Click here to close now.

Welcome!

Microservices Journal Authors: Pat Romanski, Liz McMillan, XebiaLabs Blog, Elizabeth White, Louis Evans

Related Topics: Cloud Expo, Java, Microservices Journal, Linux, Web 2.0, Security

Cloud Expo: Article

Making BYOC Work for Your Network

Similar to BYOD, this concept of bring-your-own-cloud (BYOC) is not going anywhere

The proliferation of cloud-based applications for the enterprise grows each day, and more and more professionals have grown dependent on these apps as the consumerization of IT flourishes in today's mobile enterprise. With the consumerization of IT, employees have become their own IT experts and demand that their IT departments add cloud services or enable them to use a particular app with the corporate network. IT departments, naturally, want to use the latest technologies to make the entire company more efficient and productive - and they see how the cloud can help accomplish this. What employees don't often see is that there are roadblocks to rolling out a new service or enabling an app to work with the network. Everything from budget to security to integration issues may cause the IT department to turn down the requests. However, unlike in the past, employees now have the power and the means to just use these services anyway, without IT's approval.

Similar to BYOD, this concept of bring-your-own-cloud (BYOC) is not going anywhere. Just think - it's incredibly easy for employees to access preferred technology offerings on a mobile or personal device, but it's still on the company network. Just download it, watch a YouTube video on how to make it work and voila - you have your cloud service. Any professional with a smartphone is enabled by cloud, social computing, analytics and mobile - and wants to transfer that experience seamlessly between their personal and professional computing.

This obviously poses a huge problem for the company network. IT staff either doesn't know this happened, or is forced to quickly address network and security issues, often leading to Band-Aid fixes. Results from Forrester's Forrsights Workforce Employee Survey, Q4 2012 indicate that at least 85 percent of employees use phone/tablet applications and web-based services, which is putting corporate information security under serious threat. Just to start, BYOC could hypothetically:

  • Denigrate the network - Deploying cloud technologies and operating models muddies the role that networking plays. Further, the impact of the cloud on the networks may not always be clear, and while the network is indeed important to cloud computing, the network also must change in order to facilitate these preferences. In a hybrid environment, the relationship and connection between a user's cloud and the provider's network must be secure - but the structure should be in place beforehand. The bottom line is, no network means no cloud - without networks, users cannot access their cloud services.
  • Challenge traditional security practices - It's really hard to ensure that information on employee-owned hardware and software is secure. For security professionals, BYOC seems like a nightmare. Personal devices are getting smarter and are better able to store and do more with corporate data, especially with the proliferation of personal cloud storage like Evernote, Amazon S3 and even Facebook. They also become a bigger target for hackers.
  • Introduce viruses - In BYOC environments you will inevitably have one employee who leisurely browses the web, opens email attachments, stores phantom files, freely clicks on links, and can't - or rarely - updates their security software. Without a policy in place, this is a veritable virus breeding ground.
  • Expose critical company data over unsecure networks and devices - This one seems pretty obvious, right? Downloading sensitive company files to an iPad, saving it to iCloud, and then connecting to the Starbucks Wi-Fi network down the street is not an ideal scenario - but it's a likely one.

Where does an enterprise start? The pros and cons are clear, and while it's important in this day and age to be accommodating and supportive of the innovative models that professionals take to accomplish their work, day-in and day-out, it's also very important to have a policy and framework in place that keeps all constituents on the same page while living on the same network. Let's start there - what frame of mind when devising a BYOC policy is reasonable and will be accepted by employees?

It's important to have a solid understanding of the stage at which cloud applications have infiltrated the organization. Once an organization understands the true level of cloud adoption across the board, they can better understand the true implications for their network and security, and how critical an organization-wide policy is to institute rules and regulations.

Network Monitoring and Inventory
Solutions exist that will take a complete look at your network and take stock of what is connected to your network (wired and wireless). It will know who owns it, what kind of memory it has, if and what software is installed and running, user information, network configurations and more. This is step one in your diagnosis, but also important throughout to keep track of the state of your network and to dissuade rogue users.

From there, your IT organization can determine how to protect itself from this phenomenon. Users are both the champions for this, as well as the weakest link - they likely own the device and they likely own the storage and access of the corporate data - so it's most important to invest in their knowledge, understanding and commitment to the policy.

Train and Instruct
Let employees know that they are responsible for their devices and cloud service from a cost and upkeep perspective, but also for what happens as a result of any personal computing or professional computing over personal assets. If an employee is not a good fit for any BYOC policy, such as a legal professional, instruct them of a revised policy.

Regardless, physical training of employees should happen over digital programs that they can quickly skip through and provide a digital signature without fully understanding or comprehending the responsibility that is in their hands - literally.

Security, Security, Security
Many companies are aware of how to secure devices that are introduced onto the network. For instance, there are a plethora of mobile device management solutions available that secure, monitor, manage and support mobile devices deployed across a corporate network. But for the cloud, to secure data and applications, it's important to invest in solutions with built-in data loss prevention (DLP), giving users an encrypted storage space on the mobile device to safely store business critical data.

For the network, there are a variety of network access control solutions that will give administrators the ability to enforce role-based access. In some cases, these types of solutions might just be viewed as Band-Aid fixes to a larger problem. Depending on your organization, however, these can be good first steps, building up to the implementation of a more holistic hybrid cloud environment that offers employees a full-scale cloud solution to support such bandwidth.

The bottom line, you must be in the know - you must know where your network stands at all times; you must know what your employees want from a cloud perspective; you must know what they currently have from a cloud perspective; and you must know what the best path is to take for your organization - be that a six-month path of quick-fixes and BYOC policies, or a full-fledged cloud offering that puts your mind at ease and keeps your employees happy.

More Stories By Paul Diamond

Paul Diamond is Technology Sales Engineer at Markley Group. He comes to Markley Group with over 30 years experience in various technology roles, most of them in the Banking and Financial Services sectors. Prior to joining Markley Group, he spent several years at Brown Brothers Harriman (BBH) where he served as infrastructure manager, chief technologist and project manager. While there, he lead a Strategic Planning and Innovation team charged with creating both short and long term strategic technology plans to consolidate data centers, create regional operations centers and build data storage and archival operations plans.

Paul is an innovative thinker, known for being an early adopter of trends like VOIP, which he brought to BBH in 2005 to lessen costs while improving overall service and coverage capabilities.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@MicroservicesExpo Stories
of cloud, colocation, managed services and disaster recovery solutions, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. TierPoint, LLC, is a leading national provider of information technology and data center services, including cloud, colocation, disaster recovery and managed IT services, with corporate headquarters in St. Louis, MO. TierPoint was formed through the strategic combination of some of t...
SYS-CON Events announced today that Soha will exhibit at SYS-CON's DevOps Summit New York, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Soha delivers enterprise-grade application security, on any device, as agile as the cloud. This turnkey, cloud-based service enables customers to solve secure application access and delivery challenges that traditional or virtualized network solutions cannot solve because they are too expensive, inflexible and operational...
There's a real buzz about microservices and containers in the application development and DevOps communities, and of course these are topics we've been talking about a great deal lately here at XebiaLabs too. Microservices and containers offer many attractive features, not least the potential for enhanced flexibility, and a robust architecture based on best-fit services. What we at XebiaLabs are really interested in is how organizations can effectively deliver microservices-based apps to bett...
SYS-CON Events announced today that Vicom Computer Services, Inc., a provider of technology and service solutions, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. They are located at booth #427. Vicom Computer Services, Inc. is a progressive leader in the technology industry for over 30 years. Headquartered in the NY Metropolitan area. Vicom provides products and services based on today’s requirements...
SYS-CON Events announced today that Tufin, the market-leading provider of Security Policy Orchestration Solutions, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. As the market leader of Security Policy Orchestration, Tufin automates and accelerates network configuration changes while maintaining security and compliance. Tufin's award-winning Orchestration Suite™ gives IT organizations the power and a...
Today, the demand for new applications is growing at an unprecedented rate throughout lines of business and across industries. Customer expectations for mobile and e-commerce capabilities are transforming software development speed and quality into a competitive differentiator for even the most unlikely businesses. For existing software development shops, the proliferation of platforms, increasing need for total global uptime, and accelerating pace of industry disruption by fast-paced startups h...
SYS-CON Events announced today that MangoApps will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY., and the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. MangoApps provides private all-in-one social intranets allowing workers to securely collaborate from anywhere in the world and from any device. Social, mobile, and eas...
SYS-CON Events announced today that Cloudian, Inc., the leading provider of hybrid cloud storage solutions, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Cloudian, Inc., is a Foster City, California - based software company specializing in cloud storage software. The main product is Cloudian, an Amazon S3-compliant cloud object storage platform, the bedrock of cloud computing systems, that enables c...
Change becomes the central principle of today’s enterprises, and thus business agility becomes the most important characteristic our organizations must exhibit. Agile Architecture lays out a best practice approach for achieving this agility – and thus drives and coordinates the other revolutions, as both digital and DevOps are about being able to deal with change better as well.
What exactly is a cognitive application? In her session at 16th Cloud Expo, Ashley Hathaway, Product Manager at IBM Watson, will look at the services being offered by the IBM Watson Developer Cloud and what that means for developers and Big Data. She'll explore how IBM Watson and its partnerships will continue to grow and help define what it means to be a cognitive service, as well as take a look at the offerings on Bluemix. She will also check out how Watson and the Alchemy API team up to off...
Thought experiment: let’s say your app gets a message from somewhere, perhaps from another app, but you don’t know from where. The message contains the number 47 but no other information. What should your app do with the message? The answer: nothing. There’s no way for your app to make any sense out of a single datum with no context, no additional information or metadata about the datum itself. Now, let’s scale up this thought experiment to a data lake. There are a few common definitions o...
The 17th International Cloud Expo has announced that its Call for Papers is open. 17th International Cloud Expo, to be held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, brings together Cloud Computing, APM, APIs, Microservices, Security, Big Data, Internet of Things, DevOps and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding bu...
The 5th International DevOps Summit, co-located with 17th International Cloud Expo – being held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the...
The concept and subsequent adoption of 'Containerization'' is growing at a rapid speed with the support of almost every other major player in the industry. This concept is much more efficient than the Virtualization which has been a major option for Infrastructure optimization in the past decade. The following factors distinguish a Container from a Virtual Machine. Containers contain Only the Application Specific libraries and binaries. They do not include a guest operating system. Rather ...
How do you securely enable access to your applications in AWS without exposing any attack surfaces? The answer is usually very complicated because application environments morph over time in response to growing requirements from your employee base, your partners and your customers. In his session at 16th Cloud Expo, Haseeb Budhani, CEO and Co-founder of Soha, will share five common approaches that DevOps teams follow to secure access to applications deployed in AWS, Azure, etc., and the frict...
As we recently previewed (read more about our London PoP in Jesse's post), Blue Box is opening a new Data Center in London, but hadn't announced the provider. Today we're excited to partner with TelecityGroup, whom we've selected as our data center partner in London. We chose their Powergate location, which is one of the U.K.'s most advanced, flexible and energy efficient carrier-neutral data centres. Why does that matter to you? Well, when customers choose Blue Box, they're trusting us with ...
Cloud Expo New York is happening from June 9 - 11. This event brings together the worlds of Cloud Computing, DevOps, IoT, WebRTC, Big Data and SDDC. We hope to see you there-members of the Blue Box team will exhibit in booth 218 next to the DevOps area. Plus, our Chief Product Officer, Hernan Alvarez, will present his talk "The Cloud Has a Down-and-Dirty Lining" as part of the Operations track in the DevOps Summit portion of the event on June 9 at 11 am. Learn more about his session her...
SYS-CON Events announced today that Column Technologies, a global technology solutions company, will exhibit at SYS-CON's DevOps Summit 2015 New York, which will take place June 9-11, 2015, at the Javits Center in New York City, NY. Established in 1998, Column Technologies is a leader in application performance and infrastructure management for commercial and federal markets. The company is headquartered in the United States, with a diverse and talented team of more than 350 employees around th...
Financial services organizations were among the earliest enterprise adopters of cloud computing. The ability to leverage massive compute, storage and networking resources via RESTful APIs and automated tools like Chef and Puppet made it possible for their high-horsepower IT users to develop a whole new array of applications. Companies like Wells Fargo, Fidelity and BBVA are visible, vocal and engaged supporters of the OpenStack community, running production clouds for applications ranging from d...
Operationalizing the network continues to be a driving force behind DevOps and SDN. The ability to solve real problems using programmability to automate and orchestrate infrastructure provisioning and configuration across the application release process remains the hope for many interested in one or the other - and often times both. A recent Avaya sponsored, Dynamic Markets survey (reg required) dove deep into the demesne of SDN and found that many of the problems companies have - and expect ...