Showing posts with label Steve Van Till. Show all posts
Showing posts with label Steve Van Till. Show all posts

Friday, June 25, 2010

The Federal Security Trifecta

I chose the term ‘Trifecta’ for today’s column because in horse racing, it designates three winners.  And I think that’s what we have here.
First, there’s the federal government, with ICAM, which stands for Identity, Credential and Access Management.  In a sense, it’s the other bookend to HSPD-12, which said “You must have a high quality credential.” And now ICAM comes along and says, “Here’s how you should use it.”
Second, there’s the cloud.  Or Software as a Service.  As we’ve discussed here before, it’s a new paradigm for procurement and delivery of software that says it’s smarter and more efficient for everyone concerned—both suppliers and users—to rent rather than own, consolidate rather than distribute, and by all means don’t pay for anything until you absolutely have to—which is to say, as a subscription. 
Last but not least, physical security is a big winner in all of this because it’s moving from having no seat at the IT table, to having an essential role due its newfound connection to identity and privacy.  Physical security providers have been quick to adopt cloud technologies and leverage them for a variety of new offerings informally known as Security-as-a-Service.
If you’d like to hear more, watch the Webcast on our Federal Government page.  Just click on the “Federal Security Trifecta” link in the second paragraph.

Thursday, June 3, 2010

The State of Public Sector Cloud Computing

Federal CIO Summarizes Cloud Progress in New Publication

Released in conjunction with the May 20 Federal Cloud Summit sponsored by NIST at the Department of Commerce, Vivek Kundra’s “The State of Federal Cloud Computing” outlines several new federal initiatives that will provide a big boost for cloud service providers of all stripes.

The first is Standards Acceleration to Jumpstart Adoption of Cloud Computing (SAJACC), a standards development effort that will be chaired by NIST and shared with the public through a new portal. The purpose of establishing standards is to increase portability of applications and interchangeability of service providers so that customers don’t get locked in to one particular technology stack.

The second is the Federal Risk and Authorization Management Program (FedRAMP), a much-needed cloud-era update to the aging FISMA framework for ensuring information security of federal computing applications. This “in for a dime, in for a dollar” approach leverages an initial security audit of a cloud provider from one agency across multiple other agencies who may choose to use the service at a later time. This prevents duplication of both effort and cost, and provides much faster deployment times for subsequent uses of a given cloud application.

The document also reiterates several of what are by now familiar themes previously introduced in earlier federal policy statements:
  • energy reduction through data center consolidation is facilitated by cloud computing,
  • federal budget planning for 2011 must include “an alternatives analysis that includes cloud computing,”
  • cloud computing will help close the federal government’s technology gap.
The report also concludes with 30 case studies of federal, state, and local cloud projects—a useful compendium of implementation advice, economic benefit, and deployment success.

- Steve Van Till

Thursday, April 8, 2010

Another first for “SaaS first”

Kundra advocates “cloud-first” policy for federal IT procurement

You’ve got to love it when two of your favorite trends get together and become one—sort of like the apocryphal day when peanut butter first encountered chocolate and they together became a celebrated confection.

So it was, yesterday, when Vivek Kundra, speaking at the Brookings Institution, announced that federal IT leadership means shifting to a “cloud first” policy for new IT procurement.

A little review. If you’ve been reading this blog, you’ll know that back in March we wrote about the Goldman Sachs report that was the first known articulation of the “SaaS first” approach to evaluating new IT systems. A few weeks later, we also wrote extensively about the federal budget language identifying the compelling case for cloud computing in the government. Well, we now have the top federal IT official pulling both of these concepts together in one coherent framework, with a follow-on program by NIST that will facilitate standards, security, and interoperability guidelines for the whole affair.

Kundra’s speech was titled “The Economic Gains of Cloud Computing,” and it provides a roadmap of how the federal government will move forward with its cloud computing initiative. The speech was accompanied by the release of an excellent new Brookings report, “Saving Money through Cloud Computing,” a title that leaves little to the imagination but provides an apt summary of the government case studies it outlines.

So there you have it: “SaaS first” and federal cloud adoption—two great trends that trend great together.

- Steve Van Till 

Thursday, March 25, 2010

“This Hosted Access Thing” at ISC West

Sam Pfeifle, Security Systems News, recently posted his ISC West schedule, which includes a stop by the Brivo booth. In a few short and sweet sentences, Pfeifle summed up the latest buzz at this year’s show by stating, “It seems like this hosted access thing is taking off. Brivo has had something to do with that. Thus, I’m talking to them.”

This “hosted access thing” surely is taking off, and ISC West is proving it this year. With numerous sessions relating to this topic alone, PSaaS and cloud computing are officially on display this week. Need proof? Below are just some of the many educational sessions related to these topics at ISC West:

  • Successfully Creating a Hosted Video Solution for a Recurring Revenue Stream
  • Security as a Service: The Next Wave of Integrated IP-based Monitoring 
  • The 5 Cs of Security as a Service: Why End-users Are Looking to the Cloud
And why wouldn't PSaaS and cloud computing create a buzz at this year’s show? They have been proven to offer providers an opportunity to create a cost-efficient, hosted surveillance solution, while alleviating the customer's task of software maintenance, ongoing operation, and support.

Another show item making an impression this year is Brivo’s new
OnSite Aparato, a full-featured appliance-based access control platform. Steve Lasky, Security Technology Executive’s Editor-in-Chief/Publisher, was impressed with the system’s “capacity of 1,000 readers and 500,000 active card holders.”

Aparato is also fully secure, using a Trusted Platform Model (TPM) that is ISO Standard 11889 compliant. Due out in May, Aparato will also offer a scalable licensing model, threat level lockdown, graphic maps, secure, automated back-ups, and more.

The “hosted access thing” and OnSite Aparato are just two of the vast amount of topics being discussed here at ISC West, but they sure seem to be making enough noise to stand out amongst the crowd.

-Steve Van Till

Thursday, March 18, 2010

Feds going to the cloud

First-ever cloud advocacy in new federal budget request

“Adoption of a cloud computing model is a major part of the strategy to achieve efficient and effective IT.”


                - Budget of the U.S. Government, Fiscal year 2011 [1]

And with that, the U.S. federal government puts a stake in the ground, acknowledging for the first time ever that cloud computing is a central component of their strategy for improving the IT performance of the federal enterprise. The budget goes on to say that the “new approach will redesign IT in key business areas from the ground up, based on the concept of central Federal platforms designed to streamline processes and modernize information technology services.”

This is obviously a large vote of confidence for an industry that has only recently stopped moving from acronym to acronym, finally settling in on a few standard monikers for what we do. In Brivo’s ten-year history with this computing paradigm, we’ve seen early labels such as ASP (Application Service Provider) and MSP (Managed Service Provider) give way to SaaS (Software as a Service) and now the more generalized “cloud” term. The one thing that has remained constant across all of those changes is that the motivation for centralizing computing resources is still the same: better service at a lower overall cost of ownership, which is what the federal budget IT folks are trying to achieve.

It wasn’t an easy move for federal IT leadership to give such a blanket endorsement of this new technology, given all the perceptions to be overcome regarding potential information security issues in cloud computing. The current state of this discussion, as Imperial Capital’s Jeff Kessler notes in his March, 2010 Security Industry Monitor, is that “enterprises need assurance that sensitive data can be protected in the cloud and that security can meet corporate governance and regulatory requirements.” [2]

Many expect that in the case of the federal government, this security concern will translate into the use of private clouds dedicated to federal clients, rather than public clouds shared with all comers. In this context, it is worth repeating Federal CIO Vivek Kundra’s observation that “when you look at security, it's easier to secure when you concentrate things than when you distribute them across the government.” [3]

And there’s also a green angle to it as well.  The FY2011 budget notes that the data center consolidation facilitated by cloud computing “will reduce energy consumption, space usage and environmental impacts.” This reduction fits in with the goal of Executive Order 13514—Federal Leadership in Environmental, Energy, and Economic Performance, issued in October of 2009. Under the order, agencies are compelled to “increase energy efficiency; measure, report, and reduce their greenhouse gas emissions” and to “leverage agency acquisitions to foster markets for sustainable technologies and environmentally preferable…services.”

All of which spells continuing growth and diversity of offerings in the cloud market as a whole, and, we expect, its application to physical security systems.

-Steve Van Till




[1] U.S. Office of Management and Budget, Budget of the U.S. Government, Fiscal Year 2011 (Washington, DC: U.S. Government Printing Office, 2010), Special Topics, p 323.
[2] Imperial Capital, Security Industry Monitor (Imperial Capital, March 2010), p. 51.
[3] J. Nicholas Hoover, Federal CIO Scrutinizes Spending And Eyes Cloud Computing, 14 March 2009, 15 March 2010.

Thursday, March 4, 2010

Goldman Sachs: “Unstoppable shift to SaaS continues”

Latest report reveals growing “SaaS first” attitude among buyers

In its recently released February technology software report [
1], investment bank Goldman Sachs finds that 58% of those surveyed now always consider SaaS when making new application purchase decisions. Announcing this phenomenon as a “SaaS first” trend, it describes how a majority of respondents now look to SaaS companies before considering traditional on-premise licensed software.

As someone who has been in the SaaS business for eight years now, I consider this a sea change of extraordinary magnitude—a tipping point, if you will. It signals a shift from SaaS being regarded as a niche product that only fits certain applications or industries to a view that now sees SaaS as a primary mode for application deployment.

The report’s singular phrase that caught the media’s attention—“unstoppable shift to SaaS continues”—indicates another tipping point in the industry; namely, that the sector as a whole will not only survive, but prosper at the expense of older software delivery methods.

While this is certainly welcome news for investors in this sector, it is equally welcome to prospective buyers. It means that it’s no longer a gamble to choose a SaaS solution, and that the variety and competition among providers will continue to increase.

Of particular interest to readers of this blog will be the fact that “security/compliance” software now makes the list of 20 top SaaS applications in the survey. While not a direct hit for physical security per se, it does underscore the increasing confidence that companies are placing in outsourced applications for critical or sensitive corporate functions.

We’ll see more of that next week when we look at why A&S International, the global security magazine, says in its January issues that that “Software-as-a-service (SaaS) is shaking the physical security industry.”

-Steve Van Till




[1] Goldman Sachs, Global Investment Research, February 9, 2010

Thursday, February 25, 2010

How does PSaaS work?

Two examples of how SaaS is used in physical security today 

So far we’ve been talking rather theoretically about Physical Security as a Service (PSaaS), and how various market forces are changing the security industry. Today, we’re going to get real and talk about two specific applications of Software as a Service in the physical security industry:
  • access control as a service
  • video recording as a service (surveillance)
Like all PSaaS applications, online access control uses a combination of customer-premise embedded hardware modules plus cloud-based applications and data storage. The on-premise equipment will look familiar to anyone who has been in the security industry for a while: access control panels or edge devices, card and biometric readers, switches, sensors, electric door strikes, and the like. In this context, all of these pieces basically act as a way to interface the physical world to the networked world. The big difference between this and the old way of doing things is that you no longer need the PC or server on site—nor any of the expense or hassles of maintaining your own applications. All of that is handled in the cloud, at redundant data centers operated by the SaaS provider, as shown in the diagram below:












This is especially handy if you have hundreds or thousands of sites that need to be under a single security umbrella. The service provider has already handled all of the networking and availability considerations within the architecture itself, and you can focus on policies and exception management. Accessing the applications to manage your properties is handled by—what else?—a browser, from any Internet connection available to you.

This is also true for our second example, Video as a Service, a rapidly emerging segment of the physical security and surveillance market that has seen a number of new entrants in the past year. As you can see below, the architecture for a cloud-based video service looks a lot like that of a cloud-based access control system. There’s on-premise equipment—cameras in this case—that connect your physical facilities back to the digital world by way of centralized disk storage and video management applications. Again, all of that storage and all of the applications you need to run your surveillance system are managed by your PSaaS provider.












Just like the access control example, you can view the video application from any browser, as long as you have the right permissions. Remote management and the ability to share video of security incidents immediately through digital media obviously offers huge conveniences for facilities managers.

In the best of all worlds, the video and access control systems are combined into a single application so that neither is a “stovepipe” of information. After all, an information stovepipe is still a stovepipe, even if it’s on the Internet. 

- Steve Van Till

Thursday, February 18, 2010

Current State of Electronic Security: Or, why is this market responding to the SaaS value proposition?

Every solution needs to solve a problem, or it ceases to exist. So, the fact that numerous hosted services are taking off in today’s electronic security marketplace tells me that they are answering a real need in this space. But what is that need?

Expectations

Let’s start with expectations. Our experiences with the Internet have conditioned all of us to expect that information services:
  • be easy and quick to set up;
  • not require the installation of special software; and
  • be accessible from any Internet access point
In effect, the software experiences we are having in our personal transactions, and increasingly those we are having in most commercial transactions, are spilling over into our expectations of all business software. Why, customers are asking, should my security software be any harder to use than my HR or accounting software?

Software

Let’s start by looking at the state of existing software in the electronic security business.

First of all, most of the traditional providers are still selling legacy products that require a trained expert to install them on a PC or server that meets very exacting requirements. In other words, probably not the PC or server you already own. Second, even after it’s installed, it’s not quick or easy to set up. Many of these software packages require users to attend several days of training in a stuffy hotel conference room somewhere just to learn how to use it. And then there’s Internet accessibility of these older systems:  in many cases it’s not really built in and would have to be engineered on a per-site basis, which brings up a lot of IT concerns.

All of that explains why, when we entered the business in 2002, we heard from dealers and integrators that their number one source of customer support calls, and their number one ongoing support expense was—you guessed it—keeping the software alive. For end users, the pain was similar:  no one wants to call for technical support; they just want the products to work. That’s why more and more of the security market—whether video or access control—is shifting to either SaaS or perhaps to appliances with embedded applications and Web servers that address these same points, at least for local solutions.

Hardware

And what about the hardware that’s used in electronic security systems? The mainstays of the industry—whether it be control panels, DVRs, or cameras—are either gaining IP connectivity or losing ground to a variety of technologies that do, such as edge devices, network-based storage, IP cameras, etc. But was equipment a source of pain? In many respects, yes. To the extent that it required expensive, specialty wiring, the equipment was simply inconvenient and cumbersome to install or retrofit into an existing facility. To the extent that gaining remote access—a given with any IP communications medium—then, again, yes, older equipment was a source of pain. And regardless of what it took to physically install and hook up the equipment, configuration and provisioning was a large chore that required lots of specialized expertise, and probably a large dose of involvement from the IT department if any of it was touching the network.

Integration Services

Integration services are the third leg in this stool, after software and hardware. How do they fare in a context where buyers are seeking SaaS solutions for physical security?

For those not familiar with the security industry, the role of the integrator is to understand customer needs, select from the available products and technologies that provide the best value, and then deploy the solution at the customer’s facilities. Integration labor is usually the most expensive component of any security installation, so you can be sure it has the buyer’s eye. A lot of that labor was historically driven by the complexity and difficulty-of-use of the underlying software and hardware products, as we’ve already discussed.

So, what happens when a new technology comes along and reduces the need for much of that labor? For one interesting discussion of this scenario, take a look at the recent post on
IPVideoMarket.info titled The End of Integrators? There, John Honovich argues that SaaS offerings represent a classic disruptive force within the industry (see The Innovators Dilemma [1]). In this scenario, the shift to simpler on-site integration will change the balance of services required to put physical security systems in place, and thereby alter the relationships between manufacturers (or service providers), integrators, and end users—presumably with lower-cost solutions winning out in the customer’s mind.

In speaking with an IT integrator at a recent security conference, I asked how this shift away from the traditionally heavy labor component of a security installation looked to him. He said that his company welcomed it. His reasoning: “my skilled people are in such high demand that I can't afford to waste them on jobs that can be simplified through SaaS to permit a less skilled guy to do most of the work.” In other words, in a competitive labor market, he valued the fact that he could reserve his high-value employees for high-value work.

I think that this trend is an important one for integrators, because it can change the security ROI calculation in two ways, both good. In the first instance, integrators can take advantage of SaaS efficiencies, and offer equivalent (or better) functionality at a much lower price point. Initially, this will be a way for integrators who adopt SaaS to gain market share and margin at the same time. Alternatively, an integrator who wants to offer more—say, risk management analysis or loss prevention consulting—can now bundle these professional services inside of a larger engagement that uses SaaS, and provide a much higher value service at the same price tag that the electronics alone of an older system would have cost, and still retain better earnings from moving further up the food chain.

Alternatively, those consultants who provide high value services in risk management and loss prevention, and understand the SaaS model, have an opportunity to specify more competitive systems that develop a better ROI for the customer, or mitigate more risk at less cost. Just like each of us does when we compare umbrella insurance policies and look at their features and associated costs.

Conclusion

We started today by asking what needs customers were responding to when adopting SaaS solutions for physical security. What we’ve seen is that, as with many disruptive technologies before it, the market responds to greater ease of use and lower cost while maintaining or improving the quality of service. And that’s why it’s here to stay.

-Steve Van Till


[1] Clayton M. Christenson, The Innovator's Dilemma (Boston: Harvard Business School Press, 1997).

Thursday, February 11, 2010

What is Software as a Service?

The Internet and trade literature today are rife with definitions of SaaS. It seems everyone feels a need to trot out their favorite variation on the theme, as if rearranging the words one more time will somehow make matters clearer, or turn non-believers into believers.

Confusing matters further, the related trend of “cloud computing” is often referred to in the same breath, often interchangeably, which leaves the impression that they are the same thing. We think nothing could be further from the truth, but more on that later.


In the mean time, rather than adding to the existing plethora of definitions, we are happy to provide the meanings of these two key terms by borrowing from NIST—perhaps one of the few parties currently writing on the subject without “a dog in the fight.”


Herewith, a condensed version from their recent publication on the subject:


So far, so good. The cloud is a concept and SaaS is about delivery.

Cloud Computing
Software as a Service
A model for enabling available, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.[1]
A delivery model for cloud computing, provided to the consumer to use the applications running on a cloud infrastructure and accessible from various client devices through a thin client interface such as a Web browser. The consumer does not manage or control the underlying cloud infrastructure, network, servers, operating systems, storage, or even individual application capabilities. [2]

However, we feel that there’s an important technical footnote to add to this common understanding, and that’s the notion of multi-tenancy.

The core idea of multi-tenancy is that “all users and applications share a single, common infrastructure and code base that is centrally maintained.”
[3]  Just as a building’s structural architecture will differ depending on whether it is designed for a single occupant or multiple tenants, so too will a software system’s design differ depending on whether it is intended to be used by a single “tenant” or multiple tenants. In this model, cost savings are achieved both through commonality of hardware resources, as well as sharing licensing and operating expenses more efficiently across a large population of users.

Multi-tenancy stands in sharp contrast to the practice of simply deploying a stack of client-server systems in a data center and calling it a hosted service. In its “Four Level SaaS Maturity Model,” Microsoft categorizes this approach as the “lowest level” of SaaS maturity, or roughly equivalent to the “traditional application service provider (ASP) model of software delivery, dating back to the 1990s,” which “offers few of the benefits of a fully mature SaaS solution.” 
[4]

This stack-a-box or hide-the-server approach to providing remote software services is simply a case of what many observers call “cloud envy.” And it has the net effect of trapping service providers and customers into a costly cycle of maintenance and replacement. Doing the math, it becomes obvious that the overall solution is still saddled with the same cost structure as if it were located at the customer site. Except for the fact that someone else is managing the system, the stack-a-box approach is no different than the legacy approach to application ownership.


Next week, with this background in mind, we take a deeper look at the current state of electronic security systems, and why they are ripe for improvements through SaaS.

-Steve Van Till

[1] National Institute of Standards and Technology, "Computer Security Resource Center," 19 August 2009, NIST.gov, 1 September 2009, http://csrc.nist.gov/groups/SNS/cloud-computing/index.html.
[2] ibid
[3] Salesforce.com, "Multi-Tenant Plaform," 5 Sep 2009, salesforce.com, 5 Sep 2009 http://www.salesforce.com/au/platform/why-ondemand/muti-tenant-platforms/.
[4] Microsoft Corporation, "Architecture Strategies for Catching the Long Tail," April 2006, Microsoft Developer Network, 1 October 2009 http://msdn.microsoft.com/en-us/library/aa479069.aspx.

Thursday, February 4, 2010

What is Physical Security as a Service?

In the decade or so since the widespread adoption of the Internet, Web-based application services and pay-per-use business models have established Software as a Service (SaaS) as the dominant new paradigm for application deployment and delivery.

Unbeknownst to much of the IT community, that same time period saw physical security product offerings finally catching up with the broader market’s nearly universal use of native IP networking technology. For the physical security industry, this switch to IP—from digital cameras to networked access control panels to browser-based user interfaces—was revolutionary in moving the industry out of the guard station and into the data center.

These two technology trends have merged with a general shift toward hosted, service-based offerings in which vendors manage technology roles formerly handled by end user IT staff. The result—as in numerous other business application domains where outsourcing has proven its value—is that physical security is now moving to “the cloud” and using SaaS to deliver better services, more reliably, with lower TCO.

We call this “Physical Security-as-a-Service,” or PSaaS, and it’s the exclusive focus of Cloud Cover.

What you’ll find here is an ongoing discussion of the issues unique to the delivery of physical security with Web-hosted applications. Some of the topics you can expect to see are:
  • What it is and how it works.
  • What services are available today.
  • The business case for SaaS in physical security applications.
  • How cyber-security and privacy are managed in physical-security-critical cloud applications.
  • The relationship between on-premise security equipment and SaaS services.
  • Case studies of real end-users and how SaaS worked for them.
  • Future trends in cloud-based physical security management.
Like any blog, this is intended to be an interactive forum, and we hope for your comments and feedback to help enliven this discussion as we cross this new frontier together.

-Steve Van Till