EuroCloud Deutschland_eco e.v. Cloud Computing is the future! For sure! But secure!

Similar documents
Cloud Standardization, Compliance and Certification. Class 2012 event 25.rd of October 2012 Dalibor Baskovc, CEO Zavod e-oblak

EuroCloud Star Audit. A strong partnership that provides you with a competitive advantage

On Premise Vs Cloud: Selection Approach & Implementation Strategies

Cloud Security Introduction and Overview

Attacking the roadblocks preventing aggressive adoption of Cloud Standards:

Public Cloud Workshop Offerings

Cloud Computing Flying High (or not) Ben Roper IT Director City of College Station

WP9 D9.5 Risk Analysis and Countermeasures

Strategic approach to cloud computing deployment

Cloud Computing. Bringing the Cloud into Focus

Safe Harbor Statement

USE OF CLOUD COMPUTING BY SMALL AND MEDIUM ENTERPRISES

Infrastructure as a Service

Software Defined Hybrid IT. Execute your 2020 plan

Open Certification Framework. Vision Statement

Cloud Security Certification

CLOUD SERVICE LEVEL AGREEMENTS Meeting Customer and Provider needs

What Cloud computing means in real life

How To Secure Cloud Computing

European Cloud. Computing Strategy. State of play: Ken Ducatel DG CONNECT

The NREN s core activities are in providing network and associated services to its user community that usually comprises:

Procurement Innovation for Cloud Services in Europe - PICSE

Interna'onal Standards Ac'vi'es on Cloud Security EVA KUIPER, CISA CISSP HP ENTERPRISE SECURITY SERVICES

Towards a Cloud Computing Strategy for Europe Digital Assembly, June 17, Brussels.

The European Cloud Journey. Gabriella Cattaneo, European Government Consulting IDC s European Cloud Research Team February 24, 2014

Clo l ud d C ompu p tin i g

Understanding ISO and Preparing for the Modern Era of Cloud Security

A Flexible and Comprehensive Approach to a Cloud Compliance Program

Cloud Computing Paradigm Shift. Jan Šedivý

Adding value as a Cloud Broker. Nick Hyner Director Cloud Services EMEA Twitter Dell.com/Cloud

Seamless adaptive multi-cloud management of service-based applications

Information Security ISO Standards. Feb 11, Glen Bruce Director, Enterprise Risk Security & Privacy

Hans Bos Microsoft Nederland.

Fast IT: Accelerate Your Business

The Cloud Opportunity: Italian Market 01/10/2010

SaaS Security for the Confirmit CustomerSat Software

Storage Trends Choice-Solutions Ltd.

liberate unify and secure your enterprise communications A3C Anytime Communication & Collaboration Cloud

Boosting Productivity and Innovation Through. Public Sector Compliant Cloud Services

10 Considerations for a Cloud Procurement. Anthony Kelly Erick Trombley David DeBrandt Carina Veksler January 2015

Public Clouds. Krishnan Subramanian Analyst & Researcher Krishworld.com. A whitepaper sponsored by Trend Micro Inc.

Cloud/structural funds workshop on 6 February 2014, DG Connect

COMPUTACENTER AND SYMANTEC TOGETHER: PROTECTING AND EMPOWERING DATA

IT Service Management aus der Cloud

Becloud. IaaS in the channel. Mar ch 13

SOA and Cloud in practice - An Example Case Study

The Future of Cloud Computing: Elasticity, Legacy Support, Interoperability and Quality of Service

Cloud Computing An Auditor s Perspective

Virginia Government Finance Officers Association Spring Conference May 28, Cloud Security 101

Public Sector Cloud Services - The Telecom Perspective

Information Technology: This Year s Hot Issue - Cloud Computing

Cloud Security and Managing Use Risks

Information Security Management System for Cloud Computing

COMMISSION STAFF WORKING DOCUMENT. Report on the Implementation of the Communication 'Unleashing the Potential of Cloud Computing in Europe'

How To Choose A Cloud Computing Solution

Orchestrating the New Paradigm Cloud Assurance

FLEXIANT. Utility Computing on Demand

Audit of the CFPB s Acquisition and Contract Management of Select Cloud Computing Services

Cloud certification guidelines and recommendations

The problem of cloud data governance

Service Measurement Index Framework Version 2.1

Certified Cloud Computing Professional VS-1067

Security, Compliance & Risk Management for Cloud Relationships. Adnan Dakhwe, MS, CISA, CRISC, CRMA Safeway Inc. In-Depth Seminars D32

Summary of responses to the public consultation on Cloud computing run by CNIL from October to December 2011 and analysis by CNIL

ITSM in the Cloud? Sharon Taylor Aspect Group Inc

vcloud Virtual Private Cloud Fulfilling the promise of cloud computing A Resource Pool of Compute, Storage and a Host of Network Capabilities

Managing Cloud Computing Risk

Asia/Pacific. Yanna Dharmasthira

1 The intersection of IAM and the cloud

WAN OPTIMIZATION FOR TELCOS, MANAGED SERVICE AND CLOUD PROVIDERS

Deploying Cloud Security Standards The MTCS Experience

Transcription:

Cloud Computing is the future! For sure! But secure! ISO/IEC JTC1 national day 2011

The EuroCloud Network EuroCloud Europe was founded on Jan., 22 nd 2010 in Paris Today EuroCloud is present in 27 European Countries, 17 of those with established National associations, the others are in the foundation process Romania

There is no Business without Trust 3

EuroCloud Mission 4 4

Eurocloud Deutschland_eco e.v. Expert Groups: Law and Compliance Cloud Quality Seal Interoperability and Standards Cloud Managed Services 5

Paradigm Changes How IT Innovations conquer the Market Traditional Today Innovation Commercial Utilization Private Utilization Business virtual local is

Cloud Means Customers CAPEX to OPEX Cloud Service Providers Customers CAPEX to OPEX Customers CAPEX to OPEX

Cloud Means Industrialization of IT Customers Less Individuality Customers Higher Mobility Customers Lower Costs Standardization of Production an Provisioning

Cloud Means Developer Clouds Ease of Use Increasing IP Capability of Maschines of all Kind Lower Development Costs Fast Deployment Innovation Speed increases in all Branches

Cloud Means Global Cloud Service Providers Competitive Advantage Global Market Domination European IT Ecosystem breaks Smaller CSP s partner along to Value chain Partnering requires Quality Standards

Cloud Means Fragmented Regulatory Framework National Euroepean Regulations differ Data Security and Data Privacy to be synchronized Confidence as Market Stimulator Best of Breed Global Data Protection Standards

Cloud Computing Benefits EuroCloud Deutschland_eco e.v. Question: Which Benefits do you expect from Cloud Computing? Higher Flexibility Cost Savings Better Scalability Less Complexity Higher Focus on Core Business Better Collaboration Change from CAPEX to OPEX Green IT Use of new Technologies Better Functionality Higher Security Source KPMG 2010 0% 10% 20% 30% 40% 50% 60% 70% 80% 90%

Cloud Computing Obstacle No 1: Security EuroCloud Deutschland_eco e.v. Question: What are to most concerns with Cloud Computing? Security Legal Questions Data Protection Compliance Integration Efforts Lock In Situation Availablity Insufficiant economic Benefits Insufficiant Performance Insufficiant Functionality Half backed Technology Source KPMG 2010 0% 10% 20% 30% 40% 50% 60% 70% 80%

ENISA: Cloud Computing Risk Assessment EuroCloud Deutschland_eco e.v. Link: http://www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing-risk-assessment :

ENISA: Cloud Computing Risk Assessment EuroCloud Deutschland_eco e.v. :

EuroCloud Star Audit SaaS Expertise for the Criteria Definition EuroCloud Deutschland_eco e.v. ENISA Cloud Computing Risk Report Cloud Computing Security Cornerstone Paper Security Guidance Cloud Computing IT Prüfstandards ISPRAT Study Cloud Computing Expert Group Law & Compliance Cloud Service Provider Certified Accountants

EuroCloud Star Audit SaaS Outcome Statement on the Professionalism, Trustworthiness and Reliability of the Cloud Service Provider and involved Sub-Providers Examination of the specific contractual elements, e.g. Compliance Conformity Order Processing Data Protection Regulations Book Keeping Regulations Data Export Regulations Data Center Infrastructure Capabilities Maturity of Operational Processes SLA Fullfillmant Capabilities Scalability and Interoperability

The EuroCloud Star Audit Family EuroCloud Star Audit App Ready EuroCloud Star Audit SaaS Ready EuroCloud Star Audit SaaS Law & Compliance Data Security & Data Privacy Datacenter-Infrastructure Operational Processes EuroCloud Star Audit SaaS certifies SaaS Provider with 1 to5 stars EuroCloud Star Audit SaaS Ready certifies DC-Provider with 4 to 5 stars EuroCloud Star Audit SaaS App allows SaaS Provider to certify with 4 to 5 stars, as far as the SaaS application is provided by an SaaS Ready certified DC-Provider Application Implementation and Interoperability

EuroCloud Star Audit SaaS Offerings EuroCloud Star Audit SaaS Law & Compliance EuroCloud Star Audit SaaS Ready Law& Compliance EuroCloud Star Audit SaaS App Law & Compliance Data Security & Data Privacy Datacenter- Infrastructure Datacenter Star Audit = + Data Security & Data Privacy Datacenter- Infrastructure Datacenter Star Audit Operational Processes Operational Processes Application Implementation and Interoperability Application Implementation and Interoperability

The EuroCloud Star Audit Family EuroCloud Star Audit App Ready EuroCloud Star Audit SaaS Ready EuroCloud Star Audit SaaS EuroCloud Star Audit PaaS (in 2011) EuroCloud Star Audit IaaS (in 2011) EuroCloud Star Audit SaaS certifies SaaS Provider with 1 to5 stars EuroCloud Star Audit SaaS Ready certifies DC-Provider with 4 to 5 stars EuroCloud Star Audit SaaS App allows SaaS Provider to certify with 4 to 5 stars, as far as the SaaS application is provided by an SaaS Ready certified DC-Provider eco / EuroCloud Datacenter Star Audit ISO 27001 / SAS70 Optional eco / EuroCloud Datacenter Infrastructure Certification Existing valid certifications are considered

EuroCloud Star Audit SaaS Audit Scope is Customers Choice EuroCloud Deutschland_eco e.v. Trusted Cloud High Available Trusted Cloud Advanced Trusted Cloud Company Profile Law & Compliance Data Security & Data Privacy Datacenter Infrastructure Operational Processes Application Implementiion & Interoperability

EuroCloud Star Audit Process Duration: 6 8 weeks (depending on the completeness of the Audit Questionaire Responses Customer Workshop OnSite Workshop y/n 1 NDA Order SaaS Provider: Response of the Audit Questionare Submission incl. related documentation EuroCloud: Audit Survey/ OnSite Audit Survey Generation and Provision of the Final Audit Report 2 End Decision for Rework: 4 weeks after Submission of the Final Audit Report Time for Rework: 6 Month Re-Audit Order 6 Month prior to End of Licence 2 y/n Rework-Audit 1 1 Cetification/ Licence Submission y/n End e.g. private Clouds Validity of the Certification Licence: 2 years after Final Audit Report Submission End

EuroCloud Star Audit SaaS Benefits for Provider and Customers EuroCloud Deutschland_eco e.v. Benefits for Cloud Service Provider Benefits for Cloud Customers Determination of own efficiency Quality assurance measure Quality of Service Improvement Measure of improved effectivness in Service Delivery Processes Measure of harmonized multinational European Service Offerings Persuasive Sales and Marketing argument Objective evidence for quality and safety Positive competitive positioning Easier and more cost-effective selection process Reduced effort in the tendering and procurement process Increased market transparency Precise coordination of requirements and offer Universal standards

EuroCloud Links EuroCloud Deutschland_eco e.v. www.eurocloud.de EuroCloud Europe www.eurocloud.org EuroCloud Guideline German Law, Data Protection and Compliance http://en.eurocloud.de/2011/03/04/eurocloud-guidelines-cloud-computinggerman-law-data-protection-and-compliance/ EuroCloud Star Audit SaaS eco e.v. www.saas-audit.eu www.eco.de eco (EuroCloud) Datacenter Star Audit www.dcaudit.de

Thank you for your attention! Any Questions?