Finding a Framework for Hybrid Cloud Risk Management

Interoperability: A Much Needed Cloud Computing Focus

By G C Network | February 10, 2014

Cloud computing transitions information technology (IT) from being “systems of physically integrated hardware and software” to “systems of virtually integrated services”. This transition makes interoperability the difference between the success…

Managing IaaS and DBaaS Clouds with Oracle Released

By G C Network | February 6, 2014

Over the holidays I actually spent some time reviewing the newly released “Managing IaaS and DBaaS Clouds with Oracle Enterprise Manager Cloud Control 12c“. This book is a step-by-step tutorial…

Veterans 360: Helping Young Combat Veterans Succeed

By G C Network | February 5, 2014

Refusing to accept the 30 percent unemployment rate for California veterans between the ages of 18 and 24, Veterans 360 (V360) offers recently-separated combat veterans the opportunity for a solid…

Veterans 360 Paves the Way with Cloud Certification Training

By G C Network | February 3, 2014

In keeping with their mission to support young combat veterans’ transition into civilian life, Veterans 360 plans to launch a free Cloud Technology Certification training program. Vets360-Cloud will give veterans…

DBT-Data is a Force to be Reckoned With

By G C Network | January 27, 2014

DBT-Data further established itself in the data storage industry as a formidable force with the $35 million dollar purchase of the state of the art Cyber Integration Center on 1175…

2014 Federal Intelligence Summit – Washington, DC

By G C Network | January 10, 2014

DBT Data and Potomac Officers Club are excited to announce that Al Tarasiuk, CIO of the Office of the Director of National Intelligence (ODNI), will be part of an ICITE…

3rd Annual World Congress of Cloud Computing 2014

By G C Network | January 7, 2014

Today I am proud and honored to announce that I will be participating in this year’s 3rd Annual World Congress of Cloud Computing 2014! Highlighting the theme of “Chinese Dream…

NRRC Video Series – Video 8 : Raytheon R3 Decision Support Tool and Advanced Tactical System

By G C Network | December 23, 2013

In September, the NCOIC delivered the Geospatial Community Cloud (GCC) demonstration. Sponsored by the National Geospatial-Intelligence Agency, this demonstration showed how an interoperable, hybrid-cloud operating environment can be quickly enabled…

NRRC Video Series – Video 7 : Dave Boulos Demonstrates Bring-Your-Own-Device (BYOD) Management

By G C Network | December 20, 2013

In September, the NCOIC delivered the Geospatial Community Cloud (GCC) demonstration. Sponsored by the National Geospatial-Intelligence Agency, this demonstration showed how an interoperable, hybrid-cloud operating environment can be quickly enabled…

Just Pinched Myself ! Part of a “GovCloud Dream Team” !!

By G C Network | December 12, 2013

DBT-DATA provides reliable, flexible, and cost-effective data center solutions to federal, enterprise, and internet customers. With premier facilities in Ashburn, Virginia and the Cyber Integration Center in Harrisonburg, Virginia, they…

 (Sponsored by IBM. Originally published on Point B and Beyond)

Hybrid cloud is rapidly becoming essential to today’s information technology processes. This is why hybrid cloud risk management has become the keystone to many modern corporate strategies. To effectively manage this shift, leading enterprises are reorganizing how the business side of IT is accomplished. When this reality is coupled with the rising cost of poor cybersecurity, decisions often rise to the board level.

Threats that challenge cloud-based information systems can have adverse effects on organizational operations, organizational assets, employees and partners. Malicious entities can exploit both known and unknown vulnerabilities, compromising the confidentiality, integrity or availability of the corporate information being processed, stored or transmitted by those systems. In this environment, risk management must be viewed as a holistic activity that is fully integrated into every aspect of the business.

Establishing Standards for Hybrid Cloud Risk Management

The National Institute of Standards and Technology (NIST) offers a very good model for hybrid cloud risk management that groups activities into three categories based on the level at which they address the risk-related concerns. It divides activities and concerns into:

  • The organization level (tier 1);
  • The mission and business process level (tier 2); and
  • The information system level (tier 3).

Addressing these activities in reverse order, the NIST Risk Management Framework (RMF) provides a disciplined and structured process for integrating tier 3 enterprise information security with risk management activities. Since mission or business processes govern tier 2, those details generally lie outside the scope of general treatment. Tier 1 organizational level aspects are, however, at the heart of the organizational restructuring needed to deal with risk management within today’s hybrid IT environments.

One effective approach for addressing the tier 1 aspects of a cloud ecosystem is through the use of a hybrid IT operating model construct. This distributes tactical and operational risk management activities across a front, middle and back office. Generally referred to as a cloud service brokerage, organizational risk management activities are managed through:

  • A front office that accommodates IT service choice, automated provisioning and quick service delivery;
  • A middle office that holds responsibility for decisions that involve business operations and new IT service brokerage functions; and
  • A back office that integrates orders with service provider fulfillment, thus addressing IT supply chain risk management activities in order to ensure the continuous delivery of solutions from the organization’s cloud ecosystem.

More About Cloud Service Brokerage

The IT service brokerage function addressed here is in no way similar to the real estate or financial service broker function with which many are familiar. Far more than the single transaction service of these other broker types, IT service broker functions sit between the back office (operations) and the front office (user experience).

From that position, it is responsible for new IT business operations skills such as sourcing, procurement, packaging and billing. This continuous and ongoing function defines and executes board guidance with regard to the organization’s technology sourcing strategies. It also supports the creation of solution architectures that maximize the value of the multisourced hybrid IT investments while meeting business needs.

Cyberattacks are a threat to businesses everywhere. Executives, board members and IT professionals must strategically organize to address hybrid cloud risk management. While the RMF and business-specific risk management processes are excellent options for tier 3 and tier 2 issues, a front-middle-back office organizational construct can be used to effectively manage tier 1 and the operational risk of the hybrid IT ecosystem.

Cloud Musings

( Thank you. If you enjoyed this article, get free updates by email or RSS – © Copyright Kevin L. Jackson 2015)

Follow me at https://Twitter.com/Kevin_Jackson
Posted in

G C Network