|By Mamoon Yunus||
|December 30, 2009 05:00 PM EST||
OWASP AppSec DC 2009 had a compelling session that defined cloud taxonomies and the security implications associated with the cloud computing.
The three taxonomies that have become part of our vernacular are:
- Infrastructure as a Service (IaaS): Set of virtualized components that can be assembled to build a application. Amazon EC2, Rackspace, Opsource, and GoGrid are examples of IaaS where you can rent "virtual" hardware and software as a "pay-as-you-go" services. If you need 5 Linux servers running MySQL Database for 3 months, you'd subscribe to an IaaS provider and using their REST or Web service-based API (or command line if you're too cool) to provision, de-provision and monitor your instance.
- Platform as a Service (PaaS): A runtime environment for application developer to deploy their applications in their desired programming environments with production issues such as scalability, security and reliability already addressed by the Platform. Google App Engine, the support Java and Python is a good example of PaaS. Using PaaS developers can code applications locally on developer machines and push them to the cloud. The developed applications can automatically scale to millions of invocations and thousands of users. The developers do not have to concern themselves with managing threading, concurrency and load balancing issues for such almost unbound scalability.
- Software as a Service (SaaS): Fully functional application with potentially and API for external application integration. SugrarCRM, Netsuite and Salesforce.com are classic examples of SaaS in the CRM space. SugarCRM can be used as an fully functional enterprise CRM systems and can also be accessed through Web services APIs for integrating on-premise application. See for example: Web services Testing SugarCRM.
For more details on Cloud Taxonomies and Security, see Understanding Implication of Clouds on Application Security.
- [slides] #DevOps and Immutable Infrastructure | @CloudExpo @Botchagalupe
- [session] Composable Infrastructure | @CloudExpo @HTBase @Azure #AWS
- Partners @Interoute and @Rancher_Labs | @CloudExpo #DevOps #Serverless
- [session] Composable Infrastructure | @CloudExpo @HTBase #SDN #DataCenter
- An #AI-Defined World | @CloudExpo @ReneBuest #AiDI #ArtificialIntelligence
- The Top 150 Players in Cloud Computing
- i-Technology Predictions for 2007: Where's It All Headed?
- The Top 250 Players in the Cloud Computing Ecosystem
- The Future of Cloud Computing
- Cloud Expo New York Call for Papers Now Open
- The Five Characteristics of Cloud Computing
- The Next Chapter in the Virtualization Story Begins
- CIA was Headed to an Enterprise Cloud All Along: Jill Tummler Singer
- Deputy CIO of the CIA to Keynote 1st Annual GovIT Expo
- Are Enterprises Ready for Cloud Computing?