SlideShare a Scribd company logo
© 2013 Cloud Technology Partners, Inc. / Confidential
1
David.Linthicum@cloudtp.com / Senior Vice President
Becoming a Cloud Governance Ninja
© 2013 Cloud Technology Partners, Inc. / Confidential
2
Geek Level
Your Grandparents who
are still using AOL
That guy who can convert
your name to Hex
© 2013 Cloud Technology Partners, Inc. / Confidential
3
The business benefit of cloud governance is clear.
Introduction
Combine the value of governance with the value of leveraging cloud computing in general and the core
benefits of cloud governance become even more tangible:
• Faster time to market
• Operational cost savings
• Ability to expand elastically
• Ability to better secure and control your business assets
As we move from simple, single cloud solutions, to complex multicloud implementations, the need for
governance becomes much more apparent. We’ll explore:
• What is the real value of cloud governance?
• The rise of multicloud and the use of governance
• Best practices and top emerging technologies
• Step-by-step governance process to ensure a successful deployment
© 2013 Cloud Technology Partners, Inc. / Confidential
4
What is Multicloud?
© 2013 Cloud Technology Partners, Inc. / Confidential
5
The Promise of Multicloud
On site
Hosted
Public
Source: HP
© 2013 Cloud Technology Partners, Inc. / Confidential
6
Cloud Maturity Model
Orchestrate
Automate
Virtualize
Combine
Standardize
Time
• Lower cost
• Consistent use of technology
• Enhanced performance
• Reduced complexity
• Normalize assets
• Increase efficiency
• Improve management
• Improve governance (non-automated)
• Lower cost
• Delayed provisioning
• Improved resource management and utilization
• Moving to centralized control
• Initial use of services
• Lower cost
• Self provisioning
• Automated governance
• Adaptable security
• Improved user experience
• Service oriented
• Dynamically aligned to
the business
• Self adapting
• Automated governance
and security
• Enhanced business agility
Cloud Innovator
Cloud User
Preparing for Cloud
BusinessValue
© 2013 Cloud Technology Partners, Inc. / Confidential
7
Characteristics of a “World Class” Cloud
Consumers Want
Elasticity & Scalability
Control
Productivity
Agility
Cost
• Flexible resource configurations
• Dynamic scale-up / scale-down of resources
• Seamless support of multiple clouds
• Flexible resource quotas
• Role based access controls
• Comprehensive monitoring and logging
• Image Lifecycle Management
• Integration into Incident, Change, Patching Management
• Common Self – Service Provisioning Portal into all cloud end points
• Robust Service Catalog meets all of customer cloud needs
• End to End Automation
• Supported APIs allowing the applications and data sources to communicate with one another
• Self – Service Resource Provisioning
• Rapid Elasticity
• Capacity on Demand insures resources are always available
• Rapid disaster recovery – Active / Active application support
• Seamless support for different endpoints
• Metering and Chargeback
• Pay as you go
• Consumption based
• Reliable asset tracking and usage reporting
Providers Deliver
© 2013 Cloud Technology Partners, Inc. / Confidential
8
• So, what is a multicloud? Think something more complex than a hybrid
cloud, which is typically a paired private and public cloud. Multicloud is
more clouds added into the mix, perhaps two or more public IaaS
providers, a private PaaS, on-demand management and security systems
from public clouds, private use-based accounting…you get the idea.
• This is really where we have all been headed in the last few years, creating
solutions from a complex set of best-of-breed private and public cloud
computing services. This is much the same process as when we moved to
complex distributed internal systems in the past. We built what we
needed by integrating various technologies to form the business system to
meet our exact requirements. This is no different; it just uses cloud-based
technologies.
Multicloud
© 2013 Cloud Technology Partners, Inc. / Confidential
9
Why cloud governance?
© 2013 Cloud Technology Partners, Inc. / Confidential
10
The Idea is to Place Control and Automation Into a Domain
© 2013 Cloud Technology Partners, Inc. / Confidential
11
Security&Identity
Management&ServiceGovernance
Data
Data Services/Abstraction
Transactional Services
Process Management
(BPMS)
Composites/Portals
Monitoring and Management
Rules Management
Reference Architecture
© 2013 Cloud Technology Partners, Inc. / Confidential
12
1. Governance
2. Regulatory Compliance
3. Security & Identity Management
4. Business Continuity
5. Process and Services
6. Data Management
7. System Integration
8. Resource Skills & Knowledge
9. Application Readiness
10. Network Readiness
Enterprise Vulnerabilities - Assess your Risks
COMPLEXITY OF MITIGATING RISK
RISKTOORGANIZATION
1
2
5
3
4
6
7
8
9
10
© 2013 Cloud Technology Partners, Inc. / Confidential
13
“as-is”
© 2013 Cloud Technology Partners, Inc. / Confidential
14
“to be”
© 2013 Cloud Technology Partners, Inc. / Confidential
15
Deploy
© 2013 Cloud Technology Partners, Inc. / Confidential
16
Enterprise
data center
Enterprise
data center
Private cloud Hosted private
cloud
Managed
private cloud
Enterprise
Shared cloud
services
Enterprise
A
Enterprise
B
Public cloud
services
A
Users
B
Third-party hosted
and operated
Third-party
hosted
 Private
 Implemented
on client
premises
 Client runs/
manages
 Third-party
operated
 Enterprise
owned
 Mission critical
 Packaged
applications
 Third-party
owned and
operated
 Standardization
 Centralization
 Security
 Internal network
 Mix of shared and
dedicated
resources
 Shared facility
and staff
 Virtual private
network (VPN)
access
 Subscription or
membership
based
 Shared resources
 Elastic scaling
 Pay as you go
 Public Internet
Corporate
Firewall
Source: Jimmy Mills, IBM
Consider the Emerging Architecture – and this could be for multiple
cloud providers
© 2013 Cloud Technology Partners, Inc. / Confidential
17
Cloud Governance Solutions
© 2013 Cloud Technology Partners, Inc. / Confidential
18
The Basic Idea
© 2013 Cloud Technology Partners, Inc. / Confidential
19
Cloud Governance Technology
Cloud Service/API
Governance
Runtime (Automated)
Service
Oriented
Security
Oriented
Design-
Time
Cloud Management
Platforms
Active (Automated)
Operations
Oriented
Development
Oriented
Passive
Provider Native Governance
and Management
Active
Provisioning Security Management
Passive
Types of Cloud Governance Solutions
© 2013 Cloud Technology Partners, Inc. / Confidential
20
Cloud Governance is the Center of it All
Methodology
KPI &
Monitoring
Lifecycle Process Certification
QoS
Standards Technology
Portfolios Incentives
Rules &
Resp.
People Competency
Organization
Tools
Cloud
Governance
© 2013 Cloud Technology Partners, Inc. / Confidential
21
A CMP enables Enterprises to manage many clouds as one
my network
my serversmy storage
Public Clouds Public/Private Clouds
CONFIGURATION AUTOMATION GOVERNANCE GLOBAL SERVICES
Internal DC
my serversmy storage
BARE METAL
Cloud Management Platform
IT ORGANIZATION
© 2013 Cloud Technology Partners, Inc. / Confidential
22
A Cloud Management Platforms (CMP) is an integrated suite of tools that provides
automated management of public and private cloud environments. CMPs facilitate the
operation and build out of cloud services by eliminating the need for cloud silo specific
interfaces and end user knowledge of cloud underpinnings.
• CMPs provide capabilities including:
– Self-service interfaces for
• Operations
• Monitoring
• End User requests
– Image provisioning
– Metering and billing
– Workload optimization via
• Policies
• Workflow
• Roles Based Access Control (RBAC)
What is a Cloud Management Platform
© 2013 Cloud Technology Partners, Inc. / Confidential
23
Runtime
Governance
Repository Logs
Policies
Policies
Monitoring
Service Governance is Policy-Driven
© 2013 Cloud Technology Partners, Inc. / Confidential
24
Create a Governance Model
Defined
Policies
Define Policies
Design Policies
Policy
Designs
Implement Policies
Governance
Model
Process
Model
Information
Model
Service
Model
© 2013 Cloud Technology Partners, Inc. / Confidential
25
Gartner’s Cloud Management Platform Reference Architecture
Access Management
Service Management
Service Optimization
Resource Management
Resources
Cloud API
CloudManagement
Platform
Cloud
Implementation
• Self-service interface
• Identity management
• Service catalog
• Service provisioning
• Service governor
• Service orchestration
• Resource configuration management
• Resource monitoring
• Resource pools
• Virtual and physical resources
Source: Gartner, “How to Build an Enterprise Cloud Service Architecture,” March 5, 2012
© 2013 Cloud Technology Partners, Inc. / Confidential
26
• This problem has not gone unnoticed
• All of the major software companies have offered solutions
• New vendors have entered the market, most of them from the pure cloud perspective
• Vendors typically have an application or Infrastructure focus and have expanded from
point solutions
Vendors Rush in
© 2013 Cloud Technology Partners, Inc. / Confidential
27
Policy
Policy
Policy
Policy
Governance/Security
Single consolidated control point for governance, orchestration,
and delivery
Applications
 Regulatory compliance policies
 SLA policies including autoscaling
 Configuration mgmt policies
 Security zones policies
 Lifecycle event policies
 Orchestration policies
 Access control/entitlement policies
 Workload placement policies
 VM quotas and scheduling
 Metering/charge back policies
 Backup and failover policies
 Resource capacity policies
 Storage tier policies
 Much more…
Roles
Rights & Permissions
Projects Orgs
Network Compute Storage
OS & OS Config.
SOE Agents/Util
Security and
Environment Config.
Code/Artifacts
Infrastructure & SOE
Platforms
Services
Topologies/Config
App Config.
Application Components
Cloud Management
Platform
© 2013 Cloud Technology Partners, Inc. / Confidential
28
a
A Cloud Management Platform provides automation and governance
across the application development lifecycle
Use policies to provide
both consistency and
customization:
Customize Environment
 Dev Security zone
 Dev VM quotas
 Dev charge back
 Public cloud permitted
 No autoscaling
 No failover
Customize Environment
 QA Security zone
 QA monitoring
 QA autoscaling
 Private cloud only
 QA backup/failover
Customize Environment
 Prod Security zone
 Prod monitoring
 Prod auditing
 Prod autoscaling
 Private cloud only
 Prod backup/failover
…And Enforce Consistency
 SOE packages
 App topologies
 Reg. compliance
Policy Controlled
Consistency
Policy Controlled
Customization
Dev
Blueprint
QA
Blueprint
UAT
Blueprint
…And Enforce Consistency
 SOE packages
 App topologies
 Reg. compliance
…And Enforce Consistency
 SOE packages
 App topologies
 Reg. compliance
© 2013 Cloud Technology Partners, Inc. / Confidential
29
Ask by email / David.Linthicum@cloudtp.com / www.cloudtp.com
Questions?

More Related Content

PDF
Enterprise Cloud Governance: A Frictionless Approach
PPTX
Geting cloud architecture right the first time linthicum interop fall 2013
PPTX
Calculating the true value of industry specific clouds linthicum
PDF
AgilePath's Live Webinar: Exploring the Cloud Governance Lifecycle Dec 16 2010
PPTX
Linthicum state of-the-art-cloud-platforms
PPTX
Accelerating government agility with cloud computing v1
PPTX
Governing in the Cloud
PDF
Jazoon'12 Enterprise-wide Cloud Governance
Enterprise Cloud Governance: A Frictionless Approach
Geting cloud architecture right the first time linthicum interop fall 2013
Calculating the true value of industry specific clouds linthicum
AgilePath's Live Webinar: Exploring the Cloud Governance Lifecycle Dec 16 2010
Linthicum state of-the-art-cloud-platforms
Accelerating government agility with cloud computing v1
Governing in the Cloud
Jazoon'12 Enterprise-wide Cloud Governance

What's hot (20)

PPTX
Linthicum next generation-iaa s-paas-and-database-as-a-service
PDF
Integrated Cloud Framework: Security, Governance, Compliance, Content Applica...
PDF
Cloud security design considerations
PPTX
Azure cloud governance deck
PDF
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
PPTX
Hybrid IT, Laying the "Right Mix" Foundation for Digital Transformation
PDF
Multi cloud migration decision framework
PPTX
Cloud Governance Presentation Dreamforce 2012
PPTX
Cloud Computing Design Considerations
PDF
Gartner report on cloud360 cloud management platform
PPTX
Cloud computing and migration strategies to cloud
PPTX
Cloud Migration Strategy Framework
PDF
Cloud Adoption - Journey of IT Service Management
PDF
Presentation cloud management platform
PPTX
8.cloud migration
PDF
Cloud governance - theory and tools
PDF
The Path to Broker Cloud Services
PDF
Hyper Stratus Migrating Applications to the Cloud
PPTX
Cloud migration
PDF
Multi-Cloud Strategy for Unrestricted Possibilities
Linthicum next generation-iaa s-paas-and-database-as-a-service
Integrated Cloud Framework: Security, Governance, Compliance, Content Applica...
Cloud security design considerations
Azure cloud governance deck
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Hybrid IT, Laying the "Right Mix" Foundation for Digital Transformation
Multi cloud migration decision framework
Cloud Governance Presentation Dreamforce 2012
Cloud Computing Design Considerations
Gartner report on cloud360 cloud management platform
Cloud computing and migration strategies to cloud
Cloud Migration Strategy Framework
Cloud Adoption - Journey of IT Service Management
Presentation cloud management platform
8.cloud migration
Cloud governance - theory and tools
The Path to Broker Cloud Services
Hyper Stratus Migrating Applications to the Cloud
Cloud migration
Multi-Cloud Strategy for Unrestricted Possibilities
Ad

Viewers also liked (18)

PPTX
Security and governance in the cloud
PDF
Accountability for Data Governance in the Cloud
PPTX
Mashing Up DevOps with Cloud Computing
PPTX
"What does 'Full Life-Cycle' Data Management Mean ?"
PDF
DJA PRESENTATION
PPT
Process view framework for artifact centric business processes
PPTX
Capacity Management in a Cloud Computing World
PDF
Intel IT Open Cloud - What's under the Hood and How do we Drive it?
PDF
Edelman 11on11
PDF
Authentic Leadership
PDF
The Foreign Investment Regulation Review, 3rd edition
PDF
Display_OneSheet
PDF
Companies. - Free Online Library
PPTX
Human Development Report 2013 and Ukraine Presentation [ENG]
PDF
FINAL 15-RUMC-3020-Annual-Report-Final_web
PDF
BSHS LMC 2009 2010 Annual Report
PDF
Cloud Computing and Data Governance
PPT
Sustainable and organic F&B
Security and governance in the cloud
Accountability for Data Governance in the Cloud
Mashing Up DevOps with Cloud Computing
"What does 'Full Life-Cycle' Data Management Mean ?"
DJA PRESENTATION
Process view framework for artifact centric business processes
Capacity Management in a Cloud Computing World
Intel IT Open Cloud - What's under the Hood and How do we Drive it?
Edelman 11on11
Authentic Leadership
The Foreign Investment Regulation Review, 3rd edition
Display_OneSheet
Companies. - Free Online Library
Human Development Report 2013 and Ukraine Presentation [ENG]
FINAL 15-RUMC-3020-Annual-Report-Final_web
BSHS LMC 2009 2010 Annual Report
Cloud Computing and Data Governance
Sustainable and organic F&B
Ad

Similar to Becomming a cloud governance ninja linthicum interop fall 2013 (20)

PPTX
Practical Guide to Cloud Management Platforms
PDF
Value of Enterprise DevOps
PDF
May 2013 Federal Cloud Computing Summit Keynote by David Cearly
PPTX
Choosing the Right Clouds for your Business
PDF
Cloud Customer Architecture for Securing Workloads on Cloud Services
PDF
Lessons Learned from Building a CSB Part III
PPTX
Enterprise Cloud Management - 2013 EMC World presentation
PDF
An Executive View on Cloud Service Brokers - Cloud Solutions in a CSB Model C...
PDF
Making Money in the Cloud
PDF
Conquering cloud chaos: Simplifying and centralizing multi-cloud integration ...
PDF
Building the Agile Enterprise - Cloud Computing
PDF
Practical Guide to Hybrid Cloud Computing
PDF
Moving to the Cloud-How to Develop Cloud Strategy for Your Organization
PDF
What Is Cloud Migration_ A Beginner’s Guide for Businesses in 2025.pdf
PDF
Cloud Perspectives - Ottawa Seminar - Oct 6
PDF
Govern Your Cloud: The Foundation for Success
PDF
Virtualization and cloud impact overview auditor spin enterprise gr-cv3
PPTX
Understanding Cloud Computing & How Global Trade Management Solutions Work in...
PDF
Smart Integration to the Cloud - Kellton Tech Webinar
PPT
Private cloud in the hybrid era
Practical Guide to Cloud Management Platforms
Value of Enterprise DevOps
May 2013 Federal Cloud Computing Summit Keynote by David Cearly
Choosing the Right Clouds for your Business
Cloud Customer Architecture for Securing Workloads on Cloud Services
Lessons Learned from Building a CSB Part III
Enterprise Cloud Management - 2013 EMC World presentation
An Executive View on Cloud Service Brokers - Cloud Solutions in a CSB Model C...
Making Money in the Cloud
Conquering cloud chaos: Simplifying and centralizing multi-cloud integration ...
Building the Agile Enterprise - Cloud Computing
Practical Guide to Hybrid Cloud Computing
Moving to the Cloud-How to Develop Cloud Strategy for Your Organization
What Is Cloud Migration_ A Beginner’s Guide for Businesses in 2025.pdf
Cloud Perspectives - Ottawa Seminar - Oct 6
Govern Your Cloud: The Foundation for Success
Virtualization and cloud impact overview auditor spin enterprise gr-cv3
Understanding Cloud Computing & How Global Trade Management Solutions Work in...
Smart Integration to the Cloud - Kellton Tech Webinar
Private cloud in the hybrid era

More from David Linthicum (20)

PPTX
Linthicum what is-the-true-future-of-cloud-computing
PPT
Why Cloud Computing Projects Fail
PPT
Getting Cloud Architecture Right the First Time Ver 2
PPTX
Getting an open systems cloud strategy right the first time linthicm
PPTX
Redefining cloud computing again linthicum with bonus
PPTX
Hybrid and Private Cloud Architectures
PPTX
How to get cloud architecture and design right the first time 2012
PPTX
New integration approach in a cloud computing world
PPTX
Future of cloud computing linthicum 2
PPT
How to Get Cloud Architecture and Design Right the First Time
PPTX
Future of cloud computing linthicum
PPT
False Cloud Debate Panel Interop 2011
PPT
Getting the hybrid cloud right the first time
PDF
Cloud Computing and DR Keynote DRJ Conf
PPT
Finding the true value of cloud computing
PPT
Moving to cloud computing step by step linthicum
PPT
Cloud Computing Impact On Small Business
PDF
Why Soa Governance Is Critical To Cloud Computing David Linthicum 022510
PDF
Cloud Computing And Soa Convergence Linthicum 02 09 10
PDF
Defining The Value Of Integration
Linthicum what is-the-true-future-of-cloud-computing
Why Cloud Computing Projects Fail
Getting Cloud Architecture Right the First Time Ver 2
Getting an open systems cloud strategy right the first time linthicm
Redefining cloud computing again linthicum with bonus
Hybrid and Private Cloud Architectures
How to get cloud architecture and design right the first time 2012
New integration approach in a cloud computing world
Future of cloud computing linthicum 2
How to Get Cloud Architecture and Design Right the First Time
Future of cloud computing linthicum
False Cloud Debate Panel Interop 2011
Getting the hybrid cloud right the first time
Cloud Computing and DR Keynote DRJ Conf
Finding the true value of cloud computing
Moving to cloud computing step by step linthicum
Cloud Computing Impact On Small Business
Why Soa Governance Is Critical To Cloud Computing David Linthicum 022510
Cloud Computing And Soa Convergence Linthicum 02 09 10
Defining The Value Of Integration

Recently uploaded (20)

PDF
GamePlan Trading System Review: Professional Trader's Honest Take
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
HCSP-Presales-Campus Network Planning and Design V1.0 Training Material-Witho...
PDF
madgavkar20181017ppt McKinsey Presentation.pdf
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
Comunidade Salesforce São Paulo - Desmistificando o Omnistudio (Vlocity)
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PPT
Teaching material agriculture food technology
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Empathic Computing: Creating Shared Understanding
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
Telecom Fraud Prevention Guide | Hyperlink InfoSystem
PDF
Sensors and Actuators in IoT Systems using pdf
PPTX
MYSQL Presentation for SQL database connectivity
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Electronic commerce courselecture one. Pdf
GamePlan Trading System Review: Professional Trader's Honest Take
Diabetes mellitus diagnosis method based random forest with bat algorithm
HCSP-Presales-Campus Network Planning and Design V1.0 Training Material-Witho...
madgavkar20181017ppt McKinsey Presentation.pdf
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Advanced methodologies resolving dimensionality complications for autism neur...
Comunidade Salesforce São Paulo - Desmistificando o Omnistudio (Vlocity)
Reach Out and Touch Someone: Haptics and Empathic Computing
Teaching material agriculture food technology
“AI and Expert System Decision Support & Business Intelligence Systems”
Empathic Computing: Creating Shared Understanding
CIFDAQ's Market Insight: SEC Turns Pro Crypto
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Telecom Fraud Prevention Guide | Hyperlink InfoSystem
Sensors and Actuators in IoT Systems using pdf
MYSQL Presentation for SQL database connectivity
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
NewMind AI Monthly Chronicles - July 2025
Electronic commerce courselecture one. Pdf

Becomming a cloud governance ninja linthicum interop fall 2013

  • 1. © 2013 Cloud Technology Partners, Inc. / Confidential 1 [email protected] / Senior Vice President Becoming a Cloud Governance Ninja
  • 2. © 2013 Cloud Technology Partners, Inc. / Confidential 2 Geek Level Your Grandparents who are still using AOL That guy who can convert your name to Hex
  • 3. © 2013 Cloud Technology Partners, Inc. / Confidential 3 The business benefit of cloud governance is clear. Introduction Combine the value of governance with the value of leveraging cloud computing in general and the core benefits of cloud governance become even more tangible: • Faster time to market • Operational cost savings • Ability to expand elastically • Ability to better secure and control your business assets As we move from simple, single cloud solutions, to complex multicloud implementations, the need for governance becomes much more apparent. We’ll explore: • What is the real value of cloud governance? • The rise of multicloud and the use of governance • Best practices and top emerging technologies • Step-by-step governance process to ensure a successful deployment
  • 4. © 2013 Cloud Technology Partners, Inc. / Confidential 4 What is Multicloud?
  • 5. © 2013 Cloud Technology Partners, Inc. / Confidential 5 The Promise of Multicloud On site Hosted Public Source: HP
  • 6. © 2013 Cloud Technology Partners, Inc. / Confidential 6 Cloud Maturity Model Orchestrate Automate Virtualize Combine Standardize Time • Lower cost • Consistent use of technology • Enhanced performance • Reduced complexity • Normalize assets • Increase efficiency • Improve management • Improve governance (non-automated) • Lower cost • Delayed provisioning • Improved resource management and utilization • Moving to centralized control • Initial use of services • Lower cost • Self provisioning • Automated governance • Adaptable security • Improved user experience • Service oriented • Dynamically aligned to the business • Self adapting • Automated governance and security • Enhanced business agility Cloud Innovator Cloud User Preparing for Cloud BusinessValue
  • 7. © 2013 Cloud Technology Partners, Inc. / Confidential 7 Characteristics of a “World Class” Cloud Consumers Want Elasticity & Scalability Control Productivity Agility Cost • Flexible resource configurations • Dynamic scale-up / scale-down of resources • Seamless support of multiple clouds • Flexible resource quotas • Role based access controls • Comprehensive monitoring and logging • Image Lifecycle Management • Integration into Incident, Change, Patching Management • Common Self – Service Provisioning Portal into all cloud end points • Robust Service Catalog meets all of customer cloud needs • End to End Automation • Supported APIs allowing the applications and data sources to communicate with one another • Self – Service Resource Provisioning • Rapid Elasticity • Capacity on Demand insures resources are always available • Rapid disaster recovery – Active / Active application support • Seamless support for different endpoints • Metering and Chargeback • Pay as you go • Consumption based • Reliable asset tracking and usage reporting Providers Deliver
  • 8. © 2013 Cloud Technology Partners, Inc. / Confidential 8 • So, what is a multicloud? Think something more complex than a hybrid cloud, which is typically a paired private and public cloud. Multicloud is more clouds added into the mix, perhaps two or more public IaaS providers, a private PaaS, on-demand management and security systems from public clouds, private use-based accounting…you get the idea. • This is really where we have all been headed in the last few years, creating solutions from a complex set of best-of-breed private and public cloud computing services. This is much the same process as when we moved to complex distributed internal systems in the past. We built what we needed by integrating various technologies to form the business system to meet our exact requirements. This is no different; it just uses cloud-based technologies. Multicloud
  • 9. © 2013 Cloud Technology Partners, Inc. / Confidential 9 Why cloud governance?
  • 10. © 2013 Cloud Technology Partners, Inc. / Confidential 10 The Idea is to Place Control and Automation Into a Domain
  • 11. © 2013 Cloud Technology Partners, Inc. / Confidential 11 Security&Identity Management&ServiceGovernance Data Data Services/Abstraction Transactional Services Process Management (BPMS) Composites/Portals Monitoring and Management Rules Management Reference Architecture
  • 12. © 2013 Cloud Technology Partners, Inc. / Confidential 12 1. Governance 2. Regulatory Compliance 3. Security & Identity Management 4. Business Continuity 5. Process and Services 6. Data Management 7. System Integration 8. Resource Skills & Knowledge 9. Application Readiness 10. Network Readiness Enterprise Vulnerabilities - Assess your Risks COMPLEXITY OF MITIGATING RISK RISKTOORGANIZATION 1 2 5 3 4 6 7 8 9 10
  • 13. © 2013 Cloud Technology Partners, Inc. / Confidential 13 “as-is”
  • 14. © 2013 Cloud Technology Partners, Inc. / Confidential 14 “to be”
  • 15. © 2013 Cloud Technology Partners, Inc. / Confidential 15 Deploy
  • 16. © 2013 Cloud Technology Partners, Inc. / Confidential 16 Enterprise data center Enterprise data center Private cloud Hosted private cloud Managed private cloud Enterprise Shared cloud services Enterprise A Enterprise B Public cloud services A Users B Third-party hosted and operated Third-party hosted  Private  Implemented on client premises  Client runs/ manages  Third-party operated  Enterprise owned  Mission critical  Packaged applications  Third-party owned and operated  Standardization  Centralization  Security  Internal network  Mix of shared and dedicated resources  Shared facility and staff  Virtual private network (VPN) access  Subscription or membership based  Shared resources  Elastic scaling  Pay as you go  Public Internet Corporate Firewall Source: Jimmy Mills, IBM Consider the Emerging Architecture – and this could be for multiple cloud providers
  • 17. © 2013 Cloud Technology Partners, Inc. / Confidential 17 Cloud Governance Solutions
  • 18. © 2013 Cloud Technology Partners, Inc. / Confidential 18 The Basic Idea
  • 19. © 2013 Cloud Technology Partners, Inc. / Confidential 19 Cloud Governance Technology Cloud Service/API Governance Runtime (Automated) Service Oriented Security Oriented Design- Time Cloud Management Platforms Active (Automated) Operations Oriented Development Oriented Passive Provider Native Governance and Management Active Provisioning Security Management Passive Types of Cloud Governance Solutions
  • 20. © 2013 Cloud Technology Partners, Inc. / Confidential 20 Cloud Governance is the Center of it All Methodology KPI & Monitoring Lifecycle Process Certification QoS Standards Technology Portfolios Incentives Rules & Resp. People Competency Organization Tools Cloud Governance
  • 21. © 2013 Cloud Technology Partners, Inc. / Confidential 21 A CMP enables Enterprises to manage many clouds as one my network my serversmy storage Public Clouds Public/Private Clouds CONFIGURATION AUTOMATION GOVERNANCE GLOBAL SERVICES Internal DC my serversmy storage BARE METAL Cloud Management Platform IT ORGANIZATION
  • 22. © 2013 Cloud Technology Partners, Inc. / Confidential 22 A Cloud Management Platforms (CMP) is an integrated suite of tools that provides automated management of public and private cloud environments. CMPs facilitate the operation and build out of cloud services by eliminating the need for cloud silo specific interfaces and end user knowledge of cloud underpinnings. • CMPs provide capabilities including: – Self-service interfaces for • Operations • Monitoring • End User requests – Image provisioning – Metering and billing – Workload optimization via • Policies • Workflow • Roles Based Access Control (RBAC) What is a Cloud Management Platform
  • 23. © 2013 Cloud Technology Partners, Inc. / Confidential 23 Runtime Governance Repository Logs Policies Policies Monitoring Service Governance is Policy-Driven
  • 24. © 2013 Cloud Technology Partners, Inc. / Confidential 24 Create a Governance Model Defined Policies Define Policies Design Policies Policy Designs Implement Policies Governance Model Process Model Information Model Service Model
  • 25. © 2013 Cloud Technology Partners, Inc. / Confidential 25 Gartner’s Cloud Management Platform Reference Architecture Access Management Service Management Service Optimization Resource Management Resources Cloud API CloudManagement Platform Cloud Implementation • Self-service interface • Identity management • Service catalog • Service provisioning • Service governor • Service orchestration • Resource configuration management • Resource monitoring • Resource pools • Virtual and physical resources Source: Gartner, “How to Build an Enterprise Cloud Service Architecture,” March 5, 2012
  • 26. © 2013 Cloud Technology Partners, Inc. / Confidential 26 • This problem has not gone unnoticed • All of the major software companies have offered solutions • New vendors have entered the market, most of them from the pure cloud perspective • Vendors typically have an application or Infrastructure focus and have expanded from point solutions Vendors Rush in
  • 27. © 2013 Cloud Technology Partners, Inc. / Confidential 27 Policy Policy Policy Policy Governance/Security Single consolidated control point for governance, orchestration, and delivery Applications  Regulatory compliance policies  SLA policies including autoscaling  Configuration mgmt policies  Security zones policies  Lifecycle event policies  Orchestration policies  Access control/entitlement policies  Workload placement policies  VM quotas and scheduling  Metering/charge back policies  Backup and failover policies  Resource capacity policies  Storage tier policies  Much more… Roles Rights & Permissions Projects Orgs Network Compute Storage OS & OS Config. SOE Agents/Util Security and Environment Config. Code/Artifacts Infrastructure & SOE Platforms Services Topologies/Config App Config. Application Components Cloud Management Platform
  • 28. © 2013 Cloud Technology Partners, Inc. / Confidential 28 a A Cloud Management Platform provides automation and governance across the application development lifecycle Use policies to provide both consistency and customization: Customize Environment  Dev Security zone  Dev VM quotas  Dev charge back  Public cloud permitted  No autoscaling  No failover Customize Environment  QA Security zone  QA monitoring  QA autoscaling  Private cloud only  QA backup/failover Customize Environment  Prod Security zone  Prod monitoring  Prod auditing  Prod autoscaling  Private cloud only  Prod backup/failover …And Enforce Consistency  SOE packages  App topologies  Reg. compliance Policy Controlled Consistency Policy Controlled Customization Dev Blueprint QA Blueprint UAT Blueprint …And Enforce Consistency  SOE packages  App topologies  Reg. compliance …And Enforce Consistency  SOE packages  App topologies  Reg. compliance
  • 29. © 2013 Cloud Technology Partners, Inc. / Confidential 29 Ask by email / [email protected] / www.cloudtp.com Questions?

Editor's Notes

  • #23: Cloud Management Platform is a product or integration of products used to manage the use of private, public, and multi-cloud (combination of private and public cloud consumption). The cloud management platform simplifies the use of the cloud(s) by allowing self-service provisioning of resources, capturing billing and metering data, managing resource quotas, image lifecycle management, and providing resource optimization. There is typically many dynamics that are factored into determining which cloud environments an application will reside. Examples of these factors include workload type (DEV, TEST, QA, Pre-Prod, Prod), sensitivity of the data in the application, and the need for elasticity of the application resources. Based on the defined factors, the cloud management platform provides automated management of the underlying compute environment of the applications to the appropriate cloud end-points and simplifies overall operability. Without a cloud management platform, the operability of the cloud will be cumbersome, labor intensive, and prone to errors.
  • #26: NOTES: As mentioned earlier, we use the Gartner category description of “Cloud Management Platform” for convenience… We actually think there’s room for Gartner to improve this…but it’s a good way to look at it from a high level.  Generally speaking, you can divide the capabilities defined by Gartner into two categories – those oriented toward implementing clouds and those oriented toward providing functionality across numerous clouds. Gartner basically describes four different levels. Starting from the bottom.. up…Resource level is at the bottom. Which includes your cloud infrastructure. Your servers, disks, hypervisors, storage area networks, etc. Next you’ve got Resource Mgmt. This where you start to introduce basic management capabilities to do things like resource assignments, and basic infrastructure monitoring.An example of resource mgmt could be vCenterNext you’ve got a Service Optimization layer that performs the orchestration of various workloads and topologies that you deploy, and enforces governance on those deployments using various policies. On top of that you’ve go the Service Management layer. Here you start abstracting underlying capabilities… and rolling them up and exposing them in different tools…like:A service catalog, to publish and consume different offeringsA designer tool, to assemble workloads and topologies and configure them for deploymentThe highest layer, Access Management, includes identity management… to determine if someone should have access and subscriber management, to determine what actions they’re permitted to do
  • #27: This problem has not gone unnoticed. All of the major software companies have offered solutions, most of them with a traditional service management foundation. New vendors have entered the market, most of them from the pure cloud perspective. They have either an application or Infrastructure focus. Many started with a specific (usually public) platform or from a specific set of use cases, e.g. monitoring, deployment.
  • #28: NOTES: The focus on applications and platforms is important… but those apps and platforms don’t do you much good unless you’ve also got effective governance in place…. otherwise you can’t deliver them with any meaningful self-service automation. So the way you do Could Governance and policy matters… Whatyou need is to take an application-centric approach with an extensible policy engine on the back end… When we’re talking about cloud governance in the Cloud Management Platform, we’re talking about much more than just Role-based Access Control. Or simple provisioning constraints.  Out of the box with the Cloud Management Platform, we provide over a dozen different types of application-centric policy controls. Everything from…Regulatory compliance policiesSLA policies including compound auto-scaling rules.Configuration management policies for continuous compliance of workloads after they’ve been deployed. Detailed Security zone policies including configuring firewall rules and embedding security agents and utilities. Lifecycle event policies to customize environments based on SDLC stage.Orchestration policies. Entitlement policies.Workload placement policies to limit workloads to authorized environments.Quotas, scheduling, leasing, chargeback, backup, failover, resource capacity policies.Storage tier policiesAnd much more….. And these policies apply up and down the application topology shown in the middle. So they absolutely apply to the infrastructure layer… for configuring network, for storage tiering… including storage provisioningBut also all the way up through configuration the application components, and the actually application itself The CMP insulates the cloud services consumers from needing to understand what needs to fit where and why? So the CMP represents this “control plane”…And the idea is to fully automate and govern IT resource consumption ….. and simplify the complexity of doing that across different types of clouds.
  • #29: NOTES:I mentioned the policy controls available in the Cloud Management Platform. Well, there is a lot of power and flexibility when you apply these to each stage of the SDLC.  For example:For the Dev team, You can have policies to allow EC2 usage for some projectsOr provide chargeback reports to managersFor QA, You can require that deployments only go to the internal private cloud (based on the live customer test data that’s used). You can enable autoscaling for performance testing purposes. For production, you can embed a completely different set of monitoring and security agents, and enforce different security zones, to give you a different security postureAnd yet… there are some things you may want to keep totally consistentLike the SOE… which enables certain services to be installed on all instances within a project.Or adhering to regulatory constraints … like geographic location or some other industry compliance mandate.  These policy controls provide you with a lot of flexibility and control, and allow you to set the right balance between customization and consistency for your environments.