Welcome!

OpenStack Journal Authors: Maxime Charlès, Liz McMillan, Unitiv Blog, Lori MacVittie, RealWire News Distribution

Blog Feed Post

Building Secure Cloud SaaS Applications – VMware special, part 3

vmware2This post  is sponsored by the VMware Online Forum 2013.

This part three of our VMware series will build on the second article that introduces Rackforce, one the Cloud providers implementing VMware technologies.

Enterprise SaaS Enablement

With this platform in place we can look in more detail at how organizations might approach the apps strategy that they run in these environments, under a headline banner of ‘Enterprise SaaS Enablement’, referring to transforming traditional software apps to run in a Software-as-a-Service mode.

Typically this is when it is for a commercial venture, to literally sell the software as a service, but increasingly it will also become a new practice within enterprise architecture, a means of improving how corporate IT delivers apps to users.

This is because the enterprise adoption of Cloud computing can mean both outsourcing to third party suppliers like Amazon, but also via their Private Cloud strategy internal adoption of the architectures of Cloud computing as well.

This means SaaS and PaaS, as well as the infrastructure/virtualization aspects of IaaS that are common to most Private Cloud scenarios. These layers are less common, where they impact more upon how software programmers work through new shared service architectures at the app layer.

From virtual appliances through full SaaS-enablement toolsets there are a range of ways enterprises can improve their software practices, with the core idea being benefiting from the best practices SaaS vendors have developed through running very large-scale, high availability web applications.

VMware has a comprehensive PaaS strategy built on their Cloud Foundry platform, and culminating in the launch of a dedicated joint venture with EMC called Pivotal. (learn more at the VMware Online Forum 2013.)

This two-pronged approach is key to unlocking the full transformational power of Cloud Computing, where the organization leverages both i) scale: using Cloud providers like Amazon to tap into a new low-cost capability for IaaS, and also ii) utilizing principles like SaaS enablement to re-architect applications to better make use of this resource.

Cloud Security and service catalogue standardization

One simple way to adopt this powerful business improvement is via the ongoing development of the enterprise service catalogue, introduced in the previous articles.

Not only does this provide for the core IT automations that are one of the benefits of Cloud, but this automated deployment is achieved through templates of repeatable IT configurations. Building up this inventory can be driven by a process of setting enterprise-wide standards for Private Cloud SaaS. Which authentication modules to use, and so on.

This kind of standardization effort can better consolidate and manage the IT estate, and also can manage the use of third-party vendors as part of this process, so that these standards can address key areas like Cloud Security.

vmware-vapp3VMware has an extensive partner portfolio who add value to the core suite – For example Canadian supplier AFORE offers a range of tools for Cloud Security Management, specifically intended to address securing sensitive cloud data in a multi-tenant environment when customers share application and server infrastructure, and how can security deployment be simplified so applications, virtualized workloads and hardware don’t need to be modified – often this is onerous if not impossible in cloud environments.

AFORE’s CloudLink® Secure VSA encrypts mission-critical data in motion and at rest across public, private and hybrid clouds by providing a secure software-defined storage layer between virtual machines and cloud storage infrastructure.

  • Agentless, storage infrastructure agnostic security solution – no need to modify applications or workloads

  • Full control by enterprises over security policy and key management of encrypted data in the cloud

  • Enable multi-tenant security by creating per tenant virtual storage and encrypted with tenant controlled encryption keys.

  • Unsurpassed deployment flexibility including multi-tenant virtualized private, hybrid and public cloud environments and the ability to span heterogeneous storage servers with one CloudLink management console

  • Easy adaptability for ANY IaaS clouds (VMware, CA, Amazon, Microsoft, OpenStack, CloudStack, etc) and support self-service and elastic nature of these cloud services.

  • AFORE’s CypherX secures sensitive data in hosted VDI and application stacks from cyber attackers, malicious insiders and cloud administrators. It seamlessly and efficiently places apps in secure virtual containers, encrypting and managing access to all data.

    • App Lockdown creates a secure virtual container for applications, protecting network, storage and inter-process communications with application-level granularity

    • CypherZones extend data security between groups of protected applications, allowing a complete application stack or workgroup environment to be protected.

    • Centralized control of security policy and encryption key management across many virtual machines

    • Complete end-user transparency

    • Traceability via tamper-proof audit logs that detail who/what accessed protected data, when and from where

Conclusion – Securely enabling Enterprise Agility

The key to any strategy intended to unlock better ‘enterprise agility’ is to empower employees and partners more and more.

A twin strategy of PaaS standardization and improved Cloud Security will enable IT development teams to work faster and do so by leveraging a wider range of productivity boosting Cloud services, all in a manner compliant with the organizations information security policies.

vmware2This post  is sponsored by the VMware Online Forum 2013.

The post Building Secure Cloud SaaS Applications – VMware special, part 3 appeared first on Cloud Computing Best Practices.

Read the original blog entry...

More Stories By Cloud Ventures

The Cloud Ventures Network is an expert community of leading Cloud pioneers. Follow our best practice blogs at http://CloudBestPractices.net

Cloud Expo Breaking News
All too many discussions about DevOps conclude that the solution is an all-purpose player: developer and operations guru, complete with pager for round-the-clock duty. For most organizations that is not the way forward. In his session at DevOps Summit, Bernard Golden, Vice President of Strategy at ActiveState, will discuss how to achieve the agility and speed of end-to-end automation without requiring an organization stocked with Supermen and Superwomen.
The Internet of Things promises to transform businesses (and lives), but navigating the business and technical path to success can be difficult to understand. In his session at 15th Internet of @ThingsExpo, Chad Jones, Vice President, Product Strategy of LogMeIn's Xively IoT Platform, will show you how to approach creating broadly successful connected customer solutions using real world business transformation studies including New England BioLabs and more.
“The Internet of Things is a wave that has arrived and it’s growing really fast. The concern at Aria Systems is making sure that people understand the ramifications of their attempts to monetize whatever it is they build on the Internet of Things," explained C Brendan O’Brien, Co-founder and Chief Architect at Aria Systems, in this SYS-CON.tv interview at the Internet of @ThingsExpo, held June 10-12, 2014, at the Javits Center in New York City. Internet of @ThingsExpo 2014 Silicon Valley, November 4–6, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading IoT industry players in the world.
“About two years ago Brother launched a new group called Brother Online. We thought it was a good idea for a hardware company to get into the cloud services market and our first step into that market was web conferencing,” explained Courtney Behrens, Senior Marketing Manager at Brother International, in this SYS-CON.tv interview at the 14th International Cloud Expo®, held June 10-12, 2014, at the Javits Center in New York City. Cloud Expo® 2014 Silicon Valley, November 4–6, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading Cloud industry players in the world.
"So many teams have been stuck in their own practices for the last ten years and it's really hard to sell all the latest and greatest tools, but the reality is all the tools around operations have evolved so much you are starting to see a big shift toward upgrading that tool set, focusing more on automation, more on cloud," explained Dustin Whittle, Developer Evangelist at AppDynamics, in this SYS-CON.tv interview at the DevOps Summit, held June 10-12, 2014, at the Javits Center in New York City.
“We provide disaster recovery services as well as solutions. We also provide back-up solutions that work across your internal on-premise assets as well as in the public and private cloud," stated Joel Ferman, Vice President of Marketing at InMage Systems, in this SYS-CON.tv interview at the 14th International Cloud Expo® (http://www.CloudComputingExpo.com/), held June 10-12, 2014, at the Javits Center in New York City. Cloud Expo® 2014 Silicon Valley, November 4–6, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading Cloud industry players in the world.
SYS-CON Events announced today that Harbinger Systems will exhibit at SYS-CON's 15th International Cloud Expo®, which will take place on November 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA. Harbinger Systems is a global company providing software technology services. Since 1990, Harbinger has developed a strong customer base worldwide. Its customers include software product companies ranging from hi-tech start-ups in Silicon Valley to leading product companies in the US and large in-house IT organizations.
“Distrix fits into the overall cloud and IoT model around software-defined networking. There’s a broad category around software-defined networking that’s focused on data center, and we focus on the WAN,” explained Jay Friedman, President of Distrix, in this SYS-CON.tv interview at the Internet of @ThingsExpo, held June 10-12, 2014, at the Javits Center in New York City. Internet of @ThingsExpo 2014 Silicon Valley, November 4–6, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading IoT industry players in the world.
“Dell Cloud Manager is a cloud management environment for the consumption of cloud resources and we provide a consistent interface, both in terms of API and in terms of user interface for doing a wide variety of activities core to deploying and operating software in cloud," explained James Urquhart, Technologist & Director of Cloud Management Solutions at Dell, in this SYS-CON.tv interview at the 14th International Cloud Expo®, held June 10-12, 2014, at the Javits Center in New York City. Cloud Expo® 2014 Silicon Valley, November 4–6, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading Cloud industry players in the world.
SYS-CON Events announced today that the Cloud Standards Customer Council (CSCC ) has been named “Media Sponsor” of SYS-CON's 15th International Cloud Expo®, which will take place on November 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA. The Cloud Standards Customer Council is an end user advocacy group dedicated to accelerating cloud's successful adoption, and drilling down into the standards, security and interoperability issues surrounding the transition to the cloud. The Council will provide cloud users with the opportunity to drive client requirements into standards development organizations and deliver materials such as best practices and use cases to assist other enterprises.
“Ambernet Technologies is an innovative software company and we’ve been very focused on building enterprise grade cloud management and cloud brokerage software," explained Troy Halford, CSO of Ambernet Technologies, in this SYS-CON.tv interview at the 14th International Cloud Expo®, held June 10-12, 2014, at the Javits Center in New York City. Cloud Expo® 2014 Silicon Valley, November 4–6, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading Cloud industry players in the world.
“We introduced our product called AgilData. It’s basically the first Agile view, a streaming view of looking at a database and data as a streaming real-time dynamic capability," explained Cory Isaacson, CEO/CTO of CodeFutures Corporation, in this SYS-CON.tv interview at the 14th International Cloud Expo®, held June 10-12, 2014, at the Javits Center in New York City. Cloud Expo® 2014 Silicon Valley, November 4–6, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading Cloud industry players in the world.
“As the move to the cloud started, we stayed ahead of that by providing security solutions to our enterprise customers, financial customers, and now a whole new range of customers, which are application developers," explained John Gunn, VP of Corporate Communications for VASCO Data Security, in this SYS-CON.tv interview at the 14th International Cloud Expo®, held June 10-12, 2014, at the Javits Center in New York City. Cloud Expo® 2014 Silicon Valley, November 4–6, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading Cloud industry players in the world.
The industry is heated with debates on whether adopting private or public cloud is the smartest, best, cheapest, you name it choice. But this debate is missing the mark. Businesses shouldn’t be discussing public vs. private, but rather how can they make the two work together to their greatest advantage. The ideal is to merge on-premise and off-premise into a seamless environment that can be managed as a single entity – a forward-looking stance that will eventually see major adoption. But as of late 2013, hybrid cloud was still “rare,” noted Gartner analyst Tom Bittman. In his session at 15th Cloud Expo, Marten Mickos, CEO of Eucalyptus Systems, will discuss how public clouds need on-premise satellites to win and, conversely, how on-premise environments cannot be really powerful unless they are connected to the public cloud. It’s not two competing worlds; it’s two dimensions of the same world.
SYS-CON Events announced today that the Wall Street Technology Association (WSTA) has been named "Association Sponsor" of SYS-CON's 15th International Cloud Expo®, which will take place on November 4-6, 2014, at the Santa Clara Convention Center in Santa Clara, CA. The Wall Street Technology Association (WSTA®) provides financial industry technology professionals, vendors, service providers, and consultants with forums to learn from and connect with each other. The WSTA facilitates seminars and networking events where members meet and exchange ideas and best practices that assist them in effectively capitalizing on technology advances and dealing with financial industry business challenges. Founded in 1967, the WSTA is a not-for-profit association with a long history of evolving to meet the needs of its members.