1 / 13

SIA317 Securing the Cloud: Expert Panel

SIA317 Securing the Cloud: Expert Panel. Mark Estberg Senior Director Microsoft Corporation. Security Experts. Mike Chan. Andy Malone. Marcus Murray. Mark Russinovich. Working Definition of Cloud Computing.

laban
Télécharger la présentation

SIA317 Securing the Cloud: Expert Panel

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. SIA317Securing the Cloud: Expert Panel Mark Estberg Senior Director Microsoft Corporation

  2. Security Experts Mike Chan Andy Malone Marcus Murray Mark Russinovich

  3. Working Definition of Cloud Computing • Cloud computing is a model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model promotes availability and is composed of five essential characteristics, three service models, and four deployment models. – Peter Mell & Tim Grance NIST

  4. Discussion Point #1 • Do we all agree with the NIST working definition of cloud computing? • What elements of the working definition do cloud service providers need to work on? • What is missing from the definition?

  5. Discussion Point #2 • What is preventing customers from moving to off-premise cloud computing (whether IaaS, PaaS or SaaS)? • Are there specific statutory or regulatory compliance requirements that prevent adoption? • Including data and service geolocation; • Data retention requirements/objections; • Privacy protections; • Does it make a difference if the cloud service providers offer public clouds, private clouds, or both? • What tools/technologies can cloud service providers make available to encourage customers to adopt off-premise cloud computing?

  6. Discussion Point #3 • What business functions and LOB applications will customers always keep in-house, and are they suitable for on-premise private clouds? • What tools/technologies do companies such as Microsoft need to offer to enable customers to build on-premise private clouds? • Is there a market for a “cloud in a box (or container)”?

  7. Discussion Point #4 • For customers with on-premise private clouds, what is preventing them from building hybrid clouds with off-premise public/private clouds? • Do customers want flexible solutions that they have to expend development effort with, or do they want out of the box solutions?

  8. Discussion Point #5 • How do we handle LEA, forensics and eDiscovery requests in cloud computing scenarios? • Who is obligated to satisfy legal demands? • Who owns the data? • How is chain of custody maintained? • What can cloud service providers do to help their customers?

  9. Discussion Point #6 • What is the role of organizations such as the Cloud Security Alliance and Trusted Cloud Initiative? • Should they represent customers, cloud service providers or both? • Should they develop standards, or stick to guidance and advocacy? • What about certification of cloud security practitioners – good idea or bad idea?

  10. Q&A

  11. Session Evaluations Tell us what you think, and you could win! All evaluations submitted are automatically entered into a daily prize draw*  Sign-in to the Schedule Builder at http://europe.msteched.com/topic/list/ * Details of prize draw rules can be obtained from the Information Desk.

  12. © 2010 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

More Related