Wednesday, May 6, 2020

Cloud Computing Security Problem

Question: Discuss about the Cloud Computing Security Problem. Answer: Introduction: Using Cloud computing, the organizations can directly use the best in class softwares within a matter of time. These organizations do not need to pay for the installation, licensing fee of the software, implementation cost as well for the infrastructure cost. It is because the applications are already hosted at the third party server. Organizations just have to pay the operational cost based on the usage of the application. Cloud computing has arise due to increasing need of the organizations for using the IT applications on the go especially when cost of acquiring these applications and implementing them is very huge (Cheves, Uriarte, Westphall, 2011). In simple words, it means that applications are already hosted on server (referred as cloud) maintained by the service provider and whoever wants to use the software can pay and use them. Although, it is not that straight forward as hosted applications needs to be configured also as per business requirement but this is the concept. To understand it better, assume there are 2 ways to use electricity at offices, either organization should generate electricity or to buy the electricity delivered by the power grids. In this case, most organizations will want to avoid generating electricity to avoid unnecessary overheads and efforts and prefers to buy electricity so that they can focus on their core competencies. Similar is the concept of cloud computing whe re organizations do not need to spend much effort on the IT functions and its intricacies to use the best of breed applications. (Source: https://azure.microsoft.com/en-in/) Cloud computing also makes perfect sense for the startup organizations that do not have time and resources to focus on their IT operations. They can simply take the service of cloud service providers and can focus on their dynamic work. Also, if the organizations are not happy with any Cloud service provider, it can opt for a different service provider. If organizations buys and implements the software, it will be very difficult to change the software and re implement it due to high costs specially if the software is ERP type but the task of changing the cloud service provide will be quite easy. Also, Organizations will dont have to worry about upgrades, ant viruses, downtimes, virtualization, storage, networking while using the application. As a result, Cloud computing offers huge business advantage. Cloud computing also offers numerous other facilities like disaster recovery, automatic updates. Using Cloud computing, organizations can also offers its employees work from anywhere facility and thus save its regular office expenses. ABC Payrolls is a fictitious company who has locally hosted its payroll application for their customers (mostly small businesses, sole traders and individuals). You are required to prepare a report on the benefits and challenges for ABC Payrolls to migrate to a SaaS provider. ABC has hosted its payrolls internally for its customers and planning to migrate to a SAAS provider. There are lots of benefits for ABC to migrate to a SAAS provider however there will be challenges too. Benefits include: ABC does not need to maintain the license or renew the licensing cost. It can simply migrate to SAAS provider and thus pay based on the usage. Apart from it, ABC does not need to spend on the anti viruses, disaster recovery plan, networking, storage, downtime and other numerous things. Using SAAS, ABC customers can access the latest and best of breed features in payrolls application. ABC does not need to incur the cost of updating the application. In simple words, there is no maintenance required from ABCs side and thus there is huge cost benefit. Also, Scalability will not be issue for ABC going forward because it will be paying to the service provider based on the usage. If the users will increase, it will incur more costs. However, currently as payroll is hosted internally, it will be problem in terms of data storage or cache speed as number of users will increase. Using SAAS, ABC can also provide work from anywhere facility to its employee. Some of the issues are as follows: Applications that are hosted on service providers tend to upgrade quite frequently. As a result, there is 1 new expense of training the users on the upgrades frequently. Data privacy and security: Clouds are vulnerable to numerous by insiders as well as external attackers. Since clouds are storehouse of critical and confidential information like credit card information, they are always targeted by the attackers. As of now, huge research is going on so as to make cloud safer to provide its user more safer environment free from attacks (Almorsy, Grndy, Muller, 2010). Handling customizations: Although ABC payroll application looks standard only but if it is customized, then there can be issue in migrating to SAAS as clouds generally dont offer much customization. In that case, change in business process is required which is aligned with what is provided by cloud. It is also possible that presently as users are less ABC change its business process but later realized that it is not giving value to customers by using the standard application offered by the Cloud service provider. In that case, it has to revert back. Cloud service providers offers low customizations as they are interested more in economies of scale from different organizations (Almulla, Yeun, 2010). Legal issues: Payrolls generally have very confidential information as well critical data and there are different legal requirements in different countries (Lar, Liao, Abbas, 2011). It is very important for ABC to understand the legal requirement and take decisions accordingly. Any ignorance can attract huge penalty. For example, In some countries, there is legal requirement that Finance data should not go outside the country. Service provider can say that cloud is hosted in the country but they maintain many copies of the data at different parts of the world as part of their disaster recovery plan. In such cases, it can be a legal compliance issue. All such things should be discussed in length in advance to avoid any conflict later. ABC Payrolls might consider migrating to an IaaS service provider for their services. Thus, they have additionally requested a report on the differences between expanding current infrastructure on premise and adapting cloud infrastructure provided by an IaaS Provider. Your report needs to include the critical points, other than cost, that ABC Payrolls would need to consider in choosing to migrate services to a Cloud. There are many parameters that will be critical in deciding if ABC should consider using IAAS for infrastructure needs or expand current infrastructure. Expanding current infrastructure ma risk the under utilization of infrastructure If ABC plans to expand current infrastructure, it must plan for future at least for 4, 5 years and increase the capacity accordingly as it is makes sense however that also means that for some time, and their capacity will remain under utilized. It is also possible that once they have expanded, it is difficult to contract or downsize their infrastructure even if the country does not need it (Donald, Oli, Arockiam, 2013). Cloud computing provides very good solution to these problems. ABC only needs to pay for the usage and do not worry about under utilization of the capacity. With Cloud computing, ABC can easily plan to increase and decrease the usage of the services. However, if ABC payrolls is pretty sure about next 4,5 years on the number of users of its system and convinced that capacity will be fully utilized, it can also plan to expand existing infrastructure. How well ABC is managing its systems currently/ Will Cloud really add value This is also very important aspect of making a decision. ABC payrolls should analyze how comfortable they are in managing their own IT systems currently. Are their frequent outages, are customers happy and satisfied with them managing the systems. These are some of the questions ABC needs to introspect. If they are managing their systems pretty well and smoothly without many issues and there is not much difference between cost of expanding existing infrastructure and using SAAS, then expanding current infrastructure can also be preferred. However, if the ABC is finding it difficult to manage their IT systems and there are frequent customer complains, it should consider going on cloud. It should also analyzes how Cloud services will add value to their IT department in terms of data security, storage, safety from external attacks, easy of deployment of application and agility in the system. Is there any impact on customers if ABC decided to go for cloud? Does customers notice any chang e, does it add to customer delight or customer will remain unaware are some of the things that ABC needs to think before taking a decision. Data privacy, Security Data storage is important part of IAAS as the critical payrolls data and all such details will be stored on the server provided by clouds. In such cases, ABC needs to ensure if the cloud is shared by many organizations and if there is any impact of using the shared cloud. ABC needs to prepare the various risks associated with using IAAS and how the vendor is minimizing those risks (Okoro, Idowu, 2013). It is important to analyze the approach of the vendor in handling data security, privacy and disaster recovery plan. ABC should also check if there any legal requirements and if cloud usage is not conflicting with the legal requirements. Testimonials, Case studies ABC can also ask vendors for the case studies of similar organizations that have got benefitted by it and obtained some reference. It will really help to interact with the organizations that have already implemented IAAS. Though it is difficult that organizations share their internal details but they can definitely vouch for the credibility of the service provider. References Almorsy, M., Grundy, J., Mller, I. (2010, November). An analysis of the cloud computing security problem. InProceedings of APSEC 2010 Cloud Workshop, Sydney, Australia, 30th Nov. Almulla, S. A., Yeun, C. Y. (2010, March). Cloud computing security management. InEngineering Systems Management and Its Applications (ICESMA), 2010 Second International Conference on(pp. 1-7). IEEE. De Chaves, S. A., Uriarte, R. B., Westphall, C. B. (2011). Toward an architecture for monitoring private clouds.IEEE Communications Magazine,49(12), 130-137. Donald, A. C., Oli, S. A., Arockiam, L. (2013). Mobile cloud security issues and challenges: A perspective.International Journal of Electronics and Information Technology (IJEIT), ISSN, 2277-3754. https://azure.microsoft.com/en-in/ Lar, S. U., Liao, X., Abbas, S. A. (2011, August). Cloud computing privacy security global issues, challenges, mechanisms. InCommunications and Networking in China (CHINACOM), 2011 6th International ICST Conference on(pp. 1240-1245). IEEE. Okoro, U. R., Idowu, S. A. (2013). On the Cloud Web services: A Review.International Journal Of Computers Technology,9(2), 1020-1027.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.