Accelerating Cloud adoption with Security Level Agreements automation, monitoring and industry standards compliance



Similar documents
EMC Technology Trends

EMC ACADEMIC ALLIANCE

Joachim Worf Sr. Education Delivery Manager EMC Corporation

The Federation Story. Sergei Butenko Copyright 2015 EMC Corporation. All rights reserved.

Cloud Computing Standards: Overview and ITU-T positioning

Standard Big Data Architecture and Infrastructure

Cloud Channel Summit #RCCS15

Latest in Cloud Computing Standards. Eric A. Hibbard, CISSP, ISSAP, ISSEP, ISSMP, CISA CTO Security & Privacy Hitachi Data systems

ca IT Leaders Forum Working in the Cloud using the new ISO/IEC/ITU-T Cloud Computing Standards Dr David Ross, Chief Information Security Officer,

Top 10 reasons to move to the cloud

3rd Party Audited Cloud Infrastructure SOC 1, Type II SOC 2, Type II ISO Annual 3rd party application Pen Tests.

ITU- T Focus Group Cloud Compu2ng

PUPPET FOR MANAGED HOSTING PROVIDERS

"Service Lifecycle Management strategies for CIOs"

Paul Schuman Sr Director, WW Hosting Service Providers Microsoft

Information Security ISO Standards. Feb 11, Glen Bruce Director, Enterprise Risk Security & Privacy

Attacking the roadblocks preventing aggressive adoption of Cloud Standards:

SAS CLOUD ANALYTICS MAY 2015

INTERNET OF THINGS Delight. Optimize. Revolutionize.

TRANSFORMING TO NEXT-GEN APP DELIVERY FOR COMPETITIVE DIFFERENTIATION

Global Data Center Location Insights March 2013

AVANTGARD Hosting and Managed Services

Cloud Computing Security Audit

Data Risk Management: ISM Ground to Cloud Summit. accelerate your ambition 1

September 16, 2008 Why IT Service Management Should Matter To You

Public Cloud Workshop Offerings

SMART CITIES And ENERGY. Finding new markets in a changing world

The Cloud Security Alliance

CLOUD SERVICE LEVEL AGREEMENTS Meeting Customer and Provider needs

The Next Generation Data Centers: SPECS and The 3 rd Platform.

TOOLS and BEST PRACTICES

BENEFITS OF SERVERLESS COMPUTING

Security Issues in Cloud Computing

Sybase Solutions for Healthcare Adapting to an Evolving Business and Regulatory Environment

Cloud Computing ISO Security and Privacy Standards: 27017, 27018, Mike Edwards (Chair UK Cloud Standards Committee)

Open Certification Framework. Vision Statement

AVANTGARD Private Cloud and Managed Services

Guide. Axis Webinar. User guide

Cloud Computing and Security Risk Analysis Qing Liu Technology Architect STREAM Technology Lab

Global Efforts to Secure Cloud Computing. Jason Witty President, Cloud Security Alliance Chicago

Building an Effective

WHITEPAPER Workforce Planning Pitfalls

Global Service Delivery: Industrialising Service Management

Telecom Business Assurance. Managed Services

SAP in the Cloud by EMC. Copyright 2010 EMC Corporation. All rights reserved.

When Security, Privacy and Forensics Meet in the Cloud

Security, Compliance & Risk Management for Cloud Relationships. Adnan Dakhwe, MS, CISA, CRISC, CRMA Safeway Inc. In-Depth Seminars D32

Security in the Cloud

How RSA has helped EMC to secure its Virtual Infrastructure


Global Headquarters: 5 Speen Street Framingham, MA USA P F

Agenda. Company Platform Customers Partners Competitive Analysis

Service Organization Controls 3 Report

Dr. Jesus Luna Garcia

Fujitsu World Tour Human Centric Innovation. The Future of the Datacenter. Ayman Abouseif VP Product Marketing. 0 Copyright 2015 FUJITSU

Microsoft Azure. The cloud platform built for business. Tarmo Tikerpäe DC SSP Microsoft

Key Enablers for the Cloud Service Broker: Identity, Privacy, and Security

ITSM in the Cloud. An Overview of Why IT Service Management is Critical to The Cloud. Presented By: Rick Leopoldi RL Information Consulting LLC

Your Infrastructure. Our Responsibility.

The ROI of a New Learning Management System (LMS)

WHITE PAPER MARCH TechInsights Report: The Changing Role of IT and What to Do About It

A view from the Cloud Security Alliance peephole

Leveraging the Potential of Cloud Security Service Level Agreements through Standards

Benefits to the Quality Management System in implementing an IT Service Management Standard ISO/IEC

A Comparison of IT Governance & Control Frameworks in Cloud Computing. Jack D. Becker ITDS Department, UNT & Elana Bailey

Daniel Field, Atos Spain. Towards the European Open Science Cloud, Heidelberg, 20/01/2016

Standardised SLAs: how far can we go? DIHC, Euro-Par 2013, Aachan John Kennedy Intel Labs Europe

2015 Techstravaganza The Microsoft Cloud

Corporate Fact Sheet

All Clouds Are Not Created Equal THE NEED FOR HIGH AVAILABILITY AND UPTIME

HP Software Licensing and Management Solutions (SLMS) Helping organizations maximize their software investment.

Interna'onal Standards Ac'vi'es on Cloud Security EVA KUIPER, CISA CISSP HP ENTERPRISE SECURITY SERVICES

CONSULTING SERVICES Business & technology consulting and managed services

Cloud computing and personal data protection. Gwendal LE GRAND Director of technology and innovation CNIL

Global Data Center Location Insights March 2013

Global Headquarters: 5 Speen Street Framingham, MA USA P F

How To Motivate and Retain Key Employees

Transcription:

Accelerating Cloud adoption with Security Level Agreements automation, monitoring and industry standards compliance Cirrus Workshop, Vienna, Austria, November 19, 2013 Dr. Said Tabet Senior Technologist and Industry Standards Strategist Corporate Office of the CTO, EMC 2

AGENDA Brief introduction to EMC Overview: Challenges in the industry Cloud Transforms Information technology Trust in the Cloud Standards and Open Frameworks Security SLAs Automation Actionable Agreements and aligned objectives Near real-time monitoring and proactive enforcement Summary

Investing for Growth globally More than 65,000 People Across 85 Countries Cork, Ireland Rotterdam, Netherlands St. Petersburg, Russia Seattle, WA Pleasanton, CA Burlington, Ontario Brentford, UK Pau, France Durham, NC Apex, NC Irvine, CA Duluth, GA Hopkinton, MA Vienna, Austria Roy, UT Global Headquarters Palo Alto, CA Santa Clara, CA Tokyo, Japan Shanghai, China Bedford, MA Franklin, MA Direct Presence Be'er Sheva, Tel Aviv, Israel Israel Cairo, Egypt Seoul, S. Korea Beijing, China Chengdu, China Bangalore, India Cambridge, MA R&D Center Singapore Centers of Excellence Customer Support Center Rio de Janeiro, Brazil Executive Briefing Center Sydney, Australia Melbourne, Australia Manufacturing Center Global Solution and Engineering Center as of October 18, 2011

Mobile Cloud Big Data TRUST Social

Hitting All The Wrong Headlines

When Risks become Costs 59% of Fortune 500 companies experience a minimum of 1.6 hours of downtime per week, which translates into more than $46 million per year [Dunn & Bradstreet]

What is going on in IT? 72% Maintain 28% Invest Source: Forrester Research, Inc., IT Budgets and Priorities 2013, 25 April, 2013

The Business Drivers Increase Revenue Lower Operational Costs Reduce Risk

Cloud Transforms IT Cloud Computing Increase Revenue Lower Operational Costs

Big Data Transforms Business Increase Revenue Lower Operational Costs Big Data

Security SLAs Cloud Risk management and the role of Standards

Trusted IT Means. Ensuring Availability Of Applications, Systems & Data Continuous Availability & Consistency Protecting Data Integrated Backup & Recovery Identifying & Repelling Threats Advanced Security

Why do we need Standards? Use of available technical expertise, enhanced trade Common metrics for service level expectations Essential to the cloud supply chain Open global markets Required by legal and accounting professions Increased automation

Cloud Standardization ISO SC38 ISO SC27 IETF ITU-T CSA OMG Many others NIST, ETSI ENISA,

SC38 Cloud Standards Recommends that any projects on Cloud Computing Security use the cloud computing terms and vocabulary that will appear in ISO/IEC 17788 Recommends that Cloud Computing Security Architecture should use the ISO/IEC 17789 as the base Cloud Computing Reference Architecture New working draft on Cloud SLAs Also discussion for a future SLA metrics repository

SC27 Cloud Standards 27017: Code of practice for information security controls for cloud computing services based on ISO/IEC 27002 27018: Code of practice for PII protection in public clouds acting as PII processors 27036-4: Information security for supplier relationships Part 4: Guidelines for security of cloud services Cloud-adapted Risk Management Framework (CRMF) Security SLAs

Cloud Security Alliance (CSA) Activities CSA Guidance Security Guidance for Critical Areas of Focus in Cloud Computing GRC Stack and Trusted Cloud Initiative Security SLA Working group Security as a Service (SecaaS) CSA Mobile WG CSA STAR and OCF CSA SME and ISC Council

ISO Risk Management Standards ISO/IEC 31000:2009 Risk management Related Standards: ISO Guide 73:2009, Risk management - Vocabulary complements ISO 31000 by providing a collection of terms and definitions relating to the management of risk ISO/IEC 31010:2009, Risk management Risk assessment techniques focuses on risk assessment ISO/IEC 27005:2011 Information technology -- Security techniques -- Information security risk management

Cloud Computing and Risk management Cloud computing roles have differing degrees of control over the computing and data processes Implementation of security requirements becomes a shared responsibility among the cloud computing roles. Cloud computing roles involved in orchestrating cloud computing ecosystems and providing technical services are responsible for ensuring they address the cloud service customers areas of concern

SPECS Secure Provisioning of Cloud Services based on SLA Management

SPECS Core idea Problem Statement: End-User Cloud Security (How to compare CSP?, What they grant? How to improve their security features if they do not grant enough? ) Approach: Security-as-a-Service (SECaaS), a Platform which offers security services. Service Level Agreement (SLA) for Security. End-User and CSP features described through SLAs. The SECaaS granted through the SLA life cycle

SPECS Platform

SLA Management SLA among Users, SPECS and Providers Negotiation Finding the Agreement Monitoring Veryfing the respect of Agreement Enforcement Take Action to grant the Agreement

Cloud Transforms IT Physical Server Virtual Server Virtual Data Center Months / Weeks Days / Hours Minutes / Seconds 1 Standardize Virtualize 2 3 Automate

VM Deployment Now Dominant 25.000.000 Physical Hosts Virtualized Machines 20.000.000 The Tipping Point 15.000.000 10.000.000 5.000.000 0 2005 2006 2007 2008 2009 2010 2011 2012 2013 2014 2015 Represents All CPUs (x86, RISC, CISC, EPIC) Source: IDC Server Virtualization MCS, January 2012

Summary Cloud is still facing many challenges the industry is in the middle of its IT transformation Legal/Regulatory/Jurisdictional barriers Need for Guidance, Assurance, and Certification Help application developers and Architects Automation of SLAs and Security SLAs Monitoring Leverage Semantic Technology Data protection and Privacy standardization The legal, regulatory, and operational issues require renewed and strong focus The Cloud supply Chain: Need for transparency and traceability