Presentation is loading. Please wait.

Presentation is loading. Please wait.

DISA’s Transformation to a Platform Service Provider

Similar presentations


Presentation on theme: "DISA’s Transformation to a Platform Service Provider"— Presentation transcript:

1 DISA’s Transformation to a Platform Service Provider
Defense Information Systems Agency A Combat Support Agency DISA’s Transformation to a Platform Service Provider DISA Computing Services August 2011

2 Platform Service Definition
Cloud Service Models DISA Cloud Services On-demand self-service Software as a Service (SaaS) End-user application is delivered as a service instead of on-site software installations. Platform and infrastructure are abstracted. Forge.Mil Broad network access Platform as a Service (PaaS) Application platform or middleware as a service on which custom applications and services can be deployed. Resource pooling Web Services ERP Rapid elasticity Physical infrastructure is abstracted to provide computing, storage, and networking as a service, avoiding the expense and need for dedicated systems Infrastructure as a Service (IaaS) RACE Capacity Services Measured Service On-demand self-service. A consumer can unilaterally provision computing capabilities, such as server time and network storage, as needed automatically without requiring human interaction with each service’s provider. Broad network access. Capabilities are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs). Resource pooling. The provider’s computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand. There is a sense of location independence in that the customer generally has no control or knowledge over the exact location of the provided resources but may be able to specify location at a higher level of abstraction (e.g., country, state, or datacenter). Examples of resources include storage, processing, memory, network bandwidth, and virtual machines. Rapid elasticity. Capabilities can be rapidly and elastically provisioned, in some cases automatically, to quickly scale out and rapidly released to quickly scale in. To the consumer, the capabilities available for provisioning often appear to be unlimited and can be purchased in any quantity at any time. Measured Service. Cloud systems automatically control and optimize resource use by leveraging a metering capability at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported providing transparency for both the provider and consumer of the utilized service. The Air Force Platform Service falls within the PaaS layer of the Cloud Model From NIST: The capability provided by PaaS to the consumer is to deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, or storage, but has control over the deployed applications

3 Platform Benefits Provide standardized development environment with pre-integrated services allowing developer to focus on business logic Remove IT infrastructure burden from developers Reduce development costs (H/W, S/W, administration) Allow developers to focus on application development Help application PMO better manage costs and schedule No lab infrastructure startup No waste of resources due to over provisioning Provide a fast and inexpensive path to production Provide dynamic resource allocation Share situational awareness for platform services Provide utility-based billing 3

4 Platform Hosting Model
DISA provides Hardware, Basic and Database infrastructure & support ITIL based operations model Runtime Environment and Shared Services defined by DISA Initial capability includes DISA infrastructure plus adoption of IIB authentication and MDE services Follow-on capability adds jointly confirmed shared services Custom hosting for unique applications that leverage IaaS and shared services Customer builds and delivers Custom Code for DISA to execute in Runtime Environment DISA provides path-to-production lifecycle services 4

5 PaaS v1.0 Decomposition PaaS App App App App App App Customer Apps
Air Force Apps App App App PaaS Common Ops Self Service SLM Shared SA Utility Billing PaaS STS Specific Customer Facing Elements Technology Components

6 Approach for an Enterprise Platform Service
Two Platform as a Service (PaaS) Offerings General purpose cloud platform model Secure Token Service (STS) to support Air Force Enterprise Level Security (ELS) Elastic, Self-service, Utility Pricing, Rapid Deployment of Apps Web Apps / Services, ERP Apps JBoss Open Source for 95+% of all Java Applications

7 PaaS Path To Production
Develop Test Execute Operate Standardized platform from development through production More controlled than commercial for safe, secure cloud services Easier to access than DoD production Smooth path to production with security validation Meets DoD standards for secure computing Enterprise Portal will provide access to all services Orchestration tools will support more mature cloud services Location independent capabilities for production services Platform as a Service C&A Verification Runtime Engine Platform Developer Kit Shared Situational Awareness Test Tools Dynamic Elasticity ITIL Ops Model Shared SOA Services SID Capacity Services Shared Dev / Test Services for Application Development Rapid, standard, self-service capabilities 7

8 PaaS Service Characteristic
PaaS Feature Overview PaaS Service Characteristic DISA PaaS Commercial Latest hardware – server/storage Technology refreshment Enterprise class facilities Standard development and production environments Self-service ordering and rapid provisioning Unrestricted/Restricted Service Type Private Services and Data Cleared support staff with 100% clearances (IT1/2) – no foreign nationals Defense in Depth Security Posture (DoD Information Assurance standards) Broadband access Situational awareness Program Stability (No need for contract re-compete) Service Desk – 24x7 Service Level Management Few guarantees Our value proposition dovetails with the previous slide. Customers want to compare us against a commercial competitor. Chart is intended to show what we provide that a commercial vendor can not or does not without significant extra cost. Most often we are compared on hardware, technology refreshment and service desk. Facilities and personnel security are often assumed to be equivalent, although in practicality they are not. None of the commercial facilities are on the DISN optical core, and behind the DOD DMZs. They are not on a military facility and there is little control over who is operating the infrastructure. Also often not accounted for is the real cost associated with a major potential change during a contract re-compete – a necessary element in any commercial endeavor. The major take away here is that there is a lot of value operating in a DECC that is not codified in a bottom line cost figure when evaluating alternatives. Industry competitive capabilities with strong security and faster acquisition

9 Transaction Range/month
PaaS Service Catalog PaaS Catalog PaaS Bundle Operating Environment 2 Cores, 2 GB Memory Storage – 10GB Network infrastructure Web & JEE Containers PBAC Access Management Ozone Widget Framework Oracle Database PaaS PaaS STS High Availability Clustering Additional Storage Exposure Services Tier Level Transaction Range/month Rate $0.514 1 $0.280 2 $0.170 3 $0.130 4 100k-250K $0.092 5 250K -500K $0.055 PaaS STS Bundle Operating Environment 2 Cores, 2 GB Memory Storage – 10GB Network infrastructure Web & JEE Containers STS Access Management AF Metadata Environment Oracle Database Note: Example only

10 Type accreditation for PaaS
Goal: Significantly reduce C&A timeline Concept grounded on principal of reciprocity between developed applications and DISA’s platform execution environment Implies that accreditation authorities for the PaaS platform (DISA) and the developed web services and applications will reciprocate on acceptance of each others accreditation work Customer will accept accreditation of DISA platform type accreditation DISA will accept customer’s certification of net-worthiness Approach CSD will develop a DIACAP package for type accreditation of the PaaS execution environment The customer’s development, testing and fielding process will need to ensure rigor for application code (above the line system) Acceptance of above the line and below the line IA work will be reciprocal

11


Download ppt "DISA’s Transformation to a Platform Service Provider"

Similar presentations


Ads by Google