Explores three ways to help development teams bear the burden of security: use pen test results to harden the application, leverage service virtualization for security scenarios, & adopt policy-driven development to help engineers understand and satisfy management’s security expectations. The move to the cloud brings a number of new security challenges, but the application remains your last line of defense. Engineers are extremely well poised to perform tasks critical for securing the application-provided that certain key obstacles are overcome.
SYS-CON Events announced today that the BigData-Startups, the online Big Data knowledge platform, has been named “Association Sponsor” of SYS-CON's 14th International Cloud Expo® and 5th International Big Data Expo,, which will take place on June 10–12, 2014, at the Javits Center in New York City, New York, and the 15th International Cloud Expo® and 6th International Big Data Expo, which will take place on November 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
"At InMage we are enabling the hybrid cloud. Cloud presents a lot of opportunities but there is no vehicle to take services into the hybrid cloud," noted Murali Nambiar, Sr. Product Manager for Backup and DR Products at InMage, in this SYS-CON.tv interview at the 13th International Cloud Expo®, held Nov 4–7, 2013, at the Santa Clara Convention Center in Santa Clara, CA. Cloud Expo® 2014 New York, June 10-12, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading Cloud industry players in the world.
SYS-CON Events announced today that CloudTimes has been named “Media Sponsor” of SYS-CON's 14th International Cloud Expo®, which will take place on June 10–12, 2014, at the Javits Center in New York City, New York, and the 15th International Cloud Expo®, which will take place on November 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA. CloudTimes is the premier source for thought leadership and the latest news on Cloud Computing. We are an international group of Cloud Computing experts and write on topics covering SaaS, PaaS, IaaS, Cloud Security, Virtualization, Enterprise 2.0 Applications, Cloud Services, Cloud Marketing, Social Cloud, Mobile Cloud and everything related.
Disaster Recovery (DR) has typically only been used by organizations for applications deemed to be mission critical. This was because organizations didn’t want to incur the expense associated with DR for less important applications. Today, because of cloud computing, many organizations are considering the use of DR for as many applications as is essential for the business. DR in the cloud is relatively a new concept still and, like many technology trends we’ve seen so far, there's a lot of hype and misinterpretation out there. Multiple schools of thought exist on whether or not to implement DR in the cloud.
OpenXava is an AJAX Java Framework for Rapid Development of Enterprise Web Applications. In OpenXava you only have to write the domain classes in plain Java to get a web application ready for production.
We discussed my belief that the nines (99.99…%) are more marketing than the real deal today - What do you think? The market and tools used to measure your uptime immature or do not really exist. The concept of availability in the cloud is determined by the level of responsibility and liability that the vendors have for their customers. These notions include the ability to monitor, proactively fix and maintain continuous communication with users, giving them clear and genuine visibility into what exactly is going on and when the system is expected to return to normal. It is also necessary, here, to define the concept of downtime. At a very basic level, it is when the system is not available. However, the more precise answer depends on the criticality of specific features and components of an application or service. On that note, we are interested in hearing your point of view. First and foremost, it is essential to ask, what do you consider “downtime”? How do you approach the matter of downtime with your customers? How do you compensate, if at all? Maybe even before discussing compensation, let us ask how or if you measure downtime? If so, are you able to calculate your own availability over the past week, month, or year? With your help, we can gain even greater insights on the topic.
An effort to solve data source preparation in reporting tool developing. Data sources cover the result set of SQL queries or stored procedures, and the 2D table from the text or Excel files. Owing to the technical competence or versioning, various reporting tools may only support a single data source, such as JasperReport, Quiee, BIRT, and Crystal Report.
"Lanlogic has been around since 1995 and we focus on helping customers that are traditionally less technical and need someone who’s an IT consultant, a trusted business adviser, to help them evaluate their needs," explained Joe Foos, Director of Sales & Marketing at Lanlogic, in this SYS-CON.tv interview at the 13th International Cloud Expo®, held Nov 4–7, 2013, at the Santa Clara Convention Center in Santa Clara, CA. Cloud Expo® 2014 New York, June 10-12, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading Cloud industry players in the world.
As UNIX users prepare to embrace industry-standard servers for production workloads, they have to confront some fundamental choices about how to best match the capabilities that they have come to expect from UNIX operating systems. While both Red Hat Enterprise Linux and Windows Server now have the scalability and reliability necessary to host business-critical workloads formerly reserved for UNIX, the operational practices of the two systems diverge considerably. Windows Server has traditionally been optimized for ease-of-use by providing a highly integrated environment, minimizing the choices that administrators have to confront. By contrast, Red Hat Enterprise Linux is optimized for the traditional UNIX values of modularity and flexibility, giving administrators the option to customize their environments.
For some organizations, cloud computing can be a hard sell, even before you come to the question of how to handle cloud-computing security. Public cloud, private cloud, hybrid cloud, encryption, tokenization, data residency, privacy regulations – all are factors involved and the perceived effort can sometimes seem to overshadow the benefits. But just as cloud computing comes with a slew of demonstrated business benefits, so does effective cloud computing security. Included below are three specific benefits to implementing a cloud computing security system. 1. Regulatory compliance prevents costly fines. One of the most common reasons enterprises have for investing in cloud computing security is, of course, regulatory compliance. Heavily regulated industries like finance and health care – industries that handle the most sensitive personal information – must remain in compliance with relevant regional, national, and international laws, as well as with industry-specific standards. Failure to do so can come with a high price. In fact, banks that fail to comply with the PCI DSS requirements, for example, may face fines of anywhere from $5,000 to $100,000 per month, costs that tend to get passed downstream, resulting in higher costs for all, according to the PCI Compliance Guide’s FAQ.
"It's been a great show for NetIQ - we've had the opportunity to speak about how NetIQ is enabling the cloud - how we are allowing customers to get access to cloud services that enable service providers to deliver cloud services in a secure, compliant manner," explained Gary Ardito, Chief Architect for Cloud Service Provider Solutions at NetIQ, in this SYS-CON.tv interview at the 13th International Cloud Expo®, held Nov 4-7, 2013, at the Santa Clara Convention Center in Santa Clara, CA. Cloud Expo® 2014 New York, June 10-12, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading Cloud industry players in the world.
"ActiveState is focused on the cloud market with a product called Stackato, an enterprise private PaaS solution that allows enterprises to manage and deploy their own Platform as a Service offering," explained Bart Copeland, President & CEO of ActiveState Software, in this SYS-CON.tv interview at the 13th International Cloud Expo®, held Nov 4–7, 2013, at the Santa Clara Convention Center in Santa Clara, CA. Cloud Expo® 2014 New York, June 10-12, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading Cloud industry players in the world.
German telco EWE TEL has solved performance complexity across an extended enterprise billing process by using service virtualization, which improved applications performance and gained predictive insights into composite application services behavior. To learn more about how EWE is leveraging service virtualization technologies and techniques for composite applications, we recently sat down with Bernd Schindelasch, Leader for Quality Management and Testing at EWE TEL based in Oldenburg, Germany.
The world is going cashless – and USA Technologies will be there when it does. Their Knowledge Base Study shows an average 84% increase in cashless transactions sales at their secure cashless and wireless unattended POS terminals.
"We announced what we believe is a game-changing technology in storage. We introduced a new product called the Ultrastar He6 and we announced a technology called HelioSeal, which is the process of hermetically sealing helium inside the hard drive," explained Brendan Collins, VP of Product Marketing at HGST, in this SYS-CON.tv interview at the 13th International Cloud Expo®, held Nov 4-7, 2013, at the Santa Clara Convention Center in Santa Clara, CA. Cloud Expo® 2014 New York, June 10-12, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading Cloud industry players in the world.
"Since the acquisition Terremark has been getting closer and closer and tighter with Verizon and we have some joint projects underway. We're about to set the world on fire," noted Jim Anthony, VP of Sales Engineering at Verizon Terremark, in this SYS-CON.tv interview at the 13th International Cloud Expo®, held Nov 4-7, 2013, at the Santa Clara Convention Center in Santa Clara, CA. Cloud Expo® 2014 New York, June 10-12, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading Cloud industry players in the world.
As web applications and cloud services continue to proliferate, identity theft, cyber fraud, cyber bullying, and simple misuse of confidential information online expand to chronic levels. Yet cloud providers are expected to ensure high security while maintaining a convenient user experience. MasterCard and Visa spend over $1 billion each year to fight identity theft and web companies are increasingly the subject of class action lawsuits due to online security breaches. Still, hundreds of cloud applications and portals are being hacked monthly leaving millions of passwords and confidential records in the hands of cyber fraudsters. Recently, many cloud users have started to realize that security in the cloud is, indeed, a serious issue. This trend led ASPs, cloud providers, and enterprises to actively search for more convenient methods of securing the identity of their cloud users with strong authentication. While there are a number of such solutions in the market today, not all “strong” authentication methods are strong enough to stop hackers.
Many technologies have made their presence felt this year and continue to excite us with the promises they hold for the future. Cloud computing has now reached a stage where businesses are seriously experimenting and are starting to reap the transformational benefits it can deliver. If you are in the process of determining how and what to do to get the most out of cloud computing in 2014, then here are five key strategic points to get you started immediately. Cloud-centric design of your business - whether you are a software product vendor, service provider or even an enterprise business, a cloud-centric design of your product/service or IT-enablement practice highly outweighs any ‘incremental migration' roadmap. We've observed that organizations that take a very strategic shot at cloud-enablement are better placed than those that have jumped from one piecemeal project to another. Cloud-centric considerations, architecture and design principles help optimize the investment along with the end-customer service experience.
Identity Management (IDaaS) & Access Mgmt (SSO) solve similar but separate issues, but both serve as a cornerstone of an integrated security initiative. One of the biggest misconceptions in cloud security is the perception that identity management (IDaaS) and access management (SSO) are the same thing. They’re not. And it took a viewing of the famous Star Trek episode called Mirror Mirror for me to best illustrate and articulate the difference between the creation and management of a user account and credentialed rights and the funneled applications that entity is allowed to see. For those unfamiliar with the episode, it’s the one where Kirk is transported into an alternate universe and meets evil Spock (the one with the beard)...but more about that soon.
Our new survey tells us that up to 50% of online shoppers this year will use their mobile device. Good news is that most retail stores that have an online store now also offer a mobile version, e.g., http://m.gap.com, http://m.jcpenney.com, http://m.bestbuy.com. In the past years we have done a deep dive web performance analysis on the desktop versions of these sites and blogged about it. This year we took a look at the mobile sites and found some “terrible” website performance mistakes that will most likely frustrate the mobile shopper. The “highlights” (or lowlights) that we found are:
APM is entering into a period of intense competition of technology and strategy with a multiplicity of vendors and viewpoints. While the nomenclature used within its space has five distinct dimensions that elucidate its meaning, the very acronym of APM is in question: Application Performance ... Monitoring vs. Management. It's strange to think that we would not normally use monitoring and management synonymously, but when used in the APM vernacular they seem to be interchangeable. This may be a visceral response, but I see the APM idiom converging on itself and becoming a matter of expectations vs. aspirations.
Believe it or not, a fair number of people like my workshops on mobile strategy. The problem though is a fair number don't. Why? Sometimes developers come into my sessions, stay for 15 minutes and then leave. They were expecting to learn how to develop mobile apps, or how to secure and integrate them with back-office systems. They had no interest in learning about enterprise wide mobile strategies. Enterprise wide mobile strategies are increasingly a business and IT leadership issue. They involve brand, product and service strategies. They involve plant operations, logistics and transportation. They involve asset management, field operations and sales. Enterprise wide mobile strategies touch every corner of the business. Enterprise mobility is no longer an IT issue, or just a technical discussion. Enterprise mobility is a C level discussion today. Because of this mobile solution vendors must change their marketing strategies to address the needs of both business and IT decision makers rather than developers.
As we move closer toward everything-as- a-service (XaaS), the title “Internet of Agents” seems to fit what is really happening. Agents are systems and devices that sense what is going on, and they exchange information with and act on behalf of other agents and people in ways that ultimately result in useful services being performed. When we start to view the delivery of services as a distributed cooperative effort conducted by millions of agents, as opposed to the actions of a few dedicated and single-minded service platforms, we start to get a glimpse of the huge potential of the Internet of Agents. We also must face the challenge of keeping track of this expanding service universe: managing security and permissions, making the dynamic portfolio available and usable, and ultimately monetizing all of this and ensuring that each contributor to these increasingly complex value chains is compensated for the fragments of service capability provided.
“We see many companies looking to adopt BYOD strategies for employees, but few who are solely BYOD,” observed Milja Gillespie, Director of Product Marketing, Mobile Security, SAP, in this exclusive Q&A with Cloud Computing Journal. “Often, they offer corporate devices for certain types of workers for whom mobility is a core function and BYOD for others who may want to access business resources on a personal device but don't require it for productivity purposes.” Cloud Computing Journal: Describe for us a bit the recent growth of mobile, and the projected growth over the next few years. Milja Gillespie: According to a recent Infonetics Research survey, respondent organizations reportedly averaged approximately 9,000 devices on their networks, which is expected to grow to 20 percent by 2015, and about 2/3 of those enterprises surveyed allow their employees to bring their own devices into work and connect to the company networks today.