (for example, Japanese earthquake and tsunami; Middle East crises, etc.) e-filing, complex multi-directional object submission, public collaboration, benefits transfer, and grants management -- egovernment applications 24 FEMA = Federal Emergency Management Agency
25 Mission Areas for Government Business Use Cases Broad and distributed defense, international, financial, and intelligence responsibility needing to Gather information, collaborate, analyze, visualize, develop situational awareness, and deliver information Also includes mobile delivery Examples: border surveillance, financial market surveillance, environmental monitoring Well-defined communities and regulatory responsibility to adopt a push/pull scenario for secure access to regulated distributed databases Well-defined business functions that can be typically out-sourced and acquired as SaaS, such as HR and financial management (FM) SaaS = software as a service HR = human resources 25
26 Cross-cutting Business Use Cases Most organizations perform a common set of business functions that are amenable to a cloud-based approach within the four NIST delivery models: Development and test Search and retrieval Records management services and digital notary Information dissemination e-filing electronic submission of documents/data with receipts and validation ( electronic mailroom ) Benefits and grant transfer Collaboration and information sharing Social networking Mobile access/delivery Communications ( and messaging) ediscovery, statistical analysis, and analytics Geospatial services (PAAS) Workflow management Archiving and data storage Document management Backup and recovery and continuity of operations (COOP) Data gathering and situational awareness FOIA support services ITIL and SLA management-as-a-service Managed security services (for example, identity management, penetration testing, persistent PKI, continuous monitoring, intrusion detection, managed endpoint security) NIST = National Institute of Standards and Technology PAAS = platform as a service, FOIA = Freedom of Information Act, SLA = service level agreement ITIL is a registered trademark, and a registered community trademark, of the Minister for the Cabinet and 26 is registered in the U.S. Patent and Trademark Office.
27 Secure efiling With Records Management and Interchange Across Business Partners Infrastructure-as-a-Service 27
28 GSA IAAS Provides the Infrastructure for Hosting the BUCs BUCs = business use cases GSA IAAS = General Services Administration infrastructure as a service BPA = blanket purchase agreement 28
29 GSA IAAS Provides the Infrastructure for Hosting the BUCs Issues and observations Number of awardees is high Awardees currently striving to achieve FISMA Moderate security assessment via FedRAMP The GSA BPA for IAAS DID NOT provide for system integrator (SI) services, nor any labor services for actual development and migration of agency apps/data/use cases to the cloud IAAS was pure, low-cost, commodity cloud services BPA for servers, storage, and network resources SLAs included but with differences (for example, service availability of 99.5 percent) Agencies are beginning to be inundated and perplexed as to whom to select The hard work still lies ahead regarding WHAT functions and business use cases should they implement (key risks and migration measures) GSA IAAS = General Services Administration infrastructure as a service BUCs = business use cases FISMA = Federal Information Security Management Act BPA = blanket purchase agreement SLAs = service level agreements FedRAMP is a trademark of the United States General Services Administration in the U.S. and/or other countries. 29
30 NEW: GSA as a Service (EAAS) Embeds Many NIST Business Use Cases Even more competitors are expected with $2.5 billion ceiling Now contains applications migration and integration services with 11 labor categories FedRAMP up to FISMA HIGH Many NIST cross-cutting business use cases now incorporated in lots: 30 and collaboration ediscovery and searching Archiving, storage, backup and restore services Social networking (ala Web page development) Records management services Mobile delivery Five service offerings: Lot 1: -as-a-Service (EAAS) Lot 2: Office Automation Lot 3: Electronic Records Management Lot 4: Migration Services Lot 5: Integration Services Four categories of cloud computing: Government community cloud Provider-furnished equipment private cloud Secret enclave Public cloud GSA = General Services Administration NIST = National Institute of Standards and Technology FISMA = Federal Information Security Management Act FedRAMP is a trademark of the United States General Services Administration in the U.S. and/or other countries.
31 NEW: GSA -as-a-Service Update ( 22 NOV 2011 ) General Services Administration (GSA) reopens cloud RFQ as of Tuesday, 11/22/2011, 3:45 p.m. Eastern Time GSA now: Better defines government community cloud as a multi-tenant cloud offering limited exclusively to United States federal, state, local and tribal governments with registered.gov or.mil domain addresses Asks for a designated chief information security officer and an acceptable use policy Asks for location of their data centers Calls for encrypted data to use the designated standards for data "at rest" and "in transit Calls for connection to the agency's Trusted Internet Connection gateway The cloud computing contract has a ceiling of $2.5 billion over five years. Agencies are waiting to use the blanket purchase agreement. The Office of Management and Budget said earlier this year that 15 agencies were ready to move 950,000 mail boxes to the cloud. 31
32 Observations and Final Thoughts NIST business use cases are viable for implementation in a cloud. Several implementations already exist as exemplars with lessons learned Many organizations are beginning with a private cloud a safe but less costeffective starting point. Many IT organizations view a cloud computing roadmap as a technology implementation rather than a change agent for business processes. They need to partner with the CFO and other internal stakeholders to deliver business process value first and foremost More of a business transformation than a technology revolution An enlightened design can securely integrate internal and external resources learn and appreciate the standards especially security and interoperability NIST = National Institute of Standards and Technology CFO = Chief Financial Officer 32
33 Observations and Final Thoughts The public cloud will become more secure and less risky as time goes on. Virtually every organization has something like information dissemination or e- learning that can be a test case for the public cloud Besides, you can always encrypt and store the keys in your trusted private environment Community clouds will initially form around classes of users. Over time, however, communities will align to feature certain capabilities (like financial management providers) in clouds optimized to provide that kind of service. Prescient organizations will redefine the role of the IT department as part of a move to cloud computing. Personnel will need training and eventual redeployment to harness talent and achieve efficiencies. 33
34 Thank You James J Fanning, Ph.D. SAIC Chief Engineer and Vice President Enterprise and Mission Solutions Business Unit James.J.Fanning@ (719)
35 Trademark Attributions Amazon Web Services and Flexible Payments Service are trademarks or registered trademarks of Amazon Technologies, Inc. in the U.S. and/or other countries. Brocade is a registered trademark of Brocade Communications Systems, Inc. in the U.S. and/or other countries. Cisco is a registered trademark of Cisco Technology, Inc. in the U.S. and/or other countries. Citrix and Xen are registered trademarks of Citrix Systems, Inc. in the U.S. and/or other countries. The CloudShield logo is a registered trademark of CloudShield Technologies (an SAIC Company) in the U.S. and/or other countries. CloudSwitch is a registered trademark of CloudSwitch, Inc. in the U.S. and/or other countries. Dell is a registered trademark of Dell Inc. in the U.S. and/or other countries. EMC is a registered trademark of EMC Corporation in the U.S. and/or other countries. enstratus is a trademark of enstratus Networks LLC in the U.S. and/or other countries. GoGrid is a registered trademark of GoGrid, LLC in the U.S. and/or other countries. Google is a registered trademark of Google Inc. in the U.S. and/or other countries. NEBULA is a registered trademark of the National Aeronautics and Space Administration in the U.S. and/or other countries. PayPal is a registered trademark of PayPal, Inc. in the U.S. and/or other countries. Right Scale is a registered trademark of RightScale, Inc. in the U.S. and/or other countries. Salesforce and force.com are registered trademarks of salesforce.com, inc. in the U.S. and/or other countries. The SAIC logo is a registered trademark of Science Applications International Corporation in the U.S. and/or other countries. ServerVault is a registered trademark of ServerVault Corp. in the U.S. and/or other countries. Sun is a registered trademark of Oracle America, Inc. in the U.S. and/or other countries. VCloud and VMware are registered trademarks of VMware, Inc. in the U.S. and/or other countries. Terremark is a trademark of Terremark Trademark Holdings, Inc. in the U.S. and/or other countries. Windows Azure is a trademark of Microsoft Corporation in the U.S. and/or other countries. Yahoo! Is a registered trademark of Yahoo! Inc. in the U.S. and/or other countries. ZOHO is a registered trademark of ZOHO Corporation in the U.S. and/or other countries. 35
Cloud Services Overview
Cloud Services Overview John Hankins Global Offering Executive Ricoh Production Print Solutions May 23, 2012 Cloud Services Agenda Definitions Types of Clouds The Role of Virtualization Cloud Architecture
Federal Cloud Computing Initiative Overview
Federal Cloud Computing Initiative Overview Program Status To support the Federal Cloud Computing Direction and Deployment Approach, the ITI Line of Business PMO has been refocused as the Cloud Computing
Seeing Though the Clouds
Seeing Though the Clouds A PM Primer on Cloud Computing and Security NIH Project Management Community Meeting Mark L Silverman Are You Smarter Than a 5 Year Old? 1 Cloud First Policy Cloud First When evaluating
Infrastructure as a Service (IaaS)
Infrastructure as a Service (IaaS) DLT Solutions LLC May 2011 Contact Information DLT Cloud Advisory Group 1-855-CLOUD01 (256-8301) [email protected] dl www.dlt.com/cloud Your Hosts Van Ristau Chief Technology
ITL BULLETIN FOR JUNE 2012 CLOUD COMPUTING: A REVIEW OF FEATURES, BENEFITS, AND RISKS, AND RECOMMENDATIONS FOR SECURE, EFFICIENT IMPLEMENTATIONS
ITL BULLETIN FOR JUNE 2012 CLOUD COMPUTING: A REVIEW OF FEATURES, BENEFITS, AND RISKS, AND RECOMMENDATIONS FOR SECURE, EFFICIENT IMPLEMENTATIONS Shirley Radack, Editor Computer Security Division Information
Hexaware E-book on Q & A for Cloud BI Hexaware Business Intelligence & Analytics Actionable Intelligence Enabled
Hexaware E-book on Q & A for Cloud BI Hexaware Business Intelligence & Analytics Actionable Intelligence Enabled HEXAWARE Q & A E-BOOK ON CLOUD BI Layers Applications Databases Security IaaS Self-managed
STATEMENT OF. Dr. David McClure Associate Administrator Office of Citizen Services and Innovative Technologies General Services Administration
STATEMENT OF Dr. David McClure Associate Administrator Office of Citizen Services and Innovative Technologies General Services Administration BEFORE THE HOUSE SCIENCE, SPACE AND TECHNOLOGY COMMITTEE SUBCOMMITTEE
ISSUE BRIEF. Cloud Security for Federal Agencies. Achieving greater efficiency and better security through federally certified cloud services
ISSUE BRIEF Cloud Security for Federal Agencies Achieving greater efficiency and better security through federally certified cloud services This paper is intended to help federal agency executives to better
Realizing the Value Proposition of Cloud Computing
Realizing the Value Proposition of Cloud Computing CIO s Enterprise IT Strategy for Cloud Jitendra Pal Thethi Abstract Cloud Computing is a model for provisioning and consuming IT capabilities on a need
Architectural Implications of Cloud Computing
Architectural Implications of Cloud Computing Grace Lewis Research, Technology and Systems Solutions (RTSS) Program Lewis is a senior member of the technical staff at the SEI in the Research, Technology,
Cloud Security for Federal Agencies
Experience the commitment ISSUE BRIEF Rev. April 2014 Cloud Security for Federal Agencies This paper helps federal agency executives evaluate security and privacy features when choosing a cloud service
OWASP Chapter Meeting June 2010. Presented by: Brayton Rider, SecureState Chief Architect
OWASP Chapter Meeting June 2010 Presented by: Brayton Rider, SecureState Chief Architect Agenda What is Cloud Computing? Cloud Service Models Cloud Deployment Models Cloud Computing Security Security Cloud
Cloud Computing: Making the right choices
Cloud Computing: Making the right choices Kalpak Shah Clogeny Technologies Pvt Ltd 1 About Me Kalpak Shah Founder & CEO, Clogeny Technologies Passionate about economics and technology evolving through
CLOUD COMPUTING. Agencies Need to Incorporate Key Practices to Ensure Effective Performance
United States Government Accountability Office Report to Congressional Requesters April 2016 CLOUD COMPUTING Agencies Need to Incorporate Key Practices to Ensure Effective Performance GAO-16-325 April
STATEMENT OF. Dr. David McClure Associate Administrator Office of Citizen Services and Innovative Technologies General Services Administration
STATEMENT OF Dr. David McClure Associate Administrator Office of Citizen Services and Innovative Technologies General Services Administration BEFORE THE HOUSE COMMITTEE ON HOMELAND SECURITY SUBCOMMITTEE
How To Use Cloud Computing For Federal Agencies
Cloud Computing Briefing Scott Renda Office of Management and Budget www.whitehouse.gov/omb/egov Cloud Computing Basics Style of computing Cloud Computing: What Does it Mean? Close public/private sector
With Eversync s cloud data tiering, the customer can tier data protection as follows:
APPLICATION NOTE: CLOUD DATA TIERING Eversync has developed a hybrid model for cloud-based data protection in which all of the elements of data protection are tiered between an on-premise appliance (software
Cloud Courses Description
Courses Description 101: Fundamental Computing and Architecture Computing Concepts and Models. Data center architecture. Fundamental Architecture. Virtualization Basics. platforms: IaaS, PaaS, SaaS. deployment
Running Oracle Applications on AWS
Running Oracle Applications on AWS Bharath Terala Sr. Principal Consultant Apps Associates LLC June 09, 2014 Copyright 2014. Apps Associates LLC. 1 Agenda About the Presenter About Apps Associates LLC
When Security, Privacy and Forensics Meet in the Cloud
When Security, Privacy and Forensics Meet in the Cloud Dr. Michaela Iorga, Senior Security Technical Lead for Cloud Computing Co-Chair, Cloud Security WG Co-Chair, Cloud Forensics Science WG March 26,
Cloud Computing. Bringing the Cloud into Focus
Cloud Computing Bringing the Cloud into Focus November 2011 Introduction Ken Cochrane CEO, IT/NET Partner, KPGM Performance and Technology National co-leader IT Advisory Services KPMG Andrew Brewin Vice
10 Considerations for a Cloud Procurement. Anthony Kelly Erick Trombley David DeBrandt Carina Veksler January 2015
10 Considerations for a Cloud Procurement Anthony Kelly Erick Trombley David DeBrandt Carina Veksler January 2015 www.lbmctech.com [email protected] Purpose: Cloud computing provides public sector organizations
Secure Cloud Computing through IT Auditing
Secure Cloud Computing through IT Auditing 75 Navita Agarwal Department of CSIT Moradabad Institute of Technology, Moradabad, U.P., INDIA Email: [email protected] ABSTRACT In this paper we discuss the
A COALFIRE PERSPECTIVE. Moving to the Cloud. NCHELP Spring Convention Panel May 2012
A COALFIRE PERSPECTIVE Moving to the Cloud A Summary of Considerations for Implementing Cloud Migration Plans into New Business Platforms NCHELP Spring Convention Panel May 2012 DALLAS DENVER LOS ANGELES
BUYER S GUIDE CLOUD HOSTING. This ebook will help you:
This ebook will help you: Understand the benefits of cloud computing Determine which cloud solution is best for your business needs Discover what to look for in a prospective cloud provider 877.843.7627
Cloud Computing Technology
Cloud Computing Technology The Architecture Overview Danairat T. Certified Java Programmer, TOGAF Silver [email protected], +66-81-559-1446 1 Agenda What is Cloud Computing? Case Study Service Model Architectures
VMware vcloud Powered Services
SOLUTION OVERVIEW VMware vcloud Powered Services VMware-Compatible Clouds for a Broad Array of Business Needs Caught between shrinking resources and growing business needs, organizations are looking to
Outline. What is cloud computing? History Cloud service models Cloud deployment forms Advantages/disadvantages
Ivan Zapevalov 2 Outline What is cloud computing? History Cloud service models Cloud deployment forms Advantages/disadvantages 3 What is cloud computing? 4 What is cloud computing? Cloud computing is the
Cloud Computing and Data Center Consolidation
Cloud Computing and Data Center Consolidation Charles Onstott, PMP Chief Technology Officer, Enterprise IT Services SAIC Steven Halliwell General Manager for State and Local and Education Sales Amazon
Inside the Cloud The Supporting Architecture of Cloud Computing. Jack Hanison [email protected]
Inside the Cloud The Supporting Architecture of Cloud Computing Jack Hanison [email protected] What is Cloud Computing? 2 http://www.flickr.com/photos/galego/3131005845/ Is Cloud Computing these
Cloud Security & Risk. Adam Cravedi, CISA Senior IT Auditor [email protected]
Cloud Security & Risk Adam Cravedi, CISA Senior IT Auditor [email protected] Agenda About Compass Overcast - Cloud Overview Thunderheads - Risks in the Cloud The Silver Lining - Security Approaches
Cloud Computing. What is Cloud Computing?
Cloud Computing What is Cloud Computing? Cloud computing is where the organization outsources data processing to computers owned by the vendor. Primarily the vendor hosts the equipment while the audited
Cloud Services The Path Forward. Mr. Stan Kaczmarczyk Acting Director - Strategic Solutions and Security Services FAS/ ITS, GSA
Cloud Services The Path Forward Mr. Stan Kaczmarczyk Acting Director - Strategic Solutions and Security Services FAS/ ITS, GSA November 1, 2012 Agenda Integrated Technology Services (ITS) Cloud Acquisition
Esri Managed Cloud Services and FedRAMP
Federal GIS Conference February 9 10, 2015 Washington, DC Esri Managed Cloud Services and FedRAMP Erin Ross & Michael Young Agenda Esri Managed Services Program Overview Example Deployments New FedRAMP
Cloud Computing in Banking
Financial Services the way we see it Cloud Computing in Banking What banks need to know when considering a move to the cloud Contents 1 Overview 3 2 Why Cloud Computing for Banks? 4 2.1 Cost Savings and
U.S. General Services Administration. Infrastructure as a Service (IaaS) Blanket Purchase Agreement (BPA) Fact Sheet
U.S. General Services Administration Infrastructure as a Service (IaaS) Blanket Purchase Agreement (BPA) Fact Sheet May 2014 Quick Facts Infrastructure as a Service (IaaS) BPA was awarded in October 2010
A Gentle Introduction to Cloud Computing
A Gentle Introduction to Cloud Computing Source: Wikipedia Platform Computing, Inc. Platform Clusters, Grids, Clouds, Whatever Computing The leader in managing large scale shared environments o 18 years
journey to a hybrid cloud
journey to a hybrid cloud Virtualization and Automation VI015SN journey to a hybrid cloud Jim Sweeney, CTO GTSI about the speaker Jim Sweeney GTSI, Chief Technology Officer 35 years of engineering experience
Cloud Courses Description
Cloud Courses Description Cloud 101: Fundamental Cloud Computing and Architecture Cloud Computing Concepts and Models. Fundamental Cloud Architecture. Virtualization Basics. Cloud platforms: IaaS, PaaS,
Clinical Trials in the Cloud: A New Paradigm?
Marc Desgrousilliers CTO at Clinovo Clinical Trials in the Cloud: A New Paradigm? Marc Desgrousilliers CTO at Clinovo What is a Cloud? (1 of 3) "Cloud computing is a model for enabling convenient, on-demand
NIST Cloud Computing Program Activities
NIST Cloud Computing Program Overview The NIST Cloud Computing Program includes Strategic and Tactical efforts which were initiated in parallel, and are integrated as shown below: NIST Cloud Computing
Cloud Security considerations for business adoption. Ricci IEONG CSA-HK&M Chapter
Cloud Security considerations for business adoption Ricci IEONG CSA-HK&M Chapter What is Cloud Computing? Slide 2 What is Cloud Computing? My Cloud @ Internet Pogoplug What is Cloud Computing? Compute
Cloud Computing A NIST Perspective & Beyond. Robert Bohn, PhD Advanced Network Technologies Division
Cloud Computing A NIST Perspective & Beyond Robert Bohn, PhD Advanced Network Technologies Division ISACA National Capital Area Chapter Arlington, VA, USA 17 March 2015 Cloud Program Overview Launch &
Tips For Buying Cloud Infrastructure
27 Tips For Buying Cloud Infrastructure A Comprehensive list of questions to ask yourself when reviewing potential cloud providers By Christopher Wilson @chrisleewilson Table of Contents Intro: Evaluating
Expert Reference Series of White Papers. Understanding NIST s Cloud Computing Reference Architecture: Part II
Expert Reference Series of White Papers Understanding NIST s Cloud Computing Reference Architecture: Part II [email protected] www.globalknowledge.net Understanding NIST s Cloud Computing Reference
The Hybrid Cloud: Bringing Cloud-Based IT Services to State Government
The Hybrid Cloud: Bringing Cloud-Based IT Services to State Government October 4, 2009 Prepared By: Robert Woolley and David Fletcher Introduction Provisioning Information Technology (IT) services to enterprises
IV. SHIFT TO THE CLOUD: ACHIEVING EFFICIENCY THROUGH CLOUD COMPUTING AND DATA CENTER CONSOLIDATION *
IV. SHIFT TO THE CLOUD: ACHIEVING EFFICIENCY THROUGH CLOUD COMPUTING AND DATA CENTER CONSOLIDATION * OVERVIEW The federal government is the world s largest consumer of information technology (IT), spending
Cloud Computing Discussion
Cloud Computing Discussion Dave Duden Director Deloitte Consulting, LLP October 25, 2011 Perspectives on Cloud Computing - 2 - Cloud computing Why Cloud? What s in it for me? I m not in IT, why do I care?
Dell Cloud Solutions. The simplest path to your cloud. Marian Kovacik. Solution Engineer
Dell Cloud Solutions The simplest path to your cloud Marian Kovacik Solution Engineer Cloud adoption today 56 out of 100 enterprises consider cloud to be a strategic differentiator today By 2018, the projected
White Paper on CLOUD COMPUTING
White Paper on CLOUD COMPUTING INDEX 1. Introduction 2. Features of Cloud Computing 3. Benefits of Cloud computing 4. Service models of Cloud Computing 5. Deployment models of Cloud Computing 6. Examples
The Business Benefits of Cloud Computing
The Business Benefits of Cloud Computing West Virginia Information Technology Conference 2009 Frederick Dillman Unisys CTO November 4 th, 2009 Agenda What is Cloud Computing The Benefits of Cloud Computing
Cloud Computing; What is it, How long has it been here, and Where is it going?
Cloud Computing; What is it, How long has it been here, and Where is it going? David Losacco, CPA, CIA, CISA Principal January 10, 2013 Agenda The Cloud WHAT IS THE CLOUD? How long has it been here? Where
EDC COLLABORATION WHITE PAPER Cloud Computing IT Services Delivery Transformation
EDC COLLABORATION WHITE PAPER Cloud Computing IT Delivery Transformation By W. Fred Rowell Vice President and Chief Technology Officer Companion Data, LLC APRIL, 2011 Table of Contents and List of Figures
Healthcare Enterprise View of Cloud What is Cloud Additional Needs Cloud Models Cloud Economics 101 Stack Decision Framework
Cloud 101 General Overview of Cloud Services January 21, 2015 Agenda Healthcare Enterprise View of Cloud What is Cloud Additional Needs Cloud Models Cloud Economics 101 Stack Decision Framework 2. 2014
IT Risk and Security Cloud Computing Mike Thomas Erie Insurance May 2011
IT Risk and Security Cloud Computing Mike Thomas Erie Insurance May 2011 Cloud Basics Cloud Basics The interesting thing about cloud computing is that we've redefined cloud computing to include everything
Written Testimony. Mark Kneidinger. Director, Federal Network Resilience. Office of Cybersecurity and Communications
Written Testimony of Mark Kneidinger Director, Federal Network Resilience Office of Cybersecurity and Communications U.S. Department of Homeland Security Before the U.S. House of Representatives Committee
Where in the Cloud are You? Session 17032 Thursday, March 5, 2015: 1:45 PM-2:45 PM Virginia (Sheraton Seattle)
Where in the Cloud are You? Session 17032 Thursday, March 5, 2015: 1:45 PM-2:45 PM Virginia (Sheraton Seattle) Abstract The goal of this session is to understanding what is meant when we say Where in the
Cloud Computing: Opportunities, Challenges, and Solutions. Jungwoo Ryoo, Ph.D., CISSP, CISA The Pennsylvania State University
Cloud Computing: Opportunities, Challenges, and Solutions Jungwoo Ryoo, Ph.D., CISSP, CISA The Pennsylvania State University What is cloud computing? What are some of the keywords? How many of you cannot
WHITE PAPER: STRATEGIC IMPACT PILLARS FOR EFFICIENT MIGRATION TO CLOUD COMPUTING IN GOVERNMENT
WHITE PAPER: STRATEGIC IMPACT PILLARS FOR EFFICIENT MIGRATION TO CLOUD COMPUTING IN GOVERNMENT IntelliDyne, LLC MARCH 2012 STRATEGIC IMPACT PILLARS FOR EFFICIENT MIGRATION TO CLOUD COMPUTING IN GOVERNMENT
Cloud Security. DLT Solutions LLC June 2011. #DLTCloud
Cloud Security DLT Solutions LLC June 2011 Contact Information DLT Cloud Advisory Group 1-855-CLOUD01 (256-8301) [email protected] www.dlt.com/cloud Your Hosts Van Ristau Chief Technology Officer, DLT Solutions
GAO INFORMATION SECURITY. Federal Guidance Needed to Address Control Issues with Implementing Cloud Computing. Report to Congressional Requesters
GAO United States Government Accountability Office Report to Congressional Requesters May 2010 INFORMATION SECURITY Federal Guidance Needed to Address Control Issues with Implementing Cloud Computing GAO-10-513
TECHNOLOGY TRANSFER PRESENTS MAX DOLGICER CLOUD 2.0 MOVING FROM COST SAVINGS TO AGILE IT
TECHNOLOGY TRANSFER PRESENTS MAX DOLGICER CLOUD 2.0 MOVING FROM COST SAVINGS TO AGILE IT APRIL 27-29, 2015 RESIDENZA DI RIPETTA - VIA DI RIPETTA, 231 ROME (ITALY) [email protected] www.technologytransfer.it
GAO INFORMATION TECHNOLOGY REFORM. Progress Made but Future Cloud Computing Efforts Should be Better Planned
GAO July 2012 United States Government Accountability Office Report to the Subcommittee on Federal Financial Management, Government Information, Federal Services, and International Security, Committee
SOLUTIONS. Secure Infrastructure as a Service for Production Workloads
IaaS SOLUTIONS Secure Infrastructure as a Service for Production Workloads THE CHALLENGE Now more than ever, business and government are facing the challenge of balancing conflicting demands. Market pressures
Accenture Cloud Platform Unlocks Agility and Control
Accenture Cloud Platform Unlocks Agility and Control 2 Accenture Cloud Platform Unlocks Agility and Control The Accenture Cloud Platform is at the heart of today s leading-edge, enterprise cloud solutions.
From Virtualized to ITaaS. Copyright 2011 EMC Corporation. All rights reserved.
From Virtualized to ITaaS 1 Priority Discussion Topics Laying the foundation for IT-as-a- with the right architecture Key process areas and capabilities that need to be rethought during the process (ie.
Cloud models and compliance requirements which is right for you?
Cloud models and compliance requirements which is right for you? Bill Franklin, Director, Coalfire Stephanie Tayengco, VP of Technical Operations, Logicworks March 17, 2015 Speaker Introduction Bill Franklin,
Cloud Security. A Sales Guy Talks About DoD s Cautious Journey to the Public Cloud. Sean Curry Sales Executive, Aquilent
Cloud Security A Sales Guy Talks About DoD s Cautious Journey to the Public Cloud Sean Curry Sales Executive, Aquilent The first in a series of audits DoD did not fully execute elements of the July 2012
BMC s Security Strategy for ITSM in the SaaS Environment
BMC s Security Strategy for ITSM in the SaaS Environment TABLE OF CONTENTS Introduction... 3 Data Security... 4 Secure Backup... 6 Administrative Access... 6 Patching Processes... 6 Security Certifications...
Building Out Your Cloud-Ready Solutions. Clark D. Richey, Jr., Principal Technologist, DoD
Building Out Your Cloud-Ready Solutions Clark D. Richey, Jr., Principal Technologist, DoD Slide 1 Agenda Define the problem Explore important aspects of Cloud deployments Wrap up and questions Slide 2
Overview of Cloud Computing and Cloud Computing s Use in Government Justin Heyman CGCIO, Information Technology Specialist, Township of Franklin
Overview of Cloud Computing and Cloud Computing s Use in Government Justin Heyman CGCIO, Information Technology Specialist, Township of Franklin Best Practices for Security in the Cloud John Essner, Director
Compliance and the Cloud: What You Can and What You Can t Outsource
Compliance and the Cloud: What You Can and What You Can t Outsource Presented By: Kate Donofrio Security Assessor Fortrex Technologies Instructor Biography Background On Fortrex What s In A Cloud? Pick
Cloud Based Solutions for Media and Entertainment
Tech Forum 2012 Cloud Based Solutions for Media and Entertainment by Ron Clifton Globecomm Tech Forum 2012 Hauppauge, NY 7 August 2012 RWC Rev Page: 120804 1 The Program 10:30 Cloud Solutions Part 1: Cloud
Cloud Computing @ SingularLogic:
Cloud Computing @ SingularLogic: Government cloud services: definitions and best practices Synergies with the private sector Are Greek IT companies able to provide Cloud Services? SingularLogic s Cloud
A Strawman Model. NIST Cloud Computing Reference Architecture and Taxonomy Working Group. January 3, 2011
A Strawman Model NIST Cloud Computing Reference Architecture and Taxonomy Working Group January 3, 2011 Objective Our objective is to define a neutral architecture consistent with NIST definition of cloud
GAO. INFORMATION SECURITY Governmentwide Guidance Needed to Assist Agencies in Implementing Cloud Computing
GAO For Release on Delivery Expected at 10:00 a.m. EDT Thursday, July 1, 2010 United States Government Accountability Office Testimony Before the Committee on Oversight and Government Reform and Its Subcommittee
Where Will Your Next Application Run? Abel B. Cruz WA Technology Strategist Microsoft Corporation
Where Will Your Next Application Run? Abel B. Cruz WA Technology Strategist Microsoft Corporation Users A A A VM VM VM A A A Application Compute/Storage/Network On-Premises Data Center VM Virtual Machine
How cloud computing can transform your business landscape
How cloud computing can transform your business landscape Introduction It seems like everyone is talking about the cloud. Cloud computing and cloud services are the new buzz words for what s really a not
INTRODUCING CLOUD POWER
INTRODUCING CLOUD POWER WHAT IF YOU COULD TAKE YOUR EXISTING IT INFRASTRUC- TURE AND MAKE IT MORE FLEXIBLE, MORE PRODUCTIVE, AND MORE POWERFUL ALL FOR LESS MONEY THAN YOU RE CUR- RENTLY SPENDING? Introducing
John Essner, CISO Office of Information Technology State of New Jersey
John Essner, CISO Office of Information Technology State of New Jersey http://csrc.nist.gov/publications/nistpubs/800-144/sp800-144.pdf Governance Compliance Trust Architecture Identity and Access Management
Cloud Computing Best Practices. Creating Effective Cloud Computing Contracts for the Federal Government: Best Practices for Acquiring IT as a Service
Cloud Computing Best Practices Cloud Computing Best Practices Creating Effective Cloud Computing Contracts for the Federal Government: Best Practices for Acquiring IT as a Service Overview Cloud Computing
Geospatial Segment Architecture and GeoCloud Update. Doug Nebert FGDC Architecture and Technology WG
Geospatial Segment Architecture and GeoCloud Update Doug Nebert FGDC Architecture and Technology WG Background FEA Geospatial Profile was developed for the LoB process to inform agency architectures on
Security Issues in Cloud Computing
Security Issues in Computing CSCI 454/554 Computing w Definition based on NIST: A model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources
Security Issues in Cloud Computing
Security Issues in Cloud Computing Dr. A. Askarunisa Professor and Head Vickram College of Engineering, Madurai, Tamilnadu, India N.Ganesh Sr.Lecturer Vickram College of Engineering, Madurai, Tamilnadu,
NIST Cloud Computing Security Reference Architecture (SP 500-299 draft)
NIST Cloud Computing Security Reference Architecture (SP 500-299 draft) NIST Cloud Computing Security Working Group Dr. Michaela Iorga, NIST Senior Security Technical Lead for Cloud Computing Chair, NIST
