How to get the right kind of control over your cloud: A guide

Trust in the cloud hasn’t always been universal. There was a time when security and risk management leaders feared entrusting critical data and infrastructure to a third-party cloud provider. This was understandable, arising from the history of network management, where IT teams were intimately familiar with managing the resources that made up their IT infrastructures, from the buildings they were housed in, to the electricity and cooling supply, through to the server, all the way down to the storage and networking infrastructure.

However, this familiarity isn’t possible when you delegate responsibility to your cloud provider and hanging onto it can prevent organisations from gaining optimal cloud efficiency and security. Clearly, a shift in mindset is needed.

In their report, “CISO Playbook: How to Retain the Right Kinds of Control in the Cloud” Gartner make the analogy that moving to the cloud is a bit like flying somewhere on a plane, compared to driving your own car on a journey. You are relinquishing control of your journey to the flight crew of a plane, which can cause anxiety. However, this anxiety is not rational because whereas you might check the oil, tyres and windshield washer fluid on your car once in a blue moon, the plane will be checked rigorously, every flight. To sum up, this means that migrating to the cloud requires a new outlook on how you control your data and a better understanding of what cloud service providers do to ensure security so that you feel comfortable giving up ownership of the underlying platform.

In today’s context, customers still own their data but share stewardship with cloud providers. The concept of “control” has changed from physical location-based ownership to control of processes. Information security and risk management leaders therefore need to adopt a new approach of indirect control to achieve efficiency, security and above all peace of mind. With this in mind, we will try to define how you can get the right kind of control over your cloud.

Design the right identity and access management strategy

Security teams and developers can find cloud-based control concepts difficult to grasp. But really, it’s a similar situation to giving up ownership of the fibre and copper in their wide-area networks: telecommunications carriers own the physical infrastructure, but   data remains owned and controlled by their customers. It’s all about delineating security responsibility. Once you’ve defined the hand-off point, you’ll know that beyond this your CSP is responsible for security.

Your responsibility lies in designing an Identity Access Management strategy that covers not only the cloud platform but also the applications and services that the cloud platform is presenting to the outside world. Access should be based on giving users permissions on a “least privilege” basis, rather than giving blanket authority to all. This improves audit capabilities and reduces the risk of unauthorised changes to the platform.

On top of that, you should work with your cloud provider to ensure encryption for higher degrees of logical isolation. Encryption of data at rest and in transit is often seen as another way to secure, segregate and isolate data on a public cloud platform. While it is highly unlikely that anyone would be able to break into a public cloud data centre and physically steal a disk drive containing your data, it is highly recommended that you consider using encryption of data at rest.

Increase monitoring and re-orient audit objectives

With the regulatory environment growing in complexity, organisations using the cloud are increasingly asked to demonstrate their strong governance. The fact that you’ve delegated some control to your CSP means that you’ll have to demonstrate that governance procedures are in place and are being followed.

In order to do so, you should seek to work with a cloud service provider that provides security and compliance monitoring and reporting. And, has the necessary approach and compliance attestations that ensures your cloud workloads will be able to meet the necessary requirements come audit time.

Compare your security requirements and measure CSP performance against SLAs

Another point to pay close attention to is the contractual terms that bind the CSP with respect to protection of customer data and privacy. Contracts with hyperscale cloud providers tend to overwhelmingly protect those CSPs, but it is possible to work with some CSPs to reach agreement on terms more favourable to customers.

The final impact and recommendation is around cloud service provider contracts and SLAs. Many CSPs, especially the hyperscale providers, can be extremely rigid with their SLAs, and can be very inflexible when asked to change them. It’s important to find out where your CSP stands on different aspects of compliance. Are they able to share their certifications and attestations? How flexible are they with their SLAs on subjects such as availability? Will they pay out service credits if service is not available according to the SLA? These are questions you will need to have answers to before going forward with your CSP. An extra piece of advice I would give is to compare your security requirements for externally hosted data to the capabilities of CSPs in the context of your risk appetite.

To summarise, with security risks and compliance regulations only increasing, along with the adoption of cloud services, it’s important to understand shared responsibility with regards to cloud security. Striking the right balance between relinquishing and maintaining control in the cloud will enable your business to securely leverage the many benefits of cloud services. Having control of your cloud doesn’t mean you should manage every aspect of it, but make sure you know what you are accountable for instead to gain the right kind of control.

All in Mobile to Exhibit at @CloudEXPO NY | @AllinMobileApps #Mobile #iPhone #Samsung #iOS11 #CIO

All in Mobile is a place where we continually maximize their impact by fostering understanding, empathy, insights, creativity and joy.

They believe that a truly useful and desirable mobile app doesn’t need the brightest idea or the most advanced technology. A great product begins with understanding people.

It’s easy to think that customers will love your app, but can you justify it?

They make sure your final app is something that users truly want and need. The only way to do this is by researching target group and involving users in the designing process.

read more

Announcing #Blockchain “Power Panel” Moderated by Ed @Featherston | @ExpoDX #FinTech #Hyperledger #SmartCities

Whenever a new technology hits the high points of hype, everyone starts talking about it like it will solve all their business problems. Blockchain is one of those technologies. According to Gartner’s latest report on the hype cycle of emerging technologies, blockchain has just passed the peak of their hype cycle curve. If you read the news articles about it, one would think it has taken over the technology world.

No disruptive technology is without its challenges and potential impediments that frequently get lost in the hype. The panel will discuss their perspective on what they see as they key challenges and/or impediments to adoption, and how they see those issues could be resolved or mitigated.

read more

Registration Opens for @MapR IoT Data Session | @CloudEXPO #AI #IoT #IIoT #SmartCities #DigitalTransformation

The challenges of aggregating data from consumer-oriented devices, such as wearable technologies and smart thermostats, are fairly well-understood. However, there are a new set of challenges for IoT devices that generate megabytes or gigabytes of data per second. Certainly, the infrastructure will have to change, as those volumes of data will likely overwhelm the available bandwidth for aggregating the data into a central repository. Ochandarena discusses a whole new way to think about your next-gen applications and how to address the challenges of building applications that harness all data types and sources.

read more

What makes a good bespoke app?


Sandra Vogel

18 Jul, 2018

When we think about apps, we usually think about what we can see on our smartphones. In reality, that only scratches the surface of a highly lucrative industry where software is changing the face of business.

There are countless bespoke apps out there commissioned by organisations who need tools that can help people do their jobs that bit more easily.

Every part of an organisation can benefit from bespoke apps, from logistics to human resources, from customer or user services to resources management. But getting an app that’s fitted precisely to the organisation’s needs isn’t easy. The whole point of ‘bespoke’ is that it is tailored, not ‘off the shelf’ or ‘one size fits all’. The tailoring is the skill, and it’s where bespoke apps succeed – or fail.

Design thinking

Nick Ford, chief technology evangelist at Mendix, a software platform that allows apps to be created without coding and whose clients include Kwik Fit, ING and War Child, says there’s no “silver bullet” when it comes to developing your own app, but that “taking a design thinking approach can set you off on the right path”.

Design thinking is absolutely central to the whole process of creating effective bespoke apps. Ford tells Cloud Pro that it “ensures the finished app is solving the right problems through keeping the end-user at the heart of the entire design and development process”.

“That might sound basic, but you’d be amazed at how many businesses develop apps that fail to identify or address the right problems,” he adds.

In practice, that means making sure the people who are going to use the bespoke app are involved in creating its look, its feel, and the services offered. Achieving this requires technical teams to take a step backwards, work alongside specialists in a user involvement, and figure out how to implement user requirements in the app’s design.

Keep on talking

Importantly, users need to be involved throughout the whole development cycle – and beyond. It’s no good just asking them what they want at the start, going away and asking the tech teams to produce an app, presenting it to users for a short period of testing before it is unleashed, making a couple of changes, and then retiring to focus on the next project.

Eveline Oehrlich, director of market strategy at New Relic, a company that specialises in monitoring the efficiency of apps, tells us: “As a company’s custom app usage grows, it can be increasingly difficult to ensure these apps deliver consistent quality and reliability. If left unchecked, there’s a risk that there will be a negative impact on employee productivity, customer and partner satisfaction, and, ultimately, the company’s bottom line”.

Nick Ford adds that usually “the IT team is so separated from the wider business that it’s impossible for the right conversations to be had at the right time. When apps are developed in isolation, there’s no room for snags to be caught and dealt with early”.

Avoiding avoidance

In the end, the ultimate goal in producing a bespoke app is to create something people will use. Fail to take the design thinking approach, and fail to keep end users involved throughout the process, and an organisation is simply forking out more money on bespoke for the same experience offered by an off-the-shelf product.

As Michael Macauley, general manager at Liferay, tells us: “If workers feel they’re fighting against an application, they are more likely to either try and circumvent it, or give up on that process entirely.”

Moreover, for Liferay, whose clients include T-Mobile, Airbus and Domino’s, this is about more than just apps. The design thinking approach needs to extend into every aspect of digital life – web, apps and beyond. Consistency is all.

To achieve the required level of user-friendliness requires what Nick Ford refers to as a ‘feedback loop’ – a continuous process of gathering user feedback, making its collection “part of the environment”.

“[This means] users can take an active role across the complete application lifecycle – so the finished app works for everyone,” he explains.

Just like tailored clothing that gets taken in here and let out there, as time goes on, an app needs to respond to user needs throughout its life. And that, after all, is the point of a bespoke app. As Macauley put it, “the ultimate aim of good design should be ease of use”.

Image: Shutterstock

SolarWinds acquires Trusted Metrics to add real-time threat monitoring to cloud security mix

SolarWinds is on the acquisition trail again – this time confirming the acquisition of Trusted Metrics, a real-time threat monitoring and management software provider.

The acquisition will enable SolarWinds to release a new security product under the name of SolarWinds Threat Monitor, which is an automated tool which aims to make threat detection easier for IT operations teams, managed service providers and managed security service providers.

As regular readers of this publication will testify, organisations’ cloud initiatives are becoming ever-more complex – and with that, the security factor goes up significantly. Alex Bennett, of Firebrand Training, noted security as the number one skill businesses and employees need to know in 2018 back in May, while new security snafus are rarely out of the news.

Writing for this publication in May, Srivats Ramaswami, CTO at 42Q, cited manufacturing as an industry where cloud security needed to be taken more seriously. “Remember, the best application providers and data centres have large, dedicated security teams who have implemented automated threat monitoring systems that operate 24×7,” he wrote. “In the end, the best cloud software companies have dedicated more time, resources and budget to securing our systems than most organisations are able to provide themselves.”

This makes for interesting reading when it compares to what SolarWinds are attempting to do. The new product, utilising the technology of Trusted Metrics, will aim to aggregate a plethora of data sources, such as asset data, security events, and network intrusion detection, and correlate it with continuously updated threat intelligence to ‘identify the danger signals amidst all the innocent noise of a normal network.’

“The acquisition of Trusted Metrics will allow us to offer a new product in the SolarWinds mould – powerful, easy to use, scalable – that is designed to give businesses the ability to more easily protect IT environments and business operations,” said Kevin Thompson, SolarWinds CEO in a statement.

The move complements the company’s acquisition of software as a service provider Loggly, announced at the start of this year.

This program sounds like it can play a great role—and it does!

When a new rollout of endpoint devices is on the horizon, their prospective users will most likely rejoice—but not those who are tasked with the rollout job if a central administration platform has not been put into place. Taking record of all those devices, their initial configuration, and their subsequent ongoing support significantly adds to […]

The post This program sounds like it can play a great role—and it does! appeared first on Parallels Blog.

This program sounds like it can play a great role—and it does!

When a new rollout of endpoint devices is on the horizon, their prospective users will most likely rejoice—but not those who are tasked with the rollout job if a central administration platform has not been put into place. Taking record of all those devices, their initial configuration, and their subsequent ongoing support significantly adds to […]

The post This program sounds like it can play a great role—and it does! appeared first on Parallels Blog.

Oracle unveils Bristol accelerator contenders


Clare Hopping

11 Jul, 2018

Oracle has revealed the startups taking part in its Bristol-based Oracle Startup Cloud Accelerator Programme, including Snap Tech, LettUs Grow We Build Bots, Sauce and GapSquare.

The diverse set of companies will be able to take advantage of collaborations with other businesses in the cloud space, as well as each other. They will be mentored by both Oracle engineers, technical teams and business experts, be able to make use of a co-working space and build their own opportunities by coming into contact with Oracle customers, partners and investors.

Visual search business Snap Tech offers consumers the tools to find exactly what they're looking to buy via visual search, AI, and machine learning, matching searches with the products online retailers have to offer.

LettUs Grow is a completely different kind of technology, helping vertical farms implement irrigation and control technologies, while We Build Bots' IntelAgent has been designed for contact centre agents, offering a collaboration-led customer service platform built upon AI and analytics.

Sauce's cloud-based video collaboration platform is reinventing video content for businesses, encouraging businesses to generate engaging content from a wide variety of sources.

The final business entering Oracle's accelerator programme is Gapsquare, which seeks to eradicate gender pay gaps by analysing data and generating data-driven recommendations for change.

“The startups in Bristol continue to raise the bar for global cloud innovation, and we are proud to welcome a select group of five to our second cohort,” said Reggie Bradford, senior vice president, Startup Ecosystem and Accelerator.

“Following the success of our initial cohort in Bristol, we will continue to leverage our cloud expertise, leading cloud products, and global network to support their rapid growth.”

Previous businesses taking part in Oracle's Startup Cloud Accelerator programme include Interactive Scientific, Duel, GRAKN.AI, iGeolise and Trail. The company also has similar programmes running in Austin, Bangalore, Bristol, Delhi–NCR, Mumbai, Paris, São Paulo, Singapore and Tel Aviv, helping startups around the world develop their cloud-based apps and services with the business and technical support of a tech giant.

<em>Image credit: Unite</em>

dhosting Named “Technology Sponsor” of @CloudEXPO NY | @dhosting_com @dhosting_pl #Serverless #DataCenter #Storage

Having been in the web hosting industry since 2002, dhosting has gained a great deal of experience while working on a wide range of projects. This experience has enabled the company to develop our amazing new product, which they are now excited to present! Among dHosting’s greatest achievements, they can include the development of their own hosting panel, the building of their fully redundant server system, and the creation of dhHosting’s unique product, Dynamic Edge.

read more

The cloud news categorized.