Hybrid clouds the eventual reality for risk management

Cloudwashing hype confuses CIOs, disillusionment looms
Cloud computing "the most hyped subject in IT today". (Gartner Hype Cycle image used with permission)

Cloud computing "the most hyped subject in IT today". (Gartner Hype Cycle image used with permission)

The need to manage risk will result in organisations adopting hybrid clouds as the preferred cloud delivery model, according to Dean Kingsley, who heads the technology risk practice within the Enterprise Risk Services division at Deloitte in Sydney.

The public cloud delivery model, the idealised form of cloud computing, includes easy scalability to cater for business growth, elasticity to enable scaling down as easily as scaling up, and multi-tenancy to reduce costs.

"That's a very, very tough business model to pull off at enterprise scale across key applications," Kingsley told the ISACA Summit in Sydney yesterday, pointing to recent outages by Amazon and Microsoft.

According to Gartner's Hype Cycle for Cloud Computing 2011, the public cloud model has just passed the peak of inflated expectations, and will soon plunge into the trough of disillusionment. It'll be two to five years before organisations realise the benefits of the public cloud.

"Every organisation will have some things that they are happy to take the risk of the public cloud, and they want the cost savings of scale," Kingsley said. That might include some forms of hosted email, productivity applications and social networking.

However the public cloud generally won't be appropriate for enterprise applications.

"That's the realm of private clouds, but according to the Gartner Hype Cycle that's less mature," Kingsley said. "The eventual reality will be the hybrid cloud, the least mature of the delivery models."

Cloud security and risk standards are also very immature. According to Gartner it'll be five to ten years before their mainstream adoption.

"We're still some way off," Kingsley said. "I wholeheartedly agree with the statement from Gartner that the cloud would have to be the most hyped issue in IT today."

Kingsley says CIOs are confused by cloudwashing, which he defined as "people over-selling and over-hyping the benefits of the cloud, or misusing the word 'cloud' to describe anything in IT so you can sell it."

ISACA was previously the Information Systems Audit and Control Association, but now goes by its acronym only "to reflect the broad range of IT governance professionals it serves".

Contact Stilgherrian at Stil@stilgherrian.com or follow him on Twitter at @stilgherrian

Tags: cloud computing, Dean Kingsley, hybrid clouds, risk management

Comments

1

Gnanesh PS

Wed 26/10/2011 - 20:58

Good insight regarding cloud security and current cloud management strategies,Technology benefits , providing insight into cost savings and operational efficiencies of deploying services on cloud . @http://bit.ly/pY4d6k

2

Jfez

Tue 01/11/2011 - 01:35

People fear that the initial investment and their ongoing expenses will be difficult to be amortized in time and are wondering overall if the cloud investment is worth it. http://ow.ly/7e9HT The bottom line is that a well researched cloud investment is well worth the time spent. Reading the fine print will always be key.

3

jbishop

Sun 20/11/2011 - 01:03

We often overlook that cloud deployment models can also be done on-premise http://wp.me/p1RYyA-1F When organizations chose to implement an on-premise architecture the issues shift considerably including economics and security.

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CSO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
CSO Corporate Partners
  • FirEye
  • Clear Swift
  • Trend Micro
  • Sophos
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Splunk for Security

Use Splunk to search, alert and report in real time on any user, network, system or application activity, configuration changes, and other IT data from one place.

Security Awareness Tip
Clearswift tips: Guidelines for introducing and policing an effective IT Policy

1. Make it clear that the policy is not about playing ‘Big Brother’ but to ensure the security of employees, company information and data and to safeguard the company’s reputation.
2. Invest time to get buy-in from managers and their teams.
3. Convey the message of flexibility – with regard to social media, it is not about blocking staff usage but working in everyone’s interests to ensure that threats are contained.
4. Introduce a regular company-wide training programme that everyone attends at regular intervals throughout the year, not merely as part of an induction programme.
5. Within the training programme make sure that there are specific examples to demonstrate each rule or regulation, and that there is a clear explanation of the dangers of casual or careless talk on social networking sites. Again use examples, employees need to understand the consequences of raising a throwaway comment that has negative connotations for the business, as much as they need to be aware of dangers of making a more direct but ill-considered attack on a competitor, regulator or even a fellow colleague. They need to be clearly advised on any impact on the company and/or legal action or inquires that may be raised as a result.
6. Alert employees to any changes in policy through regular clear communication.
7. Reinforce the operational policy guidelines regularly, cover everything from blogging to Facebook, LinkedIn and Twitter.
8. Ensure that the rules are fair and that they apply throughout the business.
9. Enforce the rules – if there is a deliberate or malicious contravening, disciplinary action needs to be taken. A policy isn’t worth having if it is seen to be lax and unenforced.
10. Review the policy regularly to ensure you keep up to date with new systems and technology.

Phil Vasic is Regional Director, APAC, at Clearswift, the software security company www.clearswift.com
Security ABC Guides

7 Ways to Protect Your Business Printers

Can a hacker burn down your business by remotely setting one of your printers on fire? Researchers at Columbia University have recently proposed such a scenario, although HP quickly denied that it's possible. However, even if your printers can't be used as remote firestarters, there are many risks involved in networking a printer.