Wednesday, 26 May 2010

Note on Risk Management and the Cloud

Think of it as a quadrant of conscious and unconscious competence and incompetence.

- Unconscious incompetence

- Conscious incompetence

- Unconscious competence

- Conscious competence.

We move from unawareness to awareness of problems, from unconscious incompetence, to conscious competence. It makes me laugh that unconscious competence exists because you are doing the right thing but you don't know it (!). We can see a lion in a room and know it’s a risk. It we are looking the other way it is still in the room but we are unaware of it.


The assertion of some risk experts is that there is no such thing as an unmanageable risk - we just need to plan contingency for this. Arguably the Oil leak in the gulf could have been planned and resolved but the risk threshold and the nature of risk changed over time. (Risk status is not static it can change over time - another lion enters the room which may either fight the first Lion or you have two Lions coming for you. One lowers the risk outcome the other increasing it.) It’s about risk tradeoffs. If you have a gun to mitigate the lion then you have lowered the risk. A Crash helmet is a risk mitigating device but it you travel too fast it can still not protect you and kill you etc...


In risk management there are planned risks and unplanned risks which you can atribute risk factors and weighting to. Unplanned risks can still be conscious events unplanned or worse unplanned events that you were not expecting (the oil rig issue)


In cloud computing there are known risks but there can also be unknown risks as it’s a new technology and we simply don’t have a priori knowledge of the risk or the technology to know everything.

Just moving the risk to a 3rd party does not change the existence of the threat or risk - it’s still there but it’s someone else’s problem - but we assume they ca consciously plan for it. We have examples of cloud vendors not doing this- they fail and the knock on effect is that their tenants are affected too - a classic example of devolved risk but not resolved - it’s still there.


Hope this makes sense - it’s all just risk management theory - Warwick Business School, that I have some associations with in the UK have this covered very well and as you can imagine it’s a big topic particularly with the recent finance industry failures - like Goldman Sachs - they had some serious issues of course in this area of perceived and managed risk - they arguable had institutional denial - the halo effect of assuming the best etc.


I advocate that it’s a matter of weighing up different risk scenarios - private or public or other and to get one group of people to see that it’s a lower risk better option than the other - life is rarely that straight forward but I think many technology adoption curves and transformation programs is in effective moving people across different risk weighting - consciously or subconsciously, cooperatively or coersively...

Monday, 29 March 2010

The importance of a Business Perspective on Cloud Computing




The following is a working extract a soon to be published paper for The Open Group for the CBA Project team.

The extract here covers the business value and the financial metrics of cloud. This and other aspects are planned to be in the Cloud ROI white paper to be published in The Open Group Rome in April 2010 Conference.

The importance of a Business Perspective of the Cloud

From a business perspective, the way an organization operates critical business processes and their quality of service QoS is key to business operating success. Identifying competitive business processes as well as standard commodity operations will improve the focus of innovative market growth and cost of service optimization activities made possible by cloud opportunities.

Just focusing on infrastructure improvements may result in cost rationalization but may miss the impact and value of applications and business processes to the end customer. Quality of Service QoS is an essential ingredient in evaluating the business effectiveness. The elements of QoS are made up of infrastructure, resources, activities and services spanning the whole life cycle of business.

In cloud computing the operating challenges experienced from one customer can be proactively fixed for all the other customers of the cloud service through using a shared platform. So value can be leveraged from amortizing economic economies of scale across the collective membership potential of a service ecosystem created by the cloud.

Just looking at cloud computing from a technical infrastructure point of view is potentially missing the wider picture of the impact of technology on the business.

Overall what matters is defining the Value to business. Value can be defined in many ways, not just financial value of the total cost of ownership and return on investment but can also mean customer value, seller provider value, broker value, market brand value, corporate value as well as technical value of the investment.

What is important is to take a portfolio management viewpoint such that all these value factors consider the impact and value to business.

The work of the CBA Project in The Open Group is seeking to identify the key cloud buyer questions and a Meta data lexicon that is in a language business can understand and use to target solutions to meet real business requirements.

In search of Cloud Business Value : Moving from Capex to Opex and Pay-as-you-go, a financial viewpoint

Software as a Service SaaS, utility computing and cloud computing are recent themes in information technology that seek to change the provisioning and utilization of IT.

Key to this is the change in cashflow and cost of capital investment.

Moving to a pay-as-you-go model means the cashflow of your business is changing. Sources of revenue and outgoing cash expenditure are on a usage basis. Cash flow (Cash Flow after Taxes CFAT) is a financial measure of a business ability to generate cash flow through its operations. Moving to an Opex model drives revenue increases, cash and working capital changes. Adopting the cloud computing paradigm seeks to make more money (increase revenues) while driving capital costs down through greater efficiencies of working capital. Net present value (NPV) of investments often need to consider the discounted cash flows of the cost of capital to assess the value of the investment return.

Moving from Capex to Opex is a change in the basis of capital investment usage as upfront and ongoing costs are changed by the cloud computing business model. The focus is on the ability to maximize the leverage of that capital while minimizing the risk to the business in Capital used for initial investment and ongoing maintenance charges. Using an Opex model can potentially remove and release capital that would otherwise be used for initial investment and ownership of IT assets. Alternatively investment in a cloud computing platform may require capital investment and changes to the payment and funding of the service as it is amortized over a wider shared service model for economies of scale. The cost of capital from sources of equity and cost of debt point of view can change for private and public federal companies sources of funding. The overall goal is to maximize the use of capital by best use of the debt and equity funds. In cloud computing the use of Opex moves the funding towards a an Opex model for leverage and risk management.

This white paper examines some of the metrics and performance indicators that drive business towards the cloud computing value model.

A finance viewpoint

What matters is defining Value

Weighted Average Cost of Capital WACC

The issue between the use of capital investment and the weighted average cost of capital (WACC) outlines the issue around debt and equity funding in private companies(. Public federal companies also have sources of funding that are from government sources of funding.

WACC describes the company cost of capital from a equity and debt view point. The cost of equity and the cost of the debt to the organization can be examined through the weighting of how the financing of equity and financing the debt are managed over time.

Ref: http://www.investopedia.com/terms/w/wacc.asp

Cash flow after Taxes CFAT

Focusing on the uses of the investment funds is the flows of inbound and outbound cash.

Cash flow (Cash Flow after Taxes CFAT) is a financial measure of a business ability to generate cash flow through its operations.


Net present value (NPV) of investments often need to consider the discounted cash flows of the cost of capital to assess the value of the investment return.

Ref: http://www.investopedia.com/terms/c/cfat.asp


Monday, 21 December 2009

The vote on the Service-Oriented Cloud Computing Infrastructure Project OpenGroup

I am seeing the topic of SOA to enable internal and external services to operate in Cloud infrastructures as a key topic particularly in the evolutions of SOA Design time artifacts (service contract, format protocols, portfolio) into Run time Service artifacts (API, Consumer/producer platform) that include the elastic environment specification and the specification form Security interoperability and a specification for dynamic binding and discovery among three key ones I can think of.

I have found in SOA projects that many where locked into a design time specification that was passed to developers who then figured out how to design and build the solution. Much of the web service or API design was either driven by a specific BPM style or Portlet style or more generally driven by a wrapper and service management focus. The production environment and network connectivity has typically been outside the span of a SOA project, typically putting non-functionals and production build and deployment into the area of existing infrastructure or new hardware investment to support a broad availability and utilization target. With active management and transaction level performance management in Service Management tools it is now possible to monitor and optimize individual web service calls and to fine tune network packets and database performance. This means that the goals of service oriented performance and QoS can potentially be modelled and delivered on a transaction by transaction basis.

The evolution of cloud based assets means the "up and down use" of application services can potentially reflect the real-time use of the IT services. The integration of SOA concepts with Cloud is a critical area to elaborate on how this can be done given the reality of the Cloud particularly in IaaS and PaaS is here already. An interesting area is the approach of Cloud vendors to adopt a RDF or own ontology to describe the metalanguage of the Cloud Infrastructure or to use more specific Hypervisor or API Oriented connection specifications.

One area I am hoping the SOA Cloud project will help is to understand how to design applications in an SOA style that could best use a Cloud Infrastructure Environment. My understanding for example in work I conducted with VMware last year on Vcloud and Vapps is that the direction is towards "infrastructure aware applications" as the deconstruction of application functionality is further redefined as types of logic and payload services that are virtualized and "call" cloud infrastructure resources as and when it needs it. Multiplicity functionality is a new concept that enables multiple SOA style services to run simultaneously to process multiple services and scenarios through a distributed cloud infrastructure.

A great example of this I have seen with INTEL Research work focusing on Mobile Cellphone Technology that moves high processing workloads onto a external cloud service provider and returns the result back to the mobile cellphone device. This in effect "virtualizes the CPU and memory power" of the mobile cellphone device to include the external cloud services. Suddenly the cloud makes possible to bring new services and power to a multitude of different devices.

I think the SOCC Infrastructure project will pull existing SOA artifacts and Cloud together and I hope will help define the extensions of SOA to embrace the powerful "infrastructure Services" enabled via cloud. While this area is still evolving in the Cloud Infrastructure and interoperability specification I think the design of a "Cloud contract" will be much enhanced by this project.

Saturday, 1 August 2009

The 6 M’s of Cloud oriented services

Looking at aspects of cloud computing has brought in many different operating characteristics under the spot light. What architects refer to as the “ilities” of services and marketers the “messaging”; the resulting service levels and blurring of marketarhicture has caused some greyness around how to define operating features for a cloud environment.

Differentiation of the service providers is evolving together with new technology features starting to appear under a cloud oriented portfolio. Two or three camps are emerging between services to enable clouds (typically other providers cloud platforms) and providers of cloud services and platforms. An intervening debate currently is whether there is a third segment of the market that involves brokering and aggregating cloud services, term also seen as Orchestration in this space.

A fundamental question is how to move to offer cloud services that recognize the cost benefits of IT operations but also can affect and build the business services that business want to drive. I saw a great phase recently about IT Services stating “too much green field thinking in projects” as a cause for difficulty in IT service lifecycle management. Often the incumbent brown field operation and IT estate would not just go away and vanish and the project implementing new or enhanced systems and solutions acted in a separate fashion to the deployment environment view. This is great truism of IT in that many aspects of service needs to bridge between what is being build and ran in IT and how business uses and might want to change rapidly or strategically to build new business capabilities. Cloud computing if nothing else does commoditize aspects of the hardware and software and starts to enable business service centric design and consumption patterns based on business service levels and business level consumption.

I have mentioned the word cloud services as if this is a defined term of the industry when in fact it is still an evolving term. To pick one visible development in the US with the NIST they term a design and deployment taxonomy that included the terms IaaS, PaaS, SaaS and the delivery models described in public, community, private and hybrid clouds (http://csrc.nist.gov/groups/SNS/cloud-computing/index.html ). But these definitions are architectural and don’t fully describe how services operate across these tiers of technology or the virtual or physical placement of the hosting of these services. In short, how these cloud services are seen from the perspective of business services to business.

I think these are still being characterized by the design of boundary management between the APIs, the platforms and the participants involved (internal, external or a mixture of communities). SOA defined an IT centric state of services and took a path towards IT services enablement. The Service contracts defined are now potentially being broaden out into Cloud contracts that take onboard the aspects of

So what would be the features in such a cloud contract?

I see at least six component characteristics which push the thinking of business services through the use of cloud in what I term the 6 M’s of cloud oriented services: Multi-tasking, Multiplexing, Multiplicity , Multi-Tenancy, Multi-casting and Multi-key.

· Multi-tasking

o The term multi-tasking is used here to mean the feature of repurposing the IT assets and functions to the service to what is required at the time of use. Virtualization enables logical provisioning of IT services and the recognition of assets to mean different purposes.

· Multiplexing

o This is the balancing of workloads and performance based on the actual usage of the service and not the forecast (termed statistical Multiplexing in the University of California Berkley paper Above the clouds in Feb 2009 http://www.eecs.berkeley.edu/Pubs/TechRpts/2009/EECS-2009-28.html )

· Multiplicity

o This is an interesting feature that extends the work to do in more than one instance of that work. Or to put it another way it is possible to simultaneously run many workloads depending on the service needs. Selected tasks or complex processes can be moved to the cloud. This promotes the idea of not just performing specific tasks constrained by your current task but also the possibility to run other alternative tasks scenarios. This is a new way of thinking made possible by cloning instances and services in a on-demand elastic capacity environment.

· Multi-tenancy

o The tenancy of a service can be dedicated or part of a shared community environment. Multi-tenancy extends the definition of tenancy into a definition of the tenancy in one location that can be used and representing many tenant locations. The central idea is efficiency of specification and variations to support business services for many users.

· Multi-casting

o This feature is to some extent a feature of multi-tenancy at the network level and how services can be delivered in an efficient and enterprise perspective. Multi-casting is a network capability to delivery information to a group of nodes simultaneously in an efficient way that delivers messages once and copies to multiple destinations. Used in streaming media and other IP multicast IP routing this aspect of services needs to consider the boundary of cloud service delivery at the network that may involve 3rd party networks and cloud platforms.

· Multi-Keys

o In enterprise level services the need to address large groups of security policies and user groups is a feature that needs to consider the complexity of identity and authentication services. Public and private key encryption has aspects that need administration in the context of cloud services.

Friday, 26 June 2009

The need for Multiplicity and maintaining encryption persistence – a mathematical milestone broken but not just yet

Interesting blog entry on the CCIF around IBM Solves Cryptographic Cloud Security.

http://www.elasticvapor.com/2009/06/ibm-solves-cryptographic-cloud-security.html

Reading further this discusses the topic of privacy homomorphism which focuses on one of the core issues of ensuring information privacy stored in a cloud environment and how to maintain data encryption while processing and storage in the cloud environment.

Much cloud debate has been on the subject of security access and transport of data into the cloud and then securing the information while it is held in the cloud environment. An issue often raised is when the data is decrypted at the point of use and hence a potential protection point problem where confidentially could be compromised.

While secure virtual machine containers and VPN tunnels can address the isolation issue of the cloud service as it is transported to the cloud environment; the basic problem of maintaining the encryption state of the data is when it has to be used and therefore open to view.

Alternative models of data and code obfuscation software promise a way of using the data but this has some observed limitations in many business scenarios that require strong encryption of sensitive data. A secondary issue is the additional layer of complexity that use of this approach can add to processing time and debugging.

The article indicates that IBM Researcher Craig Gentry using a mathematical method enables full interaction with encrypted data directly. This is a perfect scenario and a milestone in security computation but as flagged with various responses to the article in Forbes Magazine there is the addition of similar challenges as obfuscation algorithms in the overhead of processing. http://www.forbes.com/forbes/2009/0713/breakthroughs-privacy-super-secret-encryption.html

Multiplicity – building the capabilities of utility cloud services.

This suggests more than ever the need to build multiplicity into cloud services that enable partial or complete movement of workload processing into a cloud. This needs a step change in the way IT processes are designed into the architecture and delivered as a service. With increasingly complex processes such as language translation and security as in the example of encryption this increases the in-memory and computation workload.

Cloud is an evolving area which I see moving beyond the current utility services of Cloud which is now taking hold with strong and robust services in storage, compute and software as a service offerings becoming a reality.

A multiplicity strategy enables isolated processes to be moved to the cloud which will need service providers and cloud vendors to consider how to build added value services that better leverage infrastructure resources on-demand. The security encryption puzzle is just another barrier which shows that with ingenuity and innovation the walls of new technology adoption and be over come.

Friday, 29 May 2009

Cloud Multiplicity - the multi-cloud

Reading a great book by George Reese, Cloud Application Architectures - O'Reilly 2009. Clearly a guy with real experience of the cloud as the founder of Valtira and latterly enStratus ( a competitor to RightScale. http://www.enstratus.com/page/1/blog.jsp )

Whats an eye opener is the perspectivies of reliability of virtual instances versus physical instances. He is quite direct in his statements that virtual instances are much less reliable than physical instances. While its a AWS perspective he states that EC2 instances are much less reliable and that design for failure is a critical step in cloud design. He advocates as I do a strong separation of presentation, business modeling, business logic, and data as per the MVC paradigm and is realistic in the focus on cluster technology in application and database server scaling design for cloud elasticity benefits.

He also has some useful definitions of security around the Network intrusion and Host intrusion Tools which are clearly a key enabler for Cloud services as he points out that physical network DMZs are not possible in many externalized cloud data centers. I like also his refreshing real world view of security evolution in standards lagging in the virtualizational separation that means that separate server partitioning is a false situation in logicalization of servers via VMs.

He provides a wake up call on the I/O performance of storage which is often not suitable for NR or real time applications and squarely in the batch temporal domain of service performance which places cloud as backup as a service and archive. Perhaps AWS recent view of accelerated network I/O services is a recognition of this and that network based cloud services and strategic alliances is a critical strategy for cloud performance.

The book also illustrates the performance issues over CPU intensive operations in the cloud and also the barriers of legacy investments to cloud adoption of IaaS (He also confirms its cheapers to extend the existing infrastructure) but confirms the loss of future strategy by these challenges. (as ratified with his conversations with James Urquhart http://www.cnet.com/profile/jamesurquhart/?tag=mncol;txt ) The ability to adopt different VM strategies for legacy apps modernizations will be a key driver to cloud integration which I see as being able to work at different levels of abstraction rather than just at the IaaS and PaaS tiers. Taking a classical orchestrator view of modernization and adoption will fail as it seeks to control IT estate too much whereas a multiple use case approach to on-demand services underpined by a range of evolving platforms for IaaS and PaaS will accelerate adoption.

I believe the emergence of multiplicity strategies to support statistical multiplexing patterns will drive realistic cloud adoption including virtualization patterns in :
  • Partitioning strategies for worloads to cloud operations
  • Clone strategies for backup, replication, intelligence extensions e.g. RT language translation and multiple process services for multiple parallel temporial services
  • Applicance strategies for application extentions via API
  • PaaS and IaaS integration e.g. GoogleApps and Force.com integration
  • Adoption of mainstream Service Management challenges with Social media systems e.g. the Twitter / Facebook as a "remedy channel" effect
The advocacy of using PaaS investments to support operational I/O and CPU performance will create the tipping point to develop PaaS and SaaS services. The security of public clouds do still have partitioning problems for geographic and national law compliance but as explained in the book the technical aspects are not impossible to replicate to bring the security to a level of a private data center in may respects.

Wednesday, 6 May 2009

Cloud Clone Augmented Execution


Exploiting cloud clone augmentation

A very impressive white paper has come out from the Intel Berkley Lab from Byung-Gon Chun and Petros Maniatis titled  "Augmented Smartphone Applications Through Clone Execution".  as part of the Proceedings of the 12th Workshop on Hot Topics in Operating Systems (HotOS XII), May 2009.

http://berkeley.intel-research.net/bgchun/clonecloud-hotos09.pdf       


The paper explores a research topic of how to deploy workload intensive operations from a Smartphone platform into the cloud and return the results to exploit bursting to augment the mobile services. The project title is CloneCloud. 

http://berkeley.intel-research.net/bgchun/clonecloud/   


What is particularly interesting is the way a number of virtualization topics and augmented processes for workloads can be split between the cell phone and the cloud. The key point here is the separation and spread of workloads between different local and virtual platforms such that the computational and storage capabilities are leveraged as "one networked computer" service. Add to this augmented application services not covered in the article and you start to see a number of added value services in a business context. This approach is evident when in a recent analysis I completed of the types of cloud burst services, it is clearly not constrained to excess volume or low volume workload management but also the redirection of specific types of work loads to cloud facilities.


Another very interesting statement in the white paper has been "multiplicity"   a feature that has been in the scope of virtualization to optimize workloads but in the case of cloud computing services starts to create a number of very interesting possibilities hitherto considered as capacity resource constrained.

To quote the article:  


Use multiple copies of the  system image executed in different ways.  This can help run data parallel applications.  E.g. indexing for disjoint sets of images.  This can also help the application “see the future”, by exhaustively exploring all possible next steps within some small horizon.  To enable for scenario model checking such as in monte carlo simulation.


This is a different way of of not only considering the virtualized device cloned into the cloud but in replicating the machine image it is possible to create multiple parallel tasks and from there a range of new service augmentation possibility not envisioned by the initial invocation. As previously suggested, if you add augmented application services into this you start to see a wider set of added value services. 


What this says to me is that the on premise and off premise geographical distinction is wrong in the sense it is the device and the machine specific locations that are the real on and off premise locations.   It also supports the view that temporal transformation as seen in batch to near real time processing in traditional timeframes may now evolve into new temporal transgformations that operate beyond immediate time and create multiple versions of "parallel time services".  In a sense there are multiple arrows of time.What it does also suggest is that the concept of a cloud switch may involve a number of second level and higher tiers of event interaction and types of VM patterns than just the Hypervisor workload management.


A summary of the cloud workload distribution patterns described in the article are:


Primary functionality outsourcing
Computation hungry applications such as speech processing, video indexing, and super-resolution are auto0matically split from the user interface and other low processing within the Smartphone.
Background
Functionality that does not need to interact with users in short term time scale. E.g. virus scanning, indexing files for faster search, analyzing photos for common search, crawling news web pages,
Mainline
Sitting between the primary and background augmentation. The user may opt to run a particular application in a wrapped fashion, altering the method of execution  not the semantics. E.g. private-data leak detection (taint check an application or applcation group, fault tolerance  (e.g. use a multi-variant execution analysis to protect the application from transparent bugs), debugging (e.g. keep track dynamically of allocated memory  in the heap to catch memory leaks
Hardware
Compensation for Smartphone weaknesses e.g. memory caps or other constraints and hardware peculiarities
Multiplicity
Use multiple copies of the  system image executed in different ways.  This can help run data parallel applications.  E.g. indexing for disjoint sets of images.  This can also help the application “see the future”, by exhaustively exploring all possible next steps within some small horizon.  To enable for scenario model checking such as in monte carlo simulation.