Showing posts with label NIST. Show all posts
Showing posts with label NIST. Show all posts

Feb 20, 2013

Can we talk about SaaS for just a sec?

Don't know about you, but I've been inundated by emails, banner ads, sponsored links, LinkedIn group updates, tweets, and Facebook ads all announcing that some product is now available in a SaaS format. Yes, even by word-of-mouth. It occurred to me that many of these companies may not even know what the as-a-service moniker even means.

I recently sat in on a cloud-101 type presentation by Dan Koffler and, in his presentation, he discussed the interrelationship between IaaS, PaaS, and SaaS. To sum it up, IaaS supports both PaaS and SaaS implementations, and PaaS supports SaaS implementations. This brings up an interesting point: does SaaS conform to the NIST standard definition of cloud computing? Here's an excerpt of the NIST definition:
Software as a Service (SaaS). The capability provided to the consumer is to use the provider’s applications running on a cloud infrastructure 2.
 The footnote at the end of that sentence reads:
2 A cloud infrastructure is the collection of hardware and software that enables the five essential characteristics of cloud computing.
And, as we all know, one of the essential characteristics is "Rapid elasticity". The fact that the upper service model(s) are served by the lower one(s) indicates that any true SaaS implementation would necessarily be elastic. This is the true test of whether a product is SaaS or an ASP (application service provider) implementation where the software is simply hosted on a server.

So, the next time a vendor pitches you on a SaaS product, ask them this question: "Does the product's resources (i.e., compute power, RAM, storage) scale automatically as my organization reaches predetermined usage thresholds (e.g., % utilization of resources or number of users)? Or do I have to call you to increase these resources?" If the answer is "Yes," and "No," in that order, it's a true SaaS implementation. If the answer is "No," and "Yes," it's ASP and you should definitely ask what the SLA is on the vendor completing the request.

Whatever the answer, I assure you that the answer to this question will be telling. Whether the sales rep knows the answer or not will interesting in and of itself.

Oct 16, 2011

Innovation & Community Clouds--Part 1: What is a Community Cloud?

In this three part series, I will provide an overview about what community cloud computing is, its benefits, and its disadvantages, and how it applies to real life examples.

We've all heard the term in passing, but, just what is community cloud computing? The NIST defines it as:
"...infrastructure [that] is shared by several organizations and [that] supports a specific community that has shared concerns (e.g., mission, security requirements, policy, and compliance considerations). It may be managed by the organizations or a third party and may exist on premise or off premise."

Put simply, it's a shared service among a group of organizations that have similar needs or regulatory concerns. The shared service can be infrastructure (IaaS), platform (PaaS), or software (SaaS) and can be deployed in a private or hybrid model depending on the requirements and restrictions. These services are subject to the same criteria applied to cloud computing in general: broad network access to elastic pooled resources on-demand (self-service) in a utility based pricing model.

A community cloud can be created within a horizontal, in which a number of similar organizations participate (such as hospitals), or within a vertical, in which related but dissimilar organizations participate (manufacturer, transportation, wholesaler, retailer, end consumer, etc.).

Naturally, in any case where resources are shared among partners, an agreement must necessarily be in place to regulate and manage its usage. In either of the cases above, all participating organizations must agree on the nature of the services (including adherence to the strictest - often regulatory - requirements applicable to the partner organizations), how they will be shared, and on the procurement method for payment purposes.

As an example, the NYSE announced in a recent press release that it had built a cloud computing environment called the "Capital Markets Community Platform" through which they could "...enable customers to easily purchase the computing power required at a given time so they can focus on their core business strategy rather than complex IT infrastructure design and maintenance. It provides direct, on-demand access to the entire NYSE Technologies portfolio of high-performance, low-latency services..." Clearly, the NYSE and its partners and customers are constrained by security and regulatory requirements common to each of them and the service meets the NIST criteria for community cloud computing mentioned above.

In the next post, we will discuss the benefits of community clouds.

May 11, 2010

Cloud Computing: Nomenclature Issues

The nomenclature for cloud computing, or the model for services consumed on a utility basis, has drawn much criticism and caused much confusion.

For those of you who are not aware, cloud computing draws its name from the fact that IT resources are "in the cloud", meaning that they are somewhere on the Internet, off your network. (A stylized cloud is often used to represent the Internet in architecture diagrams.) The most common term for cloud computing is the "as-a-Service" suffix: infrastructure (IaaS), platform (PaaS), software (SaaS), and storage (such as Amazon's S3). Clearly, IaaS and PaaS are derived directly from the hardware and development platforms and provide users with instances of the underlying resources on demand while storage is the use of storage media as a resource. SaaS, however, poses a problem: is software "cloud computing"? SaaS splits the community into two distinct camps: yes, SaaS is cloud computing because it is available in the cloud; no, SaaS is not cloud computing because you are subscribing to software on a monthly basis (unlike the utility model for IaaS and PaaS).

The NIST defines cloud computing as follows:
"Cloud computing is a model for enabling convenient, on demand network access to a shared pool of configurable computing resources (e.g., networks, servers, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model promotes availability and is composed of five essential characteristics, three service models, and four deployment models."

This definition leaves a bit of room for interpretation. Because of this, I propose alternate terms: "Cloud Based Services", "Services in the Cloud", or "Cloud Services". Each of these terms indicate that the services are consumed (be they IaaS, PaaS, SaaS, or storage) are located or based in the cloud and do not confuse the issue of SaaS being a compute resource per se.

While the terms "Cloud Based Services", "Services in the Cloud", and "Cloud Services" are not revolutionary, they clarify the concept and are inclusive of the various forms of cloud computing.