Upload
peter-witsenburg
View
353
Download
1
Embed Size (px)
DESCRIPTION
Presentation of the White Paper - The Chain of Trust - A Cloud Service Provider evaluation Guide
Citation preview
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 1 18 June 2013 P.
The Chain of Trust A Cloud Service Provider Evaluation Guide
18 June 2013
1 January 2011
!
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 2 18 June 2013 P.
BELTUG X-change 10:00 Introduction
Johan Schoofs, Project Manager BELTUG (Nl – Fr) 10:10 The BELTUG “Cloud Service Provider Evaluation Guide”
Peter Witsenburg (English) + panel With Q & A and interactive audience discussion (Nl, Fr)
11:00 Coffee Break 11:20 The BELTUG “Cloud Evaluation Guide” cont.
Peter Witsenburg (English) + panel With Q & A and interactive audience discussion (Nl, Fr)
12:20 Conclusions (Dutch, French) 12:30 End
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 3 18 June 2013 P.
Setting the Scene
A few thoughts to get started ! Selected extracts from RightScale’s “State of the Cloud” report
(March 2013)
! RightScale is a SaaS-based cloud computing management solution for managing cloud infrastructure across multiple cloud providers. RightScale enables organizations to easily deploy and manage business-critical applications across public, private, and hybrid clouds.
! The report illustrates the adoption of cloud computing across a broad cross-section of organisations
! 625 respondents, 30% RightScale customers
! Full report:
http://www.rightscale.com/lp/state-of-the-cloud-report.php
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 4 18 June 2013 P.
Setting the Scene
RightScale study key findings: ! Cloud adoption is a given
! Enterprise cloud adoption is gaining steam – and it’s multi-cloud (public, private, hybrid combinations)
! Cloud competition is heating up
! Cloud experience pays off
! Cloud adoption correlates with the DevOps trend
© 2013 RightScale, Inc.
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 5 18 June 2013 P.
Setting the Scene
© 2013 RightScale, Inc.
What are the benefits realised?
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 6 18 June 2013 P.
Setting the Scene
© 2013 RightScale, Inc.
What are the challenges?
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 7 18 June 2013 P.
Cloud Computing as defined by the NIST
National Institute of Standards and Technology
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 8 18 June 2013 P.
Cloud Computing as defined by the NIST
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 9 18 June 2013 P.
NIST Cloud Characteristics
! Cloud computing as defined by the NIST
! On-demand Self-service
A consumer can unilaterally provision compu9ng capabili9es, such as server 9me
and network storage, as needed automa9cally without requiring human interac9on with each service provider
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 10 18 June 2013 P.
How much time is typically needed to provision additional resources ?
On-demand Self-service
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 11 18 June 2013 P.
Is auto-provisioning available?
On-demand Self-service
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 12 18 June 2013 P.
Is self-provisioning possible?
On-demand Self-service
!
Titel ppt 13 datum P.
Cloud Computing as defined by the NIST
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 14 18 June 2013 P.
NIST Cloud Characteristics
! Cloud computing as defined by the NIST
! Broad Network Access
Capabili9es are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client pla?orms (e.g., mobile phones,
tablets, laptops, and worksta9ons).
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 15 18 June 2013 P.
What connectivity options are offered ?
Broad Network Access
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 16 18 June 2013 P.
Does the CSP offer redundant network connectivity?
Broad Network Access
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 17 18 June 2013 P.
What is the minimum guaranteed bandwidth?
Broad Network Access
!
Titel ppt 18 datum P.
Cloud Computing as defined by the NIST
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 19 18 June 2013 P.
NIST Cloud Characteristics
! Cloud computing as defined by the NIST
! Resource Pooling
The provider’s compu9ng resources are pooled to serve mul9ple consumers using a mul9-‐tenant
model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand. There is a sense of loca9on
independence in that the customer generally has no control or knowledge over the exact loca9on of the provided resources but may be able to specify
loca9on at a higher level of abstrac9on (e.g., country, state, or datacenter)
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 20 18 June 2013 P.
What are the redundancies offered on the level of the CSP infrastructure?
Resource Pooling
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 21 18 June 2013 P.
With what type of customers will the customer have to share resources? What is the projected impact? Is additional isolation possible if needed ?
Resource Pooling
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 22 18 June 2013 P.
Backups and “no data loss” guarantee included (RPO & RTO)?
Resource Pooling
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 23 18 June 2013 P.
Is the customer allowed to define the backup/restore policies applicable to his environment?
Resource Pooling
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 24 18 June 2013 P.
How many datacenters and where are the datacenters located?
Resource Pooling
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 25 18 June 2013 P.
Are the required certificates available? Are customers/third parties allowed to audit the CSP ?
Resource Pooling
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 26 18 June 2013 P.
How do customers communicate with the CSP service organization?
Resource Pooling
!
Titel ppt 27 datum P.
Cloud Computing as defined by the NIST
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 28 18 June 2013 P.
NIST Cloud Characteristics
! Cloud computing as defined by the NIST
! Rapid Elasticity
Capabili9es can be elas9cally provisioned and released, in some cases automa9cally,
to scale rapidly outward and inward commensurate with demand. To the
consumer, the capabili9es available for provisioning oIen appear to be unlimited and can be appropriated in any quan9ty at
any 9me.
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 29 18 June 2013 P.
What are the upper resource limits (CPU cores, RAM, IO bandwidth, storage)
Rapid Elasticity
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 30 18 June 2013 P.
Is automatic scaling of resources available?
Rapid Elasticity
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 31 18 June 2013 P.
Are there resource reconfigurations that necessitate a server reboot?
Rapid Elasticity
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 32 18 June 2013 P.
Does the CSP offer price protection and flexibility ?
Rapid Elasticity
!
Titel ppt 33 datum P.
Cloud Computing as defined by the NIST
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 34 18 June 2013 P.
NIST Cloud Characteristics
! Cloud computing as defined by the NIST
! Measured Service
Cloud systems automa9cally control and op9mise resource use by leveraging a metering capability at some level of abstrac9on appropriate to the type of
service (e.g., storage, processing, bandwidth, and ac9ve user accounts). Resource usage can be monitored, controlled, and reported, providing transparency for both the provider
and consumer of the u9lized service.
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 35 18 June 2013 P.
What billing models are available?
Measured Service
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 36 18 June 2013 P.
What resource and application monitoring tools are made available ?
Measured Service
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 37 18 June 2013 P.
How is SLA compliance measured?
Measured Service
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 38 18 June 2013 P.
Some Additional Questions
Does the CSP meet required compliance and security standards?
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 39 18 June 2013 P.
Some Additional Questions
Is a service catalogue with pre-defined service templates available?
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 40 18 June 2013 P.
Some Additional Questions
What are the contract terms such as minimum duration, the renewal policy, termination conditions, …
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 41 18 June 2013 P.
Some Additional Questions
What application and management APIs are made available ?
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 42 18 June 2013 P.
Some Additional Questions
What happens to the data in case of bankruptcy of the CSP or when the contract ends? Who owns the data?
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 43 18 June 2013 P.
Some Additional Questions
What cloud migration options are provided? Are there additional expenses associated with a cloud migration?
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 44 18 June 2013 P.
BELTUG would like to thank:
! John Myklebust ! Karel Torfs ! Peter Witsenburg
for their valuable advice and technical insight used in the creation of the BELTUG Cloud Service Provider Evaluation Guide.
!
BELTUG X-change “Cloud Service Provider Evaluation Guide” 45 18 June 2013 P.
The Chain of Trust A Cloud Service Provider Evaluation Guide
18 June 2013
1 January 2011
!