0% found this document useful (0 votes)
0 views14 pages

Chapter 1 - Part 3

The document outlines the Cloud Computing Reference Architecture (CCRA) developed by NIST, which defines roles and responsibilities within the cloud ecosystem. It identifies key actors such as Cloud Services Consumers, Providers, Brokers, Auditors, Carriers, and Regulators, detailing their functions and interactions. Additionally, it emphasizes the importance of security and privacy measures across all layers of cloud services.

Uploaded by

threadhunter9
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
0 views14 pages

Chapter 1 - Part 3

The document outlines the Cloud Computing Reference Architecture (CCRA) developed by NIST, which defines roles and responsibilities within the cloud ecosystem. It identifies key actors such as Cloud Services Consumers, Providers, Brokers, Auditors, Carriers, and Regulators, detailing their functions and interactions. Additionally, it emphasizes the importance of security and privacy measures across all layers of cloud services.

Uploaded by

threadhunter9
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chap1:

Introduction to Cloud Computing

7
0
Part 3:
Cloud reference model : Role Based
Architecture

38
Cloud Computing Reference Architecture (CCRA) (NIST*)
▪ The CCRA developed by NIST is a framework that defines the roles and
responsibilities within a cloud computing ecosystem.
▪ It provides a standard model to understand, design, and discuss cloud systems,
ensuring consistent cloud service definitions.

72
Cloud Computing Reference Architecture (NIST*)

73
Actors’ Roles
▪ Cloud Services Consumer:
▪ A person or organization that maintains a business relationship with, and
uses service from, Cloud Providers.
▪ SLAs (QoS, security, remedies for performance failures) are required to
specify the technical performance requirements fulfilled by a cloud provider.

▪ Cloud Services Providers:


▪ A person, organization, or entity responsible for making a service available
to interested parties.
▪ Amazon Web Services, Microsoft Azure, Google Cloud Platform, IBM 74

Cloud, Rackspace,…
Actors’ Roles

▪ Cloud Services Providers:

75
Actors’ Roles (…)
▪ Cloud Brokers:

▪ Aggregation: enabling to consumers the consumption of cloud services via a


cloud application marketplace approved by the company

▪ Integration: facilitating the data exchange among cloud applications and on


premise applications to orchestrate business processes

▪ Customization: enhancing cloud services with security mechanisms (non-


compromised data) and Identity management services (manage user credentials)

▪ IBM Cloud Broker, RackNap, Odin Service Automation, Ubersmith, AppDirect


76
Actors’ Roles (…)
▪ Cloud Auditors:

▪ A party that can conduct independent assessment of cloud services, information system
operations, performance and security of the cloud implementation.

▪ Identify compliance requirements: corporate policies and standards, laws and


regulations (e.g., HIPAA) as well as customer service level agreements (SLA).

77
Actors’ Roles (…)
▪ Cloud Carrier:

▪ An intermediary that provides connectivity and transport of cloud services from


Cloud Providers to Cloud Consumers.

▪ Meetings constraints and SLAs

▪ Bridging the gap between networking and datacenters

▪ Securing communications among cloud actors (e.g., encrypting connections


between consumers and providers)

▪ Offering applications flexibility (centralized or decentralized)

78
Actors’ Roles (…)
▪ Regulators:

▪ The entities that ensure organizations are in compliance with the


regulatory framework. These can be government agencies,
certification bodies, or parties to a contract.

79
Architectural Components

▪ Service Deployment: public, private, community and hybrid.

▪ Service Orchestration: the composition of system components to support the


cloud providers activities.

▪ Arrangement, coordination and management of computing resources.

▪ Three layers: service layer, resource abstraction and control layer and physical resource layer

▪ Cloud Service Management: service-related functions that are necessary for the
management and operation of those services required by cloud consumers.

80
Architectural Components (…)

▪ Security: Cloud Computing systems need to address security requirements:

▪ Authentication, authorization, availability, confidentiality,

▪ identity management, integrity, audit, security monitoring,

▪ incident response, and security policy management.

▪ Security spans across all layers of the reference model, ranging from physical security to
application security.

▪ Security is not only under the responsibility of cloud providers, but also cloud
consumer, cloud carrier, cloud broker (if they are involved).

▪ Cloud auditor: audit and report security of cloud computing architecture and actors involved.
81
Architectural Components (…)

▪ Privacy: Effective and Secure collection, processing, communication, use and


disposition of personal information and personally identifiable information in the
cloud should be provided.

The involved parties/actors in cloud-based solutions are, in general, trusted and


assumed to access, manage, and share users’ information as envisioned.

 Data breaches could occur


 The confidential information could end-up being disclosed
 The sensitive data could be accessed by malicious/criminal minded users.

82
Conclusion

83

You might also like