Compliance policies and procedures followed in data centers

Compliance policies and procedures followed in data centers
Along with the growth of information technology the amount of data accumulated is also rapidly grown. The biggest threat that existing on these days is to make sure these data are secure. In order to make sure the high availability of data without cyber any attack or loosing chances it’s necessary to take necessary steps in every possible ways. 
Compliance typically involves adherence to standards set by government regulatory agencies. There are a significant number of regulations in effect worldwide related to protecting private and sensitive data. For many businesses, regulatory compliance is a topic that simply cannot be ignored. Handling confidential customer data in all its varied forms has become a routine, even essential, task in almost every industry, and companies that ignore the legal obligations they have to keep that data secure do so at significant peril. In 2018, for instance, the health insurance giant Anthem Inc. was fined a record $16 million by the US government for failing to comply fully with HIPAA standards in the wake of the data breach that occurred in December 2014-January 2015.


Have you ever thought where does all these data are existing? Simply we may say on internet or in any applications that you are using. Let’s take the example of Facebook, we are all having a Facebook account and many things related to us is available(photos, videos, personal information etc)on Facebook. You can see all these data from anywhere in the part of world just with an internet connection. There is a massive IT infrastructure is available in background to support your activity. Where does these IT infrastructures existing? The answer is nothing but on data centers. The biggest security threat that can affect your data is nothing but the insecurities in a location where it resides. Now you can imaging the necessity of complying with policies, procedures and standards in a data center. 
For a data center, providing compliance assurances is a matter of transparency and security. By providing infrastructure that meets compliance standards for data security, a facility can help their customers to better mitigate business risks and enhance reporting procedures. The best facilities build their infrastructure from the ground up with compliance in mind rather than viewing it as a “bolt-on” service to be incorporated after the fact. Some are focused on protection of specific industry information, where others are more concerned with proper disclosure of data loss incidents and general privacy attributes. Most of today’s standards and compliance regulations are concerned largely with the protection of private data at rest, during transactions, and while it traverses network connections. 
The compliance rules and regulations within a data center environment can be based on two things which are,
·      Data related
·      Non-Data related
What does it mean is Remember these two terms where we will segregate different compliance standards based on this two types.
There are three things which are said to be the pillars of compliance and namely 
·      Codes & Regulations - These are usually enforced by national law and compliance is mandatory.
·      National/International standards – This is an agreed set of minimum requirements, conformance with which ensures quality and operational performance.
·      Industry guidelines and best practices – Commonly published by manufactures to describe installation procedures for equipment. Have also been published to describe process in the absence of an appropriate standard. 


Let’s have a deep look into each of these pillars.

Codes & Regulations
Codes and regulations are usually enforced by national law and compliance is mandatory. We know that the laws has to be obeyed by every citizens without any exceptions. Depending on the region where data centers resides there will be regulations law by government entities which is mandatory to be followed. Laws are usually created to protect, 
·      The safety and health of people
·      The rights and freedoms of individuals
·      National infrastructure
·      National security
·      Personal data
And many more things. Some of the codes and regulations within the data centre you are governed by is as below,



If anybody would like to know more about above codes and standard, do let me know and I can catchup more details for you.

National/International standards

What is a standard? A standard is a published document that contains a technical specification or other precise criteria designed to be used consistently as a rule, guideline or definition. In simple standards are designed for voluntary use and do not impose any regulations. However, laws and regulations may refer to certain standards and make compliance with them compulsory.
So in a data center we would have international standards, national standards and regional standards. But as you know adoption of all standards is not compulsory unless they are mandated in contract. Let me give you an example, when you are a data center co-location provider and one of the health customer want to lease the space. It is a standard that the data center should follow the Health Insurance Portability and Accountability Act (HIPAA) when they want to lease the space for this health related customer. As you can see this is just a standard and it’s not necessary for data center to operate. They can still lease their co-location space to customers of other industry without any issues. But following HIPPA standard will become part of a regulation law when you want to host the data of this health industry based customer.
Always remember that your regional and national standards are having higher priority than international standards. Because the regional standards will be defined by understanding local conditions whereas international standards are general.
Some of the major international initiatives for standardizations are ISO(International organization for standardization), BSI(British standards), CENELEC (French: Comité Européen de Normalisation Électrotechnique; English: European Committee for Electrotechnical Standardization), ANSI(American National Standards Institute) and TIA(Telecommunications Industries Association).Some of the data center specific standardization by these bodies are as below,
·      BS EN 50600 – Information Technology- Data center facilities and infrastructure.
·      BS EN 50173-5 - Information Technology-Generic cabling systems 
·      BSEN 50174-2 - Information Technology-cabling installation
·      TIA 942- Telecommunications Infrastructure Standard for Data centers
·      ISO/IEC 24764 – Information Technology-Generic cabling systems for data centers.
·      ANSI/BICSI 002 – Data center design and implementation best practices.
·      ANSI/ASHRE standard 90.4-2016 standard for data centers.



Industry guidelines and best practices

There are many organizations that contribute to the data center industry through the publication of industry best practices and codes of conduct. They do provide the certifications also based on their criteria which is considered as a standard measures to prove the operation, design and facilities capabilities.




Some of the bodies who provides the guidelines for data centers are as following,
-       Uptime institute – Provides guidelines for improving the performance , efficiency and reliability through innovation, collaboration and independent certification. 
-       European Commission – In 2007 EU has developed a code of conduct in response to the increasing energy consumption in data centers and need to reduce the related environmental, economic and energy supply security impacts. 
-       US Department of energy – They have partnered with industry to create the data center energy practitioner program. It is reinforced proven best practices as well as introduce new tools and techniques in key areas such as IT department, air management, cooling systems and electrical systems.
-       The Green Grid – The green grid association is a non-profit, open industry consortium of information and communications technology(ICT) industry end users, policy makers, technology providers, facility architects and utility companies that works to improve IT and data center resource efficiency around the world.
-       BREEAM – It’s an international scheme that provides independent third party certification of the assessment for sustainability performance of individual buildings, communities and infrastructure projects.
-       U.S Green building council – They have developed the national certification for leadership in energy and environmental design(LEED) to encourage the construction of energy and  resource efficient buildings that are healthy to live in.
As a summary of this article we have discussed the necessity of compliance at data centers and various ways that data is protected through data center facilities.
  
Have a comment or points to be reviewed? Knowledge is power let’s grow together. Feel free to comment.












What are cloud service models

Previously we have discussed the types of cloud computing. But have you ever wondered what are the services provided through cloud computing? You know that the cloud computing is an advancement of your traditional data centers services. When we say that this is advanced, it’s pretty sure that through cloud services you should get all the services same as your existing data center with some additional features. So generally the cloud computing is serving the users through 3 different service models as below,

·      IaaS  - Infrastructure as a service
·      PaaS - Platform as a service
·      SaaS - Software as a service

Each of these has its own benefits, as well as variances, and it is necessary to understand the differences among SaaS, PaaS, and IaaS to know how to best choose one for your organization. What are the services provided by each of this service is simply existing on its name itself. Let me give you a small picture clarification that can give you a full idea in a stretch. 



So let’s take a deep look into each of it.

IaaS - Infrastructure as a service

In the simplest form IaaS services will give you a complete IT infrastructure for you to host your data or software. From the bottom up, Infrastructure as a Service (IaaS) delivers a computing infrastructure in a virtualized environment. These infrastructure resources include virtual compute and storage resources, bandwidth, network connections and more. IaaS can scale up and down as demand changes and also provide redundancy configurations to ensure high availability. 

IaaS allows businesses to purchase resources on-demand and as-needed instead of having to buy hardware outright. The cloud provider maintains the servers and networks in the data centers, assuming responsibility for all physical equipment. Security is a joint responsibility with the Shared Responsibility Model. The customer’s IT is responsible for configuration and maintenance of the guest operating systems, related applications, and resources. As companies embrace different cloud infrastructure models, IT may have to integrate public, private, multi-provider and on-premise environments.

Some of the examples for this service model is Rackspace, Amazon Web Services (AWS), Microsoft Azure, Google Compute Engine (GCE), Oracle OCI.

IaaS Advantages
IaaS offers wide variety of advantages such as,
·    The most flexible cloud computing model
·    Easy to automate deployment of storage, networking, servers, and processing power
·    Hardware purchases can be based on consumption
·    Resources can be purchased as-needed
·    Highly scalable
·    Resources are available as a service
·    Services are highly scalable
·    Organization retain complete control of the infrastructure
·    Dynamic and flexible

IaaS Limitations

·      Legacy systems operating in the cloud. While customers can run legacy apps in the cloud, the infrastructure may not be designed to deliver specific controls to secure the legacy apps. Minor enhancement to legacy apps may be required before migrating them to the cloud, possibly leading to new security issues unless adequately tested for security and performance in the IaaS systems.
·      Internal resources and training - Additional resources and training may be required for the workforce to learn how to effectively manage the infrastructure. Customers will be responsible for data security, backup, and business continuity. Due to inadequate control into the infrastructure however, monitoring and management of the resources may be difficult without adequate training and resources available inhouse.
·      Security. While the customer is in control of the apps, data, middleware, and the OS platform, security threats can still be sourced from the host or other virtual machines (VMs). Insider threat or system vulnerabilities may expose data communication between the host infrastructure and VMs to unauthorized entities.
·      Multi-tenant security - Since the hardware resources are dynamically allocated across users as made available, the vendor is required to ensure that other customers cannot access data deposited to storage assets by previous customers. Similarly, customers must rely on the vendor to ensure that VMs are adequately isolated within the multitenant cloud architecture.

PaaS – Platform as a service

Platform as a Service (PaaS) expands on the capabilities of the SaaS model by not only delivering software but also providing the platform for software development with databases, storage, web servers and operating systems. It is located in-between the SaaS and IaaS layers, supplying more than the bare infrastructure but not the full-fledged application. The PaaS layer provides developers with tools such as business process management, database, and integrations. With this platform, they can develop, run and manage their applications. For businesses who are proficient in IaaS but want the agility and flexibility of PaaS, being able to utilize both layers is an advantage. 

Some of the examples for this service model is AWS Elastic Beanstalk, Salesforce, Google App Engine, Apache Stratos, OpenShift, Visual Builder.

PaaS Advantages

·      Simple, cost-effective development and deployment of apps
·      Scalable
·      Highly available
·      Developers can customize apps without the headache of maintaining the software
·      Significant reduction in the amount of coding needed
·      Builds on virtualization technology, so resources can easily be scaled up or down as your business changes
·      Provides a variety of services to assist with the development, testing, and deployment of apps
·      Accessible to numerous users via the same development application
·      Integrates web services and databases

PaaS Limitations

·    Integrations. The complexity of connecting the data stored within an onsite data center or off-premise cloud is increased, which may affect which apps and services can be adopted with the PaaS offering. Particularly when not every component of a legacy IT system is built for the cloud, integration with existing services and infrastructure may be a challenge.
·    Vendor lock-in. Business and technical requirements that drive decisions for a specific PaaS solution may not apply in the future. If the vendor has not provisioned convenient migration policies, switching to alternative PaaS options may not be possible without affecting the business.
·    Customization of legacy systems. PaaS may not be a plug-and-play solution for existing legacy apps and services. Instead, several customizations and configuration changes may be necessary for legacy systems to work with the PaaS service. The resulting customization can result in a complex IT system that may limit the value of the PaaS investment altogether.
·    Runtime issues. In addition to limitations associated with specific apps and services, PaaS solutions may not be optimized for the language and frameworks of your choice. Specific framework versions may not be available or perform optimally with the PaaS service. Customers may not be able to develop custom dependencies with the platform.

SaaS – Software as a service

In a SaaS service model, the applications will be readily available for customers to use. These are preinstalled and predeveloped applications by different software vendors. With SaaS, the cloud service provider hosts the software and associated data and the user consumes the application on demand. Due to ease of entry, small companies now have the ability to use applications that were previously only available for larger businesses. As the mobile workforce continues to grow, SaaS helps to guarantee a similar experience for all users. 

Some of the examples for this service model is Oracle Fusion, Microsoft O365,Google G-suit and GoToMeeting.

SaaS provides numerous advantages to employees and companies by greatly reducing the time and money spent on tedious tasks such as installing, managing, and upgrading software.

SaaS Advantages

·      Accessible over the internet.
·      Less IT administrative capability is required as compared to other two service models.
·      Users not responsible for hardware or software updates.
·      Frees up plenty of time for technical staff to spend on more pressing matters and issues within the organization.
·      Managed from a central location by SAAS provider.
·      Ongoing involvement is greatly reduced, as expertise is no longer required to the same degree to configure and manage applications, conduct software upgrades, install patches, and integrate APIs.
·      Startups or small companies that need to launch ecommerce quickly and don’t have time for server issues or software.
·      SaaS application’s security and features would be high since this will be updated SaaS providers on a timely manner.

SaaS Limitations

·      Vendor lock-in. Vendors may make it easy to join a service and difficult to get out of it. For instance, the data may not be portable–technically or cost-effectively–across SaaS apps from other vendors without incurring significant cost or inhouse engineering rework. Not every vendor follows standard APIs, protocols, and tools, yet the features could be necessary for certain business tasks.
·      Lack of integration support. Many organizations require deep integrations with on-premise apps, data, and services. The SaaS vendor may offer limited support in this regard, forcing organizations to invest internal resources in designing and managing integrations. The complexity of integrations can further limit how the SaaS app or other dependent services can be used.
·      Customization. SaaS apps offer minimal customization capabilities. Since a one-size-fits-all solution does not exist, users may be limited to specific functionality, performance, and integrations as offered by the vendor. In contrast, on-premise solutions that come with several software development kits (SDKs) offer a high degree of customization options.
·      Lack of control. SaaS solutions involves handing control over to the third-party service provider. These controls are not limited to the software–in terms of the version, updates, or appearance–but also the data and governance. Customers may therefore need to redefine their data security and governance models to fit the features and functionality of the SaaS service.
·      Interoperability. Integration with existing apps and services can be a major concern if the SaaS app is not designed to follow open standards for integration. In this case, organizations may need to design their own integration systems or reduce dependencies with SaaS services, which may not always be possible.
·      Data security. Large volumes of data may have to be exchanged to the backend data centers of SaaS apps in order to perform the necessary software functionality. Transferring sensitive business information to public-cloud based SaaS service may result in compromised security and compliance in addition to significant cost for migrating large data workloads.

SaaS vs PaaS vs IaaS

Each cloud model offers specific features and functionalities, and it is crucial for your organization to understand the differences. Whether you need cloud-based software for storage options, a smooth platform that allows you to create customized applications, or complete control over your entire infrastructure without having to physically maintain it, there is a cloud service for you. No matter which option you choose, migrating to the cloud is the future of business and technology.

Have a comment or points to be review? Knowledge is power and it increases by sharing. Feel free to comment.