Continuous Compliance model for Hybrid Multi-Cloud through Self-Service Orchestrator

Rajesh Rompicharla, B. P. V.
{"title":"Continuous Compliance model for Hybrid Multi-Cloud through Self-Service Orchestrator","authors":"Rajesh Rompicharla, B. P. V.","doi":"10.1109/ICSTCEE49637.2020.9276897","DOIUrl":null,"url":null,"abstract":"Cloud Computing offers instant Infrastructure for the needs of Application & Development teams, software development phase accelerated with the adaption of DevOps model. DevOps model key tenets of success are Self-Service, Permission to act, Guardrails and Trust. Since the current Cloud Computing trend is moving towards Hybrid Multi-Cloud the Multi-Tenant phenomenon as well geared up to meet the agile business needs. The Security team's strategy for DevOps, especially related to its Self-Service tenet needs an immediate review. According to the survey in 2019, around 90% of enterprises use some type of Cloud Service; around 50% already adapted Hybrid Multi-Cloud; still 67% security teams had lack of visibility into their cloud infrastructure, security and compliance. Attacks due to Misconfigured Cloud environments was the main cause of data theft Security Incidents. Popular Incidents related to Amazon about Facebook accounts leak and Microsoft about data theft related to Box accounts primary cause is misconfiguration of the concern parties. Hence, Post-Deployment Compliance checks does not suffice the needs of required Security for Hybrid Multi-Cloud environments. Continuous and Pre-Deployment Compliant Self-Service solution for Hybrid Multi-Cloud with appropriate design and implementation procedure is the objective of this paper.","PeriodicalId":113845,"journal":{"name":"2020 International Conference on Smart Technologies in Computing, Electrical and Electronics (ICSTCEE)","volume":"128 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-10-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 International Conference on Smart Technologies in Computing, Electrical and Electronics (ICSTCEE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSTCEE49637.2020.9276897","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Cloud Computing offers instant Infrastructure for the needs of Application & Development teams, software development phase accelerated with the adaption of DevOps model. DevOps model key tenets of success are Self-Service, Permission to act, Guardrails and Trust. Since the current Cloud Computing trend is moving towards Hybrid Multi-Cloud the Multi-Tenant phenomenon as well geared up to meet the agile business needs. The Security team's strategy for DevOps, especially related to its Self-Service tenet needs an immediate review. According to the survey in 2019, around 90% of enterprises use some type of Cloud Service; around 50% already adapted Hybrid Multi-Cloud; still 67% security teams had lack of visibility into their cloud infrastructure, security and compliance. Attacks due to Misconfigured Cloud environments was the main cause of data theft Security Incidents. Popular Incidents related to Amazon about Facebook accounts leak and Microsoft about data theft related to Box accounts primary cause is misconfiguration of the concern parties. Hence, Post-Deployment Compliance checks does not suffice the needs of required Security for Hybrid Multi-Cloud environments. Continuous and Pre-Deployment Compliant Self-Service solution for Hybrid Multi-Cloud with appropriate design and implementation procedure is the objective of this paper.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
通过自助服务编排器实现混合多云的持续遵从性模型
云计算为应用程序和开发团队的需求提供了即时的基础设施,随着DevOps模型的适应,软件开发阶段加快了。DevOps模式成功的关键原则是自助服务、行动许可、护栏和信任。由于当前的云计算趋势正在向混合多云发展,因此多租户现象也正在适应敏捷的业务需求。安全团队的DevOps策略,特别是与自助服务宗旨相关的策略,需要立即进行审查。根据2019年的调查,大约90%的企业使用某种类型的云服务;大约50%的企业已经采用了混合多云;仍有67%的安全团队缺乏对云基础设施、安全性和合规性的可视性。错误配置的云环境导致的攻击是数据盗窃安全事件的主要原因。流行事件涉及亚马逊的Facebook账户泄露和微软的数据盗窃相关的Box账户,主要原因是相关方的配置错误。因此,部署后遵从性检查不能满足混合多云环境所需的安全性需求。本文的目标是为混合多云提供一个具有适当设计和实现过程的连续和预部署兼容的自助服务解决方案。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Flower Classification using Deep Learning models An Unprecedented PSO-PID Optimized Glucose Homeostasis Improving elasticity in cloud with predictive algorithms A Second Order-Second Order Generalized Integrator for Three - Phase Single – Stage Multifunctional Grid-Connected SPV System Continuous Compliance model for Hybrid Multi-Cloud through Self-Service Orchestrator
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1