OpenStack is great, but Clouds need security. Meet the Clean Cloud.

31 December 2010

OpenStack – an open source cloud computing stack announced by Rackspace, NASA, and 25 others – is tearing up the news, the blogsphere, and “the twitter” (as my friend Chris Hoff likes to say ). This is great news for enterprises as it helps address major concerns over cloud provider lock-in and standards. But security is desperately needed. Clean Clouds will emerge to address these concerns, unlocking cloud computing potential and enterprise demand

So, why does OpenStack matter? And, what the heck is a Clean Cloud?

OpenStack matters because:

But OpenStack needs security – none of the 25 partners are security companies

This is so because even more than fear of provider lock-in, insufficient security is holding back enterprise cloud adoption. Indeed if you include reliability / availability, IT governance, and regulatory compliance as security cousins, then you’ve got 5 of the top 9 enterprise concerns according to Yankee Group research

To truly unlock enterprise cloud computing adoption, OpenStack and other cloud platforms must address security concerns. But this will happen. And when it does, it will usher in the Clean Cloud

Clean Clouds will be the topic of my next report. And I admit I’m still refining my thoughts about what constitutes a Clean Cloud. But here’s what I’ve got so far:

Clean Clouds combine…

… to offer a level of security and availability unmatched by existing cloud platforms. They won’t just offer acceptable levels of auditability, isolation, and data security. They’ll be better. By baking security functions like anti-malware and denial-of-service protection into the platform, and by leveraging the network-effect across customers to turbo-charge these security functions, Clean Clouds will offer security and availability you simply can’t get elsewhere

As a result, enterprise security hawks will no longer resist cloud migrations. They’ll rush to migrate functions to Clean Clouds as the improved security and bolstered compliance will make them heroes back home. Want to find out more about home security safes?

What do you think constitutes a Clean Cloud? What security functions are table stakes and which will customer’s pay for? What cloud provider do you think will get there first?

I’m in the midst of vendor interviews for this report and would like to speak with more of you. E-mail me at tjulian@yankeegroup.com to set up a briefing