SlideShare a Scribd company logo
Perspectives on Cloud
Computing and Standards
     Peter Mell, Tim Grance
  NIST, Information Technology
            Laboratory
Standardization and
      Cloud Computing
• Cloud computing is a convergence of many
  technologies
  – Some have their own standards
• This convergence combined with massively
  scaled deployments represents “leap-ahead”
  capabilities
• We have a choice
  – proprietary stovepipe clouds
  – standards based clouds
• Standards will be vital to achieve success

• Can’t standardize what you can’t define
A NIST Definition of Cloud
            Computing
• A computing capability where the
  architecture surrounding massive clusters
  of computers is abstracted from the
  applications using it and a software and
  server framework (usually based on
  virtualization) provides clients scalable
  utility computing capabilities to elastically
  provide many servers for a single
  software-as-a-service style application or
  to host many such applications on a few
  servers.
Foundational Elements
             of Cloud Computing
     Business Models            Architecture
• Web 2.0                 • Autonomic System
• Software as a Service     Computing
  (SaaS)                  • Grid Computing
• Utility Computing       • Platform Virtualization
• Service Level           • Web Services
  Agreements              • Service Oriented
• Open standards, Data      Architectures
  Portability, and        • Web application
  Accessibility             frameworks
                          • Open source software
Need for Cloud Computing
             Standards
• Standards for the cloud architecture
     • Emerging
     • Cloud interfaces are the key
     • Leverage autonomic computing, grids, and
       virtualization?
• Standards for cloud applications
     •   Mature technologies but various approaches exist
     •   Software as a service / Utility computing
     •   Service Oriented Architecture
     •   Web Services standards
     •   Web Application frameworks
Enterprise Cloud
          Infrastructures
• The Need
  – Security and privacy concerns in using 3rd party clouds with
    sensitive data
  – Problem of security boundaries and security compliance
    (e.g., HIPAA, FISMA, SOX)
• How should large enterprises create their own clouds?
  – Which standards should be adopted?
  – What is the role of open source and proprietary software?
  – How should one leverage existing data centers (cloud
    interconnections)?
  – Can one acquire isolated instances of 3rd party clouds?
     • Government owned, contractor operated (GOCO)
  – What is the minimum size needed to make it cost effective to
    build a cloud?
The Federal Cloud
            Infrastructure
• An idea: The Federal government identifies minimal
  standards and an architecture to enable agencies to
  create or purchase interoperable cloud capabilities
  – Agencies would own cloud instances or ‘nodes’
  – Nodes would provide the same software framework for
    running cloud applications
  – Nodes would participate in the Federal cloud infrastructure
  – Federal infrastructure would promote and adopt cloud
    architecture standards (non-proprietary)
  – ‘Minimal standards’ refers to the need to ensure node
    interoperability and application portability without inhibiting
    innovation and adoption thus limiting the scale of cloud
    deployments
The Federal Cloud
            Infrastructure
• Benefits
  – Federal applications could run on any cloud node
  – Federal applications could migrate between cloud nodes
     • Contingency planning/disaster recovery
     • Scalability/elasticity
  – Centralized and standardized security enforcement and
    monitoring (intrusions, secure configurations, vulnerabilities,
    malware)
  – Interagency billing of resources used will self-optimize
    growth of cloud nodes
• Limits to agencies independently building their own
  clouds
  – Lack of the massive scale needed to leverage cloud benefits
  – Non-interoperable architectures (e.g., no disaster recovery
    capabilities)
Possible Approaches
       Moving Forward
• Should the U.S. government:
  – solely use 3rd party clouds (probably just for non-
    sensitive data)
  – procure a single USG cloud
  – procure multiple independent non-interoperable
    USG clouds
  – work towards a Federal cloud infrastructure
    (standards and architecture)
Upcoming Draft NIST
      Cloud Computing Security
             Publication
• NIST Special Publication to be created in FY09
  – Overview of cloud computing
  – Cloud computing security issues
  – Securing cloud architectures
  – Securing cloud applications
  – Enabling and performing forensics in the cloud
  – Centralizing security monitoring in a cloud
    architecture
  – Obtaining security from 3rd party cloud architectures
    through service level agreements
  – Security compliance frameworks and cloud computing
    (e.g., HIPAA, FISMA, SOX)
Questions?
•   Peter Mell
•   Senior Computer Scientist
•   NIST, Information Technology Laboratory
•   301-975-5572
•   mell@nist.gov

•   Tim Grance
•   Program Manager, Cyber and Network Security Program
•   NIST, Information Technology Laboratory
•   301-975-4242
•   grance@nist.gov

More Related Content

PDF
NIST Cloud Computing Standards
PPTX
5.cloudsecurity
PPTX
Cloud computing
PPTX
Cloud computing 9 cloud deployment models and security concerns
PPT
security Issues of cloud computing
PPTX
Cloud computing and data security
PPTX
4.cloud Deployment models
PPTX
Cloud Deployment Model
NIST Cloud Computing Standards
5.cloudsecurity
Cloud computing
Cloud computing 9 cloud deployment models and security concerns
security Issues of cloud computing
Cloud computing and data security
4.cloud Deployment models
Cloud Deployment Model

What's hot (20)

PDF
Basics of Cloud Computing
PPTX
3.cloud service delivery models
PPT
Cloud Computing
PPTX
Chapter "Cloud Computing Architecture and Services"
PPTX
Cloud computing
PPT
Cloud Security - GSFC Presentation, Sept 23 2009
PPTX
Cloud Computing Architecture
PPTX
introduction to cloud computing
PPT
CLOUD COMPUTING AND STORAGE
PPTX
Cloud Encryption
PPT
Army G6 Cloud Roadshow Brief
PPTX
cloud computing.....
PPTX
Basics of cloud
PDF
1.Introduction to cloud computing converted
PDF
Cloud Computing v.s. Cyber Security
PPTX
Cloud Computing
PPTX
Cloud computing
PDF
Cloud Computing - ISO/IEC 17788
PPTX
Chap 4 platform as a service (paa s)
PDF
The Evolution Towards Cloud Computing
Basics of Cloud Computing
3.cloud service delivery models
Cloud Computing
Chapter "Cloud Computing Architecture and Services"
Cloud computing
Cloud Security - GSFC Presentation, Sept 23 2009
Cloud Computing Architecture
introduction to cloud computing
CLOUD COMPUTING AND STORAGE
Cloud Encryption
Army G6 Cloud Roadshow Brief
cloud computing.....
Basics of cloud
1.Introduction to cloud computing converted
Cloud Computing v.s. Cyber Security
Cloud Computing
Cloud computing
Cloud Computing - ISO/IEC 17788
Chap 4 platform as a service (paa s)
The Evolution Towards Cloud Computing
Ad

Viewers also liked (20)

DOC
Cloud def-v15
PDF
Bob Burch Design Portfolio
PDF
Miguel de fuenllana
PDF
Martenot
PPS
Goodlifeadvice
PPT
Premium Analysis Presentation
PPT
Guitarristas barrocos
PDF
El método dalcroze
PDF
Destination Weddings and Honeymoons
PPT
Profilanalysering
PDF
Alfonso mudarra pdf
PDF
Autores vihuela
PDF
Cv Tim Van Veen
PDF
HRA Strategies
PPT
Water Energy
PDF
Martenot
PDF
Edgar willems
PDF
John dowland
PDF
Luys millán
PDF
Luys de narváez
Cloud def-v15
Bob Burch Design Portfolio
Miguel de fuenllana
Martenot
Goodlifeadvice
Premium Analysis Presentation
Guitarristas barrocos
El método dalcroze
Destination Weddings and Honeymoons
Profilanalysering
Alfonso mudarra pdf
Autores vihuela
Cv Tim Van Veen
HRA Strategies
Water Energy
Martenot
Edgar willems
John dowland
Luys millán
Luys de narváez
Ad

Similar to Nist cloud computing-standardsispab-dec2008p-mell-090508165235-phpapp01 (20)

PDF
Cloud Computing technologies virtrulization
DOCX
Cloud Computing presentation . docx
PPTX
Cloud Computing basic concept to understand
PPTX
Beginners Guide and general overview to Cloud Computing.pptx
PPTX
cloud computing hssdbchdfhdchdbxchbschbdhcdc
PDF
Cloud computing
PPT
Radu crahmaliuc 23feb2012
PPTX
cloud computing
PPTX
Clould Computing and its application in Libraries
PPTX
Cloud Computing and Services | PPT
PPTX
Cloud Computing genral for all concepts.pptx
PPT
4831586.ppt
PPTX
Cloud Computing (Lecture 1 & 2).pptx
PDF
CC Notes.pdf of jdjejwiwu22u28938ehdh3y2u2838e
PPTX
Cloud computing ppt presentation unit 3 FOC
PDF
Cloud computing
PPT
Cloud Computing
PPT
Alhadeff cloud computing cyber technology.ppt
PPTX
Introduction to Cloud Computing
PPTX
Introduction to Cloud Computing.pptx
Cloud Computing technologies virtrulization
Cloud Computing presentation . docx
Cloud Computing basic concept to understand
Beginners Guide and general overview to Cloud Computing.pptx
cloud computing hssdbchdfhdchdbxchbschbdhcdc
Cloud computing
Radu crahmaliuc 23feb2012
cloud computing
Clould Computing and its application in Libraries
Cloud Computing and Services | PPT
Cloud Computing genral for all concepts.pptx
4831586.ppt
Cloud Computing (Lecture 1 & 2).pptx
CC Notes.pdf of jdjejwiwu22u28938ehdh3y2u2838e
Cloud computing ppt presentation unit 3 FOC
Cloud computing
Cloud Computing
Alhadeff cloud computing cyber technology.ppt
Introduction to Cloud Computing
Introduction to Cloud Computing.pptx

Recently uploaded (20)

PDF
Complications of Minimal Access Surgery at WLH
PDF
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
PPTX
Cell Types and Its function , kingdom of life
PDF
01-Introduction-to-Information-Management.pdf
PDF
RMMM.pdf make it easy to upload and study
PDF
FourierSeries-QuestionsWithAnswers(Part-A).pdf
PDF
ANTIBIOTICS.pptx.pdf………………… xxxxxxxxxxxxx
PPTX
Cell Structure & Organelles in detailed.
PPTX
Introduction to Child Health Nursing – Unit I | Child Health Nursing I | B.Sc...
PDF
Insiders guide to clinical Medicine.pdf
PPTX
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
PPTX
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
PDF
Microbial disease of the cardiovascular and lymphatic systems
PDF
Anesthesia in Laparoscopic Surgery in India
PDF
Pre independence Education in Inndia.pdf
PDF
Physiotherapy_for_Respiratory_and_Cardiac_Problems WEBBER.pdf
PDF
Supply Chain Operations Speaking Notes -ICLT Program
PPTX
PPH.pptx obstetrics and gynecology in nursing
PDF
Classroom Observation Tools for Teachers
PDF
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
Complications of Minimal Access Surgery at WLH
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
Cell Types and Its function , kingdom of life
01-Introduction-to-Information-Management.pdf
RMMM.pdf make it easy to upload and study
FourierSeries-QuestionsWithAnswers(Part-A).pdf
ANTIBIOTICS.pptx.pdf………………… xxxxxxxxxxxxx
Cell Structure & Organelles in detailed.
Introduction to Child Health Nursing – Unit I | Child Health Nursing I | B.Sc...
Insiders guide to clinical Medicine.pdf
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
Microbial disease of the cardiovascular and lymphatic systems
Anesthesia in Laparoscopic Surgery in India
Pre independence Education in Inndia.pdf
Physiotherapy_for_Respiratory_and_Cardiac_Problems WEBBER.pdf
Supply Chain Operations Speaking Notes -ICLT Program
PPH.pptx obstetrics and gynecology in nursing
Classroom Observation Tools for Teachers
3rd Neelam Sanjeevareddy Memorial Lecture.pdf

Nist cloud computing-standardsispab-dec2008p-mell-090508165235-phpapp01

  • 1. Perspectives on Cloud Computing and Standards Peter Mell, Tim Grance NIST, Information Technology Laboratory
  • 2. Standardization and Cloud Computing • Cloud computing is a convergence of many technologies – Some have their own standards • This convergence combined with massively scaled deployments represents “leap-ahead” capabilities • We have a choice – proprietary stovepipe clouds – standards based clouds • Standards will be vital to achieve success • Can’t standardize what you can’t define
  • 3. A NIST Definition of Cloud Computing • A computing capability where the architecture surrounding massive clusters of computers is abstracted from the applications using it and a software and server framework (usually based on virtualization) provides clients scalable utility computing capabilities to elastically provide many servers for a single software-as-a-service style application or to host many such applications on a few servers.
  • 4. Foundational Elements of Cloud Computing Business Models Architecture • Web 2.0 • Autonomic System • Software as a Service Computing (SaaS) • Grid Computing • Utility Computing • Platform Virtualization • Service Level • Web Services Agreements • Service Oriented • Open standards, Data Architectures Portability, and • Web application Accessibility frameworks • Open source software
  • 5. Need for Cloud Computing Standards • Standards for the cloud architecture • Emerging • Cloud interfaces are the key • Leverage autonomic computing, grids, and virtualization? • Standards for cloud applications • Mature technologies but various approaches exist • Software as a service / Utility computing • Service Oriented Architecture • Web Services standards • Web Application frameworks
  • 6. Enterprise Cloud Infrastructures • The Need – Security and privacy concerns in using 3rd party clouds with sensitive data – Problem of security boundaries and security compliance (e.g., HIPAA, FISMA, SOX) • How should large enterprises create their own clouds? – Which standards should be adopted? – What is the role of open source and proprietary software? – How should one leverage existing data centers (cloud interconnections)? – Can one acquire isolated instances of 3rd party clouds? • Government owned, contractor operated (GOCO) – What is the minimum size needed to make it cost effective to build a cloud?
  • 7. The Federal Cloud Infrastructure • An idea: The Federal government identifies minimal standards and an architecture to enable agencies to create or purchase interoperable cloud capabilities – Agencies would own cloud instances or ‘nodes’ – Nodes would provide the same software framework for running cloud applications – Nodes would participate in the Federal cloud infrastructure – Federal infrastructure would promote and adopt cloud architecture standards (non-proprietary) – ‘Minimal standards’ refers to the need to ensure node interoperability and application portability without inhibiting innovation and adoption thus limiting the scale of cloud deployments
  • 8. The Federal Cloud Infrastructure • Benefits – Federal applications could run on any cloud node – Federal applications could migrate between cloud nodes • Contingency planning/disaster recovery • Scalability/elasticity – Centralized and standardized security enforcement and monitoring (intrusions, secure configurations, vulnerabilities, malware) – Interagency billing of resources used will self-optimize growth of cloud nodes • Limits to agencies independently building their own clouds – Lack of the massive scale needed to leverage cloud benefits – Non-interoperable architectures (e.g., no disaster recovery capabilities)
  • 9. Possible Approaches Moving Forward • Should the U.S. government: – solely use 3rd party clouds (probably just for non- sensitive data) – procure a single USG cloud – procure multiple independent non-interoperable USG clouds – work towards a Federal cloud infrastructure (standards and architecture)
  • 10. Upcoming Draft NIST Cloud Computing Security Publication • NIST Special Publication to be created in FY09 – Overview of cloud computing – Cloud computing security issues – Securing cloud architectures – Securing cloud applications – Enabling and performing forensics in the cloud – Centralizing security monitoring in a cloud architecture – Obtaining security from 3rd party cloud architectures through service level agreements – Security compliance frameworks and cloud computing (e.g., HIPAA, FISMA, SOX)
  • 11. Questions? • Peter Mell • Senior Computer Scientist • NIST, Information Technology Laboratory • 301-975-5572 • mell@nist.gov • Tim Grance • Program Manager, Cyber and Network Security Program • NIST, Information Technology Laboratory • 301-975-4242 • grance@nist.gov