Академический Документы
Профессиональный Документы
Культура Документы
December 2010
Table of Contents
Executive Summary
Foundations of Cloud Computing
Obstacles and Considerations
Future of Cloud
News of Cloud is everywhere, and its predominance in IT is a foregone conclusion. In fact, the push to adopt
“Cloud” Buzz
Cloud has been so strong that risks inherent in this model have largely been ignored
The recent economic turmoil and the promise of Cloud leading a renaissance of the tech sector are shaping the
perspective and appetite for Cloud rather than the readiness of the technology itself. Cloud is a powerful tool for
Adoption Haste
mobilizing data; however, there are no regulations, standards, or assurances of data protection from a technical
perspective
Major breaches at Google, Salesforce.com, and Amazon, have exposed the fragility of the Cloud delivery model,
and the fundamental issues of data security, privacy, and standards that have yet to be addressed. Though price
Security Risks
points gained in Cloud can be significant, businesses should weigh advantages against the hidden costs of
compromised data
Analyst sentiment seems to be the sole voice of reason. Principal analysts from Forrester, Gartner, and Yankee
Expert Views cite major security concerns with Cloud. Hackers have also highlighted the vulnerabilities of Cloud and issued a
manifesto of mayhem against it (Black Hat 2009 – Clobbering the Cloud by SensePost)
Assessing your organization’s readiness for Cloud should include the evaluation of hybrid models, hybrid
Opportunity architectures, integration constraints, and innovative data protection methods, that will offer the best approach for
business adoption
Consider the direct business benefits of Cloud for your company and your individual business needs, weighing
Key Takeaways against security and privacy concerns. In the more immediate future, look toward applications focused on
innovative data protection methods, enabling organizations to utilize Public Cloud in a private manner
“ Cloud is an evolution. It coalesces grid, utility, virtualization and web standards into a delivery paradigm. The
difference is each of these components are building blocks that solve the specific point problems of
abstracted, on-demand, distributed processing – Tony Bishop (Founder and CEO, Adaptivity)
I don't think it's a revolution as much as it's an evolution. If you want to really say what kicked this thing off,
virtualization was a big precursor to Cloud…I think “Cloud" is a little bit overused right now. I look at it as the
evolution of the data center, to do more scalable processing and computing – Ping Li (Partner, Accel
Partners)
Cloud services have shifted from a year ago. We did a focus group around 12 months ago and they pretty
much took the mickey out of Cloud. It was seen as unrealistic and CIOs weren’t considering it. What’s even
more of a surprise is that in a short period of 12 months, we’ve seen Cloud go from a bit of a joke to a
“
number two priority on the plate of CIOs today, and a very serious consideration that they are taking on
board – Paul Harapin (Director, ComputersOff.org and Ex-MD, Vmware)
“Cloud computing is a model for enabling convenient, on-demand network access to a shared pool of configurable
Definition computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and
released with minimal management effort or service provider interaction.” – Peter Mell and Tim Grance (NIST)
“ Cloud computing is an evolutionary technology because it doesn’t change the computing stack at all. It simply
distributes the stacks between the service providers and the users. It is an IT architecture with vertical services
– Steve Jin (Creator of Vmware vSphere Java API)
Applications/functionality delivered via Cloud: Accessible via standard Internet protocols, always available and scaled
to demand, programmable interface, pay as you use, full self-service features – Chenxi Wang (Ph.D., Principal
Analyst, Forrester)
The ‘Cloud’ model initially has focused on making the hardware layer consumable as on-demand computer and
storage capacity. This is an important first step, but for companies to harness the power of Cloud, complete application
infrastructure needs to be easily configured, deployed, dynamically-scaled and managed in these virtualized-hardware
“
environments – K. Sheynkman (Co-Founder, Elastra Corporation)
Source: Sysomos Software Tool; SysCon Website; Forrester Research Website; NIST Website
December 2010 | Copyright © 2010 Grail Research, LLC 5
Foundations
Obstacles and
of Cloud Future of Cloud
Considerations
Private Cloud
Public/ Dedicated to one customer/company Private Cloud is more suited for
Private Hybrid
Community organizations that need high-level
Cloud Cloud
Intranet/VPN1
Cloud
Internet Intranet/VPN1
“ CIOs know that what is sometimes dubbed "private
cloud" does not meet their goal as it does not give them
the benefits of cloud: true elasticity and capex
“ security. Though most experts believe
that ‘private cloud’ is an oxymoron,
others argue that the model offers
+ Internet elimination – Werner Vogels (VP and CTO, Amazon) better resource management to current
IT managers
Public Cloud
Made available to the general public for specific
general purposes The Public Cloud model emerged as
a great value proposition for SMB4
USERS
“ Concerns for those deploying in the public cloud are
factors such as the financial stability of the hosting
organization and the hosting organization’s deployment
“ companies and startups
Note: 1Virtual Private Network; 2Discussions during the period 25-Aug-2009 to 25-Aug-2010; 3N may include some articles/posts more than once, if repeated on
different websites; 4Small and Medium Businesses
Source: Sysomos Software Tool; CIO Website; SysCon Website; IBM X-Force: Mid-Year Trend and Risk Report
December 2010 | Copyright © 2010 Grail Research, LLC 6
Cloud Computing Foundations
Obstacles and
of Cloud Future of Cloud
Considerations
Computing
USD
37.8 Bn USD 121.1 Bn
“ We are seeing an acceleration of adoption of cloud
computing and cloud services among enterprises and an
explosion of supply-side activity as technology providers
maneuver to exploit the growing commercial opportunity
“
– Ben Pring (VP, Gartner)
India will not only see a surge in cloud computing services but
companies all over the world will look to India to support their The explosive growth in the cloud computing market will mirror
transition to cloud computing – Steve Ballmer (CEO, Microsoft) greater IT globalization trends, with India leading the market in
outsourced support for Cloud services
By 2012, nearly 85% of net-new software firms coming to market
will be built around SaaS service composition and delivery; by
2014, about 65% of new products from established ISVs will be
delivered as SaaS services. SaaS-derived revenue will account
“ It is estimated that SaaS is growing at a rate five times faster than
for nearly 26% of net new growth in the software market in the software market as a whole
2014…– IDC Report
Source: R Wang and Insider Associates; A Software Insider’s Point of View–Understanding The Many Flavors of Cloud Computing and SaaS
( R "Ray" Wang, Phil Wainewright, Michael Cote, and James Governor); Forrester Report; Grail Research Analysis
December 2010 | Copyright © 2010 Grail Research, LLC 8
Foundations
Obstacles and
of Cloud Future of Cloud
Considerations
Business
Definition Expert Views Service Provider
Value
“SaaS is perfect for small businesses, they get the benefits of world-class infrastructure,
Application licensed to enterprise-class features, and no capital investment. Frankly, I'd be surprised if the SMB market
customers doesn't shift to a SaaS-dominated sector” – Bernard Golden (CEO, HyperStratus)
SaaS
Access through “thin “The cost of comformity is the lack of flexibility. What will you do 5 years into a True SaaS scenario
client interface”, such when you are locked in and the vendor won’t add the feature or functionality you need?” – R 'Ray'
as a web browser Wang (Partner, Altimeter Group)
Set of tools and APIs “Just as platform as a service provides enterprise IT with a new model for platforms to run
provided for creating applications in the cloud, development as a service provides a new model for development tools,
customized applications giving developers the power to create applications for the cloud” – Marc Benioff (CEO,
DaaS Tools provided include
Salesforce.com)
code editors, source “I think there are going to be thousands of new platform companies -- you the end user can
control systems, and program it” – Marc Andreesen (General Partner, Andreessen Horowitz and Cofounder &
batch scripts Chairman at Ning Inc.)
“The advantages of PaaS are - Complete abstraction; considerable cost savings and faster time to
Hosting for client- market ; Better security. PaaS makes developers succeed even if they are completely ‘operations
developed applications blind” – K. Subramanian (CTO and Advisor, CloudsDirect)
PaaS Applications can be
created using “There are shortcomings in the platform as a service model as well. The biggest problem with
programming languages PaaS may be difficulty migrating existing applications from the internal data centre to the cloud” –
such as Java and .Net Tim O'Brien (Director, Platform Strategy Group, Microsoft)
Fundamental computing “Although it is not the first choice, IaaS has an obviously huge market in the enterprise because
resources (processing, there are countless servers sitting in data centers that are prime candidates to move out to IaaS
storage, network, etc.) — clouds, and countless more that will be needed in the coming years” – Scott Sanchez (Security
IaaS to run full virtual servers and Privacy Officer, ScaleUp Cloud)
Customer has control
over operating system, “In short, IaaS and other associated services has enabled startups and other businesses to focus
storage, and deployed on their core competencies without worrying much about provisioning and management of
applications infrastructure” – K. Subramanian (CTO and Advisor, CloudsDirect)
“
“There is still a strong need for awareness on the part of folks in the cybersecurity area
about cloud computing. About 21% of those folks involved in cybersecurity, their agencies
A
Requires
are unaware about cloud computing, and 34% of the respondents in total weren't familiar
with the cloud. That is the real key-take away that awareness around the cloud as it relates
to trust and security needs to continue to be increased” – Melvin Greer (Chief Strategist,
Cloud Computing, Lockheed Martin)
Awareness and understanding
of cloud computing is limited
to a small set of IT
Awareness professionals
“…the biggest security threat for cloud computing is lack of awareness about cloud security
and Clarity among the IT Pro's” – Scott C. Sanchez, CISSP (Security and Privacy Officer, ScaleUp
Cloud)
“Public cloud services are generally not providing as much customization as customers
B
want, but the cloud model is gaining popularity both among users who want to sidestep their
companies' IT departments, and from small businesses that want to get out of the IT There is a gap between
business” – Tim O'Brien (Director, Platform Strategy Group, Microsoft) customer requirements and
"Cloud solutions won't come in a box, nor are traditional internal IT technologies and skills existing cloud computing
Requires
apt to seamlessly spin up mission-ready cloud services. Neither are cloud providers so far solutions in the market
Customized able to provide custom or ‘shrinkwrapped' offerings that conform to a specific enterprise's
Solutions situation and needs” – Dana Gardner (President and Principal Analyst, Interarbor
Solutions)
“People are going to want to move data around, they're going to want to ask clouds to do
C
Requires
Cloud
things for them . We don't have any inter-cloud standards. There's a whole raft of research
work still to be done and protocols to be designed and standards to be adopted that will
allow people to manage assets” – Vint Cerf (Co-designer of the TCP/IP, VP and Chief
Internet Evangelist, Google) “ Cloud computing is still
evolving in terms of well-
defined adoption/integration
“When customers are looking to adopt cloud services, they want services that follow standards
Computing
highest standards, even though such services may follow better standards than their
Standards existing infrastructure” – Bernard Golden (CEO, HyperStratus)
Note: 1Online discussions in English on blogs, forums, news websites, and Twitter from software tool findings across regions during the period 25-Aug-2009 to
25-Aug-2010; 2European Economic Area
Source: Sysomos Software Tool; SysCon Website; CloudStorageStrategy Website; InformationLaw Group Website; Official Website of the Commonwealth of
Massachusetts; lawpracticestrategy.com
December 2010 | Copyright © 2010 Grail Research, LLC 11
Foundations
Obstacles and
of Cloud Future of Cloud
Considerations
The concept of computing resources as a utility is gaining traction among SMBs; however, the economic
model offered by Cloud service providers has yet to prove its strength of scalability to enterprise customers
“ “In the past, energy-efficient performance and connectivity have defined computing requirements. Looking
forward, security will join those as a third pillar of what people demand from all computing experiences” – Paul
Otellini (CEO, Intel)
“It’s a big win for smaller companies to leverage the cloud because you are really saving a lot–it is really
avoiding a large, up-front investment. Five years ago, we would have had to build out a data center and the
sheer cost of that would have made it much more difficult to launch our business. In a traditional data center,
we would need an IT person to rack the system, maintain the servers, and own the hardware, So rather than
hiring someone, we now have software developers that are writing on a very flexible platform that vendor
maintains” – Oliver Friedrichs (CEO, Immunet)
“Right90 didn’t start its business using third-party infrastructure, but the cost savings and flexibility of Cloud
services beckoned. Last year, the company moved out of its data centers in Calgary, Ontario and San
“
Francisco, California and adopted Amazon EC2 with backup to servers located at the firm’s own offices.
The lack of servers to manage has freed up Right90’s IT management team” – Arthur Wong (CEO, Right90)
“ “In part, this can be explained by macroeconomic factors, The financial turbulence
A
The economic downturn has
of the last 18 months has meant every organization has been scrutinizing every forced businesses to become
expenditure. An IT solution that can deliver functionality less expensively and with leaner, which in turn has fuelled
more agility (remembering that time is money) is hard to ignore against this the adoption of cost-effective
Economic backdrop” – Ben Pring (VP, Gartner Research) Cloud service models
Downturn
B
Technology
“Server technology is in the middle of a renaissance where it is driving Cloud
advancements and Cloud is, in turn, changing servers. Cloud-based ‘scale issues’
will continue to change how servers and software for them are built for years to
come” – Steve Ballmer (CEO, Microsoft)
The success of virtualization and
Internet bandwidth availability has
positioned Cloud services as a
potential market opportunity
Advancements
“In technical terms, cloud computing offers elasticity, pay-as-you-go rather than
Cloud’s on-demand model allows
capital-intensive investment, and no long-term resource commitments. In business
Industry experts believe that there is apprehension among potential Cloud customers about security and data privacy.
Insights Other major concerns include complexity in the integration of cloud-based systems and adherence to
regulatory/compliance frameworks
Expert Views
Insights IT managers don’t believe that current cloud computing solutions are at par with on-premise infrastructure solutions. To
address this concern, service providers need to offer:
“ “Having core components, such as storage, compute, security, and so on, outsourced to other
cloud providers could mean that your data and application processing exists across many
different physical providers, and the risk of outages, compliance issues, and data leaks
increases dramatically” – David Linthicum (CTO, Bick Group)
There is lack of visibility on legal and
compliance standards, and potential
customers have limited clarity on where and
how the data is stored, and who can access
the data
(2010 Survey on participants in DEF CON) “….belief from the hackers, that cloud vendors are
not doing enough to address the security issues of their services; hackers have identified
vulnerabilities in current cloud technology” – Barmak Meftah (Chief Product Officer, Fortify
Hackers and security experts believe that
Software)
Cloud vendors are not doing enough to
“When vulnerabilities are detected they can be managed more rapidly and uniformly. Cloud address identified vulnerabilities
security is able to respond to attacks more rapidly by reducing the time it takes to install
patches on thousands of individual desktops or hundreds of uniquely configured on-premise
servers” – Mike Bradshaw (Director, Google Federal, Google Inc.) Though vendors/service providers create a
“Attempts to infiltrate or disrupt online service offerings grow more sophisticated as more
“ buzz around their services, they may not be
able to match their claims as infiltration
commerce and business occurs in this venue” – John Howie (Senior Director, Microsoft)
techniques outpace readiness of Cloud
technologies
Note: Comment and Views include key snippets
Source: Ponemon Institute Report; CSA (Cloud Security Alliance); Fortify Software Website; SysCon Website; CIO Website
December 2010 | Copyright © 2010 Grail Research, LLC 15
‘Clobbering the Cloud’ Foundations
Obstacles and
of Cloud Future of Cloud
Considerations
Computing
Insights Security analysts and hackers have demonstrated major loopholes in Cloud offerings
Salesforce.com 1Amazon
Mobile Me
Hackers showed EC2’s
Hackers demonstrated how they Hackers arrived at a point where vulnerability by carrying out three
were able to circumvent controls to they could read Steve Wozniak’s separate attacks:
access restricted resources on the mail and even embed JavaScript Starting numerous machines
Force.com platform, which for continued access to his account Stealing computing
supports custom source code and services (if they were a bit time/bandwidth of other users
upload and execution more malicious) Stealing paid-for 2AMI’s
“It's possible to stitch together the “We showed attacks against the
“By piecing together publicly Amazon EC2 platform that do not
free resources to produce a
available information, we can target specific weaknesses in
useable computing platform that
generate a profile that is sufficiently technologies; rather the processes
can take advantage of the
complete for a password reset, by which complex actions took
expanded resources without
which points to flaws within the place were abused to our benefit”
incurring cost to the attacker…”
reset process” – SensePost – SensePost
– SensePost
“
“ With the exploitation of Google BlogSpot and Mobile Me, we are again seeing two common spamming practices converge –
CAPTCHA breaking techniques and exploitation of free hosted services – Mark Sunner (Chief Security Analyst, MessgeLabs)
“
“
The security of these Cloud-based infrastructure services is like Windows in 1999. It’s being widely used and nothing
tremendously bad has happened yet. But it’s just in early stages of getting exposed to the Internet, and you know bad
things are coming – John Pescatore (VP, Gartner Fellow)
Jan 2010: A hacker uses the Google Street View data to stalk victims. The attacker is able to track his victim
in few seconds without even using IP address information
"The interesting bit is I'm not piggybacking off of the browser's geo-location feature. I simply re-implemented the
feature as a server-side tool. This way if I can obtain the user's router's MAC address in any way, regardless of
browser, nationality, or age, I can typically determine their location and show up at their place with pizza and
beer later that night“ – Samy Kamkar (Co-Founder, Fonality Inc.)
Dec 2009: Zeus botnet was spotted on Amazon’s Elastic Computing Cloud (EC2) Cloud computing network. It
was running an unauthorized command and control center:
Zeus botnet enables hackers to steal login credentials, account numbers, and credit card information
through the creation of fake HTML forms on banking login pages
More than USD100 MM was lost in bank fraud due to Zeus botnet attacks in 2009
The hacker may have stolen the password from the desktop of a user
"I think it's more a target of opportunity than a target of choice” – Don DeBolt (Director, Threat Research, HCL
technologies)
July 2009: Twitter corporate and employee information was infiltrated at the top levels of the organization,
including the CEO Evan Williams’ personal email. The individual behind the attacks accessed nearly 310
documents containing confidential information belonging to Twitter. The hacker sent documentation to Tech
Crunch, the elite media organization that covers tech trends, to prove the attack
"It's a message I wanted to get out to Internet users, to show them that no system is invulnerable”
– Francois Cousteix (Hacker Croll, in his interview with French media on hacking the Twitter account)
Source: CIO Website; Snipe Website; Sean-Barton Website; Dark Reading, Computer World blog; TechCrunch
December 2010 | Copyright © 2010 Grail Research, LLC 17
Pros and Cons to Cloud Adoption Foundations
Obstacles and
of Cloud Future of Cloud
Considerations
Computing
by Company Size
PROS
Innovation flexibility at low
operating expense and no capital
Allows large enterprises to focus
on core business activities instead
“ “Companies such as AllenPort and ARC offer SMEs good
software at affordable prices with the flexibility to adjust usage
on an as-needed basis. The service model meets the financial
expenditure of IT infrastructure needs of SMEs while protecting them from the risks of non-
genuine software” – Charl Everton (Anti-Piracy Manager,
On-demand scalability to Lower cost of power, space, and Microsoft SA)
synchronize with market dynamics data center maintenance by taking
non-critical services out of data They (Mid-sized companies) face rapidly changing markets and
Ability to access information need to avoid being locked into a capital investment or any
centers
regardless of location particular mode of operations. The call option that cloud
Risk of hardware and software computing represents — the ability to change in the future
obsolescence transferred to Cloud without a penalty — is critical to a midsized company trying to
service provider succeed in a world of giant competitors and disruptive change”
– Bernard Golden (CEO, HyperStratus)
CONS
"I would argue, however, that if you have existing IT
Security, privacy, and compliance Complex integration of legacy investment, or you have requirements that push beyond the
concerns systems with Cloud systems an limits of today's cloud computing technology or business
Network latency hinders obstacle; needs can be greater models, you should consider not choosing at all” – James
application performance than current Cloud capabilities Urquhart (Blog Network Author, CNET)
Increase in security threats due to “What holds back large companies is, in a sense, their success
Cost of hardware rapidly adoption of Public Cloud with the previous generation of computing. Because they could
decreasing — can be a future Legal compliance and regulatory invest in the old model, they've now got an installed base of
concern issues if operations in multiple hardware and a large, top-notch technical staff on hand.
countries
Highly skilled IT staff and sunk
There's pressure on these businesses to justify the sunk cost of
their hardware infrastructure, so they tend to more toward a
“
investments in existing hardware vision of private cloud computing” – Bernard Golden (CEO,
infrastructure may also act as a HyperStratus)
deterrent to move to Cloud
Note: Comment and Views include key snippets
Source: Sysomos Software Tool; CIO Website; SysCon Website; Ulitzer Website; ReadWriteWeb Website; PCWorld Website; MyBroadband Website
December 2010 | Copyright © 2010 Grail Research, LLC 18
Foundations
Obstacles and
of Cloud Future of Cloud
Considerations
Cloud has been positioned as an alternative to on-premise infrastructure; however, experts believe that it is not always
Insights the most appropriate IT solution. Other factors that should be considered include cost of Internet bandwidth, third-party
support, and barriers to switching Cloud service providers or changing back to a on-premise infrastructure
Economic Model
“Risks, such as, hardware and software technological obsolescence, are Economic evaluation of Cloud adoption vs. on-premise infrastructure setup
transferred; although many considerations, including security, interoperability, varies under different business scenarios. There should be a thorough
lock-in, business process governance, and management remain, and need to internal due diligence on business requirements
be properly evaluated” – Ray DePana (Industry Consultant, NSF1)
There is no widely accepted framework to assess the value proposition of
various Cloud services vs. on-premise infrastructure setup
"I believe that the future of data centers is in the cloud because companies will
be drawn toward paying $10 per month on hosted Exchange services instead The IT community is divided — whether Cloud services are a business
of spending $10,000 on an in-house implementation of Exchange Server” – decision or a technology decision
Tim Crawford (CIO, All Covered)
Hidden Cost
“…our analysis indicates that once you’re sending over 50 gigabytes of data Bandwidth Cost: Cloud services are delivered over the Internet; Internet
daily (or a terabyte a month costing you $150 on Azure, for example), it may bandwidth usage and charges increase as resource utilization rises
make sense to leave the cloud and buy your own bandwidth to the Internet –- Third Party Support: Regulatory and compliance guidelines may require a
you’ll probably save 50 percent of your monthly bandwidth charges” – Allan third-party auditor or application, which will lead to additional cost and
Leinwand (CTO-Infrastructure Engineering, Zynga) complexity
Cloud Switch: Cloud computing service providers, eager to capture the
market, use proprietary mechanisms to deploy applications and store data.
This can lock the customer to a provider or increase complexity/cost when
switching providers/infrastructures
Note: 1National Science Foundation Initiative on Computational Thinking; Comment and Views include key snippets
Source: CIO Website; SysCon Website; GigaOM Website; CloudEco Blog; Linkedin; “Do Clouds Compute? A Framework for Estimating the Value of Cloud
Computing” by Markus Klems, Jens Nimis and Stefan Tai; SmartDataCollective Website
December 2010 | Copyright © 2010 Grail Research, LLC 19
Foundations
Obstacles and
of Cloud Future of Cloud
Considerations
Experts see the potential of cloud computing for “Green IT” through efficient power consumption; however, skeptics
Insights claim that there is no comprehensive framework to assess the value proposition of “Green Cloud”
“ “In theory, a shared resource like Amazon or Google's public clouds can have higher utilization and
thus greater power efficiency. Locate your cloud data center close to a green power source, like a
hydro plant, and you can minimize transmission line power losses and be even greener”– Marc
Hamilton (VP of Cloud Computing Sales, Sun)
“I’m sure that if you were to compare a traditional data center deployment to a near exact
Experts maintain that Cloud is greener than
individual data centers, however, there is a long
road ahead in substantiating
replication in the Cloud you'd find the Cloud to be more efficient, but the problem is there currently
is no way to justify this statement without some kind of data to support it” – Reuven Cohen (CTO, Cloud allows companies to scale down IT
Enomaly Inc.)
resources when demand is low, reducing their
“So, in a sense, the "greenness" of Cloud computing is a kind of Schroedinger's box problem today, carbon footprint significantly
in which we won't know the actual savings to the environment until someone actually observes--or
measures--it” – James Urquhart (Product Marketing Manager of Cloud Computing, Cisco
Systems) “ Green cloud as a concept depends on the
"Cloud doesn't save power but displaces it. Ultimately, roughly the same power is drawn from the ability of Cloud providers to meet their
grid, just by different companies. So it's no greener. Cloud is more about dealing with company- increasing demands through renewable sources
specific issues than planetary ones” – Andy Lawrence (Research Director, 451 Group) of energy
Note: 1 Based on 167 customer responses from email Survey conducted by Rackspace Hosting globally in 2009; Comment and Views include key snippets
Source: SysCon Website; ComputerWeekly Website; GreenBiz Website; Rackspace Hosting Survey Report; Greenpeace Report; CIO Website
December 2010 | Copyright © 2010 Grail Research, LLC 20
Foundations
Obstacles and
of Cloud Future of Cloud
Considerations
Over the last few years, start-ups and small businesses have proposed innovative solutions to mitigate the
risks associated with cloud computing, and are competing with leading players in the Cloud space
“ “I believe that Cloud computing is a powerful trend – the next platform shift in computing. It will profoundly change the
way organizations do their computing. Proof is in the fact that major vendors like IBM, Google, and Microsoft are
investing tens of billions of dollars in building out their Cloud infrastructures. Those who characterize Cloud computing
as mostly hype have short memories. It was barely a decade ago that many people characterized the Internet as
mostly hype” – Bernard Golden (CEO, HyperStratus)
“So, in terms of the first movers and the environment now, it’s going to look very different. Anybody who carved out
some space right now and some lead in the market in Cloud shouldn’t feel too comfortable about their position,
because there are companies we don’t even know about at this point, that are going to be fairly pervasive and have a
lot to say about IT five years from now” – Jim Reavis (Executive Director of Cloud Security Alliance (CSA), and
President, Reavis Consulting Group)
“Password resetting and other security mechanisms in the Cloud are always going to be a weak link, as long as user-
friendliness comes ahead of security in Cloud computing beauty stakes. Expecting regular joes to whip out a two-
factor authentication device for use with a Cloud-driven service just isn’t realistic. It’s not going to happen” – Andy
“
Cordial (MD, Origin Storage)
“Customers are increasingly looking for ways to take advantage of the flexibility
and new services in the public cloud and want to extend the security and
control of their private clouds to this new environment…TriCipher brings to
VMware important authentication and identity technologies that will accelerate
our delivery of new solutions for hybrid cloud integration and end user
“VMware delivers “TriCipher offers secure computing” – Brian Byun (VP & GM of Cloud Services and Applications,
virtualization and cloud cloud access VMware)
infrastructure solutions management with easy-
that enable IT
organizations to energize
+ to-deploy, powerful
identity solutions that
“TriCipher has been a pioneer in the field of identity and access management
as a service, providing secure authentication and seamless single sign on
businesses of all sizes” – address today's pressing access to over 3,000 public and private Web and SaaS applications…We are
VMware Website business problems” – excited to join the VMware family and further build on our foundational
TriCipher Website technology to fulfill VMware’s cloud and end user computing vision” – John De
Santis (Chairman & CEO, TriCipher)
“The other major shift impacting Intel’s core market is the trend toward Cloud Computing,
…. So the acquisition of McAfee could do three things for Intel:…It provides the capability
for Intel to develop security within a cloud computing infrastructure” – Pat Clawson
(Chairman & CEO, Lumension)
Aug 2010: "With Fortify’s leadership in static application security analysis combined with
HP’s expertise in dynamic application security analysis, organizations will have a best-in-
class solution to improve the security of their applications and services” – Bill Veghte
(Executive VP of Software and Solutions, HP)
Jul 2010: "With BigFix software integrated with IBM software offerings, IBM clients will be
able to more easily manage and secure their PCs and laptops, a complex task as the costs
and risks associated with security threats continue to grow” – Steve Robinson (GM of
Security Solutions, IBM)
Sep 2006: “Information security continues to dominate the spending intentions of CIO’s
around the world. The battlefront in security has quickly shifted from securing the network
perimeter to protecting and securing the information itself—wherever that information lives
and wherever it moves” – Joe Tucci (Chairman, President & CEO, EMC)
CloudProof will detect and prove security violations across four The Advanced Encryption Scheme applies advanced logic in
storage characteristics encrypting and decrypting to provide a secure Cloud environment
Off-Premise On-Premise
Synchronization
Source: BusinessWeek Website; AllenPort Website; Digi-Data Website; CTERA Website; Egnyte Website; TechcrunchIT Website; M86Security Website;
CRN Website
December 2010 | Copyright © 2010 Grail Research, LLC 25
Foundations
Obstacles and
of Cloud Future of Cloud
Considerations
A “
An ecosystem of Cloud service
evaluators, aggregators, and integrators
“Some compliance requirements demand that relevant data be encrypted both at
will emerge to address growing customer
rest and in transit. Many of the cloud providers do not support that” – Chenxi
concerns and potential business
Wang (Ph.D., Principal Analyst, Forrester)
opportunities. Cloud computing presents
Improved an opportunity to monetize open source
Compliance and “Customers will care more about service level agreements than the brand name applications/tools
Service-level of technology components. …Integration will emerge as the key enabler and
choke point” – R. ‘Ray’ Wang (Partner, Altimeter Group)
Agreements
IT managers are optimistic about Software
as a Service (SaaS) being the key source
of future efficiency gains
B
Evolving
“Service providers will compete not just on price, but scalability, efficiency, and
SLAs” – Stephen Fosket (Recipient of Microsoft MVP award)
Mid-size companies are more likely to
adopt Cloud services over the next few
“…Emerging Cloud based business models like gaming as a service, content
Business Models driven clouds, cloud computing can help monetize open source software…” – years, especially Infrastructure as a
Krishnan Subramanian (Chief Technologist/Advisor, CloudsDirect) Service (IaaS)
C
concerned about flexibility, control, and
clients or be acquired by others providing multiple cloud service offerings, as
growth from cloud computing services,
clients will not want to manage an endless stream of cloud service providers for
rather than security
every workload they outsource” – Ray DePana (Industry Consultant, NSF1)
Integrated/
Customized By 2012, cloud computing is predicted to
Service Offerings
“From a strategic differentiation point of view, organizations must enhance
product offerings with services, improve the customer experience with loyalty
top of mind, and tailor personalized experiences that support self-service
“ gain widespread acceptance with
corporate data centers as 20% of
businesses globally are expected to own
options and mobility” – R. ‘Ray’ Wang (Partner, Altimeter Group)
no IT assets
Note: 1National Science Foundation Initiative on Computational Thinking; Comment and Views include key snippets
Source: SoftwareInsider Website; Ulitzer Website; GestaltIt Website ;Forrester Report; SysCon Website; InfoWorld Website, Gartner Report; LinkedIn
December 2010 | Copyright © 2010 Grail Research, LLC 26
Foundations
Obstacles and
of Cloud Future of Cloud
Considerations
Hybrid architectures that offer encryption of data at the local or client level, prior
to transmission to the Cloud may offer a path forward for business consumption,
thereby combining the best of on-premise functionality with that of hosted
solutions for these on-demand services
If you are evaluating a Cloud initiative, always assess your company’s readiness, measuring the cost and
benefit for your business within the context of the competitive landscape. Consider:
What are the direct business benefits of Cloud for my company? Why would I ‘rent’ rather than ‘own’?
Will a Cloud solution support my business needs, or am I losing functionality for a perceived price benefit?
How does my solution provider’s roadmap align with my business needs?
How are my Cloud solution providers establishing standards and maintaining the security and privacy of my
information and by extension, my clients’ information?
What are my competitors doing in this space? Are they pursuing private, public, or hybrid initiatives?
Note: 1Grail interviews with Bernard Golden (CEO, HyperStratus); Chenxi Wang (Ph.D., Principal Analyst, Forrester)
Source: Grail Research Analysis
December 2010 | Copyright © 2010 Grail Research, LLC 27
For More Information Contact:
Jocelyn DeGance Graham
(jdgraham@grailresearch.com)