Securely Building Clouds: Thoughts and Concerns

Edward Haletky, Cloud Analyst, The Virtualization Practice
Edward Haletky provides Virtualization, Virtualization Security, Network Security, Secure Coding Consulting and Courseware as well as Linux Security and Application Development.

* Author of "VMware Virtual Infrastructure Security: Securing the Virtual Environment" and "VMWare ESX Server in the Enterprise: Planning and Securing Virtualization Servers", published December 2007, Copyright 2008 Pearson Education.

* Guru and moderator for and participant in the VMware Community Forums.

* Moderator for the Virtualization Security Podcast held every other week on thursday.

* Analyst and Managing Director for The Virtualization Practice, LLC.

* Participant in the VMware VMTN Communities Roundtable Podcast held every wednesday.

* Blogs about Virtualization on his own Blog, Blue Gears, as well as for the Virtualization Practice and TechTarget.

* Writer for various online and physical magazines.

Specialties
* Virtualization Security
* VMware Virtual Infrastructure
* Network Security
* Secure Coding
* Linux Security
* Linux Application Development
May 16 2012
48 mins
Securely Building Clouds: Thoughts and Concerns
More from this community:

IT Security

Webinars and videos

  • Live and recorded (2597)
  • Upcoming (175)
  • Date
  • Rating
  • Views
  • By 2014, 60% of global companies are expected to pilot, deploy or expand their BYOD programs (RainKing). As BYOD has become a fixture in the workplace, with 72% of employees clamoring to have their personal devices work-enabled, the IT industry has watched as the familiar “perimeter" model has become untenable. Data is going to more places, and ending up on a wider variety of devices, than ever before. A new model for protecting data has become a necessity. Organizations have tried to do so in a multitude of ways: extending policies to cover mobile devices, monitoring usage, MDM solutions, and even NAC; all have been methods used to try and create the most stable environment for mobile technology. Let Integralis security expert Mike Gabriel explain how to best balance mobile productivity and security in this Security Talks installment.

    Why Attend?

    1.Discover how your peers are trying to protect mobile data.
    2.See how the perimeter is being sculpted (or not) by the IT industry.
    3.Find out what the future holds for BYOD in the workplace.
  • Over the years true MSPs have had to work diligently to differentiate themselves from companies that are at best, not true MSPs and at worst, are shady fly-by-night operators. This is where the Unified Certification Standard or (UCS) for Cloud & Managed Service Providers comes in.

    The UCS was created by a team of dedicated MSPs to address the shortfalls of existing standards like ISO 27001, ITIL, CoBIT, SSAE 16, which were never intended for managed services organizations and offered little in the way of consumer protection.

    CASE IN POINT: Many MSPs do NOT fail because of technical deficiencies, but due to financial risk. Because of this, customers have very little insight into the service provider's business practices and financial strengths and capabilities.

    Attend this webcast and you will hear from real MSP executives on how the UCS certification and audit has helped them to:

    - Win new business
    - Provide needed transparency to customers
    - Achieve compliance objectives
    - Quickly develop trust with customers and prospects
    - Provide documentation on how those MSPs deliver their services
    - And much more...

    Both Cloud and Managed Service Providers should attend this webcast and at least begin to follow the standards necessary to achieve managed services and cloud computing excellence.
  • Doug Turner, CEO of Mantis Technology Group, talks about how his team built Pulse Analytics, a sentiment analysis solution using text analytics tool running on SAP HANA One. Hear how his team strengthened the capabilities of this solution while simplifying their data architecture by replacing 20 servers with only 1 SAP HANA One instance.
  • Most SMB's use a single point product for each of the different perceived security threats. This has worked in the past, but a far better approach is layering multiple products in a stouter defense.
  • APIs are a hot topic in all sectors of IT - they have gone from being niche solutions provided by big players like Amazon and Google, to being almost as ubiquitous as corporate websites. Ad hoc API development & evangelism without a formal program can leave real revenue on the table, can unintentionally leak sensitive data, and can tarnish the corporate brand with the development community. Today, developers and partners expect to be engaged with first class API programs, while businesses expect real insights to know which APIs are profitable and which APIs to bring to market next. In this webinar, Intel & Mashery outline the baseline enterprise pillars for constructing a first class API program. Learn from CapitalOne how they strategized to build an API program grounded in core business objectives. All attendees to receive a new Mobile API Buyers Guide that presents how to optimize APIs for mobile apps.
  • Are you using or considering a next-generation threat protection solution? Join this webcast and learn how you can multiply the value of your investment by integrating network and endpoint security.

    During this session you’ll learn best practices for protecting your network and your endpoints and servers from today's new breed of cyber attacks. You’ll also see firsthand how the integration of network and endpoint security solutions will help you:

    ・ Automatically confirm and prioritize alerts
    ・ Provide enterprise-wide visibility of infections to speed investigation
    ・ Drive remediation
    ・ Automatically analyze files from endpoints and servers
  • In today’s socially-connected world, conducting business effectively demands easy access to information from anywhere at any time. More people need access to more data through the use of more devices than ever before.

    Join this webcast and learn how CA Technologies helps companies across the world to enable business in a secure manner. Through the use of a Cloud Identity and Access Management service, CA allows the right people have access to the right information at the right time. By seamlessly leveraging existing investments, while extending Identity and Access Management to the cloud, CA Technologies vastly reduces the time to deliver secure new business services.
  • Join us on May 22 for a complimentary webcast on how Oracle Exalogic is the simple way to deploy and upgrade your business applications. Oracle Exalogic is hardware and software engineered together to provide extreme performance, reliability and scalability for your critical applications. Hyundai Motor Company saves more than US$1 Million per year with Exalogic and related Oracle products.

    During this webcast you will hear how Oracle customers have used Exalogic to:

    • Seize new market opportunities
    • Lower business risk
    • Reduce the cost of application deployments

    “We chose Oracle Exalogic, Oracle Exadata, Oracle WebLogic Server, and Oracle WebCenter Content over their competitors as Oracle offers stable storage for petabytes of data and high processing speeds. We have cut the time spent each day on document-related work by around 85% and saved up to US$1.1 million in printing costs.” Kang Tae-jin, Manager, General Affairs Team

    If you would like to contact Tom Smith directly for more information, his email address is tom.a.smith@oracle.com
  • Ever feel like you spend more time converting security information from one format to another, than actually connecting the dots hidden within it? The Collective Intelligence Framework (CIF) is a data processor for pulling in and normalizing out all these threat intel sources into a single combined dataset.

    Learn how to...
    Get CIF up and running
    Connect intelligence sources to CIF
    Leverage CIF with your existing security controls
    Host: Conrad Constantine, Community Manager, AlienVault
    Guest: Todd Leetham, Visiting Scientist, RSA I The Security Division of EMC
    Event Date: Tuesday, May 21, 2013 at 11am PDT
  • "People are talking about doing security in the mobile space and I ask the following question: You have spent the last 13 years building up proper, compliant infrastructures inside your four walls. Now we're going mobile. Why should you implement any lesser degree of compliance in that portion of your infrastructure than you currently have?" Winn Schwartau, one of the world's top experts on security, privacy, infowar and cyber-terrorism, discusses the importance of mobile security and the implications it can have for your pre-existing infrastructure.
  • Channel
  • Channel profile
Up Down
  • Transforming Healthcare Infrastructure Through Cloud & Virtualization Solutions Aug 7 2013 4:00 pm UTC 45 mins
    Healthcare providers have focused much of their IT investments in recent years on EMR implementations and meeting Meaningful Use requirements, but these are only the first in a long list of upcoming IT initiatives that healthcare providers must manage in the immediate future. With the shift towards Accountable Care Organizations and collaborative care models, supporting the transformation of care delivery requires the transformation of IT infrastructure. In this transformation, Frost & Sullivan believes that virtualization and cloud infrastructure will play key roles in the enablement of anytime, anywhere, always available access to clinical applications that is required to deliver quality care in the current and future healthcare environment.

    The explosion of data in healthcare and the need to rapidly and flexibly increase access to data stored across the continuum of care, combined with the need to reduce capital expenditures and IT headcount focused on data storage, make healthcare a market ripe for cloud solutions. Traditional hurdles remain in addressing concerns regarding data control and security, issues of crucial importance to healthcare stakeholders. New alignments of providers across organizations and the requirement to support mobility are pushing healthcare organizations toward desktop virtualization.

    Join us to discuss how these IT solutions are key to the transformation of healthcare delivery, and why the healthcare sector today is likely to reverse the trend of being late to the party in adopting new IT solutions.
  • Virtualizing Your SAP HANA Test and Development Environment with VMware Jun 19 2013 3:00 pm UTC 60 mins
    Join SAP and VMware for this live webinar to learn how you can increase IT agility, simplify management and lower total cost of ownership when you virtualize your SAP HANA in a supported test and development environment with VMware. We will review the performance test results of SAP HANA running on VMware vSphere, jointly performed with SAP. Also you will gain early insight to the SAP Co-Innovation project, designed to optimize the value for SAP and VMware customers who are deploying SAP HANA on vSphere.

    During this webinar, we will discuss:
    - The latest SAP Co-Innovation project, a joint collaboration between VMware and SAP to enable VMware functional capabilities around automation, flexibility, and efficiency for SAP HANA, including vMotion, High Availability (HA), Distributed Resource Scheduler (DRS), Site Recovery Manager, and the vCenter Operations Management Suite on a storage area network
    - Best practices for virtualizing SAP HANA in test and development on vSphere
    - Getting started: how VMware and SAP together can help you assess, create and adopt a virtualization strategy for your SAP HANA test and development environment
    - Answers to your questions during live Q&A

    Don’t miss this opportunity to learn how you can benefit from virtualizing your SAP HANA environment with VMware and transform your business.
  • Achieving Cloud Storage Interoperability to Benefit Enterprise Storage Clouds Jun 13 2013 6:00 pm UTC 45 mins
    Enterprise Storage moving toward the cloud requires an interoperable interface foundation to avoid vendor lock-in and provide choice. This tutorial will provide an overview of the features of a Enterprise cloud storage standard and explain how interoperability between clouds is achieved.

    What should you be requiring from your cloud vendors?
    How can you expect standards to roll out in implementations?

    Learning Objectives
    How this cloud storage standard can achieve interoperability and what this interoperability means to you.
    How you can use the cloud storage standard both internally for private clouds as well as for public clouds.
  • On-Demand High Performance Computing Jun 6 2013 8:00 pm UTC 55 mins
    Cloud promises elastic, capacity on demand. But, the explosion of data, research platforms and computational challenges continues to create strain on IT resources. Cost-effectively leveraging limited resources is particularly difficult for compute-intensive industries such as Life Science, Engineering, Retailing, Manufacturing or Oil & Gas. How do you to align performance compute directly to project periods and technology refresh cycles so that you can optimize resources and take advantage of the fastest compute technology available?

    Join this webinar to see how organizations are using Dell HPC Cloud as a flexible high-performance compute solution that is faster to deploy, easier to scale, and requires less capital and operating investment.

    In this informative webinar you will:
    - Discover how customers are using HPC Cloud today
    - Learn about the discovery & solution process for High Performance Computing
    - Uncover the value HPC and how Dell solutions HPC with the customer
  • Cloud Security: Don’t Throw Caution to the Wind Jun 6 2013 7:00 pm UTC 45 mins
    What is the cost of your proprietary data falling into the wrong hands? Did you know that today, the number one security threat in the cloud is data breach? What are your plans to secure your information the cloud? While organizations are rapidly turning to the cloud to reduce costs, provide greater flexibility and quickly ramp up support of business needs, security still remains a top concern.

    As a leading provider of information security services, Dell and its partners can provide you with expert guidance and critical security controls to protect your infrastructure, applications and data. Join us for an informative discussion that will separate fact from fiction, and help you secure your information in the cloud.

    In this webinar, security practitioners will help you:
    - Discover technological and other tools to mitigate threats in the cloud
    - Understand the types and nature of security threats
    - Learn about Dell’s unique integrated approach to cloud security, leveraging SecureWorks and Trend Micro
  • Compliance Exclusive: What Healthcare Can Teach Business about the Cloud Jun 6 2013 6:00 pm UTC 55 mins
    Few industries are exposed to the kind of regulation rigor that exists today in healthcare. HIPAA places tight regulations on electronic patient health information (ePHI), and as more data is digitally managed, providers have experience increasing costs and risks associated with ePHI management. The emergence of community clouds in the healthcare industry have provided a more sustainable and scalable model . With consumers demanding greater responsiveness and transparency from their providers and suppliers, there is much that businesses in other sectors can learn from the success of healthcare community clouds. We will showcase a case study of King’s Daughters Medical as an example of one company’s experience and the value they have realized.

    Join this webinar to:
    - Discover the risks, vulnerabilities, and challenges facing providers who must be HIPAA-compliant.
    - Learn the role that secure, cloud-based computing can play in helping healthcare organizations.
    - Understand how Dell Cloud Dedicated and community cloud strategies can help your business
  • Experience Collaboration and Sharing With Dell Cloud Service for SharePoint Jun 6 2013 5:00 pm UTC 55 mins
    You understand the value in Microsoft® SharePoint® as a proven tool for sharing and collaboration. Still, you are not convinced that the resource requirements for implementation, installation, start-up and ongoing management of the SharePoint software and hardware infrastructure make it worth the effort. Cloud sounds like the perfect solution, but how can you ensure your data is safe?

    At Dell, we understand these business challenges. Join us to find out how Dell Cloud Service for SharePoint safely allows customers to experience the full capabilities of the most powerful enterprise collaboration software without having to acquire, standup and maintain the required infrastructure.

    In this webinar you will:
    - Learn how SharePoint 2013 enhances productivity while reducing operational complexity and improving time-to-market
    - Understand the key features of enterprise-class cloud security
    - Discover the benefits of deploying SharePoint in the cloud
  • How IT and Developers Can Join Forces to Innovate in the Cloud Jun 6 2013 4:00 pm UTC 55 mins
    Developers have gained considerable power within companies and are now making key architectural decisions like the programing language(s), platform (OS), middleware as well as how data is stored. Given that it is the developer’s software that drives business advantage, it comes as no surprise that they have become the respected partners of the business, perhaps at the expense of central IT, in leading the company’s defacto cloud strategy. However, in order to really drive the scale of innovation that provides a sustainable competitive advantage – developers and business leaders cannot go it alone, they must work together with IT. While the goals of developers and IT operations often seem at odds, organizations must seek to reduce these conflicts or risk impeding the pace of innovation. Join this session to discover how understanding the needs of each side and leveraging the processes, tools and procedures that underlie “DevOps,” will enable both teams to work together to better serve the business and ultimately the customer.

    In this session you will learn about:
    - How developers rose to power
    - The key principles, tools and procedures of DevOps
    - How working together helps reduces friction, increases velocity and improves customer outcomes
    - How developers, IT and business can work together to implement and drive innovation through the Cloud
  • Is Cloud Meeting Your Expectations? Today’s Results….Tomorrow's Promises Jun 6 2013 3:00 pm UTC 55 mins
    According to IDC, cloud revenue is growing at more than 25 percent a year, and will reach $55.5 billion by 2014. I think we can agree that cloud is here to stay, but is your organization seeing the results they expected? This session will show customer success in adopting cloud; time/cost savings, and improvements to the quality of life. There will also be a discussion on up-and-coming cloud trends and how Dell is addressing these and simplifying the process with Dell best practices, cloud enabled hardware, software and services.

    Join this session to:
    - Discover how organizations like yours are successfully adopting cloud and seeing real business results
    - Understand future trends that can affect your organization, and hear how Dell is addressing these with the right solutions: hardware, software and services
    - Learn 3 key steps in making cloud adoption work best for your organization
  • Do You Know The Risks With Co-Employment? May 23 2013 2:00 pm UTC 45 mins
    For the IT employer utilizing contingent or contract worker(s) services there are best practices and considerations that need to be made in order to protect yourself and your employees.

    - Do you know how to discuss pay rates, increases or bonuses?
    - Do you know how to deal with full-time employment queries, how to properly deal with timecards or forms?
    - How do you deal with punctuality, attendance, dress code etc?
    - What do you do when you want to terminate or suspend a contingent worker?

    These are the common questions we receive and we will provide tangible tools and information that can help protect you as an employer.
  • SAP HANA One Success Story: Performing Text Analytics with SAP HANA One Recorded: May 22 2013 33 mins
    Doug Turner, CEO of Mantis Technology Group, talks about how his team built Pulse Analytics, a sentiment analysis solution using text analytics tool running on SAP HANA One. Hear how his team strengthened the capabilities of this solution while simplifying their data architecture by replacing 20 servers with only 1 SAP HANA One instance.
  • "Hybrid IT" and the Power of Cloud Recorded: May 16 2013 49 mins
    On Premise? Outsourced? Dedicated? Cloud? Harness the Power of "Hybrid" for a True "All-of-the-Above" Approach to IT Infrastructure.

    With so much focus on – and hype around – the cloud, we seem to have forgotten that for most businesses IT infrastructure remains a mix of on-premise, outsourced, physical and virtual components that must be optimized into a seamless hybrid environment. Featuring IaaS experts from Latisys and HP, we'll look at how CIOs and CTOs are allocating workloads, applications and data across a diverse infrastructure today – using every tool in their arsenal in an effort to maximize legacy assets, optimize limited IT budgets and leverage technology advancements to make their business more effective and responsive.
  • Corporate IT’s Amazon Strategy: Lead, Follow or Get Out of the Way? Recorded: May 16 2013 47 mins
    With easy access to public cloud resources like Amazon EC2, end users are completely sidestepping corporate IT and spinning up their own mini-datacenters with only a credit card in hand. This grass roots migration is gaining speed, and industry experts predict 35% of enterprise IT expenditures will go to shadow IT services like AWS in under 3 years.

    If you are in Corporate IT, join this webinar to learn more about:
    - Strategies other IT teams are pursuing regarding public cloud services, both pro and con
    - Management options for IT shops who want to embrace AWS, whether a little or a lot
    - Easy ways for corporate IT to add value to the business units and engineering teams already using Amazon EC2
    - Practical techniques for assuming a public cloud leadership role, even when resources are non-existent

    About the Presenters:
    Lynn LeBlanc, CEO and founder of HotLink Corporation, has over 25 years of enterprise software and technology experience at both Fortune 500 companies and Silicon Valley start-ups. Prior to founding HotLink, Ms. LeBlanc was founder and CEO of FastScale Technology, an enterprise software company acquired by VMware, Inc.

    Oded Haner, CTO at HotLink Corporation, is an accomplished, strategic, collaborative technology leader with extensive experience in developing and implementing innovative IT technologies. Most recently, Mr. Haner was CIO at Monster Cable where he developed and deployed a multi-year roadmap to overhaul corporate architecture towards virtualization, private cloud and SaaS based technologies. As a direct result of his vision, Monster Cable became an early adopter and internal service provider using both on-premise and cloud-based infrastructure.
  • Toward the Software-Defined Data Center Recorded: May 16 2013 49 mins
    In this session learn about a transformational shift in data center architecture, the software-defined data center. You learn about what an SDDC is, how it can benefits businesses by providing unparalleled levels of efficiency, agility, control and choice, and finally how you can make it real in your businesses with VMware vCloud suite.
  • Industry Trends for Business-Critical Apps with Virtualization and the Cloud Recorded: May 15 2013 49 mins
    Many organizations have been taking advantage of virtualization and cloud technologies to reduce server counts, and gain operational advantages. When it comes to business critical workloads such as those running Oracle, migration to virtualization and the cloud has encountered more resistance, and roadblocks.

    This presentation will examine industry trends in virtualization and cloud computing for enterprise workloads, such as Oracle, SAP, PeopleSoft, MS SQL Server, etc. Case studies will be presented that explore the advantages of a cloud strategy for mission-critical applications. Strategies for minimizing risk, and maximizing benefits will be provided.
  • Accelerating SaaS adoption in the New Enterprise Recorded: May 9 2013 38 mins
    Audience: SaaS Company Executives responsible for Sales, Service, Support, and company growth

    Synopsis: Did you know you can increase your company valuation with integration? Securing Enterprise customers is extremely challenging, and as the competitive landscape continues to grow with best of breed SaaS applications, it will be important to consistently meet customer requirements and differentiate your service from the competition.

    What you will learn:
    -Top barriers to SaaS adoption in the Enterprise
    -Overview of the New Enterprise, and what it means for SaaS providers
    -3 ways integration can increase your valuation as a SaaS provider
  • Take a Deep Dive into HANA Technology in the Cloud and Get Your $120 AWS Credit Recorded: May 8 2013 35 mins
    Our HANA One technical guru, Swapan Saha, guides us through the breakthrough analytics capabilities of Vizi (data visualization) and more new offerings with HANA One including a $120 AWS infrastructure credit to help you get started today.
  • Deploying Public, Private, and Hybrid Storage Clouds Recorded: May 7 2013 60 mins
    Everyone has heard talk of cloud but do you know how to deploy one? This session will be a technical dive into implementations of popular public, private, and hybrid storage cloud use cases and best practices examples of how they can fit into your existing IT operations. SNIA's Cloud Storage Initiative (CSI) has created the Cloud Data Management Interface (CDMI) as a de jure standard which can assist you in your cloud deployments utilizing both traditional file systems and new cloud file system formats. This presentation will dive into the details of designing and deploying public, private, and hybrid storage clouds including how CDMI can assist with cloud federation, peering, differentiation, and how CDMI can interact with external systems for event management, configuration management, workflows, auditing, billing, and authorization.

    •Understanding how cloud computing and specifically CDMI interact with traditional file systems (CIFS, NFS, FC) and new cloud formats such as Amazon S3.
    •Gain an understanding of how cloud can integrate into existing IT Service Management (ITSM) or ITIL best practices for event, configuration, incident, and problem management.
    •Presenting in detail reference architectures for cloud and an overview of the reference deployments done to date and how it fits into standard tiered storage enterprise architectures
  • A Deep Dive into New Technology of HANA in the Cloud & a $120 AWS Credit Recorded: Apr 30 2013 41 mins
    Our HANA One technical guru, Swapan Saha, guides us through the breakthrough analytics capabilities of Vizi (data visualization) and more new offerings with HANA One. Also, see how you can get a $120 AWS credit to help you get started today.
  • The Business of Social Business Recorded: Apr 25 2013 44 mins
    Social business represents a new transformational opportunity for organizations. After initial forays into external social media, many companies are now discovering the value of applying social approaches, internally as well as externally. Social business can create valued customer experiences, increase workforce productivity and effectiveness and accelerate innovation. But many companies still wrestle with the organisational and cultural challenges posed by these new ways of work.

    Join this webinar to hear the proven results from easily integrating social into your everyday tools to improve your business.

    About the speaker:
    Chris Moore is a Social Business Specialist for IBM Collaboration Solutions. He has 7 years experience and knowledge of Collaboration and Exceptional Web Experience technologies; including IBM Notes, Domino, Sametime, Connections, Docs and Web Experience Suites.
All you need to know, what it means and why it matters
Cloud computing is a general concept that incorporates software-as-a-service (SaaS), platform-as-a-service (PaaS), infrastructure-as-a-service (IaaS) and other recent well-known technology trends in which the common theme is reliance on the Internet for satisfying the computing needs of the users.

This channel features presentations by thought leaders who cover the key topic areas in this increasingly important field.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: Securely Building Clouds: Thoughts and Concerns
  • Live at: May 16 2012 12:00 pm
  • Presented by: Edward Haletky, Cloud Analyst, The Virtualization Practice
  • From:
Your email has been sent.
or close
You must be logged in to email this