building trust in the cloud

20
www.cloudindustryforum.org Building Trust in the Cloud A Journey Through Certification to the CIF Code of Practice Peter Groucutt Member, Cloud Industry Forum DATABARRACKS

Upload: databarracks

Post on 01-Jul-2015

229 views

Category:

Technology


3 download

DESCRIPTION

Peter Groucutt's presentation from the Cloud Industry Forum - Knowledge Transfer Theatre at Cloud Expo Europe 2013.

TRANSCRIPT

Page 1: Building Trust in the Cloud

www.cloudindustryforum.org

Building Trust in the Cloud

A Journey Through Certification to the CIF Code of Practice

Peter GroucuttMember, Cloud Industry ForumDATABARRACKS

Page 2: Building Trust in the Cloud

www.cloudindustryforum.org

Who are Databarracks?

Databarracks (MSP) IaaS BaaS DRaaS

• Managed Service Provider for ten years

• What qualifies me to talk to you about trust?

Page 3: Building Trust in the Cloud

www.cloudindustryforum.org

Why are we talking about TRUST?

Databarracks began life providing Managed Backup Services

Our Journey through backup is similar to where we are today with

Infrastructure as a Service

People liked the concept and the business drivers

People were worried about Data Security and Privacy

They did not trust the technology nor the providers of it

Young industry / New technology

Page 4: Building Trust in the Cloud

www.cloudindustryforum.org

What is Trust?

“Trust is the positive experience of many over time. It is a concept which is built in retrospect.” (my opinion)

Page 5: Building Trust in the Cloud

www.cloudindustryforum.org

Where are we now?

According to our latest Backup and Cloud Survey which questioned 500 business IT managers in the UK

39% of companies use online backup

Up from 23% in 2008

Page 6: Building Trust in the Cloud

www.cloudindustryforum.org

Who trusts us now?

Page 7: Building Trust in the Cloud

www.cloudindustryforum.org

How does this compare to cloud today?

Companies want to use the cloud They don’t want technology for technology’s sake Hardware doesn’t add value to the business only application Companies want users to access the information they need

to perform the function of the business as quickly as possible Managing physical infrastructure does not add value.

Page 8: Building Trust in the Cloud

www.cloudindustryforum.org

What are the drivers?

Operational Cost Saving

Flexibility of service

Scalability0%

10%

20%

Page 9: Building Trust in the Cloud

www.cloudindustryforum.org

What are the concerns?

Data Security Data Privacy Dependency on Internet

Fear of Loss of Control

Confidence in Providers

0%

20%

40%

60%

80%

100%

Page 10: Building Trust in the Cloud

www.cloudindustryforum.org

What do the concerns tell us?

They are issues of TRUST not technology

Page 11: Building Trust in the Cloud

www.cloudindustryforum.org

Can certification build trust?

Certification can build confidence and confidence can build trust

78% of respondents said they would see value in working with an organisation that was publically certified

Page 12: Building Trust in the Cloud

www.cloudindustryforum.org

Types of certification?

Management ISO9001 / ISO27001 / ISO2000

Prescriptive PCI-DSS / IL3 etc

Industry CIF Code of Practice (CoP)

Page 13: Building Trust in the Cloud

www.cloudindustryforum.org

Management certifications

• Customer complaints and support frameworks

• Identification of risks of service delivery

• Policies covering all elements of business operation

• Continuous review and improvement

• Third party audit

Page 14: Building Trust in the Cloud

www.cloudindustryforum.org

Prescriptive certifications

• Capacity planning• Prescriptive configuration of systems

(firewalls, switches and platforms etc)

• Shielding of storage areas• Log harvesting and analysis• Strict, audited access controls• Regular penetration testing

Page 15: Building Trust in the Cloud

www.cloudindustryforum.org

Industry certifications

• Tailored and specific to the service provided

• Brings together the relevant elements other certs

• Understands the specific issues

• Industry governed

Page 16: Building Trust in the Cloud

www.cloudindustryforum.org

CIF Code of Practice?

• Transparency

• Capability

• Accountability

Three Pillars

Page 17: Building Trust in the Cloud

www.cloudindustryforum.org

What did it take to certify?

• Two months total working part time• Quality Manager• Security Manager• External ISO Consultant

• Two weeks dedicated

• Lots of common ground between ISO and CoP

Page 18: Building Trust in the Cloud

www.cloudindustryforum.org

Why did Databarracks certify?

• Be part of the conversation

• Customers confidence in core values of the company

• Looking beyond price

Page 19: Building Trust in the Cloud

www.cloudindustryforum.org

Would we recommend it?

YES!Shaping the industry to revolve around the core principles set out by CIF will build confidence and TRUST.

Good for customers and good for service providers.

Page 20: Building Trust in the Cloud

www.cloudindustryforum.org

[email protected]

www.cloudindustryforum.org

Questions?