Daniel Field, Atos Spain. Towards the European Open Science Cloud, Heidelberg, 20/01/2016
|
|
|
- Kelly Corey Terry
- 10 years ago
- Views:
Transcription
1 Daniel Field, Atos Spain Towards the European Open Science Cloud, Heidelberg, 20/01/2016
2 SLALOM is ready to use Cloud SLAs SLALOM will take theory to practice, providing a trusted verifiable starting point for providers and business users to negotiate SLAs for doing business in the Cloud in a simple, fair and transparent way SLALOM Project 2
3 SLALOM in a nutshell Service Level Agreement Legal and Open Model SLALOM s principal objective is to create a Service Level Agreement (SLA) reference model consisting of: SLALOM seeks to provide clarity and reassurance to the market through establishing a baseline of fair and balanced provisions for cloud SLAs and cloud computing contracts overall. SLALOM Project 3
4 What s wrong with (some) SLAs? Provider-defined Unclear One-sided Unfair Complex Illegal Ill-defined Take it or leave it Jurisdiction? Dangerous Impossible to compare Uncertainty = risk = no thanks SLALOM Project 4
5 What s wrong with SLAs? SLALOM Project 5
6 What s wrong with SLAs? A. General *** will be the only party to determine (in its sole discretion) whether [it] has not met any of the SLAs specified herein. SLALOM Project 6
7 What s wrong with SLAs? A. General (cont) *** reserves the right to change or discontinue any or all of the SLAs detailed below at any time without notice to Customer. SLALOM Project 7
8 cloud service providers closing the gap Cloud Service Providers can base their own SLA contractual clauses and technical specifications on the SLALOM recommendations. adopters Cloud Adopters will identify use of SLALOM to mean trustworthy and fair service level contractual terms and technical specifications. legal firms We work with world class experts in the field of legal cloud contracts to provide open wording for service level issues regulation & standardization institutions research The models cover both current market We are aligned with organizations that are practice and scenarios emerging from driving the uptake of recommendations both state of the art research. by cloud providers and consumers such as EC, standards organizations, and industry associations SLALOM Project 8
9 Understandable Cloud SLAs are not simple, but SLALOM is. We establish the baseline to allow you focus only on what matters so you can make the safe jump into the cloud! Practical Make your life simpler. Forget about SLA uncertainty. SLALOM provides practical templates for SLA contractual clauses and technical specifications. Safe & Fair Compete on value. Take it or leave it is not an option. SLALOM s model terms and specifications are designed to be fair and balanced, not giving hidden advantage to either providers or adopters.
10 SLALOM is developing Cloud SLAs baseline templates built compliant with ISO ISO/IEC JTC 1/SC 38/WG * series of standards Model Terms legal standards Model Specifications technical bit.ly/slalomdownloads SLALOM Project 10
11 What are SLAs in practice? SLAs contracts should answer basic questions about service delivery: What services will be used? and what is an acceptable level of service for each one? Always the same service level? Can they be changed? How? Under what circumstances? By whom? What metrics will be used to determine whether that level is being achieved? How can they be measured and monitored? What reporting mechanisms will be used? What happens if the requirements are not met? What penalties are defined for such cases? How are they reported? 11
12 What are SLAs in practice? SLAs contracts should answer basic questions about service delivery: How are security, privacy and data protection managed? What are the implications covered and assured by the provider or its subcontractors if possible? Do they provide all necessary means to deal and assure business and personal data? Is there any process for Business Continuity? What liabilities do providers have? What are the possible limitations to such liability? Are there any force majeure circumstances in which the terms do not apply? What are the adopter s obligations to respect the terms of use of the service provided by the cloud provider? Do customers have to accept a code of usage? 12
13 SLALOM SLA Tech Specs SLA Technical Specification allows the definition of parameters & terms through a well-defined set of metrics To assure required service levels, when dealing with cloud services, organizations must work with a detailed description of the objectives and the way they will be technically measured for a number of different categories of the business cloud strategy. Performance & Availability These include, but are not limited to: Security Personal Data Protection Data Management Governance & Support Services SLALOM Project 13
14 Core SLA SLALOM Specification contains specific key metrics & terms (used to assess a property of the SLA), parameters (used for the expression of a metric), rules (used for further possible constraints of a metric), and dependencies (used for specifying the dependencies between the different metrics) 14
15 SLALOM for procurers Establish the legal baseline upfront avoid protracted legal negotiations and tenderer withdrawal Independent and neutral definitions and conditions Common definitions of SLA metrics for like-for-like comparison Shift the focus to the value proposition (and not the overall conditions) Increased legal interoperability of the supply-chain SLALOM Project 15
16 SLALOM is OPEN: Public consultation How to provide feedback? Via part or all of legal or tech documents Via phone we are happy to speak with you In person at events Small discussion groups (telcos/webinars, F2F) Have your say!! SLALOM Project 16
17 Our goal is to seek consensus and create a practical and understandable baseline for doing business in the Cloud Contact us to help us improve how Cloud SLAs should be done in the real world mailto:[email protected] SLALOM Project 17
18 And after consensus what then? Public launch event (May 2016) Constitute SLALOM Body Further updates to legal and technical SLALOM Project 18
19 The SLALOM initiative is being undertaken by consultants from global service provider Atos, the legal specialist Bird & Bird, researchers from the National Technical University of Athens and University of Pireaeus, and the Cloud Industry Forum, an industry body championing transparency and trust of online services. SLALOM Project 19
20 For more information on the initiative contact us: SLALOM Project Coordinator SLALOM is a CSA financed by European Commission under Grant agreement SLALOM Project 20
SLA Model Terms and Specifications: SLALOM Project Overview and Request for Feedback
SLA Model Terms and Specifications: SLALOM Project Overview and Request for Feedback SLALOM is an initiative aligned with the European Cloud Strategy [1]. The first phase of the initiative is an 18 month,
CLOUD SERVICE LEVEL AGREEMENTS Meeting Customer and Provider needs
CLOUD SERVICE LEVEL AGREEMENTS Meeting Customer and Provider needs Eric Simmon January 28 th, 2014 BACKGROUND Federal Cloud Computing Strategy Efficiency improvements will shift resources towards higher-value
Public Cloud Service Agreements: What to Expect & What to Negotiate. April 2013
Public Cloud Service Agreements: What to Expect & What to Negotiate April 2013 The Cloud Standards Customer Council THE Customer s Voice for Cloud Standards! Provide customer-led guidance to the multiple
The problem of cloud data governance
The problem of cloud data governance Vasilis Tountopoulos, Athens Technology Center S.A. (ATC) CSP EU Forum 2014 - Thursday, 22 nd May, 2014 Focus on data protection in the cloud Why data governance in
The Cloud Security Alliance
The Cloud Security Alliance Daniele Catteddu, Managing Director EMEA & OCF-STAR Program Director Cloud Security Alliance ABOUT THE CLOUD SECURITY ALLIANCE To promote the use of best practices for providing
European Cloud. Computing Strategy. State of play: 1-2014. Ken Ducatel DG CONNECT
European Cloud State of play: 1-2014 Computing Strategy Ken Ducatel DG CONNECT What is at stake? Cloud as a growth engine Boost GDP : 940 bn cumulative impact for 2015-2020 250bn in 2020 Boosts productivity
Public Cloud Workshop Offerings
Cloud Perspectives a division of Woodward Systems Inc. Public Cloud Workshop Offerings Cloud Computing Measurement and Governance in the Cloud Duration: 1 Day Purpose: This workshop will benefit those
Personal data and cloud computing, the cloud now has a standard. by Luca Bolognini
Personal data and cloud computing, the cloud now has a standard by Luca Bolognini Lawyer, President of the Italian Institute for Privacy and Data Valorization, founding partner ICT Legal Consulting Last
ISO/IEC/IEEE 29119 The New International Software Testing Standards
ISO/IEC/IEEE 29119 The New International Software Testing Standards Stuart Reid Testing Solutions Group 117 Houndsditch London EC3 UK Tel: 0207 469 1500 Fax: 0207 623 8459 www.testing-solutions.com 1 Stuart
CCMS Software Provider Business Assurance Statement Deed Poll
CCMS Software Provider Business Assurance Statement Deed Poll I, the of (Name of CCMS Software Provider s representative) (insert position/title) ( the Software Provider ), (insert legal entity name and
Summary of responses to the public consultation on Cloud computing run by CNIL from October to December 2011 and analysis by CNIL
Summary of responses to the public consultation on Cloud computing run by CNIL from October to December 2011 and analysis by CNIL 1. Definition of Cloud Computing In the public consultation, CNIL defined
Legal aspects of cloud computing
Legal aspects of cloud computing Belrim Events Cloud Computing - Revolution or Nightmare? Antoon Dierick, DLA Piper Brussels 20 March 2014 Agenda 1. What is Cloud computing? 2. Cloud from a regulatory
THE FOUR STEP METHOD OF CLOUD SERVICE LEVEL AGREEMENTS
THE FOUR STEP METHOD OF CLOUD SERVICE LEVEL AGREEMENTS By Bruce Daley and Alan Rudolph Were he living today, Benjamin Franklin might say, Nothing is certain, except death, taxes, and computer crashes.
Article 29 Working Party Issues Opinion on Cloud Computing
Client Alert Global Regulatory Enforcement If you have questions or would like additional information on the material covered in this Alert, please contact one of the authors: Cynthia O Donoghue Partner,
A Flexible and Comprehensive Approach to a Cloud Compliance Program
A Flexible and Comprehensive Approach to a Cloud Compliance Program Stuart Aston Microsoft UK Session ID: SPO-201 Session Classification: General Interest Compliance in the cloud Transparency Responsibility
Role of contracts in Cloud Computing an Overview. Kevin McGillivray Doctoral Candidate (NRCCL)
Role of contracts in Cloud Computing an Overview Kevin McGillivray Doctoral Candidate (NRCCL) Barriers/Challenges to Cloud Transparency Compliance Legal Shared infrastructure Subcontractors (and their
William F Crowe, CISA,CRISC, CISM, CRMA, MBA September 2013
William F Crowe, CISA,CRISC, CISM, CRMA, MBA September 2013 16 years experience in Information Security, Risk Management, Third Party Oversight and IT Audit Vice President Business IT Risk Management JPM
Open Certification Framework. Vision Statement
Open Certification Framework Vision Statement Jim Reavis and Daniele Catteddu August 2012 BACKGROUND The Cloud Security Alliance has identified gaps within the IT ecosystem that are inhibiting market adoption
AN INSIDE VIEW FROM THE EU EXPERT GROUP ON CLOUD COMPUTING
AN INSIDE VIEW FROM THE EU EXPERT GROUP ON CLOUD COMPUTING 1. Overview and Background On 27 September 2012, the European Commission adopted a strategy for "Unleashing the potential of cloud computing in
Cloud Computing and Security Risk Analysis Qing Liu Technology Architect STREAM Technology Lab [email protected]
Cloud Computing and Security Risk Analysis Qing Liu Technology Architect STREAM Technology Lab [email protected] 1 Disclaimers This presentation provides education on Cloud Computing and its security
ADVERT POSITION: SPECIALIST: CONTRACTS MANAGEMENT JOB LEVEL: 6 DURATION 3 YEAR CONTRACT LOCATION: NATIONAL OFFICE PORTFOLIO: DSU
ADVERT POSITION: SPECIALIST: CONTRACTS MANAGEMENT JOB LEVEL: 6 DURATION 3 YEAR CONTRACT LOCATION: NATIONAL OFFICE PORTFOLIO: DSU PURPOSE: To lead and facilitate effective organisation-wide contracts development,
Legal Issues in the Cloud: A Case Study. Jason Epstein
Legal Issues in the Cloud: A Case Study Jason Epstein Outline Overview of Cloud Computing Service Models (SaaS, PaaS, IaaS) Deployment Models (Private, Community, Public, Hybrid) Adoption Different types
COMMISSION STAFF WORKING DOCUMENT. Report on the Implementation of the Communication 'Unleashing the Potential of Cloud Computing in Europe'
EUROPEAN COMMISSION Brussels, 2.7.2014 SWD(2014) 214 final COMMISSION STAFF WORKING DOCUMENT Report on the Implementation of the Communication 'Unleashing the Potential of Cloud Computing in Europe' Accompanying
Contracting with a Cloud Service Provider DATA PROTECTION WORKSHOP NJERI OLWENY, MICROSOFT
Contracting with a Cloud Service Provider DATA PROTECTION WORKSHOP NJERI OLWENY, MICROSOFT Overview Cloud computing offers great opportunities for organizations, including schools, hospitals and businesses
European Cloud Computing Strategy
European Cloud Computing Strategy Key actions and state of play Jorge GASOS DG Connect, European Commission [email protected] Impact on providers and users Cloud services: market forecast Supply
Service Design, Management and Composition: Service Level Agreements Objectives
Objectives! motivation for service level agreements! definition / measurement of levels! management of SLAs! formal representation 2 Content! definition! example! metrics! negotiation! optimization! monitoring!
COPYRIGHTED MATERIAL. Contents. Acknowledgments Introduction
Contents Acknowledgments Introduction 1. Governance Overview How Do We Do It? What Do We 1 Get Out of It? 1.1 What Is It? 1 1.2 Back to Basics 2 1.3 Origins of Governance 3 1.4 Governance Definition 5
Accelerating Cloud adoption with Security Level Agreements automation, monitoring and industry standards compliance
Accelerating Cloud adoption with Security Level Agreements automation, monitoring and industry standards compliance Cirrus Workshop, Vienna, Austria, November 19, 2013 Dr. Said Tabet Senior Technologist
Recommendations for companies planning to use Cloud computing services
Recommendations for companies planning to use Cloud computing services From a legal standpoint, CNIL finds that Cloud computing raises a number of difficulties with regard to compliance with the legislation
TOOLS and BEST PRACTICES
TOOLS and BEST PRACTICES Daniele Catteddu Managing Director EMEA, Cloud Security Alliance ABOUT THE CLOUD SECURITY ALLIANCE To promote the use of best practices for providing security assurance within
ca IT Leaders Forum Working in the Cloud using the new ISO/IEC/ITU-T Cloud Computing Standards Dr David Ross, Chief Information Security Officer,
ca IT Leaders Forum Working in the Cloud using the new ISO/IEC/ITU-T Cloud Computing Standards Dr David Ross, Chief Information Security Officer, Bridge Point Communications [email protected]
Overview. FedRAMP CONOPS
Concept of Operations (CONOPS) Version 1.0 February 7, 2012 Overview Cloud computing technology allows the Federal Government to address demand from citizens for better, faster services and to save resources,
Service availability (in the clouds)
Warsaw, 24 th of March 2014 Service availability (in the clouds) Aleksander P. Czarnowski, AVET INS / EuroCloud Polska Page 1 of 16 Table of Contents 1. Introduction... 3 2. Availability concept for IaaS,
How To Protect Your Data In The Cloud
Cloud Computing Hot topics in relation to security, liability and privacy Steven De Schrijver Cloud Computing : who and what is involved? Data Cloud Service Provider (e.g. SaaS, PaaS, IaaS) Sub-contractor
Subcontractors and Supply Chain Partners Management Fee Policy
Subcontractors and Supply Chain Partners Management Fee Policy Finance Lead Responsibility Chief Financial Officer Effective From 1st November 2015 Policy Applicable to Approved by Subcontractors and Supply
Procurement Innovation for Cloud Services in Europe
Procurement Innovation for Cloud Services in Europe Bob Jones, CERN Robert.Jones cern.ch www.picse.eu @PICSEPROCURE PICSE Mission 12/06/2015 Open Standards for ICT Procurement, 12 June 2015, Brussels,
451 s Procurement and Vendor Management Capability Development Program
The case for improved Procurement and Vendor Management The current market environment is calling for increased operational efficiency and effectiveness, where value for money and market contestability
A Systematic Review of Information Security Governance Frameworks in the Cloud Computing Environment
Journal of Universal Computer Science, vol. 18, no. 6 (2012), 798-815 submitted: 15/10/11, accepted: 15/2/12, appeared: 28/3/12 J.UCS A Systematic Review of Information Security Governance Frameworks in
Don't Pay to Support CRM 'Shelfware'
Tactical Guidelines, J. Disbrow Research Note 3 May 2003 Don't Pay to Support CRM 'Shelfware' Enterprises license customer relationship management solutions that are often never totally deployed. Software
Information Security Management System for Cloud Computing
ICT Innovations 2011 Web Proceedings ISSN 1857-7288 49 Information Security Management System for Cloud Computing Sashko Ristov, Marjan Gushev, and Magdalena Kostoska Ss. Cyril and Methodius University
ARMORED TRANSPORT OPTIMIZATION
ARMORED TRANSPORT OPTIMIZATION LOWERING COSTS BY 20% CMS consultants assist financial institutions to optimize their armored transport contracts. Cash Management Solutions (CMS) consultancy service leads
European Cloud Computing. Strategy. Cloud standards. Ken Ducatel DG CONNECT
European Cloud Computing Cloud standards Strategy Ken Ducatel DG CONNECT The Cloud Computing Strategy The European Commission's strategy 'Unleashing the potential of cloud computing in Europe' Adopted
Business Capacity Management Seminar
Part 1 What is Business Capacity? Agenda Introduction to section The IT Infrastructure Library Why ITIL is wrong on Business Capacity (BCM) What Business Capacity should be Relationship between the layers
Council of the European Union Brussels, 4 July 2014 (OR. en) Mr Uwe CORSEPIUS, Secretary-General of the Council of the European Union
Council of the European Union Brussels, 4 July 2014 (OR. en) 11603/14 ADD 1 COVER NOTE From: date of receipt: 2 July 2014 To: No. Cion doc.: Subject: RECH 323 TELECOM 140 MI 521 DATAPROTECT 100 COMPET
Procurement Capability Standards
IPAA PROFESSIONAL CAPABILITIES PROJECT Procurement Capability Standards Definition Professional Role Procurement is the process of acquiring goods and/or services. It can include: identifying a procurement
LEGAL ISSUES IN CLOUD COMPUTING
LEGAL ISSUES IN CLOUD COMPUTING RITAMBHARA AGRAWAL INTELLIGERE 1 CLOUD COMPUTING Cloud computing is a model for enabling convenient, on-demand network access to a shared pool of configurable computing
EuroCloud Deutschland_eco e.v. Cloud Computing is the future! For sure! But secure!
Cloud Computing is the future! For sure! But secure! ISO/IEC JTC1 national day 2011 The EuroCloud Network EuroCloud Europe was founded on Jan., 22 nd 2010 in Paris Today EuroCloud is present in 27 European
How To Deal With Cloud Computing
A LEGAL GUIDE TO CLOUD COMPUTING INTRODUCTION Many companies are considering implementation of cloud computing services to decrease IT costs while providing the flexibility to scale usage on demand. The
OFFICE OF AUDITS & ADVISORY SERVICES CLOUD COMPUTING AUDIT FINAL REPORT
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES CLOUD COMPUTING AUDIT FINAL REPORT Chief of Audits: Juan R. Perez Audit Manager: Lynne Prizzia, CISA, CRISC Senior Auditor:
Supplier Assurance Framework Good Practice Guide
Supplier Assurance Framework Good Practice Guide Version 2.0 February 2015 1 P a g e V e r s i o n 2. 0 F e b 1 5 Contents INTRODUCTION... 3 SUPPLIER ASSURANCE FRAMEWORK OVERVIEW... 4 USING THE STATEMENT
Department of Treasury and Finance
Department of Treasury and Finance GUIDELINES FOR THE LIMITATION OF LIABILITY OF SUPPLIERS, CONSULTANTS AND CONTRACTORS Document summary Status Agency responsible Applicable to Scope Administrative instruction
Securing The Cloud. Foundational Best Practices For Securing Cloud Computing. Scott Clark. Insert presenter logo here on slide master
Securing The Cloud Foundational Best Practices For Securing Cloud Computing Scott Clark Agenda Introduction to Cloud Computing What is Different in the Cloud? CSA Guidance Additional Resources 2 What is
How to ensure control and security when moving to SaaS/cloud applications
How to ensure control and security when moving to SaaS/cloud applications Stéphane Hurtaud Partner Information & Technology Risk Deloitte Laurent de la Vaissière Directeur Information & Technology Risk
Specialist Cloud Services. Acumin Cloud Security Resourcing
Specialist Cloud Services Acumin Cloud Security Resourcing DOCUMENT: FRAMEWORK: STATUS Cloud Security Resourcing Service Definition G-Cloud Released VERSION: 1.0 CLASSIFICATION: CloudStore Acumin Consulting
CONTRACT MANAGEMENT FRAMEWORK
CONTRACT MANAGEMENT FRAMEWORK August 2010 Page 1 of 20 Table of contents 1 Introduction to the CMF... 3 1.1 Purpose and scope of the CMF... 3 1.2 Importance of contract management... 4 1.3 Managing contracts...
FLEXIANT. Utility Computing on Demand
FLEXIANT Utility Computing on Demand Flexiant Flexiant is a software and services company, one of the world's first public/private Cloud providers. We provide cloud infrastructure software and services
Cloud Computing: Legal Risks and Best Practices
Cloud Computing: Legal Risks and Best Practices A Bennett Jones Presentation Toronto, Ontario Lisa Abe-Oldenburg, Partner Bennett Jones LLP November 7, 2012 Introduction Security and Data Privacy Recent
Cloud computing and personal data protection. Gwendal LE GRAND Director of technology and innovation CNIL
Cloud computing and personal data protection Gwendal LE GRAND Director of technology and innovation CNIL 1 Data protection in Europe Directive 95/46/EC Loi 78-17 du 6 janvier 1978 amended in 2004 (France)
Determining Best Fit. for ITIL Implementations
Determining Best Fit for ITIL Implementations Michael Harris President David Consulting Group Agenda Why ITIL? The Evolution of IT Metrics Towards the Business What do businesses need from IT Introduction
Cloud Computing and HIPAA Privacy and Security
Cloud Computing and HIPAA Privacy and Security This is just one example of the many online resources Practical Law Company offers. Christine A. Williams, Perkins Coie LLP, with PLC Employee Benefits &
OPTIMIS: Improving Cloud Management With Dynamic SLAs
1 OPTIMIS: Improving Cloud Management With Dynamic SLAs Salt Lake City, July 18 Wolfgang Ziegler, Fraunhofer Institute SCAI [email protected] OPTIMIS Project IP 5th call June 2010 - May
Cloud Computing in a Regulated Environment
Computing in a Regulated Environment White Paper by David Stephenson CTG Regulatory Compliance Subject Matter Expert February 2014 CTG (UK) Limited, 11 Beacontree Plaza, Gillette Way, READING, Berks RG2
Security in the Cloud: Visibility & Control of your Cloud Service Providers
Whitepaper: Security in the Cloud Security in the Cloud: Visibility & Control of your Cloud Service Providers Date: 11 Apr 2012 Doc Ref: SOS-WP-CSP-0412A Author: Pierre Tagle Ph.D., Prashant Haldankar,
Electronic Palliative Care Co-Ordination Systems: Information Governance Guidance
QIPP Digital Technology Electronic Palliative Care Co-Ordination Systems: Information Governance Guidance Author: Adam Hatherly Date: 26 th March 2013 Version: 1.1 Crown Copyright 2013 Page 1 of 19 Amendment
SERVICE SCHEDULE INFRASTRUCTURE AND PLATFORM SERVICES
SERVICE SCHEDULE INFRASTRUCTURE AND PLATFORM SERVICES This Product Schedule Terms & Conditions is incorporated into a Services Agreement also comprising the General Terms and Conditions which the Customer
