Automation System for Validation of Configuration and Security Compliance in Managed Cloud Services

被引:2
作者
Chieu, Trieu C. [1 ]
Singh, Manas [1 ]
Tang, Chunqiang [1 ]
Viswanathan, Mahesh [2 ]
Gupta, Ashu [3 ]
机构
[1] IBM TJ Watson Res Ctr, 19 Skyline Dr, Yorktown Hts, NY 10598 USA
[2] IBM Global Technol Serv, Somers, NY 100 USA
[3] IBM India Pvt Ltd, Bangalore, Karnataka, India
来源
2012 NINTH IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE) | 2012年
关键词
Automation; configuration; compliance; quality assurance; virtual machine; provisioning; cloud computing;
D O I
10.1109/ICEBE.2012.53
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Validation of configuration and security compliance at the time of creating new service is an important part of service management process and governance in most IT delivery organizations. It is performed to ensure that security risks, governance controls and vulnerabilities are proactively managed through the lifecycle of the services, and to guarantee that all discovered problems and issues are addressed and remediated for quality assurance before the services are delivered to customers. The validation process is complex and is typically carried out by following a checklist with questions and answers through manual steps that are time consuming and error prone. This lengthy process is particularly troublesome when providing managed cloud services to enterprise customers with a pre-specified request fulfillment time in SLA. In order to improve the timeliness and quality of cloud services, we have introduced an automation system to orchestrate the validation process with executable scripts to be executed against the services. We will describe a novel policy mechanism to capture exception rules for eliminating possible interference in security configuration contained in the scripts. We will explain how our system is designed and implemented to fulfill the needs of large enterprises from both the service provider's and the service consumer's vantage points.
引用
收藏
页码:285 / 291
页数:7
相关论文
共 9 条
  • [1] [Anonymous], 2007, UND FULL VIRT PAR HA
  • [2] Buyya R., 2008, MARKET ORIENTED CLOU, P9
  • [3] Chappell D., 2008, SHORT INTRO CLOUD PL
  • [4] Foster I., 2001, Intl. J. Supercomputer Applications
  • [5] Graves D. A., 2010, US Patent, Patent No. 7710898
  • [6] Gruman Galen., 2009, InfoWorld
  • [7] Speeter T. H., 2006, US Patent Pub, Patent No. 20060179116
  • [8] Turk D. A., 2009, U.S. Patent, Patent No. 7609647
  • [9] *VMWARE INC, VMWARE ESX SERV