Improving Security in The Cloud by Using Virtual Silos
Improving Security in The Cloud by Using Virtual Silos
Improving Security in The Cloud by Using Virtual Silos
in the Cloud by
Using Virtual Silos
Dale Wickizer,
CTO, U. S. Public Sector
NASA IT Summit 2010
National Harbor, MD
August 16-18, 2010
Server Virtualization
Network Virtualization
Storage Virtualization
2010 NetApp. All rights reserved.
IT Infrastructure
Execute FY2010 data center consolidation
plans
Adopt cloud computing if best value at
acceptable risk
Cyber Security
Fund tools for continuous monitoring of
agency IT systems
Vivek Kundra, U.S. CIO, http://cio.gov/pages.cfm/page/closing-the-it-gap
2010 NetApp. All rights reserved.
Cloud
Generally, IT as a service
ITaaS
IaaS
PaaS
SaaS
StaaS
5
Non-IT
General access
Internet delivery
Low security
Low SLAs
Cheap or free
Examples:
Facebook,
iTunes
Traditional IT
Examples:
Yahoo! email (SaaS)
Google Apps (SaaS)
Private External
Examples:
Terremark (IaaS)
Public Clouds
Customers only
Private Internal
Employees only
Limited access
Internet/Intranet delivery
Security & firewalls
Enterprise SLAs
High value
HYBRID
PUBLIC
Public Clouds
PRIVATE
High SLA
Low SLA
IT as a Service (ITaaS)
Examples:
USPTO Teleworks
NASA Nebula
Other
Agencies
Internal
Users
Citizens
Business/Mission Requirements
IT Services and SLAs
IT Requirements/ Policies
Provider Services / SLAs
Internal Cloud
External Cloud
Acquisition cost
Operating cost
Simplify staff skill sets
Benefits
Efficient
Predictable (cost wise)
Elastic and Scalable
Always ON
Dynamic
Applications
Network
Storage
Servers
Secure multi-tenancy
Integrated data protection
Service automation and management
Data mobility
Storage efficiency
Automate
Standardize
Offering
IT as a
Service
Self-service
Self-Managing
Chargeback
Virtualize &
Consolidate
Centralize IT,
Policy & Management
Assess Tasks Ahead;
Determine ROI
Zones of
Virtualization on
Shared Storage
Internal
Multi-Tenant
Shared Virtual
Infrastructure
Separate
Separate
High
Low
Hours
Medium
Better
Better
Unified
Combined
High
High
Minutes
Low
Strong
Strong
Outsourced
Cloud Services
Apps
VMs
P Servers
Network
V Storage
P Storage
IT Gov
Separate
IT Budgets
Separate
Server Util
Low
Storage Util
Low
Provisioning Days/Wks
Costs
Very High
SLAs
Poor
Security
Inconsistent
Unified
Combined
High
High
Minutes
Lowest
Strong
Strong
+
Mobile
1 10
1 11
Secure Multi-Tenancy
1 12
Ordering System
User
manual
ticket
manual
Automate
service-levels
Departmental
Administrator
User
self-service
Analyze &
Ordering System
Ensure
Service Broker
Cost Effective
automated
Service
ticket
VMM1
System
Operations
At Scale
IP Adr. Sheet
manual
manual
SISM
CMDB
Level 1 Support
Datacenter
Infrastructure
From 1100*
Orchestration Layer
Service Delivery
CMDB &
Billing
Datacenter
Infrastructure
To ?? (A Lot Fewer)
1 SAP
Policy-based Management
Server Virtualization
API
Network Virtualization
API
Storage Virtualization
API
Self
Service
Portal
Subscriber
Orchestration Tool
Dataset
Service Catalog
Product View
2010 NetApp. All rights reserved.
Assurance
Monitoring
Data Protection
Provisioning
Services
SLA Tool
Monitoring Tool
Protection Tool
Provisioning Tool
Workflow Automation
Storage
Architect
Logical View
1 15
1 16
Service Catalog
Network
Orchestration
Framework
Application
Admin
Gold
Silver
Bronze
Server
Storage
Protection
policies
Provisioning
policies
Resource pool
Chargeback
metrics
Change
backup policy
for Gold
service level
to every 4
Storage/Backup
hours
Admin
1 17
Conclusion
Smart IT organizations and service providers
will virtualize application stacks and run them
on shared infrastructure to drive out cost and
provide their customers the control they desire
These virtual silos will enable multiple tenants
to run securely in a shared, service-based
infrastructure
Unified architectures at each level in the stack
minimize skill sets and processes (lowest cost)
and improve architectural flexibility
Integrated security and data protection are
foundational, to minimize risk
2010 NetApp. All rights reserved.
1 18
Thank you!
Dale Wickizer
Chief Technology Officer,
U. S. Public Sector, NetApp, Inc.
[email protected]
No IT personnel were harmed in the making of this presentation.
2010 NetApp. All rights reserved.
1 19