cloud security - cloud arena - tim willoughby

94

Upload: tim-willoughby

Post on 19-Nov-2014

364 views

Category:

Technology


3 download

DESCRIPTION

Presentation at CloudArena - on Cloud Security

TRANSCRIPT

Page 1: Cloud Security - Cloud Arena - Tim Willoughby
Page 2: Cloud Security - Cloud Arena - Tim Willoughby

My name is Tim

I explain technology…

Page 3: Cloud Security - Cloud Arena - Tim Willoughby

to people who don’t understand it…

Page 4: Cloud Security - Cloud Arena - Tim Willoughby

people who think they do understand it…

Page 5: Cloud Security - Cloud Arena - Tim Willoughby

people who despise it…

Page 6: Cloud Security - Cloud Arena - Tim Willoughby

and people who worship it.

Page 7: Cloud Security - Cloud Arena - Tim Willoughby

…that help people understand how technology might help their Organisation…

I rese

arch

,

pilot a

nd

writ

e

thin

gs...

Page 8: Cloud Security - Cloud Arena - Tim Willoughby

I live here... According to Google Streetmaps

8

Page 9: Cloud Security - Cloud Arena - Tim Willoughby

In Technical Terms

•I’m a Webservice –•Sitting between the Technical Teams and the Business Teams, translating and relating between them..•With Plenty of SOAP and REST....

Turn that noise off, can’t you see I’m busy…

keep your silly ideas to yourself - I’ve got a job to do!

Page 10: Cloud Security - Cloud Arena - Tim Willoughby

I live in Naas…

• NAAS– Network as a Service

• Used to be a Nice place to shop!

Page 11: Cloud Security - Cloud Arena - Tim Willoughby

Can Cloud Computing transform

Government?

Page 12: Cloud Security - Cloud Arena - Tim Willoughby

Not all Clouds are good!

Page 13: Cloud Security - Cloud Arena - Tim Willoughby

Open Government?

“If people don’t know what you’re doing, they don’t know what you’re doing wrong”

“Jim Hacker” Open Government (I980)

Page 14: Cloud Security - Cloud Arena - Tim Willoughby

Cloud is forcing ChangeWith or Without the Owners / Shareholders

Page 15: Cloud Security - Cloud Arena - Tim Willoughby
Page 16: Cloud Security - Cloud Arena - Tim Willoughby

So far ICT has not fundamentally changed government

• 1990s: lCT expected to make government more transparent, efficient and user oriented

• 2005+: disillusion as bureaucracy still in existence

• Can Cloud Help?

Jane E. Fountain – Gov 1.0 – Just Replicating the Silos on the Internet

Page 17: Cloud Security - Cloud Arena - Tim Willoughby

Goverment dont always Understand What the people Want?

Page 18: Cloud Security - Cloud Arena - Tim Willoughby

What governments often Deliver

Page 20: Cloud Security - Cloud Arena - Tim Willoughby
Page 21: Cloud Security - Cloud Arena - Tim Willoughby

Security is changing

• Security has to be appropriate• Security has to be measured • Can have things so secure that they are

unusable.

Page 22: Cloud Security - Cloud Arena - Tim Willoughby
Page 23: Cloud Security - Cloud Arena - Tim Willoughby
Page 24: Cloud Security - Cloud Arena - Tim Willoughby
Page 25: Cloud Security - Cloud Arena - Tim Willoughby

CIO Priorities…

Source: “ Gartner Scenario: The Current State and Future Directions of the IT Industry”

Page 26: Cloud Security - Cloud Arena - Tim Willoughby

What is Cloud

• Vendors – Whatever you want / Need it to be…

• Its too Vague – • Talking about Cloud Security – when Cloud is

defined as everything you ever wished for…

Page 27: Cloud Security - Cloud Arena - Tim Willoughby

Moving to the Cloud?

1. Leaving your apartment!

2. Moving your Data

Page 28: Cloud Security - Cloud Arena - Tim Willoughby

BarriersPsychological Barriers

Platform Lock-In, Dependence, Governance

Security Compliance Costs

Application Architecture How do we design applications lo take advantage of the cloud? Grow and shnnk on-demand (scalability) Data affinity Portability Efficiency Performance Fault-tolerance and self-healing

Page 29: Cloud Security - Cloud Arena - Tim Willoughby
Page 30: Cloud Security - Cloud Arena - Tim Willoughby

Positives

Scale Cost

CAPEX OPEX

Advance Architecture Agility Cost - Clouds are renowned for being dirt cheap

for storage and burst-y processing. Elasticity - Growth and shrinkage

Page 31: Cloud Security - Cloud Arena - Tim Willoughby
Page 32: Cloud Security - Cloud Arena - Tim Willoughby

Negatives

Security & Privacy . Conflicts with international laws?

Where is my Data - Is it safe? For Whom and at what level? Regulatory compliance: Interoperability Lack of control Standardisation SLA ( Model T Ford)

Page 33: Cloud Security - Cloud Arena - Tim Willoughby

Dark Cloud?

Letter from CSSO

Page 34: Cloud Security - Cloud Arena - Tim Willoughby

Challenges

Organisational barriers (Silo mentality) Reliability (service outage) Definition of SLAs (Service Level Agreement) Service management, Monitoring Customisation / Integration with other

applications

Page 35: Cloud Security - Cloud Arena - Tim Willoughby

If you are going to do it..

1. Understand the options and technologies2. Have a look at what you do..3. If its complex inside the firewall…Rationalize

infrastructure & applications4. leverage SOA for applications, appropriate

standards, governance5. Identify the costs per user - Compare costs with

internal hosting. 6. Start with Open Data… no arguments here….

Page 36: Cloud Security - Cloud Arena - Tim Willoughby

…We have come a long way...

Page 37: Cloud Security - Cloud Arena - Tim Willoughby

Understanding the Adoption Curve

Page 38: Cloud Security - Cloud Arena - Tim Willoughby

Pilot for Success

Page 39: Cloud Security - Cloud Arena - Tim Willoughby

Watch for

Page 40: Cloud Security - Cloud Arena - Tim Willoughby
Page 41: Cloud Security - Cloud Arena - Tim Willoughby
Page 42: Cloud Security - Cloud Arena - Tim Willoughby

Identity

• Still not fixed in the Enterprise…• Or on the Internet..

Page 43: Cloud Security - Cloud Arena - Tim Willoughby
Page 44: Cloud Security - Cloud Arena - Tim Willoughby

Legal

• Cross Border data Transfer, etc

Page 45: Cloud Security - Cloud Arena - Tim Willoughby

why is Crowd and Cloud sourcing important?

Crowd Source – Group Collaboration is more powerful than individual achievement

Page 46: Cloud Security - Cloud Arena - Tim Willoughby

Typical Individual effort

many hours, one map

Page 47: Cloud Security - Cloud Arena - Tim Willoughby

OpenStreetMap, 2012

200,000 contributors, one map

Page 48: Cloud Security - Cloud Arena - Tim Willoughby

What is Cloud?

DON’T WORRY, TRUST US, WE HAVE IT ALL UNDER CONTROL

Page 49: Cloud Security - Cloud Arena - Tim Willoughby

49

What has Cloud ever done for us?

Apart from Scale, Speed, Agility, Low Cost, Enterprise Mapping, Open Data, Standards, Google, API’s, Open Street Maps, Map Servers,

GIS - More than just Location, Spatial Analysis and wider adoption now possible

Page 50: Cloud Security - Cloud Arena - Tim Willoughby

Mashup

Page 51: Cloud Security - Cloud Arena - Tim Willoughby

Why this is so compelling: It’s a disruptive technology

• Does it meet enterprise needs

• Easy to control• SLA / Support• Good enough for

startups and SME• “Cheap” compute• Pilot and trial…

Source: upcoming research, Cloud Computing: Not Ready For The Enterprise...Yet.

Page 52: Cloud Security - Cloud Arena - Tim Willoughby
Page 53: Cloud Security - Cloud Arena - Tim Willoughby

In how many years…

Page 54: Cloud Security - Cloud Arena - Tim Willoughby

Cloud Computing Challenges

4) Cost 5) Security

2) Availability

3) Maintenance

End User

1) Scalability

Page 55: Cloud Security - Cloud Arena - Tim Willoughby

Mind the Gap…

What How Where Who When Why

DataInformationKnowledge

Wisdom

BusinessProcessesAnalysis

Collaboration

Distributed Geography

UsersAgencies

Organisations

EventsTimes

PolicyStrategy

Databases Applications NetworksSecured

UserInterfaces

Event Processing

TraceableModels

Technology Stuff

Our Stuff

Page 56: Cloud Security - Cloud Arena - Tim Willoughby

G Cloud – UK…• Distributed Cloud• Work like a Network• Everyone

• Can See• Can Play• Can Add Value (Within

Limits)• Shared Data Centres• App Store

• Issues – • Support• Code Base• Open Source Push

• My View – 3 Models• Car Boot Sale• Charity Shop• Department Store

Page 57: Cloud Security - Cloud Arena - Tim Willoughby

Virtually Unlimited Storage

For storing data

Page 58: Cloud Security - Cloud Arena - Tim Willoughby

Smart CitiesGartner: “networked sensors in everything we own will form a new Web (the Internet of Things). But it will only be of value if the ‘terabyte torrent’ of data it generates could be collected, analysed and interpreted”

… and .. just because we can….

Page 60: Cloud Security - Cloud Arena - Tim Willoughby
Page 61: Cloud Security - Cloud Arena - Tim Willoughby

Confusion or Hype

• Public Cloud• Private Cloud• Hybrid Cloud• IAAS• PAAS• NAAS• SAAS• Etc AAS

Page 62: Cloud Security - Cloud Arena - Tim Willoughby

Gcloud

Cloud

SAAS

Core

HEG

SharePoint

Mail

Planning

Fix Your Street

Open Data

PAAS

SDCC

Carlow

Wicklow

LGMA 1

LGMA 2

NAAS

IAAS

Cloud

Services

Private

Hybrid

Page 63: Cloud Security - Cloud Arena - Tim Willoughby

Sharing!

Page 64: Cloud Security - Cloud Arena - Tim Willoughby

BIG DATA?

Massive network of services: water, sewage, drains … Need to know asset location for planning and maintenance Many databases, varying accuracy and provenance Context

Ongoing street openings p.a. Safety!

Page 65: Cloud Security - Cloud Arena - Tim Willoughby

Its all about where..

Page 66: Cloud Security - Cloud Arena - Tim Willoughby

GIS Geographic Information

System• We have come a long way

Page 67: Cloud Security - Cloud Arena - Tim Willoughby

Or Wizards

GIS is now Mainstream

Page 68: Cloud Security - Cloud Arena - Tim Willoughby

DOE

DOT

Central Reporting Framework

Health

SFA

LA

LA

LALA LA LA LA LA

LA

LA

eReturns

Page 69: Cloud Security - Cloud Arena - Tim Willoughby

Future use of Cloud!

Page 70: Cloud Security - Cloud Arena - Tim Willoughby

Water Meters

• Read the Meter• View or Pay the Bill• Compare the Usage to the

Local or National Averages

• Look for areas of Savings

Page 71: Cloud Security - Cloud Arena - Tim Willoughby

My Water Usage

• Smart Metering• Change my practise

Page 72: Cloud Security - Cloud Arena - Tim Willoughby

Environment

• Advice and Tips on Money

• Energy• Recycling (locations of

Centres)• Refuse• Water• Energy Design

Page 73: Cloud Security - Cloud Arena - Tim Willoughby

Bring Banks App

Page 74: Cloud Security - Cloud Arena - Tim Willoughby

Parking

• Select County• Select Zone• Select Price willing to

pay?• Where is the Cheapest

Page 75: Cloud Security - Cloud Arena - Tim Willoughby

Tourism

• History• Old Maps• Business Interests• Tourist Sites

Page 76: Cloud Security - Cloud Arena - Tim Willoughby

Traffic

• Maps• Plan a Route• Feedback• GPS• Accidents• Salt• Weather alert

Page 77: Cloud Security - Cloud Arena - Tim Willoughby

Roadworks

• Link to System – Online Road Works Control (OLRWC)

• License for Road Opening

• Cost of Reinstatement (Local Authority Usage)

• License for any Street usage.

Page 78: Cloud Security - Cloud Arena - Tim Willoughby

Planning Applications

• View Applications• Get notified of Changes• Make Comments• Make a Submission• Notify Local Authority

of Issues?

Page 79: Cloud Security - Cloud Arena - Tim Willoughby

Check the Register

• Map the Polling Stations• Where is the Nearest• Map the Route• Check the Register

Page 80: Cloud Security - Cloud Arena - Tim Willoughby

Blue Flag Beaches

• Location• Nearest• Water Quality• History• Tides• Weather• Things to do…

Page 81: Cloud Security - Cloud Arena - Tim Willoughby

Sports

• What is available now• How do I get there• What if I have to Cancel• Pay for it now

Page 82: Cloud Security - Cloud Arena - Tim Willoughby

Parking

• Select County• Select Zone• Select Price willing to

pay?• Where is the Cheapest

Page 83: Cloud Security - Cloud Arena - Tim Willoughby

Tourism

• History• Old Maps• Business Interests• Tourist Sites

Page 84: Cloud Security - Cloud Arena - Tim Willoughby

Opportunity - Unfinished EstatesQR Codes for Public Participation

Page 85: Cloud Security - Cloud Arena - Tim Willoughby

QR Codes

Page 86: Cloud Security - Cloud Arena - Tim Willoughby

But all of these are static…..

But… would you cross the road based on 5 min old information

Page 87: Cloud Security - Cloud Arena - Tim Willoughby

Where next - Augmented Reality

Bring together Big Data, Visualisation, GIS, GPS -

A problem that needs cloud to work…

Page 88: Cloud Security - Cloud Arena - Tim Willoughby

What is Augmented Reality?

Page 89: Cloud Security - Cloud Arena - Tim Willoughby
Page 90: Cloud Security - Cloud Arena - Tim Willoughby
Page 91: Cloud Security - Cloud Arena - Tim Willoughby

Water Meter

Page 92: Cloud Security - Cloud Arena - Tim Willoughby

Water Meter

Page 93: Cloud Security - Cloud Arena - Tim Willoughby

What do Clouds currently not do?

• Anything subject to compliancy– Includes PCI-compliant applications

• Apps that call back to performance sensitive services in your data centre

• Apps that require tight coupling between instances

• Sensitive Data• Large applications that don’t fit inside VMs

Is there anything they can’t do?

Page 94: Cloud Security - Cloud Arena - Tim Willoughby

Cloud conclusions

• Government cannot ignore cloud• Public Cloud and Big Data• Public Cloud and Open Data• SLA needs to be more Open• Future is Cloudy