SlideShare a Scribd company logo
1 of 26
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Matthew McGuire, GSA, Director, Technology Solutions Division
Guy Cavallo, TSA, Executive Director, IT Operations
Brian Anderson, AWS, Sr. Consultant, Professional Services
June 20, 2016
Governance Strategies for
Cloud Transformation
Goals for the session
• Definition and overview of cloud governance
• Cloud center of excellence (CCoE)
• Stages of cloud governance
• Cloud governance best practices
• GSA — Review of business services platform (BSP)
• TSA — Discussion of governance
• Question and answer
Definition of cloud governance
The decision-making criteria, processes, and policies involved in the
planning, architecture, acquisition, deployment, operation and
management used for operating IT services in the cloud.
— Cloud governance allows IT to innovate,
automate, and quickly deploy code and
infrastructure while maintaining the
necessary requirements for security, audit,
control, and compliance.
Goals for cloud transformation
Why governance?
1. Reduction in access and security risks
2. Development of cloud standards — delivery, tools, process
3. Management of application design: CI and CD design
4. Cost optimization
5. Increased innovation for business units
6. Elimination of rogue IT and disparate cloud initiatives
7. Management of the consumption of cloud resources
Cloud governance opportunities
• Speed — Enable business at cloud speed and cost
• Integration — Complementary to existing enterprise
IT governance processes, policies, and tools
• Balance — Appropriate coverage for key decisions, investments,
and risks while achieving the benefits of the cloud
• Proactivity — Anticipate and prevent shadow clouds and
unauthorized cloud activities that expose organizational risks
• Enablement — Appropriate cloud decision making without friction
Cloud center of excellence
(CCoE)
Cloud center of excellence (CCoE)
The cloud center of excellence is a
team of executives and IT area
experts that authors cloud governance
to enables business units to access a
self-service model and provides a
catalog of standardized and templated
instances from which to select and
autoprovision
Stages of cloud governance
Levels of cloud
governance
L0 – Decentralized
control
L1 – Centralized
control
L2 – Decentralized
control with
automation
L3 – Centralized
control with self-
service
Three phases of cloud governance
Beginning
• Minimal
integration
• Reactive
environment
• Cost overruns
• Manual
deployments
• No cloud
structure
Adopting
• CCoE is in place
and policies are
maturing
• Policies
matched to
process
• Designing for
cost
• Rapid
deployment
Mature
• Full automation
and self-service
• Benefits of cloud
services realized
• Agility and control
• Optimized for
cost
• Secure and
compliant
environment
Phase 1: Beginning
1. Create the CCoE to develop and own governance and its policies
2. Develop governance model and establish policies for:
• Security
• Account management
• Cost
• Network
• Instance and storage
• Service management
• Monitoring and reporting
3. Begin to modify the deployment process and policies and look to automate
• Develop governing policies to enable automated approval cycles
• Develop financial policies to enable BUs to quickly stage POCs
Phase 2: Adopting
1. Develop self-service policies
2. Develop data governance policies
3. Develop continuous integration / deployment policy
4. Develop design-for-cost architecture guidelines
5. Develop cloud audit and compliance policies
6. Develop a common API design framework
Phase 3: Mature
1. Develop advanced automation techniques and policies to promote
further cost reduction, agility, and resiliency:
• Automated testing and code promotion from each tier to production
• Automated DR and recovery testing — Chaos Monkey / Chaos Gorilla
• Automated instance power down / power up for non-Reserved
Instances
• Utilization of Spot Instances — when and where to use
2. Develop transition policies to define services and SOA
3. Develop policies allowing existing applications to test-for-cost
(scale up / scale out)
Cloud governance best practices
• Establish a CCoE and begin developing/updating policies
• Tailor your governance process to your organization’s particular risk
tolerance
• Decide where to leverage existing processes versus establishing
new ones
• Make the process as lightweight as possible and as informative as
possible to create a positive user experience
• Start early in the transformation so you can get business and IT
feedback and support
• Rely on use-case reviews to improve your processes
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Matthew McGuire
Director, Technology Solutions Division
June 20, 2016
GSA Business Services Platform
Enabling Greater Agency Agility to Drive Mission Impact
The GSA cloud
transformation
”Worked fine in dev…” “...OPS has problems”
Then (data center)
• Days/months to provision
• Months to app ATO
• One off configs for every app
• Size to peak demand
• Long, painful outages
• Everything needs software
What is BSP and how does it transform IT
Now (BSP)
• Minutes to provision
• Weeks to app ATO
• Standard app stacks/services
• Automated scalability
• Immediate server redeployment
• Automated — Infrastructure as code,
continuous delivery
• Secure — Multitenant, security driven
architecture
• Cost effective — Pay for what you use
• Metrics — Visibility into usage and cost
• Modernization platform — Get to the cloud
BSP is a modernization platformSecuritycontrolinheritance
Degree of automation and cloud optimization
Mode 2
OS
optimization
Mode 3
Fully
automated
stack services
devops
Orchestration
Infrastructure
as code
• Choose the mode
that best suits
your application
and level of cloud
optimization
• Mode 3 apps
inherit >85% of all
ATO security
controls
Mode 1
Compute,
network,
storage
MIGRATED APPS
APP
DATA
OPTIMIZED APPS AUTOMATED APPS
APP
1. Choose app stack
Template file
• Component
Configs
• Cluster Sizes
• Auto Scaling
• Etc.
3. Stage content
4. Run preconfigured
orchestration job
5. Application fully
deployed
6. Invoke Ansible callback
7. Run Ansible config roles, including app deployment
5. Deploy
infrastructure
AWS IAM
1. Jenkins initiates deployment through Ansible Tower
2. Generate custom
AWS Identity and
Access Management
(IAM) policy and
Amazon CloudFormation
template
2. Customize stack
Developer experience
Orchestration workflow
Security & Reliability
Benefits
Enabling greater agency agility to drive mission impact
• Speed and flexibility
• Configuration control
• Scalability
• Security
• Reliability
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Guy Cavallo
Executive Director, IT Operations
Transportation Security Administration
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Question and Answer
Governance Strategies for Cloud Transformation | AWS Public Sector Summit 2016

More Related Content

What's hot

AWS Cloud Center Excellence Quick Start Prescriptive Guidance
AWS Cloud Center Excellence Quick Start Prescriptive GuidanceAWS Cloud Center Excellence Quick Start Prescriptive Guidance
AWS Cloud Center Excellence Quick Start Prescriptive Guidance
Tom Laszewski
 

What's hot (20)

FinOps for private cloud
FinOps for private cloudFinOps for private cloud
FinOps for private cloud
 
Emerging Trends in Hybrid-Cloud & Multi-Cloud Strategies
Emerging Trends in Hybrid-Cloud & Multi-Cloud StrategiesEmerging Trends in Hybrid-Cloud & Multi-Cloud Strategies
Emerging Trends in Hybrid-Cloud & Multi-Cloud Strategies
 
Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...
Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...
Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...
 
Azure Stack Fundamentals
Azure Stack FundamentalsAzure Stack Fundamentals
Azure Stack Fundamentals
 
Defining Your Cloud Strategy
Defining Your Cloud StrategyDefining Your Cloud Strategy
Defining Your Cloud Strategy
 
[보험사를 위한 AWS Data Analytics Day] 4_신한금융그룹의 데이터 댐_Do...
[보험사를 위한 AWS Data Analytics Day] 4_신한금융그룹의 데이터 댐_Do...[보험사를 위한 AWS Data Analytics Day] 4_신한금융그룹의 데이터 댐_Do...
[보험사를 위한 AWS Data Analytics Day] 4_신한금융그룹의 데이터 댐_Do...
 
Cloud Center of Excellence
Cloud Center of ExcellenceCloud Center of Excellence
Cloud Center of Excellence
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Cloud Migration: A How-To Guide
Cloud Migration: A How-To GuideCloud Migration: A How-To Guide
Cloud Migration: A How-To Guide
 
"Introduction to FinOps" – Greg VanderWel at Chicago AWS user group
"Introduction to FinOps" – Greg VanderWel at Chicago AWS user group"Introduction to FinOps" – Greg VanderWel at Chicago AWS user group
"Introduction to FinOps" – Greg VanderWel at Chicago AWS user group
 
FinOps at REA – Innovation in Finance & Operations
FinOps at REA – Innovation in Finance & OperationsFinOps at REA – Innovation in Finance & Operations
FinOps at REA – Innovation in Finance & Operations
 
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
 
A Roadmap to Cloud Center of Excellence Adoption
A Roadmap to Cloud Center of Excellence AdoptionA Roadmap to Cloud Center of Excellence Adoption
A Roadmap to Cloud Center of Excellence Adoption
 
Setting up a Cloud Center of Excellence (CCoE) for Enterprise Customers
Setting up a Cloud Center of Excellence (CCoE) for Enterprise CustomersSetting up a Cloud Center of Excellence (CCoE) for Enterprise Customers
Setting up a Cloud Center of Excellence (CCoE) for Enterprise Customers
 
AWS Cloud Center Excellence Quick Start Prescriptive Guidance
AWS Cloud Center Excellence Quick Start Prescriptive GuidanceAWS Cloud Center Excellence Quick Start Prescriptive Guidance
AWS Cloud Center Excellence Quick Start Prescriptive Guidance
 
Azure Cost Management
Azure Cost ManagementAzure Cost Management
Azure Cost Management
 
Creating an Effective Roadmap for Your Cloud Journey (ENT225-R1) - AWS re:Inv...
Creating an Effective Roadmap for Your Cloud Journey (ENT225-R1) - AWS re:Inv...Creating an Effective Roadmap for Your Cloud Journey (ENT225-R1) - AWS re:Inv...
Creating an Effective Roadmap for Your Cloud Journey (ENT225-R1) - AWS re:Inv...
 
Capgemini Cloud Assessment - A Pathway to Enterprise Cloud Migration
Capgemini Cloud Assessment - A Pathway to Enterprise Cloud MigrationCapgemini Cloud Assessment - A Pathway to Enterprise Cloud Migration
Capgemini Cloud Assessment - A Pathway to Enterprise Cloud Migration
 
Practical FinOps in Practice
Practical FinOps in PracticePractical FinOps in Practice
Practical FinOps in Practice
 
[115]쿠팡 서비스 클라우드 마이그레이션 통해 배운것들
[115]쿠팡 서비스 클라우드 마이그레이션 통해 배운것들[115]쿠팡 서비스 클라우드 마이그레이션 통해 배운것들
[115]쿠팡 서비스 클라우드 마이그레이션 통해 배운것들
 

Viewers also liked

Viewers also liked (11)

How hybrid/multi-cloud governance platform benefits your cloud strategy
How hybrid/multi-cloud governance platform benefits your cloud strategy How hybrid/multi-cloud governance platform benefits your cloud strategy
How hybrid/multi-cloud governance platform benefits your cloud strategy
 
CLOUDFX: Addressing Challenges in Cloud Migration and Paving the Way for IT T...
CLOUDFX: Addressing Challenges in Cloud Migration and Paving the Way for IT T...CLOUDFX: Addressing Challenges in Cloud Migration and Paving the Way for IT T...
CLOUDFX: Addressing Challenges in Cloud Migration and Paving the Way for IT T...
 
AWS Governance Overview - Beach
AWS Governance Overview - BeachAWS Governance Overview - Beach
AWS Governance Overview - Beach
 
Digital Transformation, Cloud Adoption and the Impact on SAM and Security
Digital Transformation, Cloud Adoption and the Impact on SAM and SecurityDigital Transformation, Cloud Adoption and the Impact on SAM and Security
Digital Transformation, Cloud Adoption and the Impact on SAM and Security
 
(ISM308) 9 Best Practices to Avoid Stalled Cloud Transformation
(ISM308) 9 Best Practices to Avoid Stalled Cloud Transformation(ISM308) 9 Best Practices to Avoid Stalled Cloud Transformation
(ISM308) 9 Best Practices to Avoid Stalled Cloud Transformation
 
The Enterprise Business Case for Cloud Transformation: Introducing Everest Gr...
The Enterprise Business Case for Cloud Transformation: Introducing Everest Gr...The Enterprise Business Case for Cloud Transformation: Introducing Everest Gr...
The Enterprise Business Case for Cloud Transformation: Introducing Everest Gr...
 
How to Manage Organizational Change and Cultural Impact During a Cloud Transf...
How to Manage Organizational Change and Cultural Impact During a Cloud Transf...How to Manage Organizational Change and Cultural Impact During a Cloud Transf...
How to Manage Organizational Change and Cultural Impact During a Cloud Transf...
 
Identity Live Sydney 2017 - Ian Sorbello
Identity Live Sydney 2017 - Ian SorbelloIdentity Live Sydney 2017 - Ian Sorbello
Identity Live Sydney 2017 - Ian Sorbello
 
API Introduction - API Management Workshop Munich from Ronnie Mitra
API Introduction - API Management Workshop Munich from Ronnie MitraAPI Introduction - API Management Workshop Munich from Ronnie Mitra
API Introduction - API Management Workshop Munich from Ronnie Mitra
 
Deep-Dive: Secure API Management
Deep-Dive: Secure API ManagementDeep-Dive: Secure API Management
Deep-Dive: Secure API Management
 
Accenture Cloud Platform: Control, Manage and Govern the Enterprise Cloud
Accenture Cloud Platform: Control, Manage and Govern the Enterprise CloudAccenture Cloud Platform: Control, Manage and Govern the Enterprise Cloud
Accenture Cloud Platform: Control, Manage and Govern the Enterprise Cloud
 

Similar to Governance Strategies for Cloud Transformation | AWS Public Sector Summit 2016

Similar to Governance Strategies for Cloud Transformation | AWS Public Sector Summit 2016 (20)

Creating an Operating Model to enable a high frequency organization
Creating an Operating Model to enable a high frequency organizationCreating an Operating Model to enable a high frequency organization
Creating an Operating Model to enable a high frequency organization
 
Microsoft Cloud Adoption Framework for Azure: Governance Conversation
Microsoft Cloud Adoption Framework for Azure: Governance ConversationMicrosoft Cloud Adoption Framework for Azure: Governance Conversation
Microsoft Cloud Adoption Framework for Azure: Governance Conversation
 
AWS re:Invent 2016: How News UK Centralized Cloud Governance Through Policy M...
AWS re:Invent 2016: How News UK Centralized Cloud Governance Through Policy M...AWS re:Invent 2016: How News UK Centralized Cloud Governance Through Policy M...
AWS re:Invent 2016: How News UK Centralized Cloud Governance Through Policy M...
 
faisal mushtaq - an enterprise cloud cost management framework
faisal mushtaq - an enterprise cloud cost management frameworkfaisal mushtaq - an enterprise cloud cost management framework
faisal mushtaq - an enterprise cloud cost management framework
 
Accenture 2014 AWS re:Invent Enterprise Migration Breakout Session
Accenture 2014 AWS re:Invent Enterprise Migration Breakout SessionAccenture 2014 AWS re:Invent Enterprise Migration Breakout Session
Accenture 2014 AWS re:Invent Enterprise Migration Breakout Session
 
(ENT210) Accelerating Business Innovation with DevOps on AWS | AWS re:Invent ...
(ENT210) Accelerating Business Innovation with DevOps on AWS | AWS re:Invent ...(ENT210) Accelerating Business Innovation with DevOps on AWS | AWS re:Invent ...
(ENT210) Accelerating Business Innovation with DevOps on AWS | AWS re:Invent ...
 
(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...
(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...
(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...
 
CSC AWS re:Invent Enterprise DevOps session
CSC AWS re:Invent Enterprise DevOps sessionCSC AWS re:Invent Enterprise DevOps session
CSC AWS re:Invent Enterprise DevOps session
 
Interop ITX: Moving applications: From Legacy to Cloud-to-Cloud
Interop ITX: Moving applications: From Legacy to Cloud-to-CloudInterop ITX: Moving applications: From Legacy to Cloud-to-Cloud
Interop ITX: Moving applications: From Legacy to Cloud-to-Cloud
 
Cloud Adoption Framework - Walking Deck (L100).pptx
Cloud Adoption Framework - Walking Deck (L100).pptxCloud Adoption Framework - Walking Deck (L100).pptx
Cloud Adoption Framework - Walking Deck (L100).pptx
 
Multi cloud governance best practices - AWS, Azure, GCP
Multi cloud governance best practices - AWS, Azure, GCPMulti cloud governance best practices - AWS, Azure, GCP
Multi cloud governance best practices - AWS, Azure, GCP
 
Azure governance
Azure governanceAzure governance
Azure governance
 
Forecast 2014: ODCA Cloud Maturity Model V2.0
Forecast 2014: ODCA Cloud Maturity Model V2.0Forecast 2014: ODCA Cloud Maturity Model V2.0
Forecast 2014: ODCA Cloud Maturity Model V2.0
 
Implementing dev ops to face a two speed it architecture
Implementing dev ops to face a two speed it architectureImplementing dev ops to face a two speed it architecture
Implementing dev ops to face a two speed it architecture
 
Migrating Thousands of Workloads to AWS at Enterprise Scale – Chris Wegmann, ...
Migrating Thousands of Workloads to AWS at Enterprise Scale – Chris Wegmann, ...Migrating Thousands of Workloads to AWS at Enterprise Scale – Chris Wegmann, ...
Migrating Thousands of Workloads to AWS at Enterprise Scale – Chris Wegmann, ...
 
Migrating thousands of workloads to AWS at enterprise scale
Migrating thousands of workloads to AWS at enterprise scaleMigrating thousands of workloads to AWS at enterprise scale
Migrating thousands of workloads to AWS at enterprise scale
 
Dep012 azure の_dev_ops_力!azure_team_でも採
Dep012 azure の_dev_ops_力!azure_team_でも採Dep012 azure の_dev_ops_力!azure_team_でも採
Dep012 azure の_dev_ops_力!azure_team_でも採
 
AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)
AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)
AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)
 
Migration Planning
Migration PlanningMigration Planning
Migration Planning
 
IT Transformation with AWS
IT Transformation with AWSIT Transformation with AWS
IT Transformation with AWS
 

More from Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 
Come costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWSCome costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWS
 

Recently uploaded

Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Recently uploaded (20)

Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 

Governance Strategies for Cloud Transformation | AWS Public Sector Summit 2016

  • 1. © 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Matthew McGuire, GSA, Director, Technology Solutions Division Guy Cavallo, TSA, Executive Director, IT Operations Brian Anderson, AWS, Sr. Consultant, Professional Services June 20, 2016 Governance Strategies for Cloud Transformation
  • 2. Goals for the session • Definition and overview of cloud governance • Cloud center of excellence (CCoE) • Stages of cloud governance • Cloud governance best practices • GSA — Review of business services platform (BSP) • TSA — Discussion of governance • Question and answer
  • 3. Definition of cloud governance The decision-making criteria, processes, and policies involved in the planning, architecture, acquisition, deployment, operation and management used for operating IT services in the cloud. — Cloud governance allows IT to innovate, automate, and quickly deploy code and infrastructure while maintaining the necessary requirements for security, audit, control, and compliance.
  • 4. Goals for cloud transformation
  • 5. Why governance? 1. Reduction in access and security risks 2. Development of cloud standards — delivery, tools, process 3. Management of application design: CI and CD design 4. Cost optimization 5. Increased innovation for business units 6. Elimination of rogue IT and disparate cloud initiatives 7. Management of the consumption of cloud resources
  • 6. Cloud governance opportunities • Speed — Enable business at cloud speed and cost • Integration — Complementary to existing enterprise IT governance processes, policies, and tools • Balance — Appropriate coverage for key decisions, investments, and risks while achieving the benefits of the cloud • Proactivity — Anticipate and prevent shadow clouds and unauthorized cloud activities that expose organizational risks • Enablement — Appropriate cloud decision making without friction
  • 7. Cloud center of excellence (CCoE)
  • 8. Cloud center of excellence (CCoE) The cloud center of excellence is a team of executives and IT area experts that authors cloud governance to enables business units to access a self-service model and provides a catalog of standardized and templated instances from which to select and autoprovision
  • 9.
  • 10. Stages of cloud governance
  • 11. Levels of cloud governance L0 – Decentralized control L1 – Centralized control L2 – Decentralized control with automation L3 – Centralized control with self- service
  • 12. Three phases of cloud governance Beginning • Minimal integration • Reactive environment • Cost overruns • Manual deployments • No cloud structure Adopting • CCoE is in place and policies are maturing • Policies matched to process • Designing for cost • Rapid deployment Mature • Full automation and self-service • Benefits of cloud services realized • Agility and control • Optimized for cost • Secure and compliant environment
  • 13. Phase 1: Beginning 1. Create the CCoE to develop and own governance and its policies 2. Develop governance model and establish policies for: • Security • Account management • Cost • Network • Instance and storage • Service management • Monitoring and reporting 3. Begin to modify the deployment process and policies and look to automate • Develop governing policies to enable automated approval cycles • Develop financial policies to enable BUs to quickly stage POCs
  • 14. Phase 2: Adopting 1. Develop self-service policies 2. Develop data governance policies 3. Develop continuous integration / deployment policy 4. Develop design-for-cost architecture guidelines 5. Develop cloud audit and compliance policies 6. Develop a common API design framework
  • 15. Phase 3: Mature 1. Develop advanced automation techniques and policies to promote further cost reduction, agility, and resiliency: • Automated testing and code promotion from each tier to production • Automated DR and recovery testing — Chaos Monkey / Chaos Gorilla • Automated instance power down / power up for non-Reserved Instances • Utilization of Spot Instances — when and where to use 2. Develop transition policies to define services and SOA 3. Develop policies allowing existing applications to test-for-cost (scale up / scale out)
  • 16. Cloud governance best practices • Establish a CCoE and begin developing/updating policies • Tailor your governance process to your organization’s particular risk tolerance • Decide where to leverage existing processes versus establishing new ones • Make the process as lightweight as possible and as informative as possible to create a positive user experience • Start early in the transformation so you can get business and IT feedback and support • Rely on use-case reviews to improve your processes
  • 17. © 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Matthew McGuire Director, Technology Solutions Division June 20, 2016 GSA Business Services Platform Enabling Greater Agency Agility to Drive Mission Impact
  • 18. The GSA cloud transformation ”Worked fine in dev…” “...OPS has problems” Then (data center) • Days/months to provision • Months to app ATO • One off configs for every app • Size to peak demand • Long, painful outages • Everything needs software
  • 19. What is BSP and how does it transform IT Now (BSP) • Minutes to provision • Weeks to app ATO • Standard app stacks/services • Automated scalability • Immediate server redeployment • Automated — Infrastructure as code, continuous delivery • Secure — Multitenant, security driven architecture • Cost effective — Pay for what you use • Metrics — Visibility into usage and cost • Modernization platform — Get to the cloud
  • 20. BSP is a modernization platformSecuritycontrolinheritance Degree of automation and cloud optimization Mode 2 OS optimization Mode 3 Fully automated stack services devops Orchestration Infrastructure as code • Choose the mode that best suits your application and level of cloud optimization • Mode 3 apps inherit >85% of all ATO security controls Mode 1 Compute, network, storage MIGRATED APPS APP DATA OPTIMIZED APPS AUTOMATED APPS APP
  • 21. 1. Choose app stack Template file • Component Configs • Cluster Sizes • Auto Scaling • Etc. 3. Stage content 4. Run preconfigured orchestration job 5. Application fully deployed 6. Invoke Ansible callback 7. Run Ansible config roles, including app deployment 5. Deploy infrastructure AWS IAM 1. Jenkins initiates deployment through Ansible Tower 2. Generate custom AWS Identity and Access Management (IAM) policy and Amazon CloudFormation template 2. Customize stack Developer experience Orchestration workflow
  • 23. Benefits Enabling greater agency agility to drive mission impact • Speed and flexibility • Configuration control • Scalability • Security • Reliability
  • 24. © 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Guy Cavallo Executive Director, IT Operations Transportation Security Administration
  • 25. © 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Question and Answer

Editor's Notes

  1. . Create the CCoE to develop and own Governance and its policies 2. Develop Governance model and establish policies for: Security – VPC design, Access Management, OS Stack (Anti Virus) Account Management – VPC creation control, instance launch control Cost – Tagging policy and naming convention Network – Encryption and allowable AWS Public / Private Access points Instance and Storage – Naming convention Service Management – Single integrated portal for ticketing / ITSM Monitoring and Reporting – Health, Availability, Logging and Audit 3. Begin to modify the deployment process and policies and look to automate Develop governing policies to enable automated approval cycles Develop financial policies to enable BU’s to quickly stage POC’s
  2. Develop Self Service Policies 2. Develop Data Governance Policies Develop RTO / RPO Policy for each Data Class Develop Data Retention Policy with automated file maintenance Develop Data Classification Policies – Restricted, confidential, etc. Develop Data Encryption and Access Policies 3. Develop Continuous Integration / Deployment Policy Develop policy to define frequency, approved methods, tools Standardize toolsets / repository locations for each BU 4. Develop Design-for-Cost Architecture Guidelines 5. Develop Cloud Audit and Compliance Policies – Financial and Risk 6. Develop a common API Design Framework for REST and JSON API Framework should apply to on-premise and cloud Centralize API repository to simplify management and deployment
  3. Choose from Catalog of Hardened App Stacks as a Service (e.g. MySQL, JBoss, Apache) Customize Stack Parameters via User-Defined Template Stage App content in Artifactory Repo Full App Stack and Content Automatically Deployed and Configured