Welcome!

Microservices Expo Authors: Pat Romanski, Elizabeth White, Jason Bloomberg, Liz McMillan, Derek Weeks

Related Topics: @CloudExpo, Java IoT, Microservices Expo, Linux Containers, Agile Computing, Cloud Security

@CloudExpo: Article

Making BYOC Work for Your Network

Similar to BYOD, this concept of bring-your-own-cloud (BYOC) is not going anywhere

The proliferation of cloud-based applications for the enterprise grows each day, and more and more professionals have grown dependent on these apps as the consumerization of IT flourishes in today's mobile enterprise. With the consumerization of IT, employees have become their own IT experts and demand that their IT departments add cloud services or enable them to use a particular app with the corporate network. IT departments, naturally, want to use the latest technologies to make the entire company more efficient and productive - and they see how the cloud can help accomplish this. What employees don't often see is that there are roadblocks to rolling out a new service or enabling an app to work with the network. Everything from budget to security to integration issues may cause the IT department to turn down the requests. However, unlike in the past, employees now have the power and the means to just use these services anyway, without IT's approval.

Similar to BYOD, this concept of bring-your-own-cloud (BYOC) is not going anywhere. Just think - it's incredibly easy for employees to access preferred technology offerings on a mobile or personal device, but it's still on the company network. Just download it, watch a YouTube video on how to make it work and voila - you have your cloud service. Any professional with a smartphone is enabled by cloud, social computing, analytics and mobile - and wants to transfer that experience seamlessly between their personal and professional computing.

This obviously poses a huge problem for the company network. IT staff either doesn't know this happened, or is forced to quickly address network and security issues, often leading to Band-Aid fixes. Results from Forrester's Forrsights Workforce Employee Survey, Q4 2012 indicate that at least 85 percent of employees use phone/tablet applications and web-based services, which is putting corporate information security under serious threat. Just to start, BYOC could hypothetically:

  • Denigrate the network - Deploying cloud technologies and operating models muddies the role that networking plays. Further, the impact of the cloud on the networks may not always be clear, and while the network is indeed important to cloud computing, the network also must change in order to facilitate these preferences. In a hybrid environment, the relationship and connection between a user's cloud and the provider's network must be secure - but the structure should be in place beforehand. The bottom line is, no network means no cloud - without networks, users cannot access their cloud services.
  • Challenge traditional security practices - It's really hard to ensure that information on employee-owned hardware and software is secure. For security professionals, BYOC seems like a nightmare. Personal devices are getting smarter and are better able to store and do more with corporate data, especially with the proliferation of personal cloud storage like Evernote, Amazon S3 and even Facebook. They also become a bigger target for hackers.
  • Introduce viruses - In BYOC environments you will inevitably have one employee who leisurely browses the web, opens email attachments, stores phantom files, freely clicks on links, and can't - or rarely - updates their security software. Without a policy in place, this is a veritable virus breeding ground.
  • Expose critical company data over unsecure networks and devices - This one seems pretty obvious, right? Downloading sensitive company files to an iPad, saving it to iCloud, and then connecting to the Starbucks Wi-Fi network down the street is not an ideal scenario - but it's a likely one.

Where does an enterprise start? The pros and cons are clear, and while it's important in this day and age to be accommodating and supportive of the innovative models that professionals take to accomplish their work, day-in and day-out, it's also very important to have a policy and framework in place that keeps all constituents on the same page while living on the same network. Let's start there - what frame of mind when devising a BYOC policy is reasonable and will be accepted by employees?

It's important to have a solid understanding of the stage at which cloud applications have infiltrated the organization. Once an organization understands the true level of cloud adoption across the board, they can better understand the true implications for their network and security, and how critical an organization-wide policy is to institute rules and regulations.

Network Monitoring and Inventory
Solutions exist that will take a complete look at your network and take stock of what is connected to your network (wired and wireless). It will know who owns it, what kind of memory it has, if and what software is installed and running, user information, network configurations and more. This is step one in your diagnosis, but also important throughout to keep track of the state of your network and to dissuade rogue users.

From there, your IT organization can determine how to protect itself from this phenomenon. Users are both the champions for this, as well as the weakest link - they likely own the device and they likely own the storage and access of the corporate data - so it's most important to invest in their knowledge, understanding and commitment to the policy.

Train and Instruct
Let employees know that they are responsible for their devices and cloud service from a cost and upkeep perspective, but also for what happens as a result of any personal computing or professional computing over personal assets. If an employee is not a good fit for any BYOC policy, such as a legal professional, instruct them of a revised policy.

Regardless, physical training of employees should happen over digital programs that they can quickly skip through and provide a digital signature without fully understanding or comprehending the responsibility that is in their hands - literally.

Security, Security, Security
Many companies are aware of how to secure devices that are introduced onto the network. For instance, there are a plethora of mobile device management solutions available that secure, monitor, manage and support mobile devices deployed across a corporate network. But for the cloud, to secure data and applications, it's important to invest in solutions with built-in data loss prevention (DLP), giving users an encrypted storage space on the mobile device to safely store business critical data.

For the network, there are a variety of network access control solutions that will give administrators the ability to enforce role-based access. In some cases, these types of solutions might just be viewed as Band-Aid fixes to a larger problem. Depending on your organization, however, these can be good first steps, building up to the implementation of a more holistic hybrid cloud environment that offers employees a full-scale cloud solution to support such bandwidth.

The bottom line, you must be in the know - you must know where your network stands at all times; you must know what your employees want from a cloud perspective; you must know what they currently have from a cloud perspective; and you must know what the best path is to take for your organization - be that a six-month path of quick-fixes and BYOC policies, or a full-fledged cloud offering that puts your mind at ease and keeps your employees happy.

More Stories By Paul Diamond

Paul Diamond is Technology Sales Engineer at Markley Group. He comes to Markley Group with over 30 years experience in various technology roles, most of them in the Banking and Financial Services sectors. Prior to joining Markley Group, he spent several years at Brown Brothers Harriman (BBH) where he served as infrastructure manager, chief technologist and project manager. While there, he lead a Strategic Planning and Innovation team charged with creating both short and long term strategic technology plans to consolidate data centers, create regional operations centers and build data storage and archival operations plans.

Paul is an innovative thinker, known for being an early adopter of trends like VOIP, which he brought to BBH in 2005 to lessen costs while improving overall service and coverage capabilities.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@MicroservicesExpo Stories
Digital means customer preferences and behavior are driving enterprise technology decisions to be sure, but let’s not forget our employees. After all, when we say customer, we mean customer writ large, including partners, supply chain participants, and yes, those salaried denizens whose daily labor forms the cornerstone of the enterprise. While your customers bask in the warm rays of your digital efforts, are your employees toiling away in the dark recesses of your enterprise, pecking data into...
SYS-CON Events announced today that Men & Mice, the leading global provider of DNS, DHCP and IP address management overlay solutions, will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. The Men & Mice Suite overlay solution is already known for its powerful application in heterogeneous operating environments, enabling enterprises to scale without fuss. Building on a solid range of diverse platform support,...
You deployed your app with the Bluemix PaaS and it's gaining some serious traction, so it's time to make some tweaks. Did you design your application in a way that it can scale in the cloud? Were you even thinking about the cloud when you built the app? If not, chances are your app is going to break. Check out this webcast to learn various techniques for designing applications that will scale successfully in Bluemix, for the confidence you need to take your apps to the next level and beyond.
I had the opportunity to catch up with Chris Corriere - DevOps Engineer at AutoTrader - to talk about his experiences in the realm of Rugged DevOps. We discussed automation, culture and collaboration, and which thought leaders he is following. Chris Corriere: Hey, I'm Chris Corriere. I'm a DevOps Engineer AutoTrader. Derek Weeks: Today we're going to talk about Rugged DevOps. It's a subject that's gaining a lot of traction in the community but not a lot of people are really familiar with wh...
SYS-CON Events announced today that Peak 10, Inc., a national IT infrastructure and cloud services provider, will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. Peak 10 provides reliable, tailored data center and network services, cloud and managed services. Its solutions are designed to scale and adapt to customers’ changing business needs, enabling them to lower costs, improve performance and focus inter...
Wow, if you ever wanted to learn about Rugged DevOps (some call it DevSecOps), sit down for a spell with Shannon Lietz, Ian Allison and Scott Kennedy from Intuit. We discussed a number of important topics including internal war games, culture hacking, gamification of Rugged DevOps and starting as a small team. There are 100 gold nuggets in this conversation for novices and experts alike.
In 2006, Martin Fowler posted his now famous essay on Continuous Integration. Looking back, what seemed revolutionary, radical or just plain crazy is now common, pedestrian and "just what you do." I love it. Back then, building and releasing software was a real pain. Integration was something you did at the end, after code complete, and we didn't know how long it would take. Some people may recall how we, as an industry, spent a massive amount of time integrating code from one team with another...
SYS-CON Events announced today that DatacenterDynamics has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY. DatacenterDynamics is a brand of DCD Group, a global B2B media and publishing company that develops products to help senior professionals in the world's most ICT dependent organizations make risk-based infrastructure and capacity decisions.
With DevOps becoming more well-known and established practice in nearly every industry that delivers software, it is important to continually reassess its efficacy. This week’s top 10 includes a discussion on how the quick uptake of DevOps adoption in the enterprise has posed some serious challenges. Additionally, organizations who have taken the DevOps plunge must find ways to find, hire and keep their DevOps talent in order to keep the machine running smoothly.
Between the mockups and specs produced by analysts, and resulting applications built by developers, there exists a gulf where projects fail, costs spiral, and applications disappoint. Methodologies like Agile attempt to address this with intensified communication, with partial success but many limitations. In his session at 18th Cloud Expo, Charles Kendrick, CTO & Chief Architect at Isomorphic Software, will present a revolutionary model enabled by new technologies. Learn how business and devel...
Call it DevOps or not, if you are concerned about releasing more code faster and at a higher quality, the resulting software delivery chain and process will look and smell like DevOps. But for existing development teams, no matter what the velocity objective is, getting from here to there is not something that can be done without a plan. Moving your release cadence from months to weeks is not just about learning Agile practices and getting some automation tools. It involves people, tooling and ...
The notion of customer journeys, of course, are central to the digital marketer’s playbook. Clearly, enterprises should focus their digital efforts on such journeys, as they represent customer interactions over time. But making customer journeys the centerpiece of the enterprise architecture, however, leaves more questions than answers. The challenge arises when EAs consider the context of the customer journey in the overall architecture as well as the architectural elements that make up each...
Much of the discussion around cloud DevOps focuses on the speed with which companies need to get new code into production. This focus is important – because in an increasingly digital marketplace, new code enables new value propositions. New code is also often essential for maintaining competitive parity with market innovators. But new code doesn’t just have to deliver the functionality the business requires. It also has to behave well because the behavior of code in the cloud affects performan...
APIs have taken the world by storm in recent years. The use of APIs has gone beyond just traditional "software" companies, to companies and organizations across industries using APIs to share information and power their applications. For some organizations, APIs are the biggest revenue drivers. For example, Salesforce generates nearly 50% of annual revenue through APIs. In other cases, APIs can increase a business's footprint and initiate collaboration. Netflix, for example, reported over 5 bi...
As the software delivery industry continues to evolve and mature, the challenge of managing the growing list of the tools and processes becomes more daunting every day. Today, Application Lifecycle Management (ALM) platforms are proving most valuable by providing the governance, management and coordination for every stage of development, deployment and release. Recently, I spoke with Madison Moore at SD Times about the changing market and where ALM is headed.
If there is anything we have learned by now, is that every business paves their own unique path for releasing software- every pipeline, implementation and practices are a bit different, and DevOps comes in all shapes and sizes. Software delivery practices are often comprised of set of several complementing (or even competing) methodologies – such as leveraging Agile, DevOps and even a mix of ITIL, to create the combination that’s most suitable for your organization and that maximize your busines...
Struggling to keep up with increasing application demand? Learn how Platform as a Service (PaaS) can streamline application development processes and make resource management easy.
New Relic, Inc. has announced a set of new features across the New Relic Software Analytics Cloud that offer IT operations teams increased visibility, and the ability to diagnose and resolve performance problems quickly. The new features further IT operations teams’ ability to leverage data and analytics, as well as drive collaboration and a common, shared understanding between teams. Software teams are under pressure to resolve performance issues quickly and improve availability, as the comple...
The goal of any tech business worth its salt is to provide the best product or service to its clients in the most efficient and cost-effective way possible. This is just as true in the development of software products as it is in other product design services. Microservices, an app architecture style that leans mostly on independent, self-contained programs, are quickly becoming the new norm, so to speak. With this change comes a declining reliance on older SOAs like COBRA, a push toward more s...
The proper isolation of resources is essential for multi-tenant environments. The traditional approach to isolate resources is, however, rather heavyweight. In his session at 18th Cloud Expo, Igor Drobiazko, co-founder of elastic.io, will draw upon their own experience with operating a Docker container-based infrastructure on a large scale and present a lightweight solution for resource isolation using microservices. He will also discuss the implementation of microservices in data and applicat...