May 16, 2011
One of the largest perceived barriers to adoption of cloud computing is the concept of security. Based on countless discussions with companies interested in adopting a cloud model, it is clear that many want to achieve the economic promise of cloud but are struggling to figure out how to use a multi-tenant, virtual environment in a way they are comfortable with, given the security concerns of their respective companies.
From an enterprise perspective, most companies are much slower to adopt change based on the amount of established process and policy around existing solutions (change implies cost). In that, one of the barriers that is getting in the way is how different cloud is from what most companies have today. Different means that companies are not as confident securing the new solution, but also different means additional cost to make it work. And while we will all agree that Google and Amazon are clouds, it does not imply that cloud is Google and Amazon.
What I mean by this is that there are many definitions of what cloud is, and while the Google and Amazon offerings are both very strong representations of a cloud solution, that does not limit the definition of cloud to be what Google and Amazon offer (and their offerings get more broad in definition every day). What each consumer needs to figure out is what solution they need, what parameters they are comfortable with (this is where security sits), and what the price needs to be for the solution to be interesting.
We have had several conversations with infrastructure service providers who are more than happy to make additional infrastructure available to companies as an extension of the customers existing infrastructure (They turn the entire system over to the customer, un-configured, and place it in a private VLAN. The customer loads their OS. The customer loads their configuration. The customer integrates the system into their cluster as they see fit), and charge the customer for the time the system is configured on the customer network. Additionally, there are software packages out there (look for "hybrid cloud" keywords) that will help acquire, configure and burst into these extra resources. Because these are complete systems and not virtual machines, customers feel more comfortable that this model is not a change from what they are doing today.
That would be one approach that would imply very little change on the consumer side and therefore minimize cost and additional security exposure. If there were still concerns about cloud resources, an additional set of steps that could be taken would involve classifying the data into security classifications (very typical security practice that may already be implemented) and specifically leverage cloud resources for only workloads that use public datasets (identify cloud-eligible workloads).
Cloud is an opportunity. Not only do companies get to realize economic benefit over time, but they also get to take advantage of emerging standards and innovations in the field of security that are evolving because of cloud. As we spend cycles adapting to cloud and retooling legacy applications into cloud-consumable footprints, they become eligible for the new security capabilities that are being designed and built for cloud. As standards are developed, certifications will become available, and then measurement and auditing will become available at a solution layer instead of at the specific implementation layer. This will help to drive the cost of security lower across the industry and, even better, allow for much more security for the same cost as today.
In summary, find a solution that minimizes change. Cloud is an opportunity to improve economic position and flexibility, and over time, improve performance and security. The more similar that we can make cloud infrastructures to the enterprise infrastructures we have today, the more comfortable customers will be with using cloud from a security perspective, and by minimizing change, we minimize the cost of transitioning to cloud, making it a viable solution for more customers sooner.
Posted by Scott Clark - May 16, 2011 @ 11:27 AM, Pacific Daylight Time
There are 0 discussion items posted.
|
Join the Discussion |
![]()
Scott Clark has been an infrastructure solution provider in the EDA/Semiconductor industry for almost 20 years.
No Recent Blog Comments
Higher education involves many collaborative projects that lend themselves to cloud services, however often those services are not tailored to the uniqueness of an academic environment. That's where the Internet2 NET+ project comes in. By partnering with 16 major cloud providers, the networking consortium is seeking to expedite the delivery of cloud services and by doing so advance research and innovation in the United States.
Read more...
May 17, 2012 |
NVIDIA GeForce GRID, a cloud gaming platform announced at the 2012 GPU Technology Conference (GTC), seeks to reduce the the latency associated with cloud gaming.
Read more...
May 15, 2012 |
New Microsoft report shows that beyond the expected financial benefits, cloud services may offer more comprehensive security features compared to in-house IT operations.
Read more...
May 14, 2012 |
During the second annual Pistoia Alliance conference, three teams demonstrated their newly-implemented cloud-based next-generation sequencing platforms.
Read more...
May 10, 2012 |
PEER1's cloud division, Zunicore, will soon be offering GPU-equipped servers on-demand.
Read more...
May 08, 2012 |
The Patriot Act leads foreign governments to question the security of US cloud services.
Read more...
04/05/2012 | Appro | Designed to meet the growing global demand for HPC solutions, Appro's Xtreme-X™ Supercomputer delivers superior performance-per-watt and reduced I/O latency while bringing significant flexibility to HPC workload configurations including capacity, hybrid, data intensive and capability computing.
04/02/2012 | AMD | Developers today are just beginning to explore the potential of heterogeneous computing, but the potential for this new paradigm is huge. This brief article reviews how the technology might impact a range of application development areas, including client experiences and cloud-based data management. As platforms like OpenCL continue to evolve, the benefits of heterogeneous computing will become even more accessible. Use this quick article to jump-start your own thinking on heterogeneous computing.