Top Banner
Cloud Based Business Continuity Murat Lostar
22

Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Jun 22, 2015

Download

Technology

Lostar
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Cloud Based Business Continuity

Murat Lostar

Page 2: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Continuity of

• Storage• Database

– SQL– NoSQL

• Application• Desktop• Network

People?• Business• IT

• Customers• Environment

Page 3: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Out of scope

• Overall reliability of cloud• Decision to move “the primary” on to the

cloud• Private cloud• Personal backup/DR in cloud

Page 4: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Business Continuity vs IT Continuity• Business Continuity:

capability of the organization to continue delivery of products or services at acceptable predefined levels following disruptive incident (Source: ISO 22301) Is about prevention – not just a cure

• Focused on critical business processes – not on particular assets or enablers like IT systems

• ICT Continuity: capability of the organization to plan for and respond to incident and disruptions in order to continue ICT services at an acceptable predefined level (Source: BS 25777)

Page 5: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Definitions

• (BCP / ICT Continuity)

• DR• RTO• RPO

• Cold standby (backups)

• Warm standby (disks)

• Hot standby (servers)

Page 6: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Principles of ICT Continuity

• Protect• Detect• React• Recover• Operate• Return

(Local / Primary site)(Manual or Cloud automation tools)

(Local + cloud) (Primary site)

(Plan before disaster!)

Page 7: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Cloud based delivery• SaaS – Software as a service (e.g. Salesforce, gmail,

GoToMeeting, Mailchimp)• PaaS – Platform as a service (e.g. Heroku, Force.com,

Google App Engine)• IaaS – Infrastructure as a service (e.g. AWS, Microsoft

Windows Azure)• DaaS – Desktop as a service (e.g. Dell, Citrix,

Deskstone)• …

Page 8: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Why prefer cloud for DR/BCP?• Cost: No Disaster -> Minimal costs• Elastic (to different structures + changes)

-> Cost Effective• Management Flexibility: No control <-> Full Control• World-class redundant facility• Up-to-date applications, defined by RTO, RPO• Cloud service provider support >

local staff + travel(Source: Cloud Security Alliance)

Page 9: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Datacenter Infrastructure Components & MaintenanceProduction• Applications

– License

• Servers– OS + Hypervisor (License)

• Storage– SAN– Primary Storage– Backup

• Network– Router– Firewall

• Disaster Recovery– Traditional

• Same as production?

– Cloud• Snapsot Storage only• Storage + DB and/or

App

Page 10: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Cloud Strategies for Continuity

• Use cloud services as backup (DR).• Use different cloud services for primary

and DR.• Use the same (DR ready) cloud service for

primary and DR.

Page 11: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

DR Strategies on cloud

• Backup & restore (encryption?)• Pilot Light– Running replicating database server (no app srv)

• Fully working low capacity standby• Multi site hot standby

Page 12: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

File Storage in cloud

• Physical (periodical) physical shipment• iSCSI Based Archiving/Sync• Backup to cloud

Page 13: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Database in cloud

• Offline file shipment• Backup & restore• Log shipment• DB Synchronization • Two phase commit

Page 14: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Applications in cloud

• Release management• Cloud awareness in SDLC

Page 15: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Risks with Cloud BCP• Security and privacy! • Change management • Adaptation of new technologies• Connectivity requirements• Activation

Page 16: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

A secure way to store data in cloud for DR• During normal operations

– Encrypt and ship data to cloud• In case of disaster

– Enable computing– Enter decryption key to servers & use

• Return to normal– Destroy decryption key on servers

• Change of provider– Destroy decryption key (& decommission service)

Page 17: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Is your cloud provider secure?Ask:• Certifications– SOC 1 Tyep 2 (SAS-

70)– ISO 27001– PCI-DSS– Others (HIPAA, etc)

• Physical– Two factor

authentication– Log, aduit

• HW, SW, Network– Change mgmt– COBIT

Page 18: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Will your cloud provider continue? Ask: • Level of redundancy

– N + 50%? N + 1? N x 2?• Cloud DRP in the redundant locations/power feeds, circuits,

networks• DR & BCP within contract• Steady state billing• Declared disaster billing• RPO, RTO options and costs• Regular DR tests

Page 19: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Cloud Based Continuity Testing• Remember KISS• Start small (unit testing)• Go big (with your own pace)• May aim full capacity & automatic failover– Include shutdown/disconnect primary site

Page 20: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Why not to prefer cloud for DR?• Data security/privacy concerns• Giving up too much control• Too much invested in current infra&staff• Cloud need to mature• Satisfied with existing infra

Source: Enterprise Strategy Group, 2011

Page 21: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Standards and References• ISO 22301• ISO 25777:2008 – Information and

Communications Technology Continuity Management: Code of Practice

• CloudSecurityAlliance.org• ISACA Journal 2011/2• Wikipedia.org/wiki/

Cloud_computing_architecture

Page 22: Cloud Based Business Continuity - Murat Lostar @ ISACA EUROCACS 2013

Thank You

Murat Lostar• Linkedin.com/in/lostar• www.lostar.com