13.07.2015 Views

Research and development for industry: Advanced ... - CSIR

Research and development for industry: Advanced ... - CSIR

Research and development for industry: Advanced ... - CSIR

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

ENABLING TECHNOLOGIESA risk <strong>and</strong> control framework<strong>for</strong> cloud computing <strong>and</strong> virtualisationThe evolution of manufacturing has given rise to computer-aided manufacturing, reconfigurable manufacturing systems <strong>and</strong>technology-intensive manufacturing. This in turn requires that new options <strong>for</strong> computing capability are investigated.Organisations have toadapt quickly to changes toretain a competitive advantage<strong>and</strong> meet targets. Reduced costs,scalability, flexibility, capacityutilisation, higher efficiencies,<strong>and</strong> mobility can be achievedthrough technologies such as cloudcomputing <strong>and</strong> virtualisation.To assist organisations withcompliance <strong>and</strong> governancerelating to these technologies,the <strong>CSIR</strong>’s Enterprise KnowledgeEngineering <strong>and</strong> Managementgroup has developed a risk <strong>and</strong>control framework <strong>for</strong> cloudcomputing <strong>and</strong> virtualisation,named the Cloud-V Framework.Cloud-V FrameworkCloud computing <strong>and</strong>virtualisation have gained clearacceptance in the in<strong>for</strong>mationtechnology (IT) <strong>industry</strong>, withstrong indications of a significantfuture. Yet threats fromcentralised <strong>and</strong> shared resourcesnow exceed the adoption of thesetechnologies. Why is this so?The reality is that althoughvirtualisation allows users toaccess power beyond their ownphysical IT environment; thisis associated with many risks.Within the cloud environment,data are no longer under thecontrol of management, <strong>and</strong>uncontrolled or un<strong>for</strong>eseenrisks <strong>and</strong> threats can lead to acompany’s in<strong>for</strong>mation beingcompromised.The Cloud-V Frameworkprovides a governancestructure <strong>and</strong> guidelines<strong>for</strong> the identification <strong>and</strong>assessment of cloudcomputing <strong>and</strong> virtualisationrisks, <strong>and</strong> controls to mitigatethe identified risks. It wasdeveloped by MarianaCarroll, a <strong>CSIR</strong> PhD student.Professors Paula Kotzé <strong>and</strong>Alta van der Merwe areCarroll’s PhD supervisors.The Cloud-V Frameworkprovides guidance todetermine an organisation’sreadiness <strong>for</strong> the deploymentof assets into the cloud.It also offers a detailedset of methods to guidethe underst<strong>and</strong>ing <strong>and</strong>identification of risks <strong>and</strong>controls to maximise thevalue of cloud computing<strong>and</strong> virtualisation. Guidelinesto assist in protecting <strong>and</strong>safeguarding applications <strong>and</strong>data, <strong>and</strong> meeting regulatoryrequirements pertainingto the cloud <strong>and</strong> virtualenvironments, are included.The risk <strong>and</strong> controlframework aims to servea diverse audience basedon their distinct needs,including businessleaders, management,<strong>and</strong> in<strong>for</strong>mationsystems professionals;those charged with ITgovernance <strong>and</strong> providingcloud computing <strong>and</strong>virtualisation services;<strong>and</strong> IT assurance <strong>and</strong>compliance auditors orconsultants.– Mariana Carroll, Prof Paula Kotzé<strong>and</strong> Prof Alta van der MerweEnquiries:Prof Paula Kotzépkotze1@csir.co.zaThe Cloud-V Framework was recently used in anassessment of access <strong>and</strong> authentication to a largeenterprise resource planning application runningin a private/community cloud at a prominentinternational beverage company where the cloud<strong>and</strong> virtualised environment is provided by amajor IT company.Feedback from the Line of Business manager included:“The cloud assessment is a must-have <strong>for</strong> anyorganisation considering a cloud-based solution ofany kind. The value derived from the assessment givesclear guidance around the potential pitfalls <strong>and</strong> hasbroadened our thinking around cloud. My hope is thatthis assessment becomes an <strong>industry</strong> st<strong>and</strong>ard <strong>for</strong> allorganisations to measure their cloud readiness against.”What is cloudcomputing?Cloud computing is the deliveryof computing as a servicerather than a product. Sharedresources, software <strong>and</strong>in<strong>for</strong>mation are provided tocomputers <strong>and</strong> other deviceswith access via a web browser ora desktop or mobile application,as a metered service over anetwork (typically the Internet).Cloud users do not need to knowthe location <strong>and</strong> other details ofthe computing infrastructure.| 62 |Consider the risk impact throughout the entire processCloud readiness assessmentStrategyIdentification <strong>and</strong> valuationArchitecture <strong>and</strong> technologyGovernance <strong>and</strong> compliancePeople <strong>and</strong> changesBusiness caseCloud-V FrameworkCloud <strong>and</strong> virtualisation risk <strong>and</strong> control assessmentUnderst<strong>and</strong>ing of thecloud <strong>and</strong>/or virtualenvironment(s)Identify controlsAssess controlsCONTROL IDENTIFICATION& VALUATIONESTABLISH CONTEXTREPORTINGMONITORING&REVIEWINGDefine scope <strong>and</strong>objectivesIdentify risksAssessrisksRISK IDENTIFICATION& VALUATIONProf Paula Kotzé (back) <strong>and</strong> Mariana CarrollCloud computing is a model <strong>for</strong>enabling convenient, on-dem<strong>and</strong>network access to a sharedpool of configurable computerresources that can be rapidlyprovisioned <strong>and</strong> released withminimal management ef<strong>for</strong>t orservice provider interaction.The market <strong>for</strong> cloud technology<strong>and</strong> integrated services iscurrently trans<strong>for</strong>ming from thehype cycle to testing, piloting,<strong>and</strong> implementation by largerenterprises. Given the potential<strong>for</strong> significant cost savings,smaller <strong>and</strong> medium-sizedorganisations are alsobecoming early adoptersof this technology.| 63 |

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!