Comments
bruce.armstrong wrote: Somebody just said it better than I did, and with more chops to say it: Open Letter to Mark Zuckerberg, Sheryl Sandberg & Facebook Mobile
Cloud Expo on Google News


2008 West
DIAMOND SPONSOR:
Data Direct
SOA, WOA and Cloud Computing: The New Frontier for Data Services
PLATINUM SPONSORS:
Red Hat
The Opening of Virtualization
GOLD SPONSORS:
Appsense
User Environment Management – The Third Layer of the Desktop
Cordys
Cloud Computing for Business Agility
EMC
CMIS: A Multi-Vendor Proposal for a Service-Based Content Management Interoperability Standard
Freedom OSS
Practical SOA” Max Yankelevich
Intel
Architecting an Enterprise Service Router (ESR) – A Cost-Effective Way to Scale SOA Across the Enterprise
Sensedia
Return on Assests: Bringing Visibility to your SOA Strategy
Symantec
Managing Hybrid Endpoint Environments
VMWare
Game-Changing Technology for Enterprise Clouds and Applications
Click For 2008 West
Event Webcasts

2008 West
PLATINUM SPONSORS:
Appcelerator
Get ‘Rich’ Quick: Rapid Prototyping for RIA with ZERO Server Code
Keynote Systems
Designing for and Managing Performance in the New Frontier of Rich Internet Applications
GOLD SPONSORS:
ICEsoft
How Can AJAX Improve Homeland Security?
Isomorphic
Beyond Widgets: What a RIA Platform Should Offer
Oracle
REAs: Rich Enterprise Applications
Click For 2008 Event Webcasts
SYS-CON.TV
Top Links You Must Click On


A Layered Approach to Securing the Cloud: Defense in Depth
As enterprise networking technology has evolved, so too has enterprise security

As enterprise networking technology has evolved, so too has enterprise security. What began simply as setting up a perimeter around the network via fairly basic security tools like firewalls and email gateways, has evolved into adding an array of virtual private networks (VPNs), virtual local area network (VLAN) segmentation, authentication, and intrusion detection systems (IDS)—necessary to handle the consistently growing number of threats to the corporate network. For most IT groups, the idea of trying to re-create a robust enterprise security model in the cloud has been a daunting proposition. Although the cost and scalability benefits of the cloud seem appealing, the perceived lack of security and control has prevented organizations from taking the plunge.

The answer lies in the notion of maintaining a layered approach or “defense in depth” when it comes to enterprise-class security. A public cloud provider shouldn’t force an enterprise into a situation that requires it to migrate sensitive data into an environment that simply adds security on top, seemingly as an afterthought. This old perimeter-based solution is no longer in the data center; but, it’s exactly what typical public cloud providers are offering today. Enterprises demand more granularity in their control of the network, and an integrated approach that considers networking and security together, can provide this type of custom functionality. A defense-in-depth model should include the use of IDS, firewalls, network segmentation, authentication, VPNs, reporting and response to maintain redundancy of security just in case any one layer fails.

First and foremost, layered security enables enterprise IT to replicate the level of control it has in its own in-house environment, extending user access controls and network permissions. Furthermore, IT should be able to use familiar interfaces, which enables the enterprise to make changes to its security on the fly.

Another critical factor to ensuring data stays secure is to separate the web, app and data tiers into different network segments using VLANs and firewalls. This type of segmentation enables IT to secure data by network segment rather than by using a host-based firewall. This also allows each tier to be load balanced and scale optimally.

For one OpSource client that decided to leverage the cloud - Aerohive Networks - security was a top priority when the company decided to move its HiveManager networks management solution to a cloud-based model. The company wanted to be able to ensure its customers that they would have the same level of security and control that they experienced with an on-premise installation of its HiveManager solution. Once the network management service was moved to the cloud, the company was able to offer enterprises all the features and functionality of a behind-the-firewall network management systems without the cost and operational headaches of an on-site dedicated system.

To ensure cloud security with HiveManager, only the necessary protocols are enabled in the cloud. Customer access is available via secure SSL as well as application level authentication and privilege authorization. Within the public cloud data center, the cloud-enabled networking application is multi-tenant, enabling Aerohive to segregate access by customer, as well as cloud operations personnel. Aerohive has also found that physical security is often better than at on-premise installations, with SAS70 type II certified operations. And finally, if managed services are utilized, a unique advantage is that third- party access directly into the corporate network is no longer required, only secure access to the cloud hosted management portal.

The public cloud offers enticing cost and scalability benefits, but until recently, the potential hazards have eclipsed them. Enterprises handling sensitive data risked major data privacy and compliance issues stemming from weak cloud security capabilities. With a reconfigured view of the public cloud and by taking defense-in-depth approach to security, IT can implement the proper layered security to make the cloud a true extension of the existing network.

About John Rowell
Over the past decade, Mr. Rowell has held senior management positions with leading hosting, telecommunications, and Internet services companies. He has extensive experience building, operating, and managing complex global IT infrastructure systems that are able to scale to meet dynamic business requirements. Prior to co-founding OpSource, Mr. Rowell led a team of over 500 people as Vice President of Operations for Metromedia Fiber Network (MFN). He was responsible for the delivery of managed services and the operation of the MFN data centers in the Americas, supporting leading enterprise customers including BP Amoco, Deutsche Bank, JP Morgan Chase, Microsoft, Paramount, and Sony. He joined MFN through the acquisition of SiteSmith, where he was Vice President of Operations. Before joining SiteSmith, Mr. Rowell was Director of Enterprise Services for UUNET Technologies, where he led the team responsible for the design, implementation, and ongoing support of large-scale enterprise environments in an outsourced model. Clients included AutoNation, Disney, The Go Network, Levi Strauss, Marriott International, mySap.com, Sony Playstation, and Symantec. Mr. Rowell holds a B.S. from the University of Alabama and attended the masters program for engineering management at George Washington University.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

Enterprise Open Source Magazine Latest Stories . . .
Grid Dynamics, an eCommerce technology solutions company, and GridGain Systems, makers of an open source in-memory platform for Big Data processing, on Wednesday announced the expansion of their partnership which began in 2008. Grid Dynamics provides personalization and big data solut...
Before embarking on using open source cloud technology for your web property, a basic understanding of cloud, as it’s used in the industry, is essential. While there might be exceptions, here are the definitions. A software application delivered on the web instead of installing standa...
Private clouds solve many problems for enterprises and bring unique operational challenges along with them. There are dozens of companies of all sizes that will build you a private cloud and turn over the keys – then what? Trying to convert a traditional enterprise IT operations team t...
The networking industry has gone through different waves over last 30+ years. In the ’80s, the first wave was all about connecting and sharing; how to connect a computer to other peripheral devices and other computers. There were many players who developed technology and services to ad...
If your organization already uses virtualized infrastructure, you are well on your way to providing IT as a Service. But as businesses demand faster results in today’s competitive market, organizations look to gain more benefits from cloud computing than just virtualized infrastructure...
In this CTO Power Panel at the 10th International Cloud Expo, moderated by Cloud Expo Conference Chair Jeremy Geelan, industry-leading CTOs & VPs of Technology will discuss such topics as: Which do you think is the most important cloud computing standard still to tackle? Who should...
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021


SYS-CON Featured Whitepapers
ADS BY GOOGLE