Showing posts with label cloud computing. Show all posts
Showing posts with label cloud computing. Show all posts

Monday, April 6, 2009

The Issue With Cloud Computing

I really like the way The Hoff puts things sometimes:
We’re told we shouldn’t have to worry about the underlying infrastructure with Cloud, that it’s abstracted and someone else’s problem to manage…until it’s not.
I think that sums up in one line the problem with Cloud Computing. You are essentially making your job easier by dumping the responsibility for Security (and Availability) onto someone else's plate. Which is fine until they post a note saying "Sorry" and you are left with no service.

Or worse - data that has gone off somewhere that you don't want it going!

Wednesday, February 18, 2009

[Incomplete Thought] Cloud Computing - WTF is it?!

Sometimes the details are important!

{I'm borrowing the idea of an Incomplete Thought Post from The Hoff - jotting down some though on my blog before it is fully complete. I hope it will lead to faster posting. I have about 25 posts that are half written which I probably should have posted but they are just not quite right. This post is something I have thought about but may be open to discussion.}

Cloud computing is new which is why it is fun. Its like a new gadget and although you probably have no idea what it is or why you need it the Cloud Computing salespeople are already convincing you that your competitors are using it to get ahead of you.

I think that the original plans for Java are pretty similar to what we are expecting from Cloud Computing. Plug in an object a server, know the interfaces to it and Bob's your uncle - you are up and running. You can do limited customisation but you really don't need to know how everything is happening - just accept that it is. In Java we called it "Black Box" and now it is called "Cloud Computing". In both cases you don't get to see the inner workings. In both cases you are not supposed to care.

The power of this is that once you have a good object defined, you can use multiple objects chained together for scaling up or multiple different objects working together for a common cause. You could even get your chain to scale up and down as needed. Likewise, you could drop new objects in place as you want to create new services. You can even change objects as you find better working examples of them.

An example of this is my Blog. I could run it on my own server and manage the server, the database, the web (HTML, code, etc). Or I could go to Blogspot, sign up and be online in a few seconds. And, if all of a sudden there is a massive interest in my Blog (pfft) then Google will supply me the bandwidth and Server power to keep my site up. This is all very well but I have other advantages now too, such as, I have thrown out the vanilla comment section and put in one that works better. I could throw out that one too if I find something better. I have gone with feedburner for managing the RSS feed but I have a few choices there. Inter-connectivity is making my Blog so much more than a static web page.

I am really benefiting from "the cloud". On the other hand - there is nothing on my Blog that is private at all. The whole point of this Blog is to "get the word out there" so the more people that read my stuff - the better. I may not want spammers getting my email but thats pretty much it.

So, honestly, I don't care where my data is stored, what happens to it in transit, who reads it, etc. It is better not to know because my head can hold only so much junk. I also benefit in that I don't have to stick everything together. (Where I do stick different pieces together - it is made very very easy for me) and I don't need to pay for a dedicated server.

On the other hand, (and this is key) if it was corporate information then the details of where, how, what, etc become important.

Thursday, December 4, 2008

What if the cloud is MORE secure?

My job usually involves the normal, boring day to day security stuff and so I don't want to bore my readers (both of them) and give away company secrets. So, I like to stay ahead of the game and blog about what the future holds.

I honestly still think that the past is where we are heading (see my earliest posts). Actually, I think that the future will be summed up thus: "New exciting technologies; good, old-fashioned security".

Some of my most valuable sources are Gartner, Securosis and Rational Survivability. They don't all agree but I use the best of each to make up my own mind.

One technology that all of them have touched on is "Cloud Computing".

This is a lovely concept which has no formal definition. Essentially, it seems to be this: you take all your systems and send them out somewhere to some company who will then host the systems for you. By "systems", I mean applications or technical functions.

The level of control that you have is very variable too but I think that one of the benefits of cloud computing is that you give up having to worry about the nuts and bolts and focus on the benefits. This is wonderful but it can also be a curse - you lose control of your processes and the protection of your data.

For a company that makes widgets not to have to take care of a data center, is excellent. And, you get to leverage off best practices in that you use experts in their own fields to manage your IT. So, you use a dedicated mail place (like GMail or Hotmail), a dedicated storage place, a dedicated CRM place, etc.

Those places can use economies of scale so that it gets cheaper the more people who use their services.

Everyone wins. And especially nowadays that CIOs (at the request of CFOs) are looking to bring their costs down.

The main issue is one of Security. Although, connectivity could be an issue as well. (Your link goes down and you are at the southern most tip of Africa and your presentation is on the other end of a broken link, in North America.. the CEO is waiting..)

But back to Security.

Obviously a company that holds private information for a number of companies would be a target for online criminals so you'd be giving your information to a company that is a target. More than that - you still hold the risk if the information is leaked but you lose the control of knowing where the information is at any one time or what is happening with it. You really only have the company's assurance that they will take good care of your information for you.


It seems that a great a number of Cloud-providers are very vague about what security measures they have in place. There is one that stands out for me though - BoardVantage. I don't use their service (or have anything to do with them really) and have no idea how secure they are but they certainly claim to be very secure - they detail what their controls are and they have had a SAS70 type 2 audit done.

Assuming that they do everything that they say that they do - they are streets ahead of most corporate networks. Going by Verizon's Breach report thing - most companies are breached by methods that are very simple and vulnerabilities that have patches that are very old. So, it may be more secure to use this company than to keep the information on your own network.

PS. I know that there is no one Cloud but as things stand at the moment most "clouds" are really walled gardens (confused yet) and so each provider takes care of their own part of "the cloud".

The answer is that you would have to really consider using a "cloud provider" instead of dismissing them off-hand. And if all major "cloud providers" became more secure then security would not be something holding this idea back but could be a good reason to investigate using the cloud.