SlideShare a Scribd company logo
Selecting a Cloud Service Provider
                 (CSP)
Steven C. Markey, MSIS, PMP, CISSP, CIPP, CISM, CISA, STS-EV, CCSK, CompTIA
                                Cloud Essentials
                           Principal, nControl, LLC
                              Adjunct Professor
  President, Cloud Security Alliance – Delaware Valley Chapter (CSA-DelVal)
Selecting a CSP
• Presentation Overview
  – Cloud Overview
  – Selection Considerations, Criteria & Tools
  – Case Studies
Selecting a CSP

• Cloud Overview
  – Why should you care about the “cloud”?
Cloud Computing Trends
            Numbers
                  Numbers around CC are always impressive:
                 80% fortune companies 1000 will pay
                 to use cloud computing services and
                 30% will pay for infrastructure.
                 Gartner

At this moment, the 5
major search engines
together have 2.000.000                                                               Market :
computers                                                                       42 billon: IDC
                                                                     95 billion: Merrill Lynch


                                                       33% of IT business will be in
                                                                  Cloud Computing
                                                                           Gartner

                                 Microsoft data centre in Chicago:
                                 610.000 servers
             8
                                           8                                     Source: Open Group
Selecting a CSP
• What is Cloud Computing?
  – Re-branded IT Business Model
     • Application Service Provider (ASP)
     • IT Outsourcing (ITO)
  – Confusion
     • Hosting
     • Virtualization
     • Service Provider
Selecting csp iapp_summit_2012 - 5-february
Selecting csp iapp_summit_2012 - 5-february
Selecting a CSP
• Selection Considerations, Criteria & Tools
  –   Risky Business
  –   Security Guidance
  –   Privacy & Data Protection Rules
  –   Service Provider / Consumer Process Alignment
  –   Portability / Interoperability
  –   Contractual / Legal Agreements
  –   Industry Tools & Tricks
Selecting a CSP
• Partly Cloudy with a chance of risk!
  – The Cloud is perceived as risky business.
     • Lack of Control
     • Regulatory Compliance
     • Hacks, outages, disasters….oh my!




                                            Source: Youtube
Selecting a CSP
• Security Guidance
  – Existing Certifications / Attestations
     •   SAS 70 Type II / SSAE 16 / ISAE 3402
     •   ISO 27001 / 2
     •   ISO 27036
     •   BITS Shared Assessments
     •   PCI DSS
     •   HIPAA / HITECH
  – Guidance Specifically for the Cloud
     •   Cloud Security Alliance (CSA) Guide v3.0
     •   CSA Security, Trust & Assurance Registry (STAR)
     •   ENISA Cloud Computing Risk Assessment
     •   NIST SP 800-144 Guidelines Security / Privacy for a Public Cloud
Selecting a CSP
• Privacy & Data Protection Rules
  – Jurisdictions*
     • Regional: EU DPA
     • National: PIPEDA, GLBA, HIPAA / HITECH, COPPA, Safe Harbor
     • Statutory: Bavarian, CA SB 1386 / 24, MA 201 CMR 17, NV SB 227
  – Data Flow & Jurisdictional Adherence
     • Backups
     • CSP Big Data: Traditional, Sensory (e.g. Logs, Metadata) & Social
     • Business / Organizational Ecosystem
  – Contract Clauses
     • European Model Contract Clauses
     • PCI DSS
  – Privacy Best Practices
     • Generally Accepted Privacy Principles (GAPP)               * Not all inclusive.
Selecting a CSP
• Svc Provider / Consumer Process Alignment
  – Change / Configuration Management
     • Process, process & some more process.
     • Automated configuration management?
     • Maturity Model
  – Vendor Loading / Off-loading
     • Provisioning / De-provisioning
  – Disaster Recovery
     • Business / Organizational Ecosystem
     • Maturity Model
Selecting a CSP
• Svc Provider / Consumer Process Alignment
  – Incident Response
     • Computer Security Incident Response Team (CSIRT)
          – Digital Forensics
     • Legal Hold / Litigation Response / e-Discovery
          – Electronic Discovery Reference Model (EDRM)
          – Federal Rules of Civil Procedure (FRCP) 30(b)(6)
  – Records and Information Management (RIM)
     •   Generally Accepted Recordkeeping Principles (GARP®)
     •   Information Governance Reference Model (IGRM)
     •   Information Lifecycle Management (ILM)
     •   MIKE2.0
Selecting a CSP
• Portability / Interoperability
  – Software
  – Data
  – Third Parties
Selecting a CSP
• Contractual / Legal Agreements
  – Service Level Agreements (SLA)
     • Uptime
     • Data Ownership
         – Escrow Data
         – Include Sensory Data, Metadata
     • Exit Clause
     • Testing
         – Disaster Recovery
         – Incident Response
         – Legal Hold / Litigation Response / e-Discovery
     • Right to Audit
         – Vendor & Vendor’s Vendors
         – Privacy Impact Assessments (PIA)
     • Additional Clauses
Selecting a CSP
Selecting a CSP
• Industry Tools & Tricks
  – Cloud Strategic Roadmap
  – Matrices & Software
  – Cloud Brokers
Selecting a CSP
• Industry Tools & Tricks
  – Cloud (Consumer) Strategic Roadmap
     • Business Model Alignment
        – Centralized / Decentralized
        – Industry Vertical
        – Ecosystem Awareness (Customers, Partners, Vendors)
     • Project Portfolio Management (PPM)
        – Assimilate Cloud Projects
            » Involves many stakeholders (business, PMO, IT, etc.).
     • Phased Implementation Approach
        – PrivateHybridPublic
        – BasicAdvanced Services
Selecting a CSP
• Industry Tools & Tricks
  – Cloud (Provider) Strategic Roadmap
     • Business Model / Product Line Scalability
          – e-Discovery, Authentication, Encryption, Scanning
              » Organic
              » Merger & Acquisition
     •   Longevity / Sustainability
     •   Industry / Jurisdiction Focus
     •   Ecosystem Awareness
     •   Technology / Enterprise Architecture (TOGAF, SABSA,
         ITIL)
Selecting a CSP
• Industry Tools & Tricks
  – Matrices & Software
     • Matrices
        – Audit / Compliance Focused
           » CSA Consensus Assessments Initiative Questionnaire
           » CSA Cloud Controls Matrix
           » BITS Enterprise Cloud Self-Assessment
     • Software
        – VMware Cloud Readiness Self-Assessment (CRSA)
        – Bit Titan MigrationWiz
        – Gravitant cloudWiz
Selecting csp iapp_summit_2012 - 5-february
Selecting csp iapp_summit_2012 - 5-february
| cloudWizTM

                                                             Step 1: Plan Capacity

                     Capacity planning is a vital component of cloud computing adoption
                     that involves understanding necessary resource requirements in
                     order to meet the anticipated needs of customers and users.
                     Companies who are able to predict their
                     computing needs can reserve capacity
                     and plan for their predicted usage
                     based on their
                     IT budgets. Other models allow
                     organizations to utilize an on-demand, pay-
                     per-use model which may be more
                     economical.




© Gravitant, Inc. All Rights Reserved. cloudMatrix Version
5.0
| cloudWizTM

                                                             Step 2: Compare Vendors

                     Once a cloudWiz user has filled out their current resource utilization
                     and projected demand, they can then compare vendors, side-by-
                     side.
                     Our inbuilt standardized vendor catalog
                     allows cloud users to compare prices from
                     multiple providers in an expedia-like
                     interface and then optimize for the best
                     vendor based on individual goals and
                     constraints such as cost, QoS and best
                     match.




© Gravitant, Inc. All Rights Reserved. cloudMatrix Version
5.0
| cloudWizTM

                                                             Step 3: Analyze ROI

                     As a cloudWiz user compares vendors across cost, QoS and other
                     constraints, they can also determine ROI Benefits to analyze the
                     effects of selecting a particular provider.




© Gravitant, Inc. All Rights Reserved. cloudMatrix Version
5.0
Selecting a CSP
• Industry Tools & Tricks
  – Cloud Brokers
     •   RightScale
     •   CloudFloor
     •   Skydera
     •   enStratus
Selecting csp iapp_summit_2012 - 5-february
Cloud Computing
• Case Study: Choosing a PaaS CSP
  – Background
     – Mid-sized Capital Management Firm
     – FINRA Regulated
     – Outsourced IT with hardware onsite.
  – Drivers
     – Cost
     – Compliance
  – Technologies
     – Microsoft Exchange / Office 365 Exchange Online
     – Onsite Symantec Enterprise Vault
Cloud Computing
• Case Study: Choosing a PaaS CSP
  – Limitations
     – Budget
     – Skill-sets
     – Resources
     – Monitoring
  – Risks
     – System / Software Interoperability
     – Availability
     – Vendor Management: Contractual / SLA Omissions
     – Scope Creep
     – Data Ownership
Cloud Computing
• Case Study: Choosing a PaaS CSP
  – Lessons Learned
     – Better Safe Than Sorry – Follow GLBA Safeguards
     – Many Moving (Technical) Parts
     – Use Existing Vendors
     – e-Discovery Helped
        – Onsite Journaling
  – Next Steps
     – Testing BCP / DR, Incident Response
     – System Architecture Upgrades
Cloud Computing
• Case Study: Choosing an IaaS CSP
  – Background
     – Venture capital funded pharmacy service provider.
     – Small HIPAA / HITECH Business Associate
     – Level 4 PCI Service Provider
  – Drivers
     – Cost Savings
     – Core Competency Focus
  – Technologies
     – Open-source solutions at a co-location facility.
     – Leverages third party / upstream system providers.
Cloud Computing
• Case Study: Choosing an IaaS CSP
  – Limitations
     – Buying / Negotiating Power
     – HIPAA / HITECH / PCI Requirements
     – Third Party Systems
  – Risks
     – Jurisdiction
     – Availability
     – Cloud / Third Party Ecosystem Reliance
Cloud Computing
• Case Study: Choosing an IaaS CSP
  – Lessons Learned
     – Bigger is not better.
     – Standardize Technology
     – Ask for the documentation from attestations.
     – Sticker Shock
  – Next Steps
     – Work with the CSP
        – Conduct a PIA.
        – Test incident response plans.
Cloud Computing
• Presentation Take Aways
  – There Are No Silver Bullets
  – Think Cloud Strategy & Business Ecosystem
  – You Are Not Alone
     – Leverage CSA, BITS & NIST’s Research
     – Leverage Industry Tools, Tips & Tricks
  – Compare Apples to Apples
     – Technology
     – Pricing
     – SLAs
Cloud Computing
• References
  –   ISO 27036: http://www.iso.org/iso/iso_catalogue/catalogue_tc/catalogue_detail.htm?csnumber=59648
  –   CSA CAIQ: https://cloudsecurityalliance.org/research/cai/
  –   CSA CCM: https://cloudsecurityalliance.org/research/ccm/
  –   CSA STAR: https://cloudsecurityalliance.org/star/
  –   CSA Guide: https://cloudsecurityalliance.org/research/security-guidance/
  –   BITS Enterprise Cloud Self-Assessment: http://sharedassessments.org/media/pdf-EnterpriseCloud-SA.pdf
  –   ENISA Risk Assessment: http://www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing-risk-
      assessment
  –   NIST SP 800-144: http://csrc.nist.gov/publications/drafts/800-144/Draft-SP-800-144_cloud-computing.pdf
  –   Core CloudInspect: https://www.corecloudinspect.com/microsite/index.html
  –   McAfee Database Security Scanner (DSS): http://www.mcafee.com/us/products/security-scanner-for-
      databases.aspx
  –   ARMA GARP: http://www.arma.org/GARP/
  –   IGRM: http://www.edrm.net/projects/igrm
  –   EDRM: http://www.edrm.net/
  –   MIKE2.0: http://mike2.openmethodology.org/
  –   VMware CRSA: http://getcloudready.vmware.com/crsa/
  –   Bit Titan MigrationWiz: https://www.migrationwiz.com/Secure/Default.aspx
  –   Gravitant cloudWiz: http://www.gravitant.com/cloudwiz-home.html
  –   RightScale: http://www.rightscale.com/
  –   CloudFloor: http://www.cloudfloor.com/
  –   Skydera: http://www.skydera.com/
  –   enStratus: http://enstratus.com/
Cloud Computing
• Personal References
  –   ISACA Journal, “Auditing Your Non-Relational, Distributed Database System”:
      http://www.isaca.org/Journal/Current-Issue/Pages/default.aspx
  –   ISACA Journal, "Testing Your Incident Response Plan": http://www.isaca.org/Journal/Current-
      Issue/Pages/default.aspx
  –   PenTest Magazine, "Scanning Your Cloud Environment": http://pentestmag.com/client-side-exploits-
      pentest-082011/
  –   e-Discovery 2.0: In the Cloud: https://s3.amazonaws.com/nControl-Docs/CSA11_Session-SMarkey.ppt
  –   Security in the Cloud: https://s3.amazonaws.com/nControl-Docs/Cloud_Computing-Security.ppt
  –   System Architecture & Engineering for the Cloud: https://s3.amazonaws.com/nControl-
      Docs/Cloud_Computing-Architecture_Engineering.ppt
  –   Cloud Computing Primer: https://s3.amazonaws.com/nControl-Docs/Cloud_Computing-Basic.ppt
  –   Cloud Computing - Authentication & Encryption: https://s3.amazonaws.com/nControl-
      Docs/Cloud_Computing_Security-Session_II.ppt
  –   Cloud Computing - Application & Virtualization Security: https://s3.amazonaws.com/nControl-
      Docs/Cloud_Computing_Security-Session_III.ppt
• Questions?
• Contact
  – Email: steve@ncontrol-llc.com
  – Twitter: @markes1, @casdelval2011
  – LI: http://www.linkedin.com/in/smarkey

More Related Content

PDF
Sukumar Nayak-Detailed-Cloud Risk Management and Audit
PDF
Cloud Computing Risk Management (Multi Venue)
PDF
Distinguishing, Evaluating, and Selecting Cloud Service Providers
PPTX
Servizi Cloud Computing: Scenario, Strategia e Mercato Nicoletta Maggiore
PDF
Asyma E3 2014 The Impact of Cloud Computing on SME's
PDF
Info Sec 2010 Possibilities And Security Challenges Of Cloud Computing (Han...
PDF
Cloud computing understanding security risk and management
PDF
Vendor Landscape: Cloud IaaS
Sukumar Nayak-Detailed-Cloud Risk Management and Audit
Cloud Computing Risk Management (Multi Venue)
Distinguishing, Evaluating, and Selecting Cloud Service Providers
Servizi Cloud Computing: Scenario, Strategia e Mercato Nicoletta Maggiore
Asyma E3 2014 The Impact of Cloud Computing on SME's
Info Sec 2010 Possibilities And Security Challenges Of Cloud Computing (Han...
Cloud computing understanding security risk and management
Vendor Landscape: Cloud IaaS

What's hot (20)

PDF
PDF
Cloud Computing Risk Management (IIA Webinar)
PDF
Cloud Security
PDF
Risk management for cloud computing hb final
PDF
The ABC of Private Clouds
PDF
Capacity Managementand the Cloud
PPT
Unleash Business Innovation with the Next Generation of Cloud Computing
PPT
2011.06.24. Cloud builder - Forum des Partenaires du Cloud IBM - Loic Simon
PPT
2011.06.24. - Cloud Services Solution Provider - Forum des Partenaires du Clo...
PDF
The cloud talk
PDF
Cloud security and adoption
PDF
Cloud Security Strategy
PPT
Cloud Computing,雲端運算-IBM資訊研發中心協理馬紹宏
PDF
Improve network safety through better visibility – Netmagic
PPT
Government cloud computing_strategy
PPTX
Cloud is not an option, but is security?
PPTX
IBM Smarter Business 2012 - PureSystems - PureData
PDF
Host your Cloud – Netmagic Solutions
PDF
OpenNASA v2.0 Slideshare Large File
PPTX
Chap 6 cloud security
Cloud Computing Risk Management (IIA Webinar)
Cloud Security
Risk management for cloud computing hb final
The ABC of Private Clouds
Capacity Managementand the Cloud
Unleash Business Innovation with the Next Generation of Cloud Computing
2011.06.24. Cloud builder - Forum des Partenaires du Cloud IBM - Loic Simon
2011.06.24. - Cloud Services Solution Provider - Forum des Partenaires du Clo...
The cloud talk
Cloud security and adoption
Cloud Security Strategy
Cloud Computing,雲端運算-IBM資訊研發中心協理馬紹宏
Improve network safety through better visibility – Netmagic
Government cloud computing_strategy
Cloud is not an option, but is security?
IBM Smarter Business 2012 - PureSystems - PureData
Host your Cloud – Netmagic Solutions
OpenNASA v2.0 Slideshare Large File
Chap 6 cloud security
Ad

Viewers also liked (8)

PPT
Maximizing your share_point_investment_final
PPTX
Cloud computing arma_nnj
PPT
Cloud computing pmi-dvc-v3
PPT
E discovery 2-cloud_v5
PPT
Securing your esi_piedmont
PPT
Bd cloud v3
PPT
Integrating garp e_discovery
PPTX
Cloud Migration - Cloud Computing Benefits & Issues
Maximizing your share_point_investment_final
Cloud computing arma_nnj
Cloud computing pmi-dvc-v3
E discovery 2-cloud_v5
Securing your esi_piedmont
Bd cloud v3
Integrating garp e_discovery
Cloud Migration - Cloud Computing Benefits & Issues
Ad

Similar to Selecting csp iapp_summit_2012 - 5-february (20)

PDF
Virtualization Into Cloud
PPTX
Moving Enterprise Applications to the Cloud
PDF
Sukhbir jasuja digital_trends_11
PDF
Developing Your Cloud Strategy
PDF
Zsl cloud-management-made-easier-with-scm
PPSX
Vendor classification & rating
PDF
Building a Cloud Offering: Perspectives from Two MSPs
PDF
Lax breakfast forum_developing_your_cloud_strategy_05_10_2012
PPT
Cloud computing adoption in sap technologies
PPTX
Nyc lunch and learn 03 15 2012 final
PDF
Cloud Security Alliance - Guidance
PDF
Are your insurance processes cloud compatible?
PPTX
2012 RightScale Road Trip - San Jose
PPT
Clearing up the cloud: ChannelNext Central
PPTX
Cloud Is Built, Now Who's Managing It?
PPTX
Making Sense of the Cloud
PPT
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...
PDF
Cloud Computing - Jan 2011 - Chandna
PPT
2012.05.11 - Cloud Builders - RV des Experts - Forum du Club Cloud des Parten...
PPT
(Dee fleming) Ccloud computing_la_press_final
Virtualization Into Cloud
Moving Enterprise Applications to the Cloud
Sukhbir jasuja digital_trends_11
Developing Your Cloud Strategy
Zsl cloud-management-made-easier-with-scm
Vendor classification & rating
Building a Cloud Offering: Perspectives from Two MSPs
Lax breakfast forum_developing_your_cloud_strategy_05_10_2012
Cloud computing adoption in sap technologies
Nyc lunch and learn 03 15 2012 final
Cloud Security Alliance - Guidance
Are your insurance processes cloud compatible?
2012 RightScale Road Trip - San Jose
Clearing up the cloud: ChannelNext Central
Cloud Is Built, Now Who's Managing It?
Making Sense of the Cloud
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...
Cloud Computing - Jan 2011 - Chandna
2012.05.11 - Cloud Builders - RV des Experts - Forum du Club Cloud des Parten...
(Dee fleming) Ccloud computing_la_press_final

Recently uploaded (20)

PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Machine learning based COVID-19 study performance prediction
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Empathic Computing: Creating Shared Understanding
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Encapsulation theory and applications.pdf
PPTX
Big Data Technologies - Introduction.pptx
PPT
Teaching material agriculture food technology
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Understanding_Digital_Forensics_Presentation.pptx
Machine learning based COVID-19 study performance prediction
Mobile App Security Testing_ A Comprehensive Guide.pdf
CIFDAQ's Market Insight: SEC Turns Pro Crypto
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Spectral efficient network and resource selection model in 5G networks
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Empathic Computing: Creating Shared Understanding
Per capita expenditure prediction using model stacking based on satellite ima...
Encapsulation theory and applications.pdf
Big Data Technologies - Introduction.pptx
Teaching material agriculture food technology
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Advanced methodologies resolving dimensionality complications for autism neur...
Unlocking AI with Model Context Protocol (MCP)
Digital-Transformation-Roadmap-for-Companies.pptx

Selecting csp iapp_summit_2012 - 5-february

  • 1. Selecting a Cloud Service Provider (CSP) Steven C. Markey, MSIS, PMP, CISSP, CIPP, CISM, CISA, STS-EV, CCSK, CompTIA Cloud Essentials Principal, nControl, LLC Adjunct Professor President, Cloud Security Alliance – Delaware Valley Chapter (CSA-DelVal)
  • 2. Selecting a CSP • Presentation Overview – Cloud Overview – Selection Considerations, Criteria & Tools – Case Studies
  • 3. Selecting a CSP • Cloud Overview – Why should you care about the “cloud”?
  • 4. Cloud Computing Trends Numbers Numbers around CC are always impressive: 80% fortune companies 1000 will pay to use cloud computing services and 30% will pay for infrastructure. Gartner At this moment, the 5 major search engines together have 2.000.000 Market : computers 42 billon: IDC 95 billion: Merrill Lynch 33% of IT business will be in Cloud Computing Gartner Microsoft data centre in Chicago: 610.000 servers 8 8 Source: Open Group
  • 5. Selecting a CSP • What is Cloud Computing? – Re-branded IT Business Model • Application Service Provider (ASP) • IT Outsourcing (ITO) – Confusion • Hosting • Virtualization • Service Provider
  • 8. Selecting a CSP • Selection Considerations, Criteria & Tools – Risky Business – Security Guidance – Privacy & Data Protection Rules – Service Provider / Consumer Process Alignment – Portability / Interoperability – Contractual / Legal Agreements – Industry Tools & Tricks
  • 9. Selecting a CSP • Partly Cloudy with a chance of risk! – The Cloud is perceived as risky business. • Lack of Control • Regulatory Compliance • Hacks, outages, disasters….oh my! Source: Youtube
  • 10. Selecting a CSP • Security Guidance – Existing Certifications / Attestations • SAS 70 Type II / SSAE 16 / ISAE 3402 • ISO 27001 / 2 • ISO 27036 • BITS Shared Assessments • PCI DSS • HIPAA / HITECH – Guidance Specifically for the Cloud • Cloud Security Alliance (CSA) Guide v3.0 • CSA Security, Trust & Assurance Registry (STAR) • ENISA Cloud Computing Risk Assessment • NIST SP 800-144 Guidelines Security / Privacy for a Public Cloud
  • 11. Selecting a CSP • Privacy & Data Protection Rules – Jurisdictions* • Regional: EU DPA • National: PIPEDA, GLBA, HIPAA / HITECH, COPPA, Safe Harbor • Statutory: Bavarian, CA SB 1386 / 24, MA 201 CMR 17, NV SB 227 – Data Flow & Jurisdictional Adherence • Backups • CSP Big Data: Traditional, Sensory (e.g. Logs, Metadata) & Social • Business / Organizational Ecosystem – Contract Clauses • European Model Contract Clauses • PCI DSS – Privacy Best Practices • Generally Accepted Privacy Principles (GAPP) * Not all inclusive.
  • 12. Selecting a CSP • Svc Provider / Consumer Process Alignment – Change / Configuration Management • Process, process & some more process. • Automated configuration management? • Maturity Model – Vendor Loading / Off-loading • Provisioning / De-provisioning – Disaster Recovery • Business / Organizational Ecosystem • Maturity Model
  • 13. Selecting a CSP • Svc Provider / Consumer Process Alignment – Incident Response • Computer Security Incident Response Team (CSIRT) – Digital Forensics • Legal Hold / Litigation Response / e-Discovery – Electronic Discovery Reference Model (EDRM) – Federal Rules of Civil Procedure (FRCP) 30(b)(6) – Records and Information Management (RIM) • Generally Accepted Recordkeeping Principles (GARP®) • Information Governance Reference Model (IGRM) • Information Lifecycle Management (ILM) • MIKE2.0
  • 14. Selecting a CSP • Portability / Interoperability – Software – Data – Third Parties
  • 15. Selecting a CSP • Contractual / Legal Agreements – Service Level Agreements (SLA) • Uptime • Data Ownership – Escrow Data – Include Sensory Data, Metadata • Exit Clause • Testing – Disaster Recovery – Incident Response – Legal Hold / Litigation Response / e-Discovery • Right to Audit – Vendor & Vendor’s Vendors – Privacy Impact Assessments (PIA) • Additional Clauses
  • 17. Selecting a CSP • Industry Tools & Tricks – Cloud Strategic Roadmap – Matrices & Software – Cloud Brokers
  • 18. Selecting a CSP • Industry Tools & Tricks – Cloud (Consumer) Strategic Roadmap • Business Model Alignment – Centralized / Decentralized – Industry Vertical – Ecosystem Awareness (Customers, Partners, Vendors) • Project Portfolio Management (PPM) – Assimilate Cloud Projects » Involves many stakeholders (business, PMO, IT, etc.). • Phased Implementation Approach – PrivateHybridPublic – BasicAdvanced Services
  • 19. Selecting a CSP • Industry Tools & Tricks – Cloud (Provider) Strategic Roadmap • Business Model / Product Line Scalability – e-Discovery, Authentication, Encryption, Scanning » Organic » Merger & Acquisition • Longevity / Sustainability • Industry / Jurisdiction Focus • Ecosystem Awareness • Technology / Enterprise Architecture (TOGAF, SABSA, ITIL)
  • 20. Selecting a CSP • Industry Tools & Tricks – Matrices & Software • Matrices – Audit / Compliance Focused » CSA Consensus Assessments Initiative Questionnaire » CSA Cloud Controls Matrix » BITS Enterprise Cloud Self-Assessment • Software – VMware Cloud Readiness Self-Assessment (CRSA) – Bit Titan MigrationWiz – Gravitant cloudWiz
  • 23. | cloudWizTM Step 1: Plan Capacity Capacity planning is a vital component of cloud computing adoption that involves understanding necessary resource requirements in order to meet the anticipated needs of customers and users. Companies who are able to predict their computing needs can reserve capacity and plan for their predicted usage based on their IT budgets. Other models allow organizations to utilize an on-demand, pay- per-use model which may be more economical. © Gravitant, Inc. All Rights Reserved. cloudMatrix Version 5.0
  • 24. | cloudWizTM Step 2: Compare Vendors Once a cloudWiz user has filled out their current resource utilization and projected demand, they can then compare vendors, side-by- side. Our inbuilt standardized vendor catalog allows cloud users to compare prices from multiple providers in an expedia-like interface and then optimize for the best vendor based on individual goals and constraints such as cost, QoS and best match. © Gravitant, Inc. All Rights Reserved. cloudMatrix Version 5.0
  • 25. | cloudWizTM Step 3: Analyze ROI As a cloudWiz user compares vendors across cost, QoS and other constraints, they can also determine ROI Benefits to analyze the effects of selecting a particular provider. © Gravitant, Inc. All Rights Reserved. cloudMatrix Version 5.0
  • 26. Selecting a CSP • Industry Tools & Tricks – Cloud Brokers • RightScale • CloudFloor • Skydera • enStratus
  • 28. Cloud Computing • Case Study: Choosing a PaaS CSP – Background – Mid-sized Capital Management Firm – FINRA Regulated – Outsourced IT with hardware onsite. – Drivers – Cost – Compliance – Technologies – Microsoft Exchange / Office 365 Exchange Online – Onsite Symantec Enterprise Vault
  • 29. Cloud Computing • Case Study: Choosing a PaaS CSP – Limitations – Budget – Skill-sets – Resources – Monitoring – Risks – System / Software Interoperability – Availability – Vendor Management: Contractual / SLA Omissions – Scope Creep – Data Ownership
  • 30. Cloud Computing • Case Study: Choosing a PaaS CSP – Lessons Learned – Better Safe Than Sorry – Follow GLBA Safeguards – Many Moving (Technical) Parts – Use Existing Vendors – e-Discovery Helped – Onsite Journaling – Next Steps – Testing BCP / DR, Incident Response – System Architecture Upgrades
  • 31. Cloud Computing • Case Study: Choosing an IaaS CSP – Background – Venture capital funded pharmacy service provider. – Small HIPAA / HITECH Business Associate – Level 4 PCI Service Provider – Drivers – Cost Savings – Core Competency Focus – Technologies – Open-source solutions at a co-location facility. – Leverages third party / upstream system providers.
  • 32. Cloud Computing • Case Study: Choosing an IaaS CSP – Limitations – Buying / Negotiating Power – HIPAA / HITECH / PCI Requirements – Third Party Systems – Risks – Jurisdiction – Availability – Cloud / Third Party Ecosystem Reliance
  • 33. Cloud Computing • Case Study: Choosing an IaaS CSP – Lessons Learned – Bigger is not better. – Standardize Technology – Ask for the documentation from attestations. – Sticker Shock – Next Steps – Work with the CSP – Conduct a PIA. – Test incident response plans.
  • 34. Cloud Computing • Presentation Take Aways – There Are No Silver Bullets – Think Cloud Strategy & Business Ecosystem – You Are Not Alone – Leverage CSA, BITS & NIST’s Research – Leverage Industry Tools, Tips & Tricks – Compare Apples to Apples – Technology – Pricing – SLAs
  • 35. Cloud Computing • References – ISO 27036: http://www.iso.org/iso/iso_catalogue/catalogue_tc/catalogue_detail.htm?csnumber=59648 – CSA CAIQ: https://cloudsecurityalliance.org/research/cai/ – CSA CCM: https://cloudsecurityalliance.org/research/ccm/ – CSA STAR: https://cloudsecurityalliance.org/star/ – CSA Guide: https://cloudsecurityalliance.org/research/security-guidance/ – BITS Enterprise Cloud Self-Assessment: http://sharedassessments.org/media/pdf-EnterpriseCloud-SA.pdf – ENISA Risk Assessment: http://www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing-risk- assessment – NIST SP 800-144: http://csrc.nist.gov/publications/drafts/800-144/Draft-SP-800-144_cloud-computing.pdf – Core CloudInspect: https://www.corecloudinspect.com/microsite/index.html – McAfee Database Security Scanner (DSS): http://www.mcafee.com/us/products/security-scanner-for- databases.aspx – ARMA GARP: http://www.arma.org/GARP/ – IGRM: http://www.edrm.net/projects/igrm – EDRM: http://www.edrm.net/ – MIKE2.0: http://mike2.openmethodology.org/ – VMware CRSA: http://getcloudready.vmware.com/crsa/ – Bit Titan MigrationWiz: https://www.migrationwiz.com/Secure/Default.aspx – Gravitant cloudWiz: http://www.gravitant.com/cloudwiz-home.html – RightScale: http://www.rightscale.com/ – CloudFloor: http://www.cloudfloor.com/ – Skydera: http://www.skydera.com/ – enStratus: http://enstratus.com/
  • 36. Cloud Computing • Personal References – ISACA Journal, “Auditing Your Non-Relational, Distributed Database System”: http://www.isaca.org/Journal/Current-Issue/Pages/default.aspx – ISACA Journal, "Testing Your Incident Response Plan": http://www.isaca.org/Journal/Current- Issue/Pages/default.aspx – PenTest Magazine, "Scanning Your Cloud Environment": http://pentestmag.com/client-side-exploits- pentest-082011/ – e-Discovery 2.0: In the Cloud: https://s3.amazonaws.com/nControl-Docs/CSA11_Session-SMarkey.ppt – Security in the Cloud: https://s3.amazonaws.com/nControl-Docs/Cloud_Computing-Security.ppt – System Architecture & Engineering for the Cloud: https://s3.amazonaws.com/nControl- Docs/Cloud_Computing-Architecture_Engineering.ppt – Cloud Computing Primer: https://s3.amazonaws.com/nControl-Docs/Cloud_Computing-Basic.ppt – Cloud Computing - Authentication & Encryption: https://s3.amazonaws.com/nControl- Docs/Cloud_Computing_Security-Session_II.ppt – Cloud Computing - Application & Virtualization Security: https://s3.amazonaws.com/nControl- Docs/Cloud_Computing_Security-Session_III.ppt
  • 37. • Questions? • Contact – Email: steve@ncontrol-llc.com – Twitter: @markes1, @casdelval2011 – LI: http://www.linkedin.com/in/smarkey