Welcome!

FinTech Journal Authors: Liz McMillan, Yeshim Deniz, Elizabeth White, Pat Romanski, Mehdi Daoudi

Blog Feed Post

Building Secure Cloud SaaS Applications – VMware special, part 3

vmware2This post  is sponsored by the VMware Online Forum 2013.

This part three of our VMware series will build on the second article that introduces Rackforce, one the Cloud providers implementing VMware technologies.

Enterprise SaaS Enablement

With this platform in place we can look in more detail at how organizations might approach the apps strategy that they run in these environments, under a headline banner of ‘Enterprise SaaS Enablement’, referring to transforming traditional software apps to run in a Software-as-a-Service mode.

Typically this is when it is for a commercial venture, to literally sell the software as a service, but increasingly it will also become a new practice within enterprise architecture, a means of improving how corporate IT delivers apps to users.

This is because the enterprise adoption of Cloud computing can mean both outsourcing to third party suppliers like Amazon, but also via their Private Cloud strategy internal adoption of the architectures of Cloud computing as well.

This means SaaS and PaaS, as well as the infrastructure/virtualization aspects of IaaS that are common to most Private Cloud scenarios. These layers are less common, where they impact more upon how software programmers work through new shared service architectures at the app layer.

From virtual appliances through full SaaS-enablement toolsets there are a range of ways enterprises can improve their software practices, with the core idea being benefiting from the best practices SaaS vendors have developed through running very large-scale, high availability web applications.

VMware has a comprehensive PaaS strategy built on their Cloud Foundry platform, and culminating in the launch of a dedicated joint venture with EMC called Pivotal. (learn more at the VMware Online Forum 2013.)

This two-pronged approach is key to unlocking the full transformational power of Cloud Computing, where the organization leverages both i) scale: using Cloud providers like Amazon to tap into a new low-cost capability for IaaS, and also ii) utilizing principles like SaaS enablement to re-architect applications to better make use of this resource.

Cloud Security and service catalogue standardization

One simple way to adopt this powerful business improvement is via the ongoing development of the enterprise service catalogue, introduced in the previous articles.

Not only does this provide for the core IT automations that are one of the benefits of Cloud, but this automated deployment is achieved through templates of repeatable IT configurations. Building up this inventory can be driven by a process of setting enterprise-wide standards for Private Cloud SaaS. Which authentication modules to use, and so on.

This kind of standardization effort can better consolidate and manage the IT estate, and also can manage the use of third-party vendors as part of this process, so that these standards can address key areas like Cloud Security.

vmware-vapp3VMware has an extensive partner portfolio who add value to the core suite – For example Canadian supplier AFORE offers a range of tools for Cloud Security Management, specifically intended to address securing sensitive cloud data in a multi-tenant environment when customers share application and server infrastructure, and how can security deployment be simplified so applications, virtualized workloads and hardware don’t need to be modified – often this is onerous if not impossible in cloud environments.

AFORE’s CloudLink® Secure VSA encrypts mission-critical data in motion and at rest across public, private and hybrid clouds by providing a secure software-defined storage layer between virtual machines and cloud storage infrastructure.

  • Agentless, storage infrastructure agnostic security solution – no need to modify applications or workloads

  • Full control by enterprises over security policy and key management of encrypted data in the cloud

  • Enable multi-tenant security by creating per tenant virtual storage and encrypted with tenant controlled encryption keys.

  • Unsurpassed deployment flexibility including multi-tenant virtualized private, hybrid and public cloud environments and the ability to span heterogeneous storage servers with one CloudLink management console

  • Easy adaptability for ANY IaaS clouds (VMware, CA, Amazon, Microsoft, OpenStack, CloudStack, etc) and support self-service and elastic nature of these cloud services.

  • AFORE’s CypherX secures sensitive data in hosted VDI and application stacks from cyber attackers, malicious insiders and cloud administrators. It seamlessly and efficiently places apps in secure virtual containers, encrypting and managing access to all data.

    • App Lockdown creates a secure virtual container for applications, protecting network, storage and inter-process communications with application-level granularity

    • CypherZones extend data security between groups of protected applications, allowing a complete application stack or workgroup environment to be protected.

    • Centralized control of security policy and encryption key management across many virtual machines

    • Complete end-user transparency

    • Traceability via tamper-proof audit logs that detail who/what accessed protected data, when and from where

Conclusion – Securely enabling Enterprise Agility

The key to any strategy intended to unlock better ‘enterprise agility’ is to empower employees and partners more and more.

A twin strategy of PaaS standardization and improved Cloud Security will enable IT development teams to work faster and do so by leveraging a wider range of productivity boosting Cloud services, all in a manner compliant with the organizations information security policies.

vmware2This post  is sponsored by the VMware Online Forum 2013.

The post Building Secure Cloud SaaS Applications – VMware special, part 3 appeared first on Cloud Computing Best Practices.

Read the original blog entry...

More Stories By Cloud Best Practices Network

The Cloud Best Practices Network is an expert community of leading Cloud pioneers. Follow our best practice blogs at http://CloudBestPractices.net

@ThingsExpo Stories
We build IoT infrastructure products - when you have to integrate different devices, different systems and cloud you have to build an application to do that but we eliminate the need to build an application. Our products can integrate any device, any system, any cloud regardless of protocol," explained Peter Jung, Chief Product Officer at Pulzze Systems, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA
SYS-CON Events announced today that Hitachi Data Systems, a wholly owned subsidiary of Hitachi LTD., will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City. Hitachi Data Systems (HDS) will be featuring the Hitachi Content Platform (HCP) portfolio. This is the industry’s only offering that allows organizations to bring together object storage, file sync and share, cloud storage gateways, and sophisticated search and...
SYS-CON Events announced today that Progress, a global leader in application development, has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Enterprises today are rapidly adopting the cloud, while continuing to retain business-critical/sensitive data inside the firewall. This is creating two separate data silos – one inside the firewall and the other outside the firewall. Cloud ISVs ofte...
SYS-CON Events announced today that Fusion, a leading provider of cloud services, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Fusion, a leading provider of integrated cloud solutions to small, medium and large businesses, is the industry’s single source for the cloud. Fusion’s advanced, proprietary cloud service platform enables the integration of leading edge solutions in the cloud, including cloud...
Five years ago development was seen as a dead-end career, now it’s anything but – with an explosion in mobile and IoT initiatives increasing the demand for skilled engineers. But apart from having a ready supply of great coders, what constitutes true ‘DevOps Royalty’? It’ll be the ability to craft resilient architectures, supportability, security everywhere across the software lifecycle. In his keynote at @DevOpsSummit at 20th Cloud Expo, Jeffrey Scheaffer, GM and SVP, Continuous Delivery Busine...
SYS-CON Events announced today that delaPlex will exhibit at SYS-CON's @CloudExpo, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. delaPlex pioneered Software Development as a Service (SDaaS), which provides scalable resources to build, test, and deploy software. It’s a fast and more reliable way to develop a new product or expand your in-house team.
SYS-CON Events announced today that Progress, a global leader in application development, has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Enterprises today are rapidly adopting the cloud, while continuing to retain business-critical/sensitive data inside the firewall. This is creating two separate data silos – one inside the firewall and the other outside the firewall. Cloud ISVs oft...
SYS-CON Events announced today that Cloud Academy will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Cloud Academy is the industry’s most innovative, vendor-neutral cloud technology training platform. Cloud Academy provides continuous learning solutions for individuals and enterprise teams for Amazon Web Services, Microsoft Azure, Google Cloud Platform, and the most popular cloud computing technologies. Ge...
The 21st International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Digital Transformation, Machine Learning and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding busin...
SYS-CON Events announced today that WineSOFT will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Based in Seoul and Irvine, WineSOFT is an innovative software house focusing on internet infrastructure solutions. The venture started as a bootstrap start-up in 2010 by focusing on making the internet faster and more powerful. WineSOFT’s knowledge is based on the expertise of TCP/IP, VPN, SSL, peer-to-peer, mob...
Internet of @ThingsExpo, taking place October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with the 21st International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. @ThingsExpo Silicon Valley Call for Papers is now open.
DevOps at Cloud Expo – being held October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's largest enterprises – and delivering real r...
SYS-CON Events announced today that T-Mobile will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. As America's Un-carrier, T-Mobile US, Inc., is redefining the way consumers and businesses buy wireless services through leading product and service innovation. The Company's advanced nationwide 4G LTE network delivers outstanding wireless experiences to 67.4 million customers who are unwilling to compromise on ...
DevOps is often described as a combination of technology and culture. Without both, DevOps isn't complete. However, applying the culture to outdated technology is a recipe for disaster; as response times grow and connections between teams are delayed by technology, the culture will die. A Nutanix Enterprise Cloud has many benefits that provide the needed base for a true DevOps paradigm.
SYS-CON Events announced today that Ocean9will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Ocean9 provides cloud services for Backup, Disaster Recovery (DRaaS) and instant Innovation, and redefines enterprise infrastructure with its cloud native subscription offerings for mission critical SAP workloads.
SYS-CON Events announced today that Carbonite will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Carbonite protects your entire IT footprint with the right level of protection for each workload, ensuring lower costs and dependable solutions with DoubleTake and Evault.
Existing Big Data solutions are mainly focused on the discovery and analysis of data. The solutions are scalable and highly available but tedious when swapping in and swapping out occurs in disarray and thrashing takes place. The resolution for thrashing through machine learning algorithms and support nomenclature is through simple techniques. Organizations that have been collecting large customer data are increasingly seeing the need to use the data for swapping in and out and thrashing occurs ...
Detecting internal user threats in the Big Data eco-system is challenging and cumbersome. Many organizations monitor internal usage of the Big Data eco-system using a set of alerts. This is not a scalable process given the increase in the number of alerts with the accelerating growth in data volume and user base. Organizations are increasingly leveraging machine learning to monitor only those data elements that are sensitive and critical, autonomously establish monitoring policies, and to detect...
SYS-CON Events announced today that CollabNet, a global leader in enterprise software development, release automation and DevOps solutions, will be a Bronze Sponsor of SYS-CON's 20th International Cloud Expo®, taking place from June 6-8, 2017, at the Javits Center in New York City, NY. CollabNet offers a broad range of solutions with the mission of helping modern organizations deliver quality software at speed. The company’s latest innovation, the DevOps Lifecycle Manager (DLM), supports Value S...
SYS-CON Events announced today that A&I Solutions named "Bronze Sponsor" of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Founded over 15 years ago in 1999, A&I Solutions continues to provide companies with premier integrated enterprise solutions. By partnering with the trusted and proven solutions of leading technology companies, our customers are assured high performance levels across all IT environments including:...