NIST Cloud Computing Program Current Activities

Slides:



Advertisements
Similar presentations
State of Indiana Business One Stop (BOS) Program Roadmap Updated June 6, 2013 RFI ATTACHMENT D.
Advertisements

ELTSS Alignment to Nationwide Interoperability Roadmap DRAFT: For Stakeholder Consideration in response to public comment.
Cloud computing security related works in ITU-T SG17
DMTF Cloud Standards Cloud Management & OVF Update to ITU-T SG13.
NIST Cloud Computing Program 1 NIST Cloud Computing Program - Highlights & Next Steps NIST Mission: To promote U.S. innovation and industrial competitiveness.
Building an Operational Enterprise Architecture and Service Oriented Architecture Best Practices Presented by: Ajay Budhraja Copyright 2006 Ajay Budhraja,
September 30, 2011 OASIS Open Smart Grid Reference Model: Standards Landscape Analysis.
Delivering Mission Agility Through Agile SOA Governance 13 th SOA e-Government Conference 4/12/2012 Presented by Wolf Tombe Chief Technology Officer (CTO)
Decision Making Tools for Strategic Planning 2014 Nonprofit Capacity Conference Margo Bailey, PhD April 21, 2014 Clarify your strategic plan hierarchy.
Clouds C. Vuerli Contributed by Zsolt Nemeth. As it started.
e-Framework Components and Responsibilities.
SmartER Semantic Cloud Sevices Karuna P Joshi University of Maryland, Baltimore County Advisors: Dr. Tim Finin, Dr. Yelena Yesha.
Connecting People With Information DoD Net-Centric Services Strategy Frank Petroski October 31, 2006.
Geneva, Switzerland, 14 November 2014 Cloud computing reference architecture Olivier Le Grand, Standardization Senior Manager on Future Networks, Orange.
Annie W. Sokol, IT Specialist, NIST
A Tour of Federated Clouds Robert Bohn, PhD Advanced Network Technologies Division GEOSS 25 March 2015 Norfolk, VA.
1 ISO/RTO Council Wholesale Demand Response Projects & OpenADR David Forfia.
Cloud Computing Guide & Handbook SAI USA Madhav Panwar.
Framework for Improving Critical Infrastructure Cybersecurity Overview and Status Executive Order “Improving Critical Infrastructure Cybersecurity”
Securing and Auditing Cloud Computing Jason Alexander Chief Information Security Officer.
NIST Information Technology Laboratory Cloud Computing Program NIST Cloud Computing Program Current Activities Robert Bohn OASIS – International Cloud.
DOCUMENT #:GSC15-PLEN-08 FOR:Presentation SOURCE:ISACC AGENDA ITEM:Opening Plenary (4.5) CONTACT(S):Jim MacFie ISACC Activities Since GSC-14 Jim MacFie.
April 2, 2013 Longitudinal Data system Governance: Status Report Alan Phillips Deputy Director, Fiscal Affairs, Budgeting and IT Illinois Board of Higher.
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All ITU-T Focus Group on Cloud Computing Olivier Colas, ITU-T FGCC Vice-Chairman Document No: GSC16-PLEN-45.
Information Technology Laboratory Cloud Computing Program Beyond the Definition – Categorizing & Classifying Cloud Services using the Collaboratively Developed.
3 Cloud Computing.
Desired Quality Characteristics in Cloud Application Development Leah Riungu-Kalliosaari.
Jim Reavis, Executive Director Cloud Security Alliance November 22, 2010 Developing a Baseline On Cloud Security.
Security and Privacy Services Cloud computing point of view October 2012.
18 th Annual Canadian IT Law Association Conference Insider View from the EU Expert Group on Cloud Computing Dr Sam De Silva Partner, Head of IT & Outsourcing.
Engineering, Operations & Technology | Information TechnologyAPEX | 1 Copyright © 2009 Boeing. All rights reserved. Architecture Concept UG D- DOC UG D-
National Institute of Standards and Technology Information Technology Laboratory 1 USG Cloud Computing Technology Roadmap Highlights NIST Cloud Computing.
The Challenge of IT-Business Alignment
INTOSAI Public Debt Working Group Updating of the Strategic Plan Richard Domingue Office of the Auditor General of Canada June 14, 2010.
ETICS2 All Hands Meeting VEGA GmbH INFSOM-RI Uwe Mueller-Wilm Palermo, Oct ETICS Service Management Framework Business Objectives and “Best.
CSI - Introduction General Understanding. What is ITSM and what is its Value? ITSM is a set of specialized organizational capabilities for providing value.
Copyright © 2004 by The Web Services Interoperability Organization (WS-I). All Rights Reserved 1 Interoperability: Ensuring the Success of Web Services.
DRAFT – For Discussion Only HHSC IT Governance Executive Briefing Materials DRAFT April 2013.
Governance Sub-Committee Report: A Proposal to Measure Progress Toward Realizing the NSDI Vision NGAC Governance Sub-Committee December 2, 2009.
Advanced Next gEneration Mobile Open NEtwork Tridentcom th International Conference on Testbeds and Research Infrastructures for the Development.
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All SMART GRID ICT: SECURITY, INTEROPERABILITY & NEXT STEPS John O’Neill, Senior Project Manager CSA.
National Institute of Standards and Technology Information Technology Laboratory 1 USG Cloud Computing Technology Roadmap Next Steps NIST Mission: To promote.
August 3, 2010ETDD Architecture GroupPage 1 Enforcement Targeting & Data Division (ETDD) Architecture Scope, Accomplishments, Challenges.
Smart Grid Interoperability Panel & ISO / RTO Council Smart Grid Projects David Forfia SGIP Governing Board Member – Stakeholder Category 21 ISO/RTO Sponsor.
Geneva, Switzerland, April 2012 Introduction to session 7 - “Advancing e-health standards: Roles and responsibilities of stakeholders” ​ Marco Carugi.
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All Cloud Computing in TTC Kazunori MATSUO, TTC Cloud Computing Advisory Group Document No: GSC16-PLEN-17.
FEA DRM Management Strategy Presented by : Mary McCaffery, US EPA.
DOCUMENT #:GSC15-PLEN-82r2 FOR:Presentation SOURCE:ATIS AGENDA ITEM: PLEN 6.14 CONTACT(S): Andrew White ATIS’
GSC-17, Jeju / Korea Standards for Shared ICT Standardization Activities on Cloud Computing in TTA, KOREA Eui-Nam Huh, TTA PG420 Chair Document No: GSC17-PLEN-17.
Government and Industry IT: one vision, one community Vice Chairs April Meeting Agenda Welcome and Introductions GAPs welcome meeting with ACT Board (John.
OASIS Cloud Authorization TC (CloudAuthZ) Rakesh Radhakrishnan, TC Member.
CISC 849 : Applications in Fintech Namami Shukla Dept of Computer & Information Sciences University of Delaware A Cloud Computing Methodology Study of.
Presented by Eliot Christian, USGS Accessibility, usability, and preservation of government information (Section 207 of the E-Government Act) April 28,
NIST Cloud Computing Standards Roadmap Working Group (CCSRWG) April 21, 2011 National Institute of Standards and Technology U.S. Department of Commerce.
INTRODUCTION TO CLOUD COMPUTING. CLOUD  The expression cloud is commonly used in science to describe a large agglomeration of objects that visually appear.
ISO - Cloud Computing Standards 1 Cloud Computing Standards ISO Addresses the Challenge Cloud Computing Standards ISO Addresses the Challenge
Dr. Ir. Yeffry Handoko Putra
ITU-T Focus Group on Cloud Computing
Next Generation Distribution System Platform (DSPx)
EIN 6133 Enterprise Engineering
Standards for success in city IT and construction projects
HIS Smart Grid – Summary (1)
EOSC Governance Development Forum
Developing a Baseline On Cloud Security Jim Reavis, Executive Director
3 Cloud Computing.
IP and NGN Projects in ITU-T Jean-Yves Cochennec France Telecom SG13 Vice Chair Workshop on Satellites in IP and Multimedia - Geneva, 9-11 December 2002.
NIST Cloud Computing Reference Architecture
Cloud Management & OVF Update to ITU-T SG13
Recent Standardization Activities on Cloud Computing
EOSC-hub Contribution to the EOSC WGs
Presentation transcript:

NIST Cloud Computing Program Current Activities Robert Bohn, Ph.D. NIST Cloud Computing Program Manager ETSI - Cloud Standards Coordination  5 December 2012, Cannes, France

Outline Roadmap Activities Updates on PAPs/Working Groups Security RA SLA Guidance Cloud Metrics Cloud Broker Security RA Standards Update

USG Cloud Computing Roadmap – Volume I Prioritized strategic and tactical requirements that must be met for USG agencies to further cloud adoption; Interoperability, portability, and security standards, guidelines, and technology needed to satisfy these requirements; Recommended list of Priority Action Plans (PAPs) -- candidates for voluntary self-tasking by the stakeholder community. Collaboration through public working groups & Federal Cloud Computing Standards & Technology Working Group Intent is to leverage PAPs that are identified as complete or under way by cloud stakeholder community; some may fall within NIST scope

USG Cloud Computing Technology Roadmap requirements R 1:  International voluntary consensus based interoperability, portability and security standards (interoperability, portability, and security standards) R 2: Solutions for high priority Security Requirements (security technology) R 3:  Technical specifications to enable development of consistent, high quality Service Level Agreements (interoperability, portability, and security standards and guidance) R 4: Clearly and consistently categorized cloud services (interoperability and portability guidance and technology) R 5:  Frameworks to support seamless implementation of federated community cloud environments (interoperability and portability guidance and technology) R 6:  Technical security solutions which are de-coupled from organizational policy decisions (security guidance, standards and technology) R 7:  Defined unique government regulatory requirements, technology gaps, and solutions (interoperability, portability and security technology) R 8:  Collaborative parallel strategic “future cloud” development initiatives (interoperability, portability, and security technology) R 9:  Defined and implemented reliability design goals (interoperability, portability, and security technology) R 10: Defined and implemented cloud service metrics (interoperability and portability standards)

USG CC Roadmap – Volume II Use collaboration through public working groups & Federal Cloud Computing Standards & Technology Working Group to continue to validate findings Reference Architecture & Taxonomy Recommend Industry Mapping so that USG agencies & others can more easily and consistently compare cloud services In parallel, support formal standards development process leveraging the reference architecture Standards Provide avenue for USG agency engagement Continue standards roadmap Target Business Use Cases & SAJACC Expand initial use case set & use SAJACC to identify gaps Security leverage working groups to finalize special publication focusing on challenging security requirements Continue technical advisor role – e.g. FedRAMP, continuous monitoring, conformity assessment system

USG CC Roadmap – Volume III BUILDS ON the first two volumes of the USG Cloud Computing Technology Roadmap IS FOR USG agency technical planning and implementation teams - AND ANYONE ELSE THAT FINDS IT USEFUL HAS A GOAL to inform decision makers regarding questions and decision factors in the context of Cloud Computing use cases DESCRIBES HOW to leverage the Federal Cloud Computing Strategy Decision Framework for Cloud Migration and the collaborative NIST Cloud Computing Program work

Decision Framework

16 aspects… Selection Provision Manage Efficiency Aggregate demand Agility Innovation Security Requirements Service characteristics Market Characteristics Network infrastructure Government readiness Technology lifecycle Provision Aggregate demand Integrate services Contract effectively Realize value Manage Shift mindset Actively monitor Re-evaluate periodically

Application Categories Collaboration Tools Planning/Management Tools Web Server/Content Management Identity Management Document Retrieval/Library System PaaS IaaS

Next Steps for PAPs/Working Groups Goal 1 - Requirement 3: Address “Technical Specifications for High-Quality Service-Level Agreements”. Goal 2 - Requirement 10: Address “Defined & Implemented Cloud Service Metrics”. Goal 3 -Advanced Actor Analysis - To further the discussion on the roles of and interactions of cloud computing actors (consumer/auditor/broker/carrier).

SLA Taxonomy Chair: John Messina (NIST) and Ken Stavinoha (Cisco) Purpose: Address Roadmap Requirement 3 on Service Level Agreements (SLA)s Goals: Create a mindmap/taxonomy identifying the major elements that should appear within a high-quality SLA. Write report on how to create high-quality SLA Status: Mindmap/taxonomy draft complete (available on NIST CC twiki public website) Report draft complete (available on NIST CC twiki public website) Moving Forward: Establish Federal SLA collaborative activities Submit material to international standards bodies for further development

Mind Map of a Master Service Agreement

Contents of SLA Business Level Objectives Roles & Responsibilities Requirements Operational Policies Continuity Limitations Financial Glossary of Terms Service Level Objectives Resources Performance Indicators Service Deployment Service Management Description Security Privacy

Cloud Business Requirements

Performance Indicators

Cloud Metrics Chair: Frederic J. de Vaulx and Steve Woodward (CloudPersectives) Purpose: Address Roadmap Requirement 10 on Cloud Metrics Goals: Improve consistency & terminology to facilitate valuable comparative analysis Create a framework to help clarify measures, definitions and collection methods Align with the roadmap high priority goals like SLAs Status: Cloud reference and description list (available on NIST CC twiki public website) Draft concept model for cloud metrics, measures and usages (available on NIST CC twiki public website) Moving Forward: Present the concept model to organizations involved in cloud metrics Write the Cloud Measure document based on the draft outline

Cloud Metrics Work Areas & Priorities

Goal 3: Advanced Actor Analysis – Cloud Broker Intermediate Cloud Service Provider dd Consumer accesses multiple provider services through a single broker interface The Cloud Consumer retains visibility into the cloud service providers they use Intermediary uses additional providers as invisible components of its own service, presented as integrated offering No consumer visibility into or control over additional cloud providers

The NIST Cloud Computing Reference Architecture Cloud Carrier Cloud Auditor Security Audit Privacy Impact Audit Performance Audit Cloud Service Consumer Cloud Broker Service Intermediation Aggregation Arbitrage Cloud Service Provider Privacy Physical Resource Layer Hardware Facility Resource Abstraction and Control Layer Service Layer IaaS SaaS PaaS Cloud Service Management Business Support Provisioning/ Configuration Portability/ Interoperability

NIST Security Reference Architecture Physical Resource Layer Hardware Facility Resource Abstraction and Control Layer Service Layer IaaS SaaS PaaS Biz Process/ Operations App/Svc Usage Scenarios Software as a Service Cloud Provider Application Development Platform as a Service Develop, Test, Deploy and Manage Usage Scenarios Note that the supporting technology for each service model is different. This also will result in different security considerations. Each service model will likely have very different security architectures. Infrastructure as a Service Create/Install, Manage, Monitor Usage Scenarios IT Infrastructure/ Operation

Draft NIST CC Reference Architecture Cloud Consumer Cloud Consumer Cloud Provider Cloud Broker Cloud Orchestration Cloud Service Management Service Layer SaaS Service Intermediation Business Support Cloud Auditor PaaS IaaS Provisioning/ Configuration Service Aggregation Security Audit Resource Abstraction and Control Layer Privacy Impact Audit Physical Resource Layer Portability/ Interoperability Service Arbitrage Hardware Performance Audit Facility Cloud Carrier Cross Cutting Concerns: Security, Privacy, etc

NIST Security Reference Architecture – formal model

Cloud Computing Standards Developers IEEE ISO IEC IETF ITU-T PSDO SG 11 Signalling requirements, protocols and test specifications SG 13 Future networks including mobile and NGN SG 17 Security ISO TC 68 Financial services ISO/IEC JTC 1 Information Technology JTC 1 PAS Submitters OASIS OMG SNIA TCG W3C OGF CA OCC SC 2 Financial Services, security SC 7 Software & systems engineering SC 27 IT security techniques SC 38 Distributed application platforms & services ATIS CSA Kantara TIA others Key: PSDO = Partner Standards Development Organization; PAS = Publicly Available Specification; = private sector, national member-based international standards body; = UN agency, member state-based international standards body; = international consortium standards developer 23

NIST SP 500-291 Recommendations Accelerating Development and Use of Cloud Standards Contribute Agency Requirements Participate in Standards Development Encourage Compliance Testing to Accelerate Technically Sound Standards-Based Deployments Specify Cloud Computing Standards USG-Wide Use of Cloud Computing Standards Dissemination of Information on Cloud Computing Standards Contribute Agency Requirements Participate in Standards Development Encourage Compliance Testing to Accelerate Technically Sound Standards-Based Deployments Specify Cloud Computing Standards USG-Wide Use of Cloud Computing Standards Dissemination of Information on Cloud Computing Standards

New Topics for Consideration Accessibility Conformity Assessment Performance Reliability Forensics Law Enforcement Education

NIST Cloud Computing Special Publications CC Standards Roadmap ……………………..500-291 CC Reference Architecture………………….500-292 USG CC Technology Roadmap Draft......500-293 Guidelines on Security and Privacy …….800-144 Definition of Cloud Computing …………..800-145 CC Synopsis & Recommendations……....800-146 Searchable as “NIST SP xxx-nnn”

Contacts Dr. Chris Greer chris.greer@nist.gov Dr. Robert Bohn robert.bohn@nist.gov John Messina john.messina@nist.gov Dr. Michaela Iorga micheala.iorga@nist.gov Annie Sokol annie.sokol@nist.gov Mike Hogan michael.hogan@nist.gov Eric Simmon eric.simmon@nist.gov Frederic de Vaulx frederic.devaulx@nist.gov Acting SES Program Mgr RA/Tax Co-Convener Security Standards Volume III Metrics NIST ITL Cloud Computing Home Page http://www.nist.gov/itl/cloud NIST Cloud Computing Collaboration Site (twiki) http://collaborate.nist.gov/twiki-cloud-computing/bin/view/CloudComputing