{"id":7389,"date":"2017-04-19T10:00:22","date_gmt":"2017-04-19T18:00:22","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/04\/19\/news-1180\/"},"modified":"2017-04-19T10:00:22","modified_gmt":"2017-04-19T18:00:22","slug":"news-1180","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/04\/19\/news-1180\/","title":{"rendered":"Pragmatic Hybrid Cloud Security"},"content":{"rendered":"<p><strong>Credit to Author: Mark Nunnikhoven (Vice President, Cloud Research)| Date: Wed, 19 Apr 2017 17:48:49 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"169\" src=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-300x169.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-300x169.jpg 300w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-768x432.jpg 768w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-1024x576.jpg 1024w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-640x360.jpg 640w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-900x506.jpg 900w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-440x248.jpg 440w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-380x214.jpg 380w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682.jpg 1280w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>It\u2019s easy to get lost in a sea of marketing terms. Recently \u201cHybrid Cloud\u201d has bubbled up more and more. The good news here is that the term is an accurate and useful way to describe the reality that most organizations are facing\u2026and will continue to face for the foreseeable future.<\/p>\n<p>Unless you started your company today or in the past couple of months, you have a set of IT assets running somewhere. They aren\u2019t running themselves for free. You\u2019ve got an existing investment that you\u2019re going to want to get the most out of that you can . The cloud\u2014a dynamic environment that lets your innovate faster\u2014is the clear future.<\/p>\n<p>But the reality is that you\u2019re going to have to manage both environments for a while until you can sunset the existing assets. <b>This is the hybrid cloud.<\/b><\/p>\n<h2>Planning For Hybrid<\/h2>\n<p>The trap most organizations fall into is treating the two environments differently. Setting up unique tooling and processes for each.o make the hybrid cloud work, live by this simple rule, \u201cDo the work once.\u201d <\/p>\n<p>This isn\u2019t as easy as it sounds\u2014is it ever? On-premises environments tend to use a lot of manual processes and are divided into silos. In the cloud, processes are implemented in systems and automated workflows break down traditional silos (see: <a href=\"https:\/\/en.wikipedia.org\/wiki\/DevOps\"> DevOps<\/a>).<\/p>\n<p>The goal is to have one workflow regardless of the environment. Unfortunately, the reality is that you\u2019re going to have to make an exception for a few systems and areas on-premises. A lot of existing systems simply weren\u2019t designed with automation and integration in mind.<\/p>\n<p>Try to have as few exceptions as possible. Deploying and running a web server should work the same way for your teams on-premises and in the cloud, or at least as reasonably close to the same way as possible.<\/p>\n<h2>Tooling<\/h2>\n<p>One key driver for unification is a strong set of tools. Choosing cloud-first or \u201cborn in the cloud\u201d tools is a great way to start. These tools are typically designed with scalability and flexibility in mind. <\/p>\n<p>With the end state focused on unified processes, start by prioritizing tools that are going to move the needle the most for your organization. This will also help change your processes and update the skill sets for your teams.<\/p>\n<p>Start with tools in the following categories:<\/p>\n<ol>\n<li>Orchestration\u2028<\/li>\n<li>Monitoring &amp; analytics\u2028<\/li>\n<li>Security\u2028<\/li>\n<li>Build pipeline (CI\/CD)\u2028<\/li>\n<\/ol>\n<p>Orchestration is critical because it can provide a series of quick wins that ease everyone\u2019s workload. Tools like <a href=\"https:\/\/aws.amazon.com\/opsworks\/\"> AWS OpsWorks<\/a>, <a href=\"https:\/\/www.chef.io\/\"> Chef<\/a>, <a href=\"https:\/\/puppet.com\/\">Puppet<\/a>, and <a href=\"https:\/\/www.ansible.com\/\">Ansible<\/a>  are designed to help coordinate the deployment and maintenance of your environment. And they work just as well on-premises as in the cloud.<\/p>\n<p>Providing a set of early wins is critical to getting buy-in from on-premises teams. You\u2019re going to be making changes to their day-to-day workflows and eventually changing the structure of their teams. You need them on board.<\/p>\n<p>With that credibility established, you can start to move on to monitoring, security and the build pipeline. In each case, you\u2019re going to need a cloud-first tool that:<\/p>\n<ul>\n<li>can scale up and down\u2028<\/li>\n<li>has data flowing in and out in standard formats\u2028<\/li>\n<li>is programmable\u2028<\/li>\n<\/ul>\n<h2>Visibility<\/h2>\n<p>The tooling adjustment you make will provide a strong return on the effort invested. But they also have the added benefit of increasing your visibility into what\u2019s happening in your workloads.<\/p>\n<p>To take those efforts to the next level, you need to start to integrate data sources from your cloud provider. The advantage of the <a href=\"http:\/\/blog.trendmicro.com\/cloud-security-shared-responsibility-action\/\"> shared responsibility model<\/a>  is that you delegate day-to-day operations of some areas to your cloud service provider (CSP), but you often give up visibility into those layers.<\/p>\n<p>However in recent years, CSPs have made substantial efforts to provide visibility into those actions for your workloads. The challenge is that you need to configure your monitoring and analytics tools to consume these new data sources (another reason to go to cloud-first tooling).<\/p>\n<p>Each CSP provides their own version of these services but they basically work the same way. Using either a file drop or API, the CSP provides a series of data points for you to monitor the state of your workload. Sometimes these data series come in the form of traditional logs, but more often than not, it\u2019s a series of <a href=\"https:\/\/en.wikipedia.org\/wiki\/JSON\"> JSON documents<\/a> .<\/p>\n<p>JSON is easy to work with in any programming language (despite the name) and often means you\u2019re getting a much richer data set than traditional on-premises logs. No more parsing logs by spaces or tabs!<\/p>\n<h2>Automation<\/h2>\n<p>To make the tooling and visibility come together, you\u2019re going to need to push automation into every aspect of solution delivery. The cloud tends to lean towards automation, but traditional on-premises environments have always been a challenge to automate.<\/p>\n<p>That shouldn\u2019t stop you from trying andwill also serve as motivation to migrate to \u201call in\u201d on the cloud faster. <\/p>\n<p>Automating the cloud layer is relatively straight forward using the function as a service (FaaS) offering in your cloud of choice (<a href=\"https:\/\/aws.amazon.com\/lambda\/\">AWS Lambda<\/a> , <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/functions\/\"> Azure Functions<\/a>, or <a href=\"https:\/\/cloud.google.com\/functions\/\"> Cloud Functions<\/a>). Everything from a CSP is available via an API and FaaS makes it easy to glue these API calls together to create more value in your workload.<\/p>\n<p>Building on the foundations from your CSP environment, your orchestration tool allows you to automate your operating system, application and\u2014ideally\u2014security tools. It\u2019s this one two punch that provides \u201cone click deployment\u201d and other benefits to your teams.<\/p>\n<p>And while automation is a topic that\u2019s been covered extensively, one area that\u2019s often ignored is that when a workflow is automated, it can also be tracked. Ensuring that your automation scripts are tracked in source control not only provides the ability to manage changes but also a very strong audit trail.<\/p>\n<p>You can now replicate your environment at any point in time. Simply re-run the commit for the time in question. That\u2019s an extremely powerful tool to have for troubleshooting, scaling and compliance.<\/p>\n<h2>Hybrid Cloud Is The New Normal<\/h2>\n<p>To maximize your existing investments, you\u2019re going to be dealing with at least two environments for the foreseeable future. If you hedge your bets and start leveraging more than one CSP, you could be trying to co-ordinate three or more distinct environments.<\/p>\n<p>The best strategy to address any of these scenarios is the same, \u201c<b>Do the work once.<\/b>\u201d It\u2019s not a hard strategy to sell. No one wants to do more work than necessary!<\/p>\n<p>To make that work, you need to focus on unified tooling, gaining visibility in both environments and automating everything. The technology aspects of hybrid cloud are manageable with the right strategy. It\u2019s the cultural challenges that will take time and persistence.<\/p>\n<p>But both are worth it. The reality for everyone over the next few years is hybrid.Embrace it. Plan for it. Work each environment in order to maximize the benefits to your organization.<\/p>\n<p>As much as we\u2019d like to believe that you can simply migrate environments instantly, that\u2019s simply not true. Focusing on these three areas\u2014tooling, visibility, automation\u2014will make sure you don\u2019t get stuck with a massive legacy environment that stops you from innovating.<\/p>\n<hr \/>\n<p>[ <i>Editor\u2019s note:<\/i> The Trend Micro team is on-site at the AWS Summit in San Francisco where  <a href=\"https:\/\/twitter.com\/werner\">Werner Vogel\u2019s<\/a> has announced the new AWS Marketplace SaaS Contracts feature. Trend MIcro is proud to be a launch partner and now offers <a href=\"https:\/\/aws.amazon.com\/marketplace\/pp\/B06Y3XT5LZ?qid=1492621297568&amp;sr=0-4&amp;ref_=srh_res_product_title\">annual contracts for Deep Security as a Service<\/a> . This is a great solution to procurement for hybrid cloud deployments. Deploy in the AWS Cloud and protect assets in all of your environments\u2026with licensing taken care of your AWS bill. ]<\/p>\n<hr \/>\n<p><a href=\"http:\/\/blog.trendmicro.com\/pragmatic-hybrid-cloud-security\/\" target=\"bwo\" >http:\/\/feeds.trendmicro.com\/TrendMicroSimplySecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Mark Nunnikhoven (Vice President, Cloud Research)| Date: Wed, 19 Apr 2017 17:48:49 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"169\" src=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-300x169.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-300x169.jpg 300w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-768x432.jpg 768w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-1024x576.jpg 1024w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-640x360.jpg 640w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-900x506.jpg 900w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-440x248.jpg 440w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682-380x214.jpg 380w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/04\/iStock-528303682.jpg 1280w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>It\u2019s easy to get lost in a sea of marketing terms. Recently \u201cHybrid Cloud\u201d has bubbled up more and more. The good news here is that the term is an accurate and useful way to describe the reality that most organizations are facing\u2026and will continue to face for the foreseeable future. Unless you started your&#8230;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10413],"tags":[12010,11064,12023],"class_list":["post-7389","post","type-post","status-publish","format-standard","hentry","category-security","category-trendmicro","tag-aws","tag-cloud-computing","tag-hybrid-cloud"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7389","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=7389"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7389\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=7389"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=7389"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=7389"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}