Monday, 8 February 2010

Cloud and Enterprise Security Architecture

So, I let myself get volunteered to do another web-cast for BrightTALK.

I'm giving the first presentation at their 3rd Cloud Security Summit on the 11th of May. My last web-cast was a fairly generic overview of the security risks associated with cloud computing. My next presentation is a bit more ambitious... I'm aiming to try and bring cloud computing security within the context of wider enterprise architecture. It's either going to be great or one of the more cringe-inducing web-casts on the Interweb :-)

I would like to take a little time to explain the philosophy behind this upcoming presentation. I’ve been thinking for a while now that those of us working in the cloud space need to work harder to bring the technologies into the mainstream – whilst the hype around cloud computing was really useful in bringing it to the forefront, I fear it is now counterproductive to mainstream adoption. By treating cloud as somehow different, or apart from traditional IT delivery, all we are doing is making it appear scarier than it need be to potential consumers. After all, it
is human nature to be wary of things that are different or unknown. What I aim to do is to show that we can bring cloud computing into the wider architecture context of an enterprise – yes cloud brings some unique opportunities and unique challenges, just not necessarily more so than other means of IT delivery. In-house, traditional out-sourcing, cloud – all have their own quirks and are all unique in their own special ways…

So please, tune in to http://www.brighttalk.com/webcasts/8490/attend on the 11th and see whether I manage to pull it off or fall flat on my face!

Friday, 22 January 2010

It really is true!

After years of saying that security is a genuine enabler to business and not just a blocker (or speedbump) on the way, I was fortunate enough to get some proof of my statements recently.

I'm currently working on an information sharing solution between various disparate organisations - most of these organisations have now agreed to share more, particularly sensitive, information (of immense business value) based on their confidence in the security model. Result!

Only a short post today but I thought I ought to have something a bit more positive up here than my last post - especially if it's going to be a while til the next one :-)

Thursday, 7 January 2010

Is it just me?

As much as I would have liked to start 2010 with a nice positive post, I'm going to have to start with a bit of a whinge. What is it about the subject of security that means that everybody working in IT believes that they know how to do it? I rarely see non-DBAs telling their DBAs how their databases should be partitioned but I'll regularly see non-security types discussing security with great authority but little in the way of informed opinion!

So, I'm happy to accept the charge that part of the brief of the security professional is to educate the masses - but I do find it incredibly frustrating that the masses seem pre-programmed with the belief that they already understand security and risk management...

Is it just me?

Tuesday, 1 December 2009

Amusing vulnerability

I came across one of the more entertaining recent vulnerability announcements this morning - take a look at http://www.kb.cert.org/vuls/id/261869. I think it falls into the "well it's obvious now I think about it" category however I hadn't really thought about it... In summary, the way that clientless VPN servers re-write URLs breaks the same origin policy - pretty obvious if you've ever used one of these products and looked at the various URLs that get returned. This means that "bad things" can happen - take a look at the advisory. I'd suggest that any organisation using these kinds of clientless VPNs to provide remote access functionality prevent Internet browsing through these servers; after all, if a user can get to the VPN server he/she has Internet access so why do they need to go through the VPN server?

Why do I view this as entertaining? Well, it's always a little ironic when security products present attack vectors and I'm a big fan of irony. I also know several organisations that make use of this technology and I can't wait to point them to the link...

Thursday, 5 November 2009

AWS in the Enterprise

I managed to get to the Amazon Web Services in the Enterprise event earlier this week. It was a well attended event, with an audience predominantly suited and enterprisey in appearance. Despite an equipment failure (dodgy projector), which necessitated some juggling around with the schedule, I think Amazon managed to get their messages across with respect to the way that their services are currently being used to generate real business value. As ever with these kinds of events, it was the customer presentations that generated the most interest as far as I am concerned. Vendor presentations are fine and dandy but I’m much more interested in what real organisations are doing and the lessons that such organisations have learned during their initial experiences. The presentation from Bob Harris of Channel 4 was particularly encouraging – especially the statement that AWS is now their default platform of choice for web facing applications; C4 projects now need to justify any decision not to use AWS. Bob also provided an interesting anecdote of a senior technical architect from a major SI making a particularly ill-informed comment regarding the security implications of using S3. Lesson here is to be even more diligent than usual when choosing your SI if working in the cloud space. I will admit to a vested interest here :-).
Overall, I think the message that most people will take away from the event is that the AWS platform is maturing and that confidence is increasing amongst enterprises that tricky issues such as compliance and security can be managed. The other message that AWS clearly wanted to get across is that early adopters are likely to obtain a substantial competitive advantage over their more timid competitors due to increased agility and speed to market. We’ll have to see how that one plays out…

Friday, 30 October 2009

Hostage to fortune

So in my previous blog I provided my thoughts from the Cloud World Forum event. During that event I was asked what I believed the cloud market would be like in 5-10 years time. Well I had a stab at an answer at the time but I've had more time to think now and I think I'd revise my answer a little. As much as I hate offering up a hostage to fortune, I think it may be fun to check back in a year or two to see just how wrong I am :o)

First things first. I'll be using the NIST definitions for cloud computing - check them out, they're good and they're vendor-independent. [One beef I did have with the speakers at the Cloud WF was that they all insisted on giving us their own definition of cloud computing. We really should be over that by now... Particularly when they all mentioned the Internet and then a number went on to talk about private clouds.]

Let's have some initial assumptions:

i) IaaS will become more interoperable and portable - either provider-supported through the use of standard APIs (check out http://www.occi-wg.org) or by default through meta-cloud providers reverse engineering closed APIs.

ii) PaaS and SaaS vendors will have a big question to answer around the granularity of the services that they offer.

iii) Consumers will have some serious thinking to do with respect to the amount of lock-in (and subsequent pricing consequences) they are willing to endure.

So in my future IaaS will become seriously commoditised with consumers able to switch loads or other basic IT needs as and when necessary through the use of meta-clouds or other mechanisms for managing multiple cloud providers. I think that's a given. [I'm not going to talk about private or community clouds much in this post, let's just assume that most internal IT systems will be delivered by either private or community cloudy resources - let's face it, there's not much that won't be virtualised in 5 years time other than the obvious usual suspects, y'know those guys still running Cobol on legacy kit...]

The PaaS and SaaS space is much more interesting. In an ideal world, these kinds of providers would completely open up and offer very granular services, presumably charged per transaction or subscription, that consumers could use on a per-service basis from outside of the provider environment. Enabling SOA via cloud services. That would be good. What I fear is that PaaS providers in particular will be very close minded in their thinking and actually encourage the PaaS lock-in that has many cloud commentators (including this one) worried. Why would they do this? Well, once a consumer is effectively locked-in there'll be every temptation to start upping the prices - as long as the pain to the consumer is less than migrating away from the PaaS it's a definite win for the provider. Ah, but competition will prevent this I hear you say. Well, only if the competition isn't doing the same thing!

So that's my view of how the future will pan out. Anyone care to share theirs?

Friday, 23 October 2009

Cloud World Forum

I attended the rather grandly titled Cloud World Forum in London yesterday. Have to say that it was an excellent event, certainly more business focussed than other events such as Cloud Camp (which is always good fun if more IT oriented) or the rather disappointing CloudStorm event a couple of weeks ago.

Highlights and interesting tidbits from the event:
o Kate Craig-Wood of Memset, Intellect and the BCS is now co-leading the technical architecture stream of the Cabinet Office data centre consolitation work
o Asite are a public cloud service that have apparently obtained HMG accreditation for use by the Environment Agency. Unfortunately the presenter left before I had a chance to quiz him on the accreditation aspect!
o Lots of good presentations from the likes of Gartner and BT and some interesting panel sessions, particularly interested in the Gartner research that showed security was still the leading concern with organisations yet to adopt cloud computing. Also interesting that the main drivers for those organisations that have adopted cloud computing were cost and functionality. Who'd have thought it? ;-)
o If you have an interest in collaboration then certainly check out www.huddle.net - collaboration tools, video conferencing etc all in one user-friendly cloud-based offering.
o BT's virtual data centre is an interesting proposition - they do not run VMs for more than one customer on a physical blade. Of course, from a paranoid perspective you may still have de-commissioning concerns when the blade is returned to the wider resource pool. Not dug into the real low-level details here.
o Mimecast have released a Forrester Consulting report into the "total economic impact" of their solution. Yes, the report is specific to Mimecast, however the methodology of the report is of interest and it's useful to have a (vaguely) independent, albeit funded, report showing a detailed ROI argument for a cloud-based service. The report should be downloadable from the Mimecast web-site but I don't think it's there yet.


Downsides:
o Terribly dull presentation from VMWare, Cisco and EMC. Everybody else talking about business benefits, these guys droning on for a long time about IT and infrastructure issues. Bored everyone to tears. Content was actually not bad from a technical perspective but was wrong for the event and the delivery was way too dry. [Example of the problem with the presentation, when talking of moving to cloud services "...got to start with server virtualisation" - well, only if you're talking IaaS and I'd personally start with identifying what you want to do from a business perspective!]
o Still a general ignorance with respect to security - lots of mentions of it during the day but no real understanding of how to manage risk in a cloud environment. [One panellist even described escapes from VMs as 'a bit of a myth' - a bit problematic given that exploits have been published which do just that...]
o Slightly disappointing presentation on cloud security from Cryptocard which was basically yet another demonstration of using Cain and Abel to intercept passwords (*yawn*) and an overly broad statement that 2 factor authentication solves all authentication issues in a cloud environment. Yes, they would say that being as they sell 2FA solutions but it's blatantly not true!

Overall - good event, will definitely try to attend next year's. The attendees were left with the feeling that cloud computing is here, is real and is delivering benefits to the early adopters.