We all know that getting to the truth sometimes requires a little digging through marketing hype, hyperbole, and perhaps a bit of deception. I’m sure we’re all stunned to find that some are disputing the marketing claim that Cocoa Krispies cereal will help to boost a child’s immunity to illness.
In the Internet domain there is no shortage of products which claim to have some form of “webification.” With the explosive growth of internet technologies, companies are scrambling to ensure that their solutions are perceived as being compatible with the Web. Coupling that with all of the media attention on “cloud computing” and Software as a Service (SaaS) there is growing confusion on the differences between Web-enabled and Web-hosted systems.
Here are the main characteristics of Web-enabled and Web-hosted systems;
Web-hosted Products:
Web-hosted products are centrally operated at a data center and shared amongst thousands of different companies. This is called a multi-tenant SaaS application, and it’s the reason that they are very robust and cost-effective. The entire application is accessible from a browser and can generally be used on any computer or mobile device. Web-hosted solutions are also self-provisioned, scalable on demand, and typically purchased on a “pay as you go” basis. It should not be necessary for you to purchase any application software to operate a Web-hosted product.
Web-enabled Systems:
Web-enabled systems are often mistaken for Web-hosted systems because they both use a browser for their user interface. That’s generally where the similarities end.
Web-enabled systems fall into two basic categories, 1) native Web and
2) after-market Web. Native Web systems are designed from the ground up to operate over the Internet using an on-board Ethernet connection and providing Administrative access to the application via a standard Web browser. Aftermarket Web-enabled products are typically client/server applications accompanied by hardware that does not communicate natively over Ethernet. It’s fairly easy to spot these products since they will have to be paired with external Web servers to “webify” the application and terminal servers to add Ethernet connectivity to the devices. If a product cannot stand on its own without the auxiliary devices, then it is an aftermarket Web-enabled solution.
Aftermarket Web products tend to suffer from some large deficiencies as compared to native web products. The first obvious problem is that other devices are required to make the solution work over the web. This increases their complexity and cost while decreasing the chances that the overall solution will migrate well as web technologies evolve. Another obvious problem is that information security gaps can appear between the original product and its bolt-on components. Both of these issues should raise serious concerns if you are evaluating an after-market web solution.
What’s a Buyer To DO?:
It is sometimes difficult to sort through the “webified” marketing descriptions associated with products. However, a little close examination and some pointed questions will help you get to the information you need to make the best decision.
-John Szczygiel
Showing posts with label John Szczygiel. Show all posts
Showing posts with label John Szczygiel. Show all posts
Thursday, July 1, 2010
Thursday, June 17, 2010
Privacy Best Practices—How important is TRUSTe Certification for Security as a Service Platforms?
Recently, Brivo joined other leaders in the online community such as Intuit and Salesforce.com in completing the process to become certified in the TRUSTe® Privacy Program. A TRUSTe® certification means that Brivo abides by the Safe Harbor Framework as outlined by the U.S. Department of Commerce and the European Union.
TRUSTe’s program requirements are based upon the Federal Trade Commission’s (FTC) Fair Information Principles, which include:
Do you know if your SaaS providers are similarly committed to such high standards of data and privacy protection? Or, if you’re a SaaS provider, what level of importance do such industry standards hold for your organization?
- John Szczygiel
TRUSTe’s program requirements are based upon the Federal Trade Commission’s (FTC) Fair Information Principles, which include:
- Notification of how personal data is collected and used
- Choice/consent regarding uses of such data
- Access by individuals to their personal information so that it can be reviewed and corrected
- Security to protect against unauthorized access, destruction, use, or disclosure of the data
- Redress/enforcement to ensure compliance
Do you know if your SaaS providers are similarly committed to such high standards of data and privacy protection? Or, if you’re a SaaS provider, what level of importance do such industry standards hold for your organization?
- John Szczygiel
Thursday, May 27, 2010
The 5 Cs of Security as a Service
Conclusions
The 5 Cs finishes with our conclusions on why end users are quickly moving to Security as a Service.
Conclusions
Change, Compliance, Cost, Continuity, and Coverage; these are all basic considerations for an organization. For anyone challenged with evaluating and implementing technical solutions, these factors provide a useful lens through which available options can be viewed. With the past as our guide it is clear that the future will demand more flexibility, reach, and capacity more quickly and at lower costs. The Internet has already changed the way we live, the way we learn, and the way we communicate with each other. It is also changing the nature of software and how we interact with it. We are moving from static applications purchased in boxes to living cyber platforms shared with thousands of users, adopted as needed and discarded if not valued.
SaaS changes our relationship with software by allowing us to focus on what it does for us rather than the infrastructure required to make it work. This change allows business to invest more in their people and the technology that allows them to differentiate themselves from their competition and less on non-strategic functions.
SaaS also changes our relationships with software providers by creating a mutually dependant environment in which the seller of the service is fully committed to the customer’s outcomes. No one expects a customer to continuously pay for a solution that is not providing value to their organizations. The Software as a Service model creates a vendor vested relationship from the very start and places the consumer in a very powerful position. If your organization would be best served by rapid access to state of the art technology delivered with minimal internal resource requirements, tremendous scalability and predictable costs over time, you should consider a SaaS based option for your physical security.
-John Szczygiel
The 5 Cs finishes with our conclusions on why end users are quickly moving to Security as a Service.
Conclusions
Change, Compliance, Cost, Continuity, and Coverage; these are all basic considerations for an organization. For anyone challenged with evaluating and implementing technical solutions, these factors provide a useful lens through which available options can be viewed. With the past as our guide it is clear that the future will demand more flexibility, reach, and capacity more quickly and at lower costs. The Internet has already changed the way we live, the way we learn, and the way we communicate with each other. It is also changing the nature of software and how we interact with it. We are moving from static applications purchased in boxes to living cyber platforms shared with thousands of users, adopted as needed and discarded if not valued.
SaaS changes our relationship with software by allowing us to focus on what it does for us rather than the infrastructure required to make it work. This change allows business to invest more in their people and the technology that allows them to differentiate themselves from their competition and less on non-strategic functions.
SaaS also changes our relationships with software providers by creating a mutually dependant environment in which the seller of the service is fully committed to the customer’s outcomes. No one expects a customer to continuously pay for a solution that is not providing value to their organizations. The Software as a Service model creates a vendor vested relationship from the very start and places the consumer in a very powerful position. If your organization would be best served by rapid access to state of the art technology delivered with minimal internal resource requirements, tremendous scalability and predictable costs over time, you should consider a SaaS based option for your physical security.
-John Szczygiel
Thursday, May 20, 2010
The 5 Cs of Security as a Service
The 5th C...Coverage
Coverage
Organizations often find that the best way to accelerate profitable growth is through geographic expansion. Expansion comes with significant challenges, risks, and expenses. Management teams will be extended a bit further, along with scarce company resources. Solutions that provide good results in one location or at small campus can turn troublesome when multiplied for many geographically dispersed sites. Typically, these types of installations expose the vulnerabilities, complexities, and hidden expenses of traditional client/server solutions.
Security as a Service solutions provide very clear benefits for organizations with geographically dispersed sites. The low initial costs and wide scalability of SaaS solutions give organizations access to world-class technologies with an economic model that promotes expansion rather than restricting it. Securely using the public Internet as a communication medium greatly simplifies the deployment of remote sites for IT Departments. Best yet, the centrally hosted SaaS model provides all the central oversight and management that is needed in well run organizations without requiring costly investments in dedicated infrastructure.
This architecture eliminates the need to have applications running at each secured property, which eliminates the expense and headaches of the local computing resources that have been the Achilles ’ heel of legacy security systems. Instead, it relies on a centrally hosted platform for identity, device, and asset management; as well as all alerts, alarms, email notifications, and general reporting. Multiple data centers throughout the US provide redundancy and disaster recovery capability, with SAS-70 audits to provide assurance on information security and compliance concerns.
-John Szczygiel
Coverage
Organizations often find that the best way to accelerate profitable growth is through geographic expansion. Expansion comes with significant challenges, risks, and expenses. Management teams will be extended a bit further, along with scarce company resources. Solutions that provide good results in one location or at small campus can turn troublesome when multiplied for many geographically dispersed sites. Typically, these types of installations expose the vulnerabilities, complexities, and hidden expenses of traditional client/server solutions.
Security as a Service solutions provide very clear benefits for organizations with geographically dispersed sites. The low initial costs and wide scalability of SaaS solutions give organizations access to world-class technologies with an economic model that promotes expansion rather than restricting it. Securely using the public Internet as a communication medium greatly simplifies the deployment of remote sites for IT Departments. Best yet, the centrally hosted SaaS model provides all the central oversight and management that is needed in well run organizations without requiring costly investments in dedicated infrastructure.
It's a small world, but I wouldn't want to have to paint it, Steven Wright
Brivo introduced SaaS into the security industry in 2001. The company offers a hosted Security Management System that provides centralized access control, video surveillance, notifications, and related services. As shown below, the SaaS applications connect to a variety of on-premise security equipment ranging from cameras to control panels and other sensors.A SaaS-based security platform gives you the power to drop an access control point anywhere in world and have it communicating, configured, and controlling your facility in a matter of hours. With complete synchronization to your master database and with total audit capability from wherever you happen to be. With the complexity of local software and hardware configurations removed from the equation, installers with modest training can successfully implement a SaaS based physical access control solution.
Illustration: SaaS in Physical Security Today
Illustration: SaaS in Physical Security Today
This architecture eliminates the need to have applications running at each secured property, which eliminates the expense and headaches of the local computing resources that have been the Achilles ’ heel of legacy security systems. Instead, it relies on a centrally hosted platform for identity, device, and asset management; as well as all alerts, alarms, email notifications, and general reporting. Multiple data centers throughout the US provide redundancy and disaster recovery capability, with SAS-70 audits to provide assurance on information security and compliance concerns.
-John Szczygiel
Thursday, May 13, 2010
The 5 Cs of Security as a Service
The 4th C…Continuity
The 5 Cs continues with yet another in our reasons why end-users are quickly moving to Security as a Service. The 4th C is for Continuity.
Continuity
Our collective experiences with events such as September 11 2001, Hurricane Katrina, and a host of other disasters and outages have brought into clear focus the need for redundancy and resiliency in the systems that support our organizations. It’s not enough to ask how well are we protected or how many back-ups exist, but also how fast can we resume operations if everything goes wrong?
Organizations routinely spend hundreds of thousands of dollars creating resiliency in their physical security platforms. This commonly includes hot-standby computers, back-up power sources, and disaster recovery locations. These measures are not only expensive; they are often reliant on internal computer networks that are likely to be challenged by any form of massive disaster. Further, if employees cannot get to the machines that operate the security platform, all the redundant measure may be fruitless. While security is certainly a high priority, if an organization’s core revenue generating capabilities are down, what will be addressed first?
Fortunately, the SaaS model provides numerous answers for these types of challenges. Multi-tenant SaaS services are normally hosted in highly reliable data centers with built-in redundancy. The best providers also employ separate disaster recovery centers to restore full operations if the primary center is disabled. Redundancy in the communication path is built into this model due to the Internet’s capability to send information via a large number of routes. Even if broadband service is down, it’s possible to establish the same communication paths via cellular cards and cellular equipped access panels. Since no special computers or software is required to operate a SaaS-based physical security application, any computer connected to the Internet can be placed into service during an emergency.
The redundancy and disaster recovery capabilities of the SaaS model are even more remarkable when you consider that it’s all part of the basic service and thus is available at the same level of quality for consumers with one reader or one thousand readers.
-John Szczygiel
The 5 Cs continues with yet another in our reasons why end-users are quickly moving to Security as a Service. The 4th C is for Continuity.
Continuity
Our collective experiences with events such as September 11 2001, Hurricane Katrina, and a host of other disasters and outages have brought into clear focus the need for redundancy and resiliency in the systems that support our organizations. It’s not enough to ask how well are we protected or how many back-ups exist, but also how fast can we resume operations if everything goes wrong?
Organizations routinely spend hundreds of thousands of dollars creating resiliency in their physical security platforms. This commonly includes hot-standby computers, back-up power sources, and disaster recovery locations. These measures are not only expensive; they are often reliant on internal computer networks that are likely to be challenged by any form of massive disaster. Further, if employees cannot get to the machines that operate the security platform, all the redundant measure may be fruitless. While security is certainly a high priority, if an organization’s core revenue generating capabilities are down, what will be addressed first?
Fortunately, the SaaS model provides numerous answers for these types of challenges. Multi-tenant SaaS services are normally hosted in highly reliable data centers with built-in redundancy. The best providers also employ separate disaster recovery centers to restore full operations if the primary center is disabled. Redundancy in the communication path is built into this model due to the Internet’s capability to send information via a large number of routes. Even if broadband service is down, it’s possible to establish the same communication paths via cellular cards and cellular equipped access panels. Since no special computers or software is required to operate a SaaS-based physical security application, any computer connected to the Internet can be placed into service during an emergency.
The redundancy and disaster recovery capabilities of the SaaS model are even more remarkable when you consider that it’s all part of the basic service and thus is available at the same level of quality for consumers with one reader or one thousand readers.
-John Szczygiel
Thursday, May 6, 2010
The 5 Cs of Security as a Service
The 3rd C…Cost
Moving on through the 5 Cs of Security as a Service, let's examine the motivations for customers to seek cloud services. The 3rd “C” is for Cost.
Cost
The survival of every organization hinges on its ability to deliver value for its customers. It’s impossible to deliver high levels of value without addressing the cost for operating your organization. Referring back to the power example, what would it cost each of us to have a personal power generation plant for our homes? How much would the installation cost, how much labor would be required to operate it and maintain the equipment? While it seems quite obvious that a personal power generation plant wouldn’t make sense, most physical security applications are delivered exactly in this way. Software and hardware is purchased with sufficient capacity to handle present and some portion of future needs. The equipment is installed, powered, and maintained with internal resources. Very often excess resources exist in the host computers and within each machine that is operating the client software. When you add up the total cost of ownership, you will most likely be very surprised.
The SaaS-based Security as a Service model provides an excellent alternative to the traditional options, thus allowing organizations to focus on their core business. SaaS delivers outstanding economic value for the following reasons;
In the case of physical security, our own study finds that for a typical branch office or managed property scenario, the SaaS model for security management offers significant operational and financial savings. This is due to both upfront cost reductions and the economies of scale of hosted application services. This study found that a Security as a Service solution enjoyed an advantage of nearly $26,000 (or 76%) over the server-based solution. [2]
- John Szczygiel
Moving on through the 5 Cs of Security as a Service, let's examine the motivations for customers to seek cloud services. The 3rd “C” is for Cost.
Cost
The survival of every organization hinges on its ability to deliver value for its customers. It’s impossible to deliver high levels of value without addressing the cost for operating your organization. Referring back to the power example, what would it cost each of us to have a personal power generation plant for our homes? How much would the installation cost, how much labor would be required to operate it and maintain the equipment? While it seems quite obvious that a personal power generation plant wouldn’t make sense, most physical security applications are delivered exactly in this way. Software and hardware is purchased with sufficient capacity to handle present and some portion of future needs. The equipment is installed, powered, and maintained with internal resources. Very often excess resources exist in the host computers and within each machine that is operating the client software. When you add up the total cost of ownership, you will most likely be very surprised.
The SaaS-based Security as a Service model provides an excellent alternative to the traditional options, thus allowing organizations to focus on their core business. SaaS delivers outstanding economic value for the following reasons;
- All users share a common computing infrastructure, to the economic benefit of all.
- The cost model is scalable with users only paying for what they actually use.
- The consumers of an application are free of all “back-end” management and maintenance expenses.
- Up-front capital expenditures are replaced with flat, subscription-based operational expenses.
In the case of physical security, our own study finds that for a typical branch office or managed property scenario, the SaaS model for security management offers significant operational and financial savings. This is due to both upfront cost reductions and the economies of scale of hosted application services. This study found that a Security as a Service solution enjoyed an advantage of nearly $26,000 (or 76%) over the server-based solution. [2]
- John Szczygiel
[1] “Total Cost of Ownership Reduction with VMware,” VMware.com (March 10, 2008).
[2] Interested readers are referred to the full study, found here.
[2] Interested readers are referred to the full study, found here.
Thursday, April 29, 2010
The 5 Cs of Security as a Service
The 2nd C: Compliance
Continuing from our last train of thought, we are exploring the primary motivations for organizations to seek alternatives to traditional client/server architecture and on-premise software installations. The second “C” is for Compliance
Compliance
Corporate governance, risk management, and compliance with policies and regulations are in sharp focus for most organizations. It’s not enough to express intent to follow regulations and policies, but organizations must measure and transparently report on how completely they are being followed. Efforts to ensure consistent experiences for customers and to wring efficiencies from standardization are often competing with individual workers whose sense of privilege or creativity conflicts with the corporate standard. Getting it wrong in this area can have devastating consequences on the viability and competitiveness of any firm. Correspondingly, many organizations invest huge amounts of resources in auditing and assurance services to ensure compliance with standards and to evaluate controls.
In the context of physical security, compliance failures can result in data breeches, exposure to financial losses, denial of services, and bodily injury to employees and visitors. The use of traditional physical security client/server architecture exposes company assets and personal information to constant threats. A typical corporate installation may include dozens of PCs, each with access to security controls and sensitive personal information. Providing any assurance of how access to these resources is managed and what standards are being followed is a daunting task. From SOX to FISMA, detailed audits of data integrity are required. Imagine how much it would cost to perform an audit of dozens of access control PCs spread throughout the world. It could easily cost more than the systems themselves.
SaaS architecture greatly simplifies enforcement of polices and audits for compliance by providing centralized capabilities to establish standards as well as tools to track and report on compliance. Since a SaaS solution database is centralized, the cost for performing compliance audits is significantly reduced. Many SaaS providers are also able to provide evidence of internal controls certified by independent auditors, thus eliminating the need for a subscriber to incur these costs.
- John Szczygiel
Continuing from our last train of thought, we are exploring the primary motivations for organizations to seek alternatives to traditional client/server architecture and on-premise software installations. The second “C” is for Compliance
Compliance
Corporate governance, risk management, and compliance with policies and regulations are in sharp focus for most organizations. It’s not enough to express intent to follow regulations and policies, but organizations must measure and transparently report on how completely they are being followed. Efforts to ensure consistent experiences for customers and to wring efficiencies from standardization are often competing with individual workers whose sense of privilege or creativity conflicts with the corporate standard. Getting it wrong in this area can have devastating consequences on the viability and competitiveness of any firm. Correspondingly, many organizations invest huge amounts of resources in auditing and assurance services to ensure compliance with standards and to evaluate controls.
In the context of physical security, compliance failures can result in data breeches, exposure to financial losses, denial of services, and bodily injury to employees and visitors. The use of traditional physical security client/server architecture exposes company assets and personal information to constant threats. A typical corporate installation may include dozens of PCs, each with access to security controls and sensitive personal information. Providing any assurance of how access to these resources is managed and what standards are being followed is a daunting task. From SOX to FISMA, detailed audits of data integrity are required. Imagine how much it would cost to perform an audit of dozens of access control PCs spread throughout the world. It could easily cost more than the systems themselves.
SaaS architecture greatly simplifies enforcement of polices and audits for compliance by providing centralized capabilities to establish standards as well as tools to track and report on compliance. Since a SaaS solution database is centralized, the cost for performing compliance audits is significantly reduced. Many SaaS providers are also able to provide evidence of internal controls certified by independent auditors, thus eliminating the need for a subscriber to incur these costs.
- John Szczygiel
Thursday, April 22, 2010
The 5 Cs of Security as a Service
The 1st C: Change
As a follow up to my last post, we are exploring the primary motivations for organizations to seek alternatives to traditional client/server architecture and on-premise software installations. The first “C” is for change.
Change
Organizations face a constantly changing array of pressures from various sources. Competitive threats, new regulations, financial uncertainty, technological shifts, and business risk all force managers to maintain a state of perpetual vigilance. Globalization and technological advancements have enabled new business models and competitors to spring up seemingly overnight. The ability of businesses respond to these pressures can be in itself a source of sustainable competitive advantage.
Savvy managers are taking cues from Darwin and are building lithe organizations with systems and infrastructure capable of responding to threats and capitalizing on opportunities with amazing speed. Today’s CEOs look to CIOs and CSOs for answers on how to be more competitive, not simply to deliver a service to the organization. Any CSO who fails to consider business agility and speed to market in their planning is likely to be consumed by a hostile business environment.
The SaaS delivery model supports these objectives by providing capabilities that can be rapidly deployed and retracted based on the needs of the business. In the context of physical security, SaaS applications allow CSOs to provision new security capabilities as needed, and where needed, without investing in the technology and human resources required to support the service. Also, since the SaaS model is built around ever improving technology supported by monthly fees, CSOs can ensure their organizations access to the latest features without ever having to concern themselves with upgrade patches and hardware limitations.
Thus the agility offered by forgoing fixed technology investments and using “rented” IT resources allows organizations to be positioned to move quickly in response to whatever may be around the next corner.
-John Szczygiel
As a follow up to my last post, we are exploring the primary motivations for organizations to seek alternatives to traditional client/server architecture and on-premise software installations. The first “C” is for change.
Change
Organizations face a constantly changing array of pressures from various sources. Competitive threats, new regulations, financial uncertainty, technological shifts, and business risk all force managers to maintain a state of perpetual vigilance. Globalization and technological advancements have enabled new business models and competitors to spring up seemingly overnight. The ability of businesses respond to these pressures can be in itself a source of sustainable competitive advantage.
Savvy managers are taking cues from Darwin and are building lithe organizations with systems and infrastructure capable of responding to threats and capitalizing on opportunities with amazing speed. Today’s CEOs look to CIOs and CSOs for answers on how to be more competitive, not simply to deliver a service to the organization. Any CSO who fails to consider business agility and speed to market in their planning is likely to be consumed by a hostile business environment.
The SaaS delivery model supports these objectives by providing capabilities that can be rapidly deployed and retracted based on the needs of the business. In the context of physical security, SaaS applications allow CSOs to provision new security capabilities as needed, and where needed, without investing in the technology and human resources required to support the service. Also, since the SaaS model is built around ever improving technology supported by monthly fees, CSOs can ensure their organizations access to the latest features without ever having to concern themselves with upgrade patches and hardware limitations.
Thus the agility offered by forgoing fixed technology investments and using “rented” IT resources allows organizations to be positioned to move quickly in response to whatever may be around the next corner.
-John Szczygiel
Thursday, April 15, 2010
The 5 Cs of Security as a Service
Why End-Users are looking to the cloud
When you wake up in the morning and turn on the light, you probably don’t think about the source of the power. As you switch on the television and start the coffee maker your thoughts are likely to be on the day ahead and not whether you have enough capacity to power the items you’re using in your home. You’re free of these worries because the power company has created a reliable service, shared among the whole community that scales to your individual, immediate demands. The service is metered so you pay your fair share based on what you use.
The basic concept behind cloud computing is very similar to this example. The Cloud is like a power plant for computing resources, ready to deliver what you need, when you need it. The Internet is like the power lines, a means to deliver the power reliably and efficiently to individual users. Many companies are creating Cloud services that you can use as you need them and pay for them as you consume them. There are already a host of shared capabilities grouped beneath the broad umbrella of cloud computing. These include sharing networks, computers, storage, and also software applications.
The main accelerant for the growth of these cloud services is the Internet. In the past ten years we have seen the Internet evolve from the dial-up based “world wide wait” to the blazing fast medium for the exchange of data, audio, and video. The speed of the Internet, coupled with excellent reliability and security improvements has made it the engine for innovation in the delivery of a wide range of services. Most of us use the Internet for much more than gathering information and sending email. We use it to manage our finances, coordinate calendars, purchase music, and back-up our files amongst a host of other capabilities.
Software as a Service, or SaaS, is the moniker for software applications delivered via the Internet from companies such as Amazon, IBM, Salesforce.com, Microsoft, Google, and others. SaaS is contrasted with the traditional “shrink wrapped” model for application delivery where the user installs and configures the software on a machine they own and maintain. Growth trends for Saas are strong, Gartner, Inc. predicts that the SaaS market will continue to grow at least 22.1% per year [1] and that by 2011, 25% or more of new software systems will be delivered as SaaS applications.[2]
So why is SaaS emerging as the dominant computing model today? The answer is because of the way the technology addresses the key needs and concerns of consumers.
Physical and logical security are among the top priorities for most organizations today. Having a sound risk management plan for security is as basic as having a sales and financial strategy. However, security seldom contributes to the bottom line of an organization and as such Chief Security Officers (CSOs) and Chief Information Officers (CIOs) must find ways to ensure that their function contributes as much as it can, while consuming the fewest resources possible. Each successful organization today is constantly asking how things can be done better at a lower cost. To understand the potential impact of Security as a Service, we will explore five areas that are of strategic importance to all organizations, otherwise known as “The 5 Cs”.
Over the following posts we will reveal each of the 5 Cs and describe how each can be addressed by cloud-based solutions.
-John Szczygiel
When you wake up in the morning and turn on the light, you probably don’t think about the source of the power. As you switch on the television and start the coffee maker your thoughts are likely to be on the day ahead and not whether you have enough capacity to power the items you’re using in your home. You’re free of these worries because the power company has created a reliable service, shared among the whole community that scales to your individual, immediate demands. The service is metered so you pay your fair share based on what you use.
The basic concept behind cloud computing is very similar to this example. The Cloud is like a power plant for computing resources, ready to deliver what you need, when you need it. The Internet is like the power lines, a means to deliver the power reliably and efficiently to individual users. Many companies are creating Cloud services that you can use as you need them and pay for them as you consume them. There are already a host of shared capabilities grouped beneath the broad umbrella of cloud computing. These include sharing networks, computers, storage, and also software applications.
The main accelerant for the growth of these cloud services is the Internet. In the past ten years we have seen the Internet evolve from the dial-up based “world wide wait” to the blazing fast medium for the exchange of data, audio, and video. The speed of the Internet, coupled with excellent reliability and security improvements has made it the engine for innovation in the delivery of a wide range of services. Most of us use the Internet for much more than gathering information and sending email. We use it to manage our finances, coordinate calendars, purchase music, and back-up our files amongst a host of other capabilities.
Software as a Service, or SaaS, is the moniker for software applications delivered via the Internet from companies such as Amazon, IBM, Salesforce.com, Microsoft, Google, and others. SaaS is contrasted with the traditional “shrink wrapped” model for application delivery where the user installs and configures the software on a machine they own and maintain. Growth trends for Saas are strong, Gartner, Inc. predicts that the SaaS market will continue to grow at least 22.1% per year [1] and that by 2011, 25% or more of new software systems will be delivered as SaaS applications.[2]
So why is SaaS emerging as the dominant computing model today? The answer is because of the way the technology addresses the key needs and concerns of consumers.
Physical and logical security are among the top priorities for most organizations today. Having a sound risk management plan for security is as basic as having a sales and financial strategy. However, security seldom contributes to the bottom line of an organization and as such Chief Security Officers (CSOs) and Chief Information Officers (CIOs) must find ways to ensure that their function contributes as much as it can, while consuming the fewest resources possible. Each successful organization today is constantly asking how things can be done better at a lower cost. To understand the potential impact of Security as a Service, we will explore five areas that are of strategic importance to all organizations, otherwise known as “The 5 Cs”.
Over the following posts we will reveal each of the 5 Cs and describe how each can be addressed by cloud-based solutions.
-John Szczygiel
[1] Scheier, Robert L. August 20, 2007. “Your Data's Less Safe Today than Two Years Ago,” InfoWorld, http://www.infoworld.com/article/07/08/20/data-is-less-safe_1.html (January 4, 2008).
[2] “Gartner: SaaS Market Heats Up.” September 28, 2006 ebizq, http://www.ebizq.net/news/7314.html (January 20, 2008).
Monday, April 5, 2010
ISC West Field Report
I think we get IT
The security industry has been talking for years now about the “takeover from IT,” the emergence of IP technologies, and of course, convergence; and you know I think it’s starting to sink in. I've based this conclusion on the quality of the questions we received at the Brivo booth during this year’s ISC West show.
In the past, I’ve noticed that many visitors are armed to the teeth with a list of feature specific questions. Things like “Do you support ODBC?” or “Are you integrated with Acme VMS?” At this year’s ISC West, I noted a measurable increase in solution oriented rather than feature focused questions. Many visitors asked how we would solve a particular problem, rather than if we could match a pre-determined list of features. Many went on to ask about the implications of various types of solution approaches.
I believe this is due in part to the influence of IT on security and representative of the convergence of physical and logical security mindsets. It’s also evidence that the risk-management approach to security design is taking hold. In the IT world there are endless ways to solve any problem. In this environment it’s essential to evaluate the total approach rather than just a few marketing bullet points gleaned from datasheets. When prospects ask a lot of feature oriented questions, they risk skimming the surface for sound bites, getting a bunch of sales noise, and not truly understanding how a particular product or solution can benefit them. When they pose open-ended, solution oriented questions they invite the vendor to truly understand their objectives and to be creative in their problem solving. It’s in these open discussions where you have your true “ah-ha!” moments.
I find solution discussions to be more open, rewarding, and stimulating than simple feature Q&A. I also believe that integrators and end-users will be far more satisfied with the results they achieve by focusing on the total solution rather than getting sucked into the cold war of features. And after all, I think most integrators and end-users go to shows like ISC West to look a provider in the eye and know that they understand the problem and have the ability to solve it, not simply to surf the floor for new features. For me, this is evidence that we are adopting the type of solution finding that has been practiced in the IT world for quite a while and it’s nice to see.
- John Szczygiel
The security industry has been talking for years now about the “takeover from IT,” the emergence of IP technologies, and of course, convergence; and you know I think it’s starting to sink in. I've based this conclusion on the quality of the questions we received at the Brivo booth during this year’s ISC West show.
In the past, I’ve noticed that many visitors are armed to the teeth with a list of feature specific questions. Things like “Do you support ODBC?” or “Are you integrated with Acme VMS?” At this year’s ISC West, I noted a measurable increase in solution oriented rather than feature focused questions. Many visitors asked how we would solve a particular problem, rather than if we could match a pre-determined list of features. Many went on to ask about the implications of various types of solution approaches.
I believe this is due in part to the influence of IT on security and representative of the convergence of physical and logical security mindsets. It’s also evidence that the risk-management approach to security design is taking hold. In the IT world there are endless ways to solve any problem. In this environment it’s essential to evaluate the total approach rather than just a few marketing bullet points gleaned from datasheets. When prospects ask a lot of feature oriented questions, they risk skimming the surface for sound bites, getting a bunch of sales noise, and not truly understanding how a particular product or solution can benefit them. When they pose open-ended, solution oriented questions they invite the vendor to truly understand their objectives and to be creative in their problem solving. It’s in these open discussions where you have your true “ah-ha!” moments.
I find solution discussions to be more open, rewarding, and stimulating than simple feature Q&A. I also believe that integrators and end-users will be far more satisfied with the results they achieve by focusing on the total solution rather than getting sucked into the cold war of features. And after all, I think most integrators and end-users go to shows like ISC West to look a provider in the eye and know that they understand the problem and have the ability to solve it, not simply to surf the floor for new features. For me, this is evidence that we are adopting the type of solution finding that has been practiced in the IT world for quite a while and it’s nice to see.
- John Szczygiel
Subscribe to:
Posts (Atom)

