Practical Guide to Cloud Service Agreements, Version 2.0
http://cloud-council.org/resource-hub.htm#practical-guide-to-cloud-service- agreements-version-2
June, 2015
- - PowerPoint PPT Presentation
Practical Guide to Cloud Service Agreements, Version 2.0 http://cloud-council.org/resource-hub.htm#practical-guide-to-cloud-service- agreements-version-2 June, 2015 The Cloud Standards Customer Council THE Customers Voice for Cloud Standards!
June, 2015
2
2011/2012 Deliverables
2013/2014 Deliverables
http://cloud-council.org
2015 Projects (partial)
3
Revision Highlights
made - SLA replaced by CSA
updated to reflect current market dynamics
Evaluating Cloud Service Agreements section have been updated to reflect current best practices
standards have been updated
CSCC whitepapers
4
Current Landscape
public cloud
terms
down to all customers
5
A reference to help enterprise IT & business decision
Understand roles and responsibilities
Evaluate business level policies
Understand service and deployment model differences
Identify critical performance objectives
Evaluate security and privacy requirements
Identify service management requirements
Prepare for service failure management
Understand the disaster recovery plan
Define an effective governance process
"Cloud service agreements are important to clearly set expectations for service between cloud consumers and
to decision makers on what to expect and what to be aware of as they evaluate and compare SLAs from cloud computing providers is critical since standard terminology and values for cloud SLAs are emerging but currently do not exist.“ Melvin Greer, Senior Fellow and Chief Strategist, Cloud Computing, Lockheed Martin
6
Considerations
responsibilities between the cloud service customer and the cloud service provider is critical
statements about activities and responsibilities of the various customer and provider subroles
and reporting incidents should be clearly stated in the CSA
Cloud Service Customer Cloud Service Provider Cloud Service Partner
Cloud service user Cloud service administrator Cloud service integrator Cloud service business manager cloud service administrator cloud service
manager cloud service business manager cloud service security & risk manager cloud service deployment manager network provider customer support & care representative inter-cloud provider Cloud service developer Cloud auditor Cloud service broker
Source: ISO/IEC 17789
7
Business Policies
Data Policies
8
Deployment Model
service agreement with internal users
multitenancy safe and effective
integration requirements between internal and external resources
Service Model
performance of the servers, network and data storage
and “deploy-based solutions”
standards like OASIS’ TOSCA
performance of the application
9
10
Evaluate Security
requirements, especially on data breaches
the unauthorized use of data
as IP range blocking, etc.
11
Evaluate Privacy
whose data is being stored?
apply?
backup, and retention?
regulations?
12
Considerations
services they use
13
Considerations
meet expected behavior
available
14
Considerations
face of disaster
15
Considerations
between customer and provider
compliance
agreement
16
Considerations
inaccessible copies of customer data
audit data
periods may be required by law
17
– To have an impact on customer use case based standards requirements – To learn about all Cloud Standards within one organization – To help define the CSCC’s future roadmap – Membership is free & easy: http://www.cloud-council.org/application
– Join one or more of the CSCC Working Groups
16
19
20