Secure DevOps for Government in MOC Hanscom milCloud Secure DevOps for Government in MOC
DoD Software “Development” More than $32B per year on IT Systems Test, Evaluation & Certification Process $2.2B over budget $948M over budget $2.4B over budget $808M over budget Official Acquisition Process
DoD & Cloud Mixed messages Slow adoption Evolving policy Mapping old policies & process to new world Data center vs. cloud Mostly in IaaS phase Paperwork Process
What is Hanscom milCloud (HmC) HmC delivers cloud and security orchestration… simultaneously across multiple public & private clouds… with Automation and Validation… and DevOps across the your favorite tools and the entire lifecycle. It provides self service access to… automated provisioning of applications, configs & data, source code builds, and ElasticTest™, for functional & performance tests, security scans, and network defense. Along with… workflow orchestration, a whole new level of system design discipline, and access to shared library of assets for true collaboration.
HmC & MOC Integration Windows server & desktop USAF Challenges Need for security stack Remote access restricted No Windows (AF loves Windows!) Use Government issues credentials Accreditation Data distribution controls Get things done HmC Implementation AWS VPC-like infrastructure Browser based Remote access to console Windows server & desktop PKI support for auth-n Umbrella accreditation Impact Level governance All other CONS3RT capabilities, inc. ElasticTest™ for functional, performance and security validation
Standard OpenStack Project Flat network No firewall, NAT, etc. Limited logging Protection limited to security groups Separation of activities requires individual OpenStack projects public router user-network user A VM user B VM
CONS3RT Deployed Open Stack Project Each cloudspace has an Open Stack router Each user network has perimeter system to provide firewall logging nat other network services as needed CONS3RT creates and configures: networks nat instance firewall rules
Powered by: www.cons3rt.com Peter Walsh peter.walsh@jackpinetech.com (617) 816-6001