Untitled Document
 Register Now & Save!
Untitled Document
2009 Gold Sponsor
Untitled Document
2009 Silver Sponsor
Untitled Document
2009 Panel Sponsor
Untitled Document
2009 Exhibitors
Untitled Document
2009 Media Sponsors
Latest News
We are a part of a dynamically connected world whe...
In this CTO Power Panel at the 10th International ...
Citrix has acquired Virtual Computer, a little Mas...
The cloud has many benefits, but when it comes to ...
As the Diamond Sponsor of Cloud Expo New York, SHI...
BMC Software Monday adopted a defensive poison pil...
Whether you are a large enterprise, a growing busi...
Hybrid is an end state for most customers as it ba...
Nvidia Tuesday unveiled a VGX platform – reportedl...
Enterprise IT organizations want to deploy a virtu...
Can't Miss RSS Feed
Subscribe to the RSS Feed & Get All The Conference News As It Happens!
Standards Acceleration to Jump-Start Adoption of Cloud Computing
National Institute of Science and Technology (NIST) leads the direction to developing a cloud standard

One major concern with the adoption of cloud computing is the lack of a defined standard or standards that are specific to operations impacting security, interoperability & mobility within the Cloud ecosystem.

As most managers of security departments will attest to, there is a fine line between security and operations. While we as business managers want to ensure that we maximize the ROI on our operational investments and ensure that availability is paramount  for our users, we do not want to do so at the expense of our security measures, policies and protocols.

On the other hand we do not want to lock down a system providing maximum security, but to such an extent that there is a degradation in availability - thus negatively impacting operations and our revenue stream by extension.

In the traditional IT Security/Operational world we balance tools and metrics from ITIL and ISO 27001 with that of ISO 27002, COBIT and TOGAF for instance.These to integrate with requirements from FISMA, HIPAA,SOX 404, SAS 70 -2, GLBA etc; but what happens in the cloud ecosystem when we are placing assets in care of a provider who may have systems distributed internationally?  How does all of this fit into the management of risk, governance and compliance of a multinationally distributed system?

IT Scientists at NIST in an attempt to address this gap impacting standards and levels of uncertainty that follows the adoption of related new technologies, proposed SAJAAC.

SAJAAC aims is to initiate the process of hammering out a standard that focuses on "strategy, process and protocol" while reduce the uncertainty which is following the lack of standards within the cloud arena.

NIST in its focus on cloud adoption, believes that" by validating key cloud specifications & sharing information," enterprises can "build confidence in cloud computing technology in the interim before formalized standards are available."

SAJAAC is represented by Scientists at NIST as follows:

SAJAAC

Source - Overview: NIST Cloud Computing Effort presented by Dawn Leaf : May 20th 2010.

As shown in the schematic, there is a NIST hosted portal which is publicly accessible; its aim is to catalyze verifiable information as it is exchanged. Then there is an area of specifications and use cases with ongoing contributions from cloud computing stakeholders based within the areas of industry, academia, and government.

These use cases will be published on the portal and available publicly after a period of vetting and improvements;they will focus on interpreting "requirements in the form of behavioral scenarios which describe the interaction between people and computer systems."

The purpose of these scenarios is to ensure that aspects of portability, interoperability, and security are met for cloud computing end users.

SAJAAC's implementation will act as a key provider of data which will be included in a special publication on cloud computing that scientists at NIST are currently working on.

The advantage of this model, is it's openness to input and collaboration from industry and other relevant avenues, its ongoing parameters and its objectivity.

In closing one question still needs to be addressed which is; Will an addendum to 18 USC 1030 or the UK computer misuse act be crafted to prosecute a cracker who infiltrates our assets held in a cloud located in an area that may fall outside the FBI's jurisdiction or warrant no cooperation from a foreign government?

References

1.NIST Cloud Computing

http://csrc.nist.gov/groups/SNS/cloud-computing/

2.State Of Public Sector Cloud Computing

http://www.cio.gov/documents/StateOfPublicSectorCloudComputing.pdf

3.Overview: NIST Cloud Computing Effort presented by Dawn Leaf : May 20th 2010.

About Jon Shende
Jon RG Shende is an executive with over 18 years of industry experience. He commenced his career, in the medical arena, then moved into the Oil and Gas environment where he was introduced to SCADA and network technologies,also becoming certified in Industrial Pump and Valve repairs. Jon gained global experience over his career working within several verticals to include pharma, medical sales and marketing services as well as within the technology services environment, eventually becoming the youngest VP of an international enterprise. He is a graduate of the University of Oxford, holds a Masters certificate in Business Administration, as well as an MSc in IT Security, specializing in Computer Crime and Forensics with a thesis on security in the Cloud. Jon, well versed with the technology startup and mid sized venture ecosystems, has contributed at the C and Senior Director level for former clients. As an IT Security Executive, Jon has experience with Virtualization,Strategy, Governance,Risk Management, Continuity and Compliance. He was an early adopter of web-services, web-based tools and successfully beta tested a remote assistance and support software for a major telecom. Within the realm of sales, marketing and business development, Jon earned commendations for turnaround strategies within the services and pharma industry. For one pharma contract he was responsibe for bringing low performing districts up to number 1 rankings for consecutive quarters; as well as outperforming quotas from 125% up to 314%. Part of this was achieved by working closely with sales and marketing teams to ensure message and product placement were on point. Professionally he is a Fellow of the BCS Chartered Institute for IT, an HITRUST Certified CSF Practitioner and holds the CITP and CRISC certifications. A recognised thought Leader, Jon has been invited to speak for the SANs Institute, has spoken at Cloud Expo in New York as well as sat on a panel at Cloud Expo Santa Clara, and has been an Ernst and Young CPE conference speaker. His personal blog is located at http://jonshende.blogspot.com/view/magazine "We are what we repeatedly do. Excellence, therefore, is not an act, but a habit."

Untitled Document

Call 201 802-3021 or Click Here to Save $400!

Save $400

 Sponsorship Opportunities

SYS-CON's International Cloud Computing Conference & Expo, held each year in California, New York and Prague is the leading event covering the fast-emerging Cloud Computing market for Enterprise IT professionals. Co-located with the International Virtualization Conference & Expo, the combined event will surely deliver the #1 i-Technology educational and networking opportunity of the year for those seeking to establish a market lead anywhere in the multiple layers of the Cloud Computing ecosystem.





Who Should Attend?

Senior Technologists including CIOs, CTOs, VPs of technology, IT directors and managers, network and storage managers, network engineers, enterprise architects, communications and networking specialists, directors of infrastructure Business Executives including CEOs, CMOs, CIOs, presidents, VPs, directors, business development; product and purchasing managers.


Video Coverage of Cloud Computing Expo

Brian Stevens: The Opening of Virtualization
Jon Wallace: User Environment Management – The Third Layer of the Desktop
Brian Duckering & Ken Berryman: Managing Hybrid Endpoint Environments
Preeti Somal: Game-Changing Technology for Enterprise Cloud and Applications

 Conference Media Sponsor: Cloud Computing Journal

Cloud Computing Journal aims to help open the eyes of Enterprise IT professionals to the economics and strategies that utility/cloud computing provides. Cloud computing - the provision of scalable IT resources as a service, using Internet technologies - potentially impacts every aspect of how IT deploys and operates software.

Government IT Conference & Expo 2009
Allstar Conference Faculty Lineup Will Include...


CHEVALIER

Novell Canada

DICARLO

Sun Micosystems

FOXWELL

Sun Microsystems Federal

GABHART

Web Age Solutions

GREENBERG

Integralis

HAHN

Tranxition

WILLIAMS

Maxworks

JACKSON

Dataline, LLC

KHOSLA

IBM

KRZYSKO

US Departement of Defense

LIBERMAN

Lieberman Software

MARKS

AgilePath

MORGENTHAL

QinetiQ North America

RYAN

Asankya

TRAJMAN

Vertica

WHITE

BDNA


SYS-CON EVENTS


Past Events Archive

Cloud Computing Conference & Expo
2009 East

cloudcomputingexpo
2009east.sys-con.com/
Virtualization Conference & Expo
2009 East

virtualizationconference
2009east.sys-con.com/
Cloud Computing Conference & Expo
2008 West

cloudcomputingexpo
2008west.sys-con.com/
SOAWorld Conference & Expo 2008 West
soaworld2008.com/
Virtualization Conference & Expo 2008 West
virtualizationconference
2008west.sys-con.com
AJAXWorld Conference & Expo 2008 West
ajaxoct08.sys-con.com
SOAWorld Conference & Expo 2008 East
soa2008east.sys-con.com
Virtualization Conference & Expo 2008 East
virt2008east.sys-con.com
AJAXWorld 2008 Conference & Expo East
ajaxmar08.sys-con.com
SOAWorld Conference & Expo 2007 West
www.soaworld2007.com
Virtualization Conference & Expo 2007 West
virt2007west.sys-con.com
AJAXWorld 2007 Conference & Expo West
ajaxoct07.sys-con.com

Cloud Computing Expo Alumni Delegates Represents...

• AccuRev
• Adea Solutions
• Adobe Systems, Inc [3 delegates]
• ADP
• Aeropostale, Inc
• Aetna
• Akbank Training Center
• American Family Insurance
• American International College
• American Modern Insurance
• Amphion Innovations
• Amplify LLC, Clipmarks [2 delegates]
• Anderson Consulting
• Arrow Electronics [3 delegates]
• Ashcroft Inc
• Athabasca University
• ATS
• Audatex
• Avanade, Inc.
• Avaya Inc. [5 delegates]
• Azul [2 delegates]
• Backbase [2 delegates]
• Bank of America
• Bank of NY
• Barnes and Noble
• Barnex Investment International Limited
• BEA
• Bear Stearns [2 delegates]
• Bendel Newspaper Company Limited
• BizInnovative
• Bloomberg [2 delegates]
• BlueBrick Inc.
• BMC Software
• Boeing
• Bottomline Technologies [2 delegates]
• BP
• Broadcom

   read more...
Cloud Computing Blogs
In other words, VMware’s server density is higher. Boles suggests this means that customers should be “assessing virtualisation on a ‘cost per application’ basis. VM density has a sign
Traditionally, the way people have implemented high availability is by using a high-availability management package like Linux-HA[1], then configure it in detail for each application, file system moun