28
cloudofdata.com Dr Paul Miller The Cloud of Data [email protected] Information Security & Cloud Computing

Information Security and Cloud Computing

Embed Size (px)

DESCRIPTION

A short presentation on Information Security and Cloud Computing, prepared for an event of the UK's Society of Archivists.The slides were intended to shape the issues ahead of a longer discussion session.

Citation preview

Page 1: Information Security and Cloud Computing

cloudofdata.com

Dr Paul Miller

The Cloud of Data

[email protected]

Information Security & Cloud Computing

Page 2: Information Security and Cloud Computing

cloudofdata.com

Cloud Stack redux

Some (quick!) ‘truths’ about the Cloud

Information Security?

Topics

Page 3: Information Security and Cloud Computing

cloudofdata.com

The Cloud Stack‘The Cloud’ lumps different concepts/capabilities together

www.flickr.com/photos/wonderlane/3089163372/

Page 4: Information Security and Cloud Computing

cloudofdata.com

“convenient, on-demand network access to a shared pool of configurable computing resources...”

csrc.nist.gov/groups/SNS/cloud-computing/

Page 5: Information Security and Cloud Computing

cloudofdata.com

Software/Application [as a Service](SaaS)

Platform [as a Service](PaaS)

Infrastructure [as a Service](IaaS)

Traditional 3 layer model - there are plenty of others!all ‘Cloud’… but DIFFERENT!

Page 6: Information Security and Cloud Computing

cloudofdata.com

SaaS

PaaS

Infrastructure as a Service (IaaS)

computers (Amazon EC2, Rackspace, GoGrid...)storage (Amazon S3, MobileMe, Google Drive...)

Elasticity (Rightscale…)Bandwidth (Limelight, Amazon CloudFront…)

ElectricityCooling

etc.

outsource raw infrastructure - avoid significant CapExscale to meet demand - Eli Lilly, payrollpublic/ private/ hybrid

Page 7: Information Security and Cloud Computing

cloudofdata.com

SaaS

Platform as a Service (PaaS)

Salesforce force.comApprenda SaaSGridGoogle App Engine

Microsoft AzureAppistry

Talis Platform

IaaS

‘does heavy lifting’concentrate on your app’s USP

least developed but most potential?

Page 8: Information Security and Cloud Computing

cloudofdata.com

Software as a Service (SaaS)

Google Apps, ZohoAcrobat.com, iWork.com

Kashflow, FreeAgentWordPress.com

MobileMeSalesforce.com

PaaS

IaaS

lightweight applications, delivered over Webmostly low-end disruptors for now...

Page 9: Information Security and Cloud Computing

cloudofdata.com www.flickr.com/photos/dpicker/2255136085/

Some ‘Truths’ about the Cloud

Some more true than others!

Page 10: Information Security and Cloud Computing

cloudofdata.com

It’s All Off-Premise

Microsoft Data Centre, Dublin Cisco, VMware et al pushing on-premise

G-Cloud, here and in USA...

www.datacenterknowledge.com/wp-content/uploads/2009/09/aerial-1000.jpg

Page 11: Information Security and Cloud Computing

cloudofdata.com

It’s Cheap

www.flickr.com/photos/esdrascalderan/357434020/

For elastic or periodic jobs.Less clear-cut for ‘normal’ load

Page 12: Information Security and Cloud Computing

cloudofdata.com

It’s Green

www.flickr.com/photos/venteco/2851026377/

Probably… but Simon Wardley

http://tr.im/greenclouds

Page 13: Information Security and Cloud Computing

cloudofdata.com

It’s Not Reliable

www.flickr.com/photos/raver_mikey/2300514593/

Numbers don’t add up...

Page 14: Information Security and Cloud Computing

cloudofdata.com

It’s Not Secure

www.flickr.com/photos/8323834@N07/500995147/

And your data centre ?

Page 15: Information Security and Cloud Computing

cloudofdata.com

USA will read my data

www.flickr.com/photos/whitehouse/3484013571/

PATRIOT Act and data territoriality are real… but manageable

Page 16: Information Security and Cloud Computing

cloudofdata.com

It’s Amazon

www.flickr.com/photos/lucasartoni/2967023166/

And Rackspace, and Microsoft, and Sun, and HP, and Google, and...

Page 17: Information Security and Cloud Computing

cloudofdata.com

0

750

1,500

2,250

3,000

July September November January March May

Amazon Rackspace Joyent GoGrid OpSource FlexiScale

www.jackofallclouds.com/2010/05/state-of-the-cloud-may-2010/

Guy Rosen has begun tracking trends, using QuantCast’s top 500,000 sites

Page 18: Information Security and Cloud Computing

cloudofdata.com

“It’s like computers on the Internet, innit?”

With thanks to Simon Wardley

www.flickr.com/photos/fimbrethil/2642775023/

Page 19: Information Security and Cloud Computing

cloudofdata.com

Security

What are you securing…and Why?

5 broad areas...

Page 20: Information Security and Cloud Computing

cloudofdata.com

Secure Physical Infrastructurewww.flickr.com/photos/treborrenrut/4481585336/

Page 21: Information Security and Cloud Computing

cloudofdata.com

Secure the Network

Page 22: Information Security and Cloud Computing

cloudofdata.com

Secure Applications

Page 23: Information Security and Cloud Computing

cloudofdata.com

Secure Data

Page 24: Information Security and Cloud Computing

cloudofdata.com

Secure People

Page 25: Information Security and Cloud Computing

cloudofdata.com

Conclusion

Page 26: Information Security and Cloud Computing

cloudofdata.com

it can be!

what matters?

security costs time, money and effort

identify appropriate levels of security…

always remember that people will be people.

Page 27: Information Security and Cloud Computing

cloudofdata.com

Dr Paul Miller

The Cloud of Data

[email protected]

skype: cloudofdata

phone: +44 7769 740083

Except where otherwise noted, this work is licensed under the Creative Commons Attribution Licence. To view a copy of this licence, visit creativecommons.org/licenses/by/2.0/uk/ or send a letter to

Creative Commons, 171 Second St, San Francisco, CA 94105, United States of America

Thank you

cloud of data

Download this presentationslideshare.net/cloudofdata

Made on a

Mac

Page 28: Information Security and Cloud Computing