Peter Coffee kicking off this afternoon by NOT talking about cloud directly... And talking about social media and email. More importantly, Coffee said that Canadian brands can be global brands today because of social media. As a measure of this theory, Facebook traffic has exploded whereas coporate website traffic has declined markedly. Google "Yourfavoritedomainname + sucks" and you'll find out exactly how much customers don't like an organisation.
A few thoughts from Coffee on social customers:
- Prospective service providers seek public feedback
- Buyers collaborate on competitor research
- Customers tell the world when they're not happy
Companies need to react and adapt to this new competitive environment and push the customer satisfaction metric to the lowest possible level in the organisation.
Coffee also peered into the future by using a healthcare model that used event driven demand to shape the dlivery of services. He gave another example of using educational modeling by using instantaneous quizzing of students to determine whether the content is effective. This could be interesting because the nature of our demand for services has changed: service providers are being asked to provide services when desired. This is important for healthcare because on-demand healthcare is causing the congestion we see in emergency rooms and walk-in clinics.
IT departments, according to Coffee, do not adhere to the concept of social customers and are basically the opposite of social. Of course, this is the ultimate reason why cloud computing still faces adoption challenges in Canada and continues to do so, albeit to a lesser extent, in the US. How does IT adapt to this in order to become a purveyor of value instead of a consumer of capital?
Even though we haven't heard much about community clouds recently, Coffee brought up the concept of securing environments to the highest common level as a way of showing value to a given market segment and quoted Forrester as stating that multi-tennant architectures can be more secure than individual VMs. Luckily, he qualified this by saying transparency is the key to earning trust from customers. Trust is an important concept because cloud + security are not commonly understood yet even though AAA and the CIA triad are basic concepts that can be applied to cloud computing. Shock! Horror!
Security remains an important issue for cloud adopters. But to what extent is security truly preventing them from adopting cloud based services? Is it really that big of a deal?
Of course security is a real issue in IT; as a company doing business on the Internet, security is one of those things that, if you get it wrong, your business can be seriously hurt by the consequences. Security threats range in complexity but all have one thing in common: people are the main security threat, always have been, and always will be, through ignorance, accidental misconfiguration, or malicious behavior.
So why, then, is security in the cloud such a big deal? Governance. There is a lack of visibility into the security of cloud based services generally due to the nature of the contracts and the remedies offered as well as the lack of regulation whether it be industry, government, or some combination of the two. In Canada, privacy law requires that the owner of private information (the organization(s) to whom the individual has provided the information) ensure that the information is held in confidence by whatever vendor/service provider makes legal use of that information. This means that the Government has mandated industry to regulate itself by making the organizations liable for any disclosure of that information including that by a third party such as a cloud services provider.
At its core, this is an issue of risk tolerance; how tolerant is an organization to risk. The answer to this question is not complete without considering the tolerance to the magnitude of the impact to the organization (say $ for argument's sake). Basically, The greater the risk and the greater the impact, the more reluctant organizations will be. This is the basis for a basic risk response matrix.
(There are obviously more complex risk tolerance matrices, but it is sufficient for the purposes of this posting. Accept=make use of cloud based services as is. Mitigate=take measures to offset risks such as including remedies in contracts. Avoid=don't make use of cloud based services.)
There are those, even some at Cloud Connect 2011, that are claiming that security is a non issue. Unfortunately, most organizations are still worried about it and beg to differ. Countless polls prove this point. That said, this shouldn't be anything new to us. This very same argument/concern/issue has been dealt with before. At least twice: during the rise of e-commerce as we know it and again around the increase in outsourcing. Why is cloud any different? Let's figure out a way to secure our services, federate them, govern them, and then let's move on!
OK, so I oversimplified. The point is, there is too much discussion and not enough action. SaaS vendors have caught on. Their contracts address the issue of security. So, if customers want it, why aren't more vendors providing it, and why are yet others claiming that it's not a big deal?
By now, everyone has looked at Neal Sample's presentation from Cloud Connect 2011 (arguably the most important keynote as far as I am concerned) of how eBay makes use of the public cloud. I dare say, that they have shown significant and very real cost savings.
Up until early March, the best we could do was theorize and sort of guesstimate at how much could be saved on costs by making use of a cloud based architecture; how much were servers costing, what was their utilization, how many person hours were spent managing them, etc. vs. spinning up AWS instances and shunting excess or unplanned workload into the public cloud. Many vendors offer their own version of cost/benefit calculators and "financial checklists" but they mostly miss the point: consumers of cloud based services need to be honest with themselves about how they consume IT assets and services before they can really estimate their cost savings. eBay did that. They looked at the whole enchilada, discovered where their efficiencies or inefficiencies lie and showed huge cost savings.
I have no doubt that eBay's model has inspired at least a few organizations to look at their utilization. The trick is for them to decide what is right for the organization. eBay's model certainly isn't a one-size-fits-all. It is up to individual organizations to understand their asset utilization profile, their tolerance to risk, and to see how cloud based services fit into their governance model before making such a leap, however compelling it may be.
Jinesh just echoed some thoughts I've been incubating regarding security and risk: GRC/security boils down to risk tolerance. If you have a high tolerance to risk, then there is no problem using AWS; if you have low tolerance to risk, involve your security team early and often and make them a part of the decision making process.
Comment from the audience: "My legal wants to redline the AWS contract but I don't think Amazon would go for that." According to Jinesh, Amazon has a legal team that is available to address legal concerns. I will have to look into this given the work that the team at QMUL did on cloud based services contracts.
"Enterprise IT is under pressure to transform from bottleneck to business enabler. The rise of public cloud services such as Amazon EC2 have provided a clear example of what enterprise IT is expected to become: A simple, self-service on-demand infrastructure provider. IT organizations that fail to make this transformation will watch in vain as rogue workloads follow the path of least resistance to the public cloud."
How's that for using fear as a marketing tool? That was the introductory paragraph for an invitation to join a webinar on transforming the IT organization into the purveyor of on-demand services.
Of course, they're right at a certain level. Anyone with a credit card can spin up an instance and have your data crunched, client information or sensitive documents stored off your secure network, or generally in an environment that has not been vetted according to your organization's security practice.
So, how then, does one go about transforming the IT organization into a 'business enabler'? It seems to me that this same question was posed a decade ago when IT budgets were running rampant and accounted for a significant chunk of an organizations expenses.
This particular situation has arisen not because IT is not a business enabler, but because of a perceived lack of flexibility, long delivery times for IT service requests, and expense policies that, while originally robust, now have loopholes that allow anyone with a credit card to acquire off net compute power.
Any potential solution should include the following:
- Revise IT processes to increase flexibility in meeting user requests.
- Review IT service metrics to determine delivery times and work to reduce them.
- Refresh expense policies to take into account this new reality and educate employees about the new policies and how they will help reduce risk for the organization.
In general, this requires an update of the organization's governance structure to ensure that its processes are adequate to manage this new technology, whether it is a planned introduction or not.
Another way that IT can help resolve this problem is to partner with a cloud services provider or identify an approved vendor for future demand of cloud based services. Of course, this requires that the organization have a more mature level of understanding of what cloud based services can offer as well as the will to adopt these services before such a relationship can be created.
Employees under pressure to perform and meet goals will follow the path of least resistance to achieve them. Perhaps management should consider clarifying employees' roles in this context as well and in parallel to all other efforts.
I've decided that I'm going to start working on building the Cloud Security Alliance (CSA) - Canada Chapter. There seems to be interest so I thought I would write up a quick entry to see if anyone was interested in joining the Canadian chapter.
The CSA is a fledgling organization dedicated to "promote the use of best practices for providing security within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing." As of this posting, there are 2 official chapters and 5 chapters in development. In addition, there are several working groups:
Group 1. Architecture and Framework
Group 2. Governance, Risk Management, Compliance, Audit, Physical, BCM, DR
Group 3. Legal and eDiscovery
Group 4. Portability & Interoperability and Application Security
Group 5. Identity and Access Mgt, Encryption & Key Mgt
Group 6. Data Center Operations and Incident Response
Group 7. Information Lifecycle Management & Storage
Group 8. Virtualization and Technology Compartmentalization
Editorial Group
Educational Working Group
Solution Provider Advisory Council
It's obvious to me that the questions of governance and security (issues important to me) are not going to go away by themselves. Nor should it be left solely to industry to develop competing views/models/tools - it's simply inefficient. It behooves us, the denizens of the industry, to help in those efforts.
Please let me know if you are interested in joining the CSA - Canada Chapter by sending your coordinates (name, company, title, email, phone) to pano(dot)xinos(at)gmail(dot)com.
[Edit: added working groups. --PX--]
Judith Hurwitz, of Hurwitz & Associates, has a slide in one of her presentations that refers to protecting data in the cloud and reads, "Government and Industry regulation must be adhered to regardless of the location of your applications and your information."
The first thing that popped into mind was the classic 70s cop show scene where the cops, all sporting mutton chops and polyester leisure suites, are arguing about ownership of the crime scene...
The next thing that popped into mind was how confusing this must be; organizations have to be aware of, and comply with, the laws and/or regulations that apply to their operations in the country where the application(s) and data sit as well as their own country's. There can be no other interpretation of the slide because we know that privacy laws in Europe can be tough and those in the US are different but yet there is an expectation of data privacy in both jurisdictions. The slide deck contains several examples ranging from specific country laws, co-mingling of data, secondary data use, and the next point, data transfer across borders.
What about data in transit? Is data subject to the laws and/or regulations of the jurisdictions through which it passes en route to/from the site hosting the application? There are restrictions on sending data out of some European countries unless the receiving end complies with European requirements on data security, but what of the countries in between? Data stored in Europe usually go through gateways to get to North America and then through a gateway into the US, Canada, or Mexico and vice-versa. I suppose that the argument can be made that data in transit over backbone infrastructure is not susceptible to attack. But then I recall a certain government agency that wanted to snoop Internet data streams not too long ago...
What of the end users' expectation of privacy? If these users are in yet another country, can the requirements of that country be imposed on the applications' owner? Can lawsuits be filed in this case?
The simplest and most efficient solution would be to comply with the common requirements and the most stringent requirements from each country in order to be compliant with all. Not sure if this is the answer but it seems that it could be. Then again, I'm no lawyer so I may be wrong here.
Interesting article at Government Technology about government organizations trying to cut costs by reducing maintenance fees. Not that this is real news since many "cash-starved" organizations are trying to cut costs. It makes you wonder how this will play out. Maintenance fees can range anywhere from 18% to 24% of net costs with the typical rate set at 20%. If vendors give in, their revenue streams suffer and they have to make up the difference elsewhere by increasing services costs or product pricing to satisfy shareholders.
On the other hand, cloud based services do not have maintenance surcharges (they're built in to the pricing model). The States of Oregon and Arizona have adopted Google Apps in their education system and the City of Los Angeles was actively debating it last year as well. But does SaaS serve government as well as on premise hardware and software?
Well, it all depends on your governance model. Cloud providers are feverishly working on securing their offerings in order to attract customers. However, it begs the question: can clouds be as secure as your own network? I suppose it is possible, but your network is secured according to your own governance and security policies. Unless the provider agrees to secure the environment according to your policies, it may not be sufficient. Add to that the fact that availability and SLAs suffer with multiple providers (99.99% telco uptime, 99.5% cloud provider uptime = 99.49% effective uptime guarantee) and we see why governance is a major issue facing cloud adopters, not the least of which is governments.
That said, it would be surprising if security and governance concerns would not be resolved. It seems to me that those organizations that would benefit most from cloud will modify their governance policies accordingly and cloud providers will improve their offerings so that the two will meet at some compromising middle ground. Is this the beginning of the end for maintenance contracts? I don't think so, but I bet they're going to change as cloud gains traction...
InformationWeek published a story on their site about how IT departments are 'losing ground' on cloud computing. The premise is that individuals in the organization are adopting cloud services with or without IT's knowledge and/or approval.
The article suggests that this is a security issue which, at the end of the day, it is. But, security is a part of information and organizational governance and, as such, this should be treated as a governance issue. If IT can't control usage of cloud services by the organization, is this a failure of IT or the organization? I can understand why someone would just use a credit card to get what they needed done sooner than later. However, this is no excuse for ignoring organizational business practice and compliance policies. In some organizations this would be grounds for dismissal.
Granted, IT departments can be slow. How, then, can IT help resolve this problem? How can IT be part of the solution? Clearly, employees need to be sensitized to the risks and issues surrounding their use of cloud based services in the organization and who better to do so than IT? Of course, this should not be taken to mean that IT should scare the bejeesus about of them, rather this should be an ooprtunity for IT to move closer to the employees and the business by seriously considering cloud based services and their impact on the organization, good or bad.
A great quote from the article: "Hello: it's 2010 and do you know where your data resides?"