Cutter IT Journal
Total Page:16
File Type:pdf, Size:1020Kb
Cutter The Journal of IT Journal Information Technology Management Vol. 28, No. 10 October 2015 “IaaS is here to stay in many organizations, especially IaaS: Ready for Liftoff? smaller firms and startups, and it will be the dominant form of corporate IT infra- Opening Statement structure in the coming years.” by Vince Kellen . 3 — Vince Kellen, What Should a CIO Consider When Running a Cloud RFP? Guest Editor by James Mitchell and Frank Khan Sullivan . 6 Cloud-Native Design — What Has Changed? by Lukasz Paciorkowski . 11 The Reasons for (and Benefits of) Moving to IaaS: A Case Study at FINRA by Saman Michael Far . 20 Adopting IaaS: The Legal and Security Issues You Can’t Ignore by Annie C. Bai . 25 Darkness on the Edge of Cloud by Vince Kellen . 28 NOT FOR DISTRIBUTION For authorized use, contact Cutter Consortium: +1 781 648 8700 [email protected] Cutter IT Journal About Cutter IT Journal Cutter IT Journal® Cutter Business Technology Council: Part of Cutter Consortium’s mission is to Cutter IT Journal subscribers consider the Rob Austin, Ron Blitstein, Tom DeMarco, Lynne Ellyn, Israel Gat, Vince Kellen, foster debate and dialogue on the business Journal a “consultancy in print” and liken Tim Lister, Lou Mazzucchelli, technology issues challenging enterprises each month’s issue to the impassioned Ken Orr, and Robert D. Scott today, helping organizations leverage IT for debates they participate in at the end of Editor Emeritus: Ed Yourdon competitive advantage and business success. a day at a conference. Publisher: Karen Fine Coburn Cutter’s philosophy is that most of the issues Group Publisher: Chris Generali that managers face are complex enough to Every facet of IT — application integration, Managing Editor: Karen Pasley merit examination that goes beyond simple security, portfolio management, and testing, Production Editor: Linda M. Dias Client Services: [email protected] pronouncements. Founded in 1987 as to name a few — plays a role in the success American Programmer by Ed Yourdon, or failure of your organization’s IT efforts. Cutter IT Journal® is published 12 times a year by Cutter Information LLC, Cutter IT Journal is one of Cutter’s key Only Cutter IT Journal and Cutter IT Advisor 37 Broadway, Suite 1, Arlington, MA deliver a comprehensive treatment of these venues for debate. 02474-5552, USA (Tel: +1 781 648 critical issues and help you make informed 8700; Fax: +1 781 648 8707; Email: The monthly Cutter IT Journal and its com- decisions about the strategies that can [email protected]; Website: panion Cutter IT Advisor offer a variety of improve IT’s performance. www.cutter.com; Twitter: @cuttertweets; perspectives on the issues you’re dealing with Facebook: Cutter Consortium). Print Cutter IT Journal is unique in that it is written ISSN: 1522-7383; online/electronic today. Armed with opinion, data, and advice, ISSN: 1554-5946. you’ll be able to make the best decisions, by IT professionals — people like you who ©2015 by Cutter Information LLC. employ the best practices, and choose the face the same challenges and are under the All rights reserved. Cutter IT Journal® same pressures to get the job done. Cutter right strategies for your organization. is a trademark of Cutter Information LLC. IT Journal brings you frank, honest accounts No material in this publication may be Unlike academic journals, Cutter IT Journal of what works, what doesn’t, and why. reproduced, eaten, or distributed without doesn’t water down or delay its coverage of written permission from the publisher. timely issues with lengthy peer reviews. Each Put your IT concerns in a business context. Unauthorized reproduction in any form, Discover the best ways to pitch new ideas including photocopying, downloading month, our expert Guest Editor delivers arti- electronic copies, posting on the Internet, cles by internationally known IT practitioners to executive management. Ensure the success image scanning, and faxing is against the that include case studies, research findings, of your IT organization in an economy that law. Reprints make an excellent training and experience-based opinion on the IT topics encourages outsourcing and intense inter- tool. For information about reprints enterprises face today — not issues you were national competition. Avoid the common and/or back issues of Cutter Consortium pitfalls and work smarter while under tighter publications, call +1 781 648 8700 dealing with six months ago, or those that or email [email protected]. are so esoteric you might not ever need to constraints. You’ll learn how to do all this and Subscription rates are US $485 a year learn from others’ experiences. No other more when you subscribe to Cutter IT Journal. in North America, US $585 elsewhere, journal brings together so many cutting- payable to Cutter Information LLC. edge thinkers or lets them speak so bluntly. Reprints, bulk purchases, past issues, and multiple subscription and site license rates are available on request. Start my print subscription to Cutter IT Journal ($485/year; US $585 outside North America) SUBSCRIBE TODAY Name Title Request Online License Company Address Subscription Rates City State/Province ZIP/Postal Code For subscription rates for online licenses, contact us at [email protected] or Email (Be sure to include for weekly Cutter IT Advisor) +1 781 648 8700. Fax to +1 781 648 8707, call +1 781 648 8700, or send email to [email protected]. Mail to Cutter Consortium, 37 Broadway, Suite 1, Arlington, MA 02474-5552, USA. Opening Statement by Vince Kellen, Guest Editor The uncertain future of cloud computing seems to requirements “in the middle of what the market offers,” have stabilized among IT leaders with the acceptance as overly specific requirements and the attendant cus- of infrastructure as a service (IaaS). IaaS is here to stay tomization will drive up costs. They also suggest that in many organizations, especially smaller firms and working with a cloud financial broker can help organi- startups, and it will be the dominant form of corporate zations maximize their vendor choices and get the best IT infrastructure in the coming years. With the breaking price overall. of Moore’s law (at least for the foreseeable future and From such high-level concerns, we turn our attention with regard to silicon-based computing), IaaS may pro- to the cloud’s underpinnings in Lukasz Paciorkowski’s vide everyday computing cost benefits thanks to the article on cloud-native design. While he acknowledges efficiencies large-scale dedicated vendors can provide. that the subject of building and operating cloud-native But many organizations, most notably the larger and applications “is a very technical discussion,” he argues more conservative companies, are still on the fence that “it can have a profound impact on the business and about moving their infrastructure to an IaaS model. operational model, [and thus] it should not be ignored IaaS can be deployed in different models, including by anybody who is serious about capturing the value of on-premises and off-premises, managed by a third cloud computing.” After exploring the techniques, plat- party or managed internally, and/or using private forms, and powerful new tools that make this design or public cloud environments. approach possible, Paciorkowski outlines the business benefits of cloud-native design and discusses the char- Which model(s) should an organization adopt? How acteristics that might make an organization a good — or do firms know if moving their hardware, software, not so good — fit for this emerging solution. servers, storage, and other infrastructure components to a third-party provider is right for them? Should In our next article, Saman Michael Far takes us from they consider IaaS only for temporary or experimental theory to practice in his case study of IaaS impleme- workloads? Also worth considering and planning for ntation at FINRA, an independent nongovernmental are the technical/security risks, scalability, and legal/ organization that monitors and regulates US securities contract issues that are critical to a successful IaaS plat- trading. Seeking to reduce its infrastructure spending, form deployment. In this issue of Cutter IT Journal, our automate its production support, and increase its ana- authors share their insights on the issues organizations lytics capability, FINRA found that moving to a virtual should contemplate before moving to IaaS. private cloud using Amazon Web Services (AWS) and open source platforms was the best way to achieve its objectives. Far discusses the reasoning behind this deci- IN THIS ISSUE sion, as well as many issues organizations face when We begin the issue with an article by Cutter Senior moving to the cloud, such as security, business and Consultant James Mitchell and his colleague Frank architectural concerns, disaster recovery planning, and Khan Sullivan who offer CIOs and their organizations impacts on culture. advice on running a successful cloud RFP. Using a Next, Annie C. Bai reminds us that “information dining analogy to demonstrate why a multi-vendor security can never be fully outsourced.” As tempting approach provides more flexibility, reliability, and as it might be to consider security, privacy, and data lower costs, they ask, “Are you worried that even if you integrity someone else’s problems once you move to went to that single restaurant that had everything you IaaS, the unfortunate truth is that all these things are wanted on the menu, the quality might degrade over still your organization’s responsibility. After all, she time?... No single cloud vendor is good at everything.” notes, “it is your business that will suffer the conse- Observing that cloud’s cost-cutting promise depends quences of any interruption of access or any flaws in on sharing, they counsel organizations to specify their your data integrity.” Bai gives recommendations for Get The Cutter Edge free: www.cutter.com NOT FOR DISTRIBUTION • For authorized use, contact Vol.