Cloud Computing in the Federal Sector: What is it, what to worry about, and what to negotiate. Presented by: Sabrina M. Segal, USITC, Counselor to the.

Slides:



Advertisements
Similar presentations
Pros and Cons of Cloud Computing Professor Kam-Fai Wong Faculty of Engineering The Chinese University of Hong Kong.
Advertisements

Clouds: What’s new is old is new… Joseph Alhadeff, VP Global Public Policy; CPO, Oracle.
Security, Privacy and the Cloud Connecticut Community Providers’ Association June 20, 2014 Steven R Bulmer, VP of Professional Services.
Chapter 22: Cloud Computing and Related Security Issues Guide to Computer Network Security.
Cloud Computing NSAA Tallahassee September 2010 Brian Rue
Clouds C. Vuerli Contributed by Zsolt Nemeth. As it started.
Cloud SUT proposal OSGcloud group. Objective To fill in the Research the group about the thinking within the OSG working group To solicit new ideas/proposals.
The Cloud: Demystified Neil Cattermull Frontier Technology.
Wally Kowal, President and Founder Canadian Cloud Computing Inc.
Be Smart, Use PwrSmart What Is The Cloud?. Where Did The Cloud Come From? We get the term “Cloud” from the early days of the internet where we drew a.
Cloud Computing Guide & Handbook SAI USA Madhav Panwar.
SPRING 2011 CLOUD COMPUTING Cloud Computing San José State University Computer Architecture (CS 147) Professor Sin-Min Lee Presentation by Vladimir Serdyukov.
Design of New or Changed Services in the Cloud: An ISO/IEC Perspective Ronald Dattero Missouri State University, CIS Dept. Stuart D. Galup Florida.
Securing and Auditing Cloud Computing Jason Alexander Chief Information Security Officer.
Cloud computing Tahani aljehani.
Discussion on LI for Mobile Clouds
Plan Introduction What is Cloud Computing?
NARA’s FAQ and Bulletin on Managing Federal Records in Cloud Computing Environments Arian D. Ravanbakhsh Electronic Records Policy Specialist RACO Chicago.
Introduction to Cloud Computing Zsolt Németh MTA SZTAKI.
Effectively and Securely Using the Cloud Computing Paradigm.
Cloud Computing. 2 A division of Konica Minolta Business Solutions USA Inc. What is Cloud Computing? A model for enabling convenient, on-demand network.
CLOUD COMPUTING & COST MANAGEMENT S. Gurubalasubramaniyan, MSc IT, MTech Presented by.
Introduction to Cloud Computing
“ Does Cloud Computing Offer a Viable Option for the Control of Statistical Data: How Safe Are Clouds” Federal Committee for Statistical Methodology (FCSM)
Celoxis Intro Celoxis is a web-based project management software company based in India. The Celoxis application integrates management of projects, resources,
By Naranchuluun Davaanyam. IT Perspective for Developer Capital Expenditure (CapEx) for development environ. could be high Acquisition of hardware, software,
Cloud Computing Saneel Bidaye uni-slb2181. What is Cloud Computing? Cloud Computing refers to both the applications delivered as services over the Internet.
Cloud computing is the use of computing resources (hardware and software) that are delivered as a service over the Internet. Cloud is the metaphor for.
CLOUD COMPUTING  IT is a service provider which provides information.  IT allows the employees to work remotely  IT is a on demand network access.
Cloud Computing. What is Cloud Computing? Cloud computing is a model for enabling convenient, on-demand network access to a shared pool of configurable.
Computer Science and Engineering 1 Cloud ComputingSecurity.
M.A.Doman Short video intro Model for enabling the delivery of computing as a SERVICE.
Cloud Computing: The Basics, Benefits and Risks Image:
Plan  Introduction  What is Cloud Computing?  Why is it called ‘’Cloud Computing’’?  Characteristics of Cloud Computing  Advantages of Cloud Computing.
Cloud Computing Project By:Jessica, Fadiah, and Bill.
LEGAL ISSUES IN CLOUD COMPUTING
The Cloud Earl C. Rich, CRM. We’re Gonna Talk About: Define what The Cloud is Discuss the different types of Clouds Discuss Cloud service-types RIM issues.
Cloud Computing. Definition  The Cloud is a metaphor for the Internet  Cloud computing is a model for enabling ubiquitous, convenient, on-demand network.
PaaSport Introduction on Cloud Computing PaaSport training material.
Cloud Computing Use Case Draft v2.
Cloud computing Cloud Computing1. NIST: Five essential characteristics On-demand self-service Computing capabilities, disks are demanded over the network.
CLOUD COMPUTING RICH SANGPROM. What is cloud computing? “Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a.
Software Acquisition Management. Cloud Computing 2.
3/12/2013Computer Engg, IIT(BHU)1 CLOUD COMPUTING-1.
Web Technologies Lecture 13 Introduction to cloud computing.
G-Cloud - The Delivery of a Shared Computing Platform for Government Ian Osborne Director, Digital Systems KTN Intellect.
Towards the Cloud! Ian Osborne Director, Digital Systems KTN, Intellect.
ISA 201 Intermediate Information Systems Acquisition.
Template V.17, July 29, 2011 What’s the Cloud Got to do with HR Transformation? Heath Brownsworth, Director Technology Strategy.
© 2012 Eucalyptus Systems, Inc. Cloud Computing Introduction Eucalyptus Education Services 2.
INTRODUCTION TO CLOUD COMPUTING. CLOUD  The expression cloud is commonly used in science to describe a large agglomeration of objects that visually appear.
Private KEEP OFF! Private KEEP OFF! Open! What is a cloud? Cloud computing is a model for enabling convenient, on-demand network access to a shared.
Corporate Concerns on Cloud Services Environment กษิภัท ธนิตธนาคุณ คอลัมนิสต์ “IT Auditing” นิตยสาร ELEADER กรรมการผู้จัดการ บริษัท เคที ไอที โซลูชั่น.
The National Institute of Standards and Technology (NIST) define Cloud Computing as “a model for enabling convenient, on-demand network access to a shared.
Chapter 6: Securing the Cloud
Understanding The Cloud
Avenues International Inc.
Paul Woods Chair, MITIGATION: Ensuring we procure cloud services taking into account of the risks involved Paul Woods Chair, ISNorthEast.
Cloud Computing Kelley Raines.
Chapter 21: Cloud Computing and Related Security Issues
Introduction to Cloud Computing
Chapter 22: Cloud Computing Technology and Security
CNIT131 Internet Basics & Beginning HTML
Clouds: What’s new is old is new…
Cloud Computing Cloud computing refers to “a model of computing that provides access to a shared pool of computing resources (computers, storage, applications,
CACUBO Risk Management and Cloud Security
Cloud Computing: Concepts
Computer Science and Engineering
Basics of Cloud Computing
Presentation transcript:

Cloud Computing in the Federal Sector: What is it, what to worry about, and what to negotiate. Presented by: Sabrina M. Segal, USITC, Counselor to the Inspector General, Reference in this presentation to any specific commercial products, processes, or services, or the use of any trade, firm, or corporation name is not intended to express endorsement, recommendation, or favoring by the United States Government or USITC of any views expressed, or commercial products or services offered by the commercial providers.

Gartner Hype Cycle: Where are we now?

Cloud Computing: What is it?

So what is this “cloud”….? Cloud computing is defined by the National Institute of Standards and Technology (NIST) as “a model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.” NIST has identified five essential characteristics of cloud computing: on-demand service, broad network access, resource pooling, rapid elasticity, and measured service. Helpful, right? I’m from the Government and I’m here to help… - Federal Cloud Computing Strategy, February 8, 2011

In the traditional model of computing, both data and software are fully contained on the user's computer. Traditional Computing v. Cloud Computing

In cloud computing, the user's computer may contain almost no software or data (perhaps a minimal operating system and web browser only), serving as little more than a display terminal for processes occurring on a network of computers far away. Traditional Computing v. Cloud Computing

One last attempt to explain the Cloud…. PII HR Investigations Payroll Procurement Finance CLOUD Your Information

One last attempt to explain the Cloud…. PII Finance CLOUD Your Information Procurement Investigations Incident (that you had no control over or could mitigate) Payroll HR

Private cloud - The cloud infrastructure is operated solely for an organization. It may be managed by the organization or a third party and may exist on premise or off premise. Community cloud - The cloud infrastructure is shared by several organizations and supports a specific community that has shared concerns (e.g., mission, security requirements, policy, and compliance considerations). It may be managed by the organizations or a third party and may exist on premise or off premise. Public cloud - The cloud infrastructure is made available to the general public or a large industry group and is owned by an organization selling cloud services. Hybrid cloud - The cloud infrastructure is a composition of two or more clouds (private, community, or public) that remain unique entities but are bound together by standardized or proprietary technology that enables data and application portability (e.g., cloud bursting for load-balancing between clouds). Types of Clouds

Cloud Computing Service Models Client Application Platform Infrastructure Server You Your Information Cloud Service Models

Cloud Software as a Service (SaaS) - applications are accessible from various client devices through an interface such as a web browser (e.g., web-based ). The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings. Cloud Platform as a Service (PaaS) - the ability to deploy consumer- created or acquired applications created using programming languages and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, or storage, but has control over the deployed applications and possibly application hosting environment configurations. Cloud Infrastructure as a Service (IaaS) – provides processing, storage, networks, and other fundamental computing resources where the consumer is able to deploy and run software, which can include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure but has control over operating systems, storage, deployed applications, and possibly limited control of select networking components (e.g., host firewalls). Client Application Platform Infrastructure Server

Cloud Computing: What to worry about?

Some Questions to Think About Who has access to the data, both in its live state and when backups are made? How is the data handled? Encryption? What are the vendor obligations? What are the geographic boundaries? Where are the servers located and how will this impact the access and security of the data? What are the incident response guidelines? How are the upgrades and maintenance handled? Can the vendor access or use the information in aggregate? How do we cancel the contract and migrate the information? How are data and media destroyed?

Eight Concerns to Address Upfront 1.Data Security 2.Compliance 3.Termination & Transition 4.Asset Availability 5.Maintenance 6.Pricing and Time 7.Intellectual Property 8.Inspector General needs ** Always consider office specific issues But how do I do that? Negotiate!

1. Data Security/Access Access to live and backup data (ie – encryption, access, destruction, etc.) Access to network traffic (ie – monitoring, EINSTEIN, TIC, etc.) Incident Response (ie – timing, reporting, forensics, etc.) Physical security and location of data (ie – CONUS?) Vendor obligations and duties Disposal of data (and hardware)

2. Compliance Statutorily Required Compliance (ie - Privacy Act, FISMA, Federal Records Act, FOIA, e-discovery, etc.) Classified Information (Spills?) Law enforcement, intelligence data Non-disclosure agreements Timeliness Treatment of non-public information Government Indemnification

3. Termination & Transition How will data be protected, conveyed, and destroyed? Proof? What are the lasting data sensitivities after a contract ends? In what format will the data be provided for transition? Timing for termination and transition?

4. Asset Availability Data availability/disaster recovery? Hardware/software compatibility with agency? Software updates? Hardware refresh? Estimated outage time and frequency? Response time if an emergency takes system offline?

5. Maintenance Patching? Version control? Compatibility? 6. Pricing and Time Additional cost for information access (ie – FOIA, IG needs, etc.)? Address time requirements for compliance? Cost for “out of the box” v. government requirements? Cost for back up cloud?

Actual costs? Cloud Costs

Reality Cloud Costs Back-up for the Back-up Data Access / FOIA / e-discovery Incident Response

7. Intellectual Property Protect government and set boundaries for vendor How will infringing material be handled? Level of indemnity provided by vendor or government? (Consider ADA) Access to vendor IP (especially for IG investigations and audits)?

8. Inspector General needs Clear and clean access to agency information and vendor facilities Ability to conduct criminal investigations (Wiretapping? Network monitoring?) Provider agreement to procedures and processes (information preservation, reporting, etc.) Unencumbered auditability of systems IG access at no additional cost Inspectors General are responsible for promoting and preserving efficiency, effectiveness, and integrity within the agencies over which they have jurisdiction. They do this by conducting audits, evaluations, inspections, and criminal investigations.

Cloud Computing: What to negotiate?* * EVERYTHING!

Cloud Contracts and Service Level Agreements OCIO Client Office General Counsel Info Sec Management/Administration Inspector General And remember, present ALL aspects of the technology to decision makers – pros and cons. If any aspect is withheld, especially cons, it will be impossible to defend the decision. Have the right people at the table…

Thank you for your attention! Questions?