Solving Cloud Access Complexity
February 27, 2012, Cloud Security Alliance Summit, San Francisco—Girish Juneja from Intel offered a broker model as an alternative to the growing complexity in cloud operations and management.
People are finally realizing that enterprises are moving applications into the cloud. This been going on for many years, with examples like pay roll services on ADP. Now people are moving data into apps and on to the cloud, so companies need governance of multiple procedures, SLA, agreements, management and control, and all other aspects of cloud operations.
The cloud should be simple, therefore a broker could provide services to connect providers and third parties and enable the provision of various capabilities across platforms. The cloud service broker simplifies the complexities and streamlines the integration of applications across multiple apps and through integration of internal apps with the cloud.
There are three primary classifications for broker services. The first is an integration forum, second is an aggregation of sales and services, and third is focused on processes. An example is an identity broker, a services aggregator that takes different identities on multiple counts with no standard provisioning and manages all of these identities. Problems that these services address include the generation of orphans—broken links between services and identities—and the lack strong authentication and device authentication.
A broker can help by providing a single sign-on to all applications and full lifecycle management of identities. These services provide enterprise-level control through second factor authentication methods and use standards like NIST and the CSA reference guidelines.
Intel is announcing their SSO identity management services with McAfee security features. This is a simple and secure cloud access management tool that is standards-based and certified and works in cloud and hybrid modes. It provides full identification lifecycle management for both provisioning and de-provisioning identities to multiple apps. The goal of these services is to reduce costs and improve productivity.
The service is a simple setup that only requires three steps and allows for background administration. It has context aware authentication and can limit access through the user’s context as well a second factors from trusted hardware.


