SlideShare una empresa de Scribd logo
1 de 39
Descargar para leer sin conexión
Sao Paulo
Cloud Procurement
Best Practices for Public Sector Customers
David DeBrandt, Business Development
AWS Worldwide Public Sector
Agenda – Cloud Procurement
• Cloud Procurement Overview
• Procurement Models
• Solicitation Details
• Budget and Pricing
• Security and Cyber Controls
• Legal and Legislative Issues
Cloud Procurement Overview
Characteristics of Cloud
Old World IT New World of Cloud Computing
Price lock Low variable costs
Vendor lock-in No required minimum commitments
Rigid structure Rapid innovation
CapEx OpEx
Budget for tech refresh Cloud providers continually upgrading
Months to plan and order Rapid deployments
Design lock-in Agile architecture
Successful Public Sector Adoption Has Several Steps
Security and Compliance
Procurement
Culture
Broad Adoption
Business Uses/Definition
Policy
Government Organizations Should Plan Early
• Involve all key stakeholders at an early stage:
– Procurement
– Legal
– Budget/finance
– Security
– IT
– Business leadership
• Get comfortable with the cloud model
Understand Different Cloud Models
Networking
Storage
Servers
Virtualization
Operating System
Middleware
Runtime
Data
Applications
Infrastructure
(as a Service)
Networking
Storage
Servers
Virtualization
Data
Applications
Platform
(as a Service)
Operating System
Middleware
Runtime
Networking
Storage
Servers
Virtualization
Software
(as a Service)
Operating System
Middleware
Runtime
Data
Applications
Provider Responsible Consumer Responsible
Government
Sponsor
(CIO, etc.)
Gov Cust
1
Gov Cust
2
Gov Cust
3
Gov Cust
n
AWS Training
Strategy&Roadmap
SolutionArch&Design
TechReview&Audit
ReqAnalysis
AppDevlpSupt
Professional Services
ServiceDesk
ProgramMgmt
Billing&AccountMgt
Program Support
Implement/Migration
ConfigMgt/COOP
IT O&M
Governance
Security
Controls
Infrastructure
Direct
Providers
Reselling
Cloud Migration and Service Providers
All-Inclusive System Integrators
Cloud Brokers
Packaging/Bundling of Cloud IaaS/PaaS
Typical
Project
Packages
Vendor/
Owner
Types
Cloud Service
Provider
Government
Customer
Array of Cloud Project/Program Services
Cloud Governance
• Ownership and sovereignty
– Public Sector entity owns all data
• No long term contracts or exclusivity
– Public Sector entity can terminate at any time
• Choose location of your data
– E.g.; Region in Brazil
Separate Infrastructure from Services/Labor
• Separate the purchase of infrastructure from
services (planning, development,
implementation, and maintenance).
• Results in maximum pricing efficiencies
Procurement Models
Procurement Approach
• Indirect purchase:
– Managed Service Provider (MSP)
– Independent Software Vendor (ISV)
– Consultant/System Integrator/Reseller
• Direct purchase from CSP
Broad Eco-System of Partners
A marketplace for software in the Cloud
Over 2,100 listings across
23 categories
Procurement Models
• Understand different procurement models to buy
cloud:
– Cloud catalogue procurements
– Solution procurement
– Immediate cloud needs
Procurement Models – Cloud Catalogues
A pre-approved catalogue that can be used by
multiple purchasers – a ‘license to hunt’
• Commercial Item: a utility-type service with no
custom-built deliverables
• Flexible pricing models: cloud vendors have
different approaches
• Quantities: not known in advance
Procurement Models – Solution Procurement
• Traditional IT procurement – cloud infrastructure
is only a component
• Seek best value of cloud resources
Procurement Models – Immediate Needs
• On-demand infrastructure
• Emergent or temporary needs
• Use cloud catalogue, existing vendor contract
Solicitation Details
Don’t Be Overly Prescriptive
• Focus on overall performance
• Do no dictate specific methods, hardware or
equipment
• Leverage commercial best practices
New and Updated Services
• Take advantage of new and improved services
• Avoid including restrictions or consent
requirements for CSPs ability to change/improve
services (and related terms)
Cloud Provider Evaluation Criteria
Evaluation Question to Ask AWS Value
Experience How long has the vendor been providing cloud related
services?
AWS has been building and managing its cloud services since
2006.
Service Breadth and
Depth
Provide details on how deep and wide the set of
services provided go?
40+ services to support any cloud computing workload
Pace of Innovation How does the vendor continue to innovate its offerings? AWS has released over 1,100 new services or major features
since 2008 (including 516 in 2014).
Global Footprint How large is the vendor’s global footprint? AWS serves customers through our 11 Regions, 28 Availability
Zones, and 52 Edge Locations.
Pricing Philosophy
and History
How does the vendor offer its pricing? Is there a long-
term lock in? What is the history of price reductions?
For each AWS service, you pay for exactly the amount of
resources you actually need in a utility-style pricing model.
AWS has lowered prices 48 times in the last eight years.
Total Cost of
Ownership (TCO)
Does the vendor provide a complete TCO analysis (not
just an “apples to apples” approach measuring potential
hardware expense alongside utility pricing)?
AWS offers the following TCO tool: http://aws.amazon.com/tco-
calculator/
Ecosystem How extensive is the ecosystem of vendors that work
with the CSP?
8,000+ SIs and ISVs; 2,000+ AWS Marketplace products.
Security and Audit
Certifications
Does the CSP have industry-acknowledged
certifications and accreditations?
AWS can cite many security frameworks, best practices, audit
standards, and standardized controls, including: SOC 1, SOC 2,
SOC 3, PCI DSS, ISO 27001, ISO 9001, and U.S. FedRAMP,
Industry Analysis How is the provider assessed by independent analysts? AWS has been assessed by multiple independent analysts,
including Gartner, Inc., Forrester Research, and IDC
Budgets and Pricing
Flexible Pricing Model
• Pay as you go model
• Fluctuating/variable prices
• Accept multiple pricing models from CSPs
– Don’t compare ‘apples to apples’
• Transparency
Supervising and Controlling Budget and
Consumption
• Utilizing Resellers/Solution Providers to manage
consumption of CSP Infrastructure and Platforms
• Create internal control organization to manage
utilization
• Explore existing contract models such buying
electricity for models
Security and Cyber Controls
Certifications and accreditations for workloads that matter
Architected for Government Security Requirements
Leverage 3rd Party Accreditations for
Security, Privacy, & Audit
• Leverage industry best practices on security and
audit
• Avoid mandating your unique security protocols
• Take into account levels of security required
AWS Foundation Services
Compute Storage Database Networking
AWS Global Infrastructure
Regions
Availability Zones
Edge Locations
Identity Data Infrastructure
Customer applications & content
You
You get to
define your
controls IN the
Cloud
AWS takes care
of the security
OF
the Cloud
Understand Security is a Shared Responsibility
Legal and Legislative
Terms & Conditions
• Commercial item: an item sold, leased, licensed, or
otherwise offered for sale to the general public
• Evolving terms and conditions
– Take advantage of continuous evolution of cloud’s enhanced
features and efficiencies
• Avoid unnecessary restrictions or change consent
• Identify only relevant requirements and terms
Service Level Agreements
• Accept Commercial Cloud Provider SLAs
– The scalability and low cost of the cloud is directly linked to a
single model for all customers
• If required, additional SLAs could be handled by
reseller or solution partner
Minimized Admin Burdens
• Minimize needs for project requirements
– If working with CSP directly, avoid, project meetings, customized
reporting, non standard notifications
– Rely on resellers/partners for add-on project requirements
Legislative Issues
• Understand how existing laws and policy can
affect this approach:
– Security standards;
– Audits;
– Pricing controls;
– Inability to accept changing terms;
Conclusion
Cloud Procurement Best Practices
April 9, 2015
• CSPs provide foundational services to build solutions/house workloads.
• Accept different vendor approaches – CSP offerings are not apples to apples.
• Understand different ways to buy SaaS v. IaaS/PaaS.
• Focus on application-level and performance-based requirements – not
dictating specific methods, infrastructure or hardware. Ultimately, you are not
buying a physical asset.
• Embrace on-demand, utility-like, OpEx model cloud pricing. Traditional IT
pricing approaches can reduce or eliminate benefits of cloud.
• Accept different vendor pricing models – do not create single pricing model.
• Shared security/compliance model between the CSP & end user.
• Leverage industry best practices on security and audit.
• View cloud as a commercial item and consider appropriate terms & conditions
• A mechanism to incorporate CSP’s unique terms and conditions.
• Leverage CSP’s commercial SLAs, i.e. uptime, durability, reliability etc.
• A model to obtain cloud services directly from CSP and/or an indirect model in
which cloud services are procured through partners or reseller.
• Do not consider or treat CSPs as System Integrators (SIs).
Cloud Models
Performance Based
Requirements
Pricing
Security/Assurance/Audit
Terms & Conditions and SLAs
Vendor Types and
Partner Ecosystem
• Separate purchase of cloud infrastructure from the purchase of services and
labor for planning, developing, and executing, migrations & workloads.
Services vs. Infrastructure
Cloud Procurement Next Steps
• Understand the cloud model, security and how it
is different from traditional IT
• Understand working with partners/resellers
• Understand Cloud pricing and SLA constructs
• Focus on requirements that are cloud specific –
not traditional IT
4. cloud procurement

Más contenido relacionado

La actualidad más candente

Perennial systems corporate overview presentation
Perennial systems corporate overview presentationPerennial systems corporate overview presentation
Perennial systems corporate overview presentation
Perennial Systems
 

La actualidad más candente (20)

Assessing Your Company's Cloud Readiness
Assessing Your Company's Cloud ReadinessAssessing Your Company's Cloud Readiness
Assessing Your Company's Cloud Readiness
 
Perennial systems corporate overview presentation
Perennial systems corporate overview presentationPerennial systems corporate overview presentation
Perennial systems corporate overview presentation
 
Simplilearn Overview
Simplilearn OverviewSimplilearn Overview
Simplilearn Overview
 
The Importance of Business Change Management in Cloud Adoption
The Importance of Business Change Management in Cloud AdoptionThe Importance of Business Change Management in Cloud Adoption
The Importance of Business Change Management in Cloud Adoption
 
Technical Due Diligence with AWS
Technical Due Diligence with AWSTechnical Due Diligence with AWS
Technical Due Diligence with AWS
 
AWS Enterprise Summit :: 클라우드 운영 - Cloud CoE, Cloud Ops, Cloud MSP (이원일 시니어 컨...
AWS Enterprise Summit :: 클라우드 운영 - Cloud CoE, Cloud Ops, Cloud MSP (이원일 시니어 컨...AWS Enterprise Summit :: 클라우드 운영 - Cloud CoE, Cloud Ops, Cloud MSP (이원일 시니어 컨...
AWS Enterprise Summit :: 클라우드 운영 - Cloud CoE, Cloud Ops, Cloud MSP (이원일 시니어 컨...
 
Cloud Migration Strategy Framework
Cloud Migration Strategy FrameworkCloud Migration Strategy Framework
Cloud Migration Strategy Framework
 
Application Modernization using the Strangler Pattern
Application Modernization using the Strangler PatternApplication Modernization using the Strangler Pattern
Application Modernization using the Strangler Pattern
 
Cloud Migration
Cloud MigrationCloud Migration
Cloud Migration
 
VisiQuate: Azure cloud migration case study
VisiQuate: Azure cloud migration case studyVisiQuate: Azure cloud migration case study
VisiQuate: Azure cloud migration case study
 
AWS vs Azure - Cloud Services Comparison
AWS vs Azure - Cloud Services ComparisonAWS vs Azure - Cloud Services Comparison
AWS vs Azure - Cloud Services Comparison
 
Cloud Migration, Application Modernization, and Security
Cloud Migration, Application Modernization, and Security Cloud Migration, Application Modernization, and Security
Cloud Migration, Application Modernization, and Security
 
Google Cloud Connect Korea - Sep 2017
Google Cloud Connect Korea - Sep 2017Google Cloud Connect Korea - Sep 2017
Google Cloud Connect Korea - Sep 2017
 
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
 
Cloud computing ppt by Binesh
Cloud computing ppt by BineshCloud computing ppt by Binesh
Cloud computing ppt by Binesh
 
Multi Cloud Architecture Approach
Multi Cloud Architecture ApproachMulti Cloud Architecture Approach
Multi Cloud Architecture Approach
 
Cloud Migration: Cloud Readiness Assessment Case Study
Cloud Migration: Cloud Readiness Assessment Case StudyCloud Migration: Cloud Readiness Assessment Case Study
Cloud Migration: Cloud Readiness Assessment Case Study
 
AWS 클라우드 이해하기-사례 중심 (정민정) - AWS 웨비나 시리즈
AWS 클라우드 이해하기-사례 중심 (정민정) - AWS 웨비나 시리즈AWS 클라우드 이해하기-사례 중심 (정민정) - AWS 웨비나 시리즈
AWS 클라우드 이해하기-사례 중심 (정민정) - AWS 웨비나 시리즈
 
Microsoft azure
Microsoft azureMicrosoft azure
Microsoft azure
 
What is Cloud Computing and its Types.pdf
What is Cloud Computing and its Types.pdfWhat is Cloud Computing and its Types.pdf
What is Cloud Computing and its Types.pdf
 

Destacado

Emotional intellegence
Emotional intellegenceEmotional intellegence
Emotional intellegence
Creatingdemand
 
Positive cloud swot
Positive cloud   swotPositive cloud   swot
Positive cloud swot
Lou Briot
 

Destacado (9)

The Impact of Cloud on Procurement Presentation 30th may 2012
The Impact of Cloud on Procurement Presentation 30th may 2012The Impact of Cloud on Procurement Presentation 30th may 2012
The Impact of Cloud on Procurement Presentation 30th may 2012
 
Acquisition Strategies and Contract Vehicles in the Public Sector
Acquisition Strategies and Contract Vehicles in the Public SectorAcquisition Strategies and Contract Vehicles in the Public Sector
Acquisition Strategies and Contract Vehicles in the Public Sector
 
Cloud Workflows for Procurement
Cloud Workflows for ProcurementCloud Workflows for Procurement
Cloud Workflows for Procurement
 
Bob Jones, CERN on PICSE: Procurement of cloud services in Europe
Bob Jones, CERN on PICSE: Procurement of cloud services in EuropeBob Jones, CERN on PICSE: Procurement of cloud services in Europe
Bob Jones, CERN on PICSE: Procurement of cloud services in Europe
 
Emotional intellegence
Emotional intellegenceEmotional intellegence
Emotional intellegence
 
Positive cloud swot
Positive cloud   swotPositive cloud   swot
Positive cloud swot
 
Visual Online - Cloud Computing - 4 Mars 2011
Visual Online - Cloud Computing - 4 Mars 2011Visual Online - Cloud Computing - 4 Mars 2011
Visual Online - Cloud Computing - 4 Mars 2011
 
Mastering Your EQ
Mastering Your EQMastering Your EQ
Mastering Your EQ
 
Train the trainer
Train the trainerTrain the trainer
Train the trainer
 

Similar a 4. cloud procurement

Cloud_Testing_The_future_of_softwareV1.04
Cloud_Testing_The_future_of_softwareV1.04Cloud_Testing_The_future_of_softwareV1.04
Cloud_Testing_The_future_of_softwareV1.04
Mrityunjaya Hikkalgutti
 
Chapter 1 & 2 - Introduction-to-Cloud-Computing.pptx
Chapter 1 & 2 - Introduction-to-Cloud-Computing.pptxChapter 1 & 2 - Introduction-to-Cloud-Computing.pptx
Chapter 1 & 2 - Introduction-to-Cloud-Computing.pptx
haileysuszelalem
 

Similar a 4. cloud procurement (20)

Key Considerations for Cloud Procurement - AWS Innovate Ottawa:
 Key Considerations for Cloud Procurement - AWS Innovate Ottawa: Key Considerations for Cloud Procurement - AWS Innovate Ottawa:
Key Considerations for Cloud Procurement - AWS Innovate Ottawa:
 
navigating the cloud key considerations for cloud computing solutions.pdf
navigating the cloud key considerations for cloud computing solutions.pdfnavigating the cloud key considerations for cloud computing solutions.pdf
navigating the cloud key considerations for cloud computing solutions.pdf
 
Get Started Today with Cloud-Ready Contracts | AWS Public Sector Summit 2016
Get Started Today with Cloud-Ready Contracts | AWS Public Sector Summit 2016Get Started Today with Cloud-Ready Contracts | AWS Public Sector Summit 2016
Get Started Today with Cloud-Ready Contracts | AWS Public Sector Summit 2016
 
Get Started Today with Cloud-Ready Contracts | AWS Public Sector Summit 2017
Get Started Today with Cloud-Ready Contracts | AWS Public Sector Summit 2017Get Started Today with Cloud-Ready Contracts | AWS Public Sector Summit 2017
Get Started Today with Cloud-Ready Contracts | AWS Public Sector Summit 2017
 
So You’ve Decided to Buy Cloud, Now What? | AWS Public Sector Summit 2016
So You’ve Decided to Buy Cloud, Now What? | AWS Public Sector Summit 2016So You’ve Decided to Buy Cloud, Now What? | AWS Public Sector Summit 2016
So You’ve Decided to Buy Cloud, Now What? | AWS Public Sector Summit 2016
 
Cloud Economics - Crayon Optimization Services
Cloud Economics - Crayon Optimization ServicesCloud Economics - Crayon Optimization Services
Cloud Economics - Crayon Optimization Services
 
(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...
(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...
(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...
 
Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0
Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0
Public Cloud Service Agreements: What to Expect and What to Negotiate V2.0
 
Concorde Solutions ITAM Review Tools Day
Concorde Solutions ITAM Review Tools Day Concorde Solutions ITAM Review Tools Day
Concorde Solutions ITAM Review Tools Day
 
Approach to Enterprise Cloudification with a focus on SaaS
Approach to Enterprise Cloudification with a focus on SaaSApproach to Enterprise Cloudification with a focus on SaaS
Approach to Enterprise Cloudification with a focus on SaaS
 
Accenture 2014 AWS re:Invent Enterprise Migration Breakout Session
Accenture 2014 AWS re:Invent Enterprise Migration Breakout SessionAccenture 2014 AWS re:Invent Enterprise Migration Breakout Session
Accenture 2014 AWS re:Invent Enterprise Migration Breakout Session
 
Chapter 1 Introduction to Cloud Computing
Chapter 1 Introduction to Cloud ComputingChapter 1 Introduction to Cloud Computing
Chapter 1 Introduction to Cloud Computing
 
Accelerating innovation and reducing cost using cloud based software procurement
Accelerating innovation and reducing cost using cloud based software procurementAccelerating innovation and reducing cost using cloud based software procurement
Accelerating innovation and reducing cost using cloud based software procurement
 
Migrating thousands of workloads to AWS at enterprise scale
Migrating thousands of workloads to AWS at enterprise scaleMigrating thousands of workloads to AWS at enterprise scale
Migrating thousands of workloads to AWS at enterprise scale
 
Driving Business Agility with AWS Serverless -Atlanta
Driving Business Agility with AWS Serverless -AtlantaDriving Business Agility with AWS Serverless -Atlanta
Driving Business Agility with AWS Serverless -Atlanta
 
Cloud_Testing_The_future_of_softwareV1.04
Cloud_Testing_The_future_of_softwareV1.04Cloud_Testing_The_future_of_softwareV1.04
Cloud_Testing_The_future_of_softwareV1.04
 
Best Practices for Multi-Cloud Security and Compliance
Best Practices for Multi-Cloud Security and ComplianceBest Practices for Multi-Cloud Security and Compliance
Best Practices for Multi-Cloud Security and Compliance
 
Transforming cloud security into an advantage
Transforming cloud security into an advantageTransforming cloud security into an advantage
Transforming cloud security into an advantage
 
Get Started Today with Cloud-Ready Contracts | AWS Public Sector Summit 2017
Get Started Today with Cloud-Ready Contracts | AWS Public Sector Summit 2017Get Started Today with Cloud-Ready Contracts | AWS Public Sector Summit 2017
Get Started Today with Cloud-Ready Contracts | AWS Public Sector Summit 2017
 
Chapter 1 & 2 - Introduction-to-Cloud-Computing.pptx
Chapter 1 & 2 - Introduction-to-Cloud-Computing.pptxChapter 1 & 2 - Introduction-to-Cloud-Computing.pptx
Chapter 1 & 2 - Introduction-to-Cloud-Computing.pptx
 

Más de Amazon Web Services LATAM

Más de Amazon Web Services LATAM (20)

AWS para terceiro setor - Sessão 1 - Introdução à nuvem
AWS para terceiro setor - Sessão 1 - Introdução à nuvemAWS para terceiro setor - Sessão 1 - Introdução à nuvem
AWS para terceiro setor - Sessão 1 - Introdução à nuvem
 
AWS para terceiro setor - Sessão 2 - Armazenamento e Backup
AWS para terceiro setor - Sessão 2 - Armazenamento e BackupAWS para terceiro setor - Sessão 2 - Armazenamento e Backup
AWS para terceiro setor - Sessão 2 - Armazenamento e Backup
 
AWS para terceiro setor - Sessão 3 - Protegendo seus dados.
AWS para terceiro setor - Sessão 3 - Protegendo seus dados.AWS para terceiro setor - Sessão 3 - Protegendo seus dados.
AWS para terceiro setor - Sessão 3 - Protegendo seus dados.
 
AWS para terceiro setor - Sessão 1 - Introdução à nuvem
AWS para terceiro setor - Sessão 1 - Introdução à nuvemAWS para terceiro setor - Sessão 1 - Introdução à nuvem
AWS para terceiro setor - Sessão 1 - Introdução à nuvem
 
AWS para terceiro setor - Sessão 2 - Armazenamento e Backup
AWS para terceiro setor - Sessão 2 - Armazenamento e BackupAWS para terceiro setor - Sessão 2 - Armazenamento e Backup
AWS para terceiro setor - Sessão 2 - Armazenamento e Backup
 
AWS para terceiro setor - Sessão 3 - Protegendo seus dados.
AWS para terceiro setor - Sessão 3 - Protegendo seus dados.AWS para terceiro setor - Sessão 3 - Protegendo seus dados.
AWS para terceiro setor - Sessão 3 - Protegendo seus dados.
 
Automatice el proceso de entrega con CI/CD en AWS
Automatice el proceso de entrega con CI/CD en AWSAutomatice el proceso de entrega con CI/CD en AWS
Automatice el proceso de entrega con CI/CD en AWS
 
Automatize seu processo de entrega de software com CI/CD na AWS
Automatize seu processo de entrega de software com CI/CD na AWSAutomatize seu processo de entrega de software com CI/CD na AWS
Automatize seu processo de entrega de software com CI/CD na AWS
 
Cómo empezar con Amazon EKS
Cómo empezar con Amazon EKSCómo empezar con Amazon EKS
Cómo empezar con Amazon EKS
 
Como começar com Amazon EKS
Como começar com Amazon EKSComo começar com Amazon EKS
Como começar com Amazon EKS
 
Ransomware: como recuperar os seus dados na nuvem AWS
Ransomware: como recuperar os seus dados na nuvem AWSRansomware: como recuperar os seus dados na nuvem AWS
Ransomware: como recuperar os seus dados na nuvem AWS
 
Ransomware: cómo recuperar sus datos en la nube de AWS
Ransomware: cómo recuperar sus datos en la nube de AWSRansomware: cómo recuperar sus datos en la nube de AWS
Ransomware: cómo recuperar sus datos en la nube de AWS
 
Ransomware: Estratégias de Mitigação
Ransomware: Estratégias de MitigaçãoRansomware: Estratégias de Mitigação
Ransomware: Estratégias de Mitigação
 
Ransomware: Estratégias de Mitigación
Ransomware: Estratégias de MitigaciónRansomware: Estratégias de Mitigación
Ransomware: Estratégias de Mitigación
 
Aprenda a migrar y transferir datos al usar la nube de AWS
Aprenda a migrar y transferir datos al usar la nube de AWSAprenda a migrar y transferir datos al usar la nube de AWS
Aprenda a migrar y transferir datos al usar la nube de AWS
 
Aprenda como migrar e transferir dados ao utilizar a nuvem da AWS
Aprenda como migrar e transferir dados ao utilizar a nuvem da AWSAprenda como migrar e transferir dados ao utilizar a nuvem da AWS
Aprenda como migrar e transferir dados ao utilizar a nuvem da AWS
 
Cómo mover a un almacenamiento de archivos administrados
Cómo mover a un almacenamiento de archivos administradosCómo mover a un almacenamiento de archivos administrados
Cómo mover a un almacenamiento de archivos administrados
 
Simplifique su BI con AWS
Simplifique su BI con AWSSimplifique su BI con AWS
Simplifique su BI con AWS
 
Simplifique o seu BI com a AWS
Simplifique o seu BI com a AWSSimplifique o seu BI com a AWS
Simplifique o seu BI com a AWS
 
Os benefícios de migrar seus workloads de Big Data para a AWS
Os benefícios de migrar seus workloads de Big Data para a AWSOs benefícios de migrar seus workloads de Big Data para a AWS
Os benefícios de migrar seus workloads de Big Data para a AWS
 

Último

Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
VictoriaMetrics
 
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
masabamasaba
 
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
masabamasaba
 
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
chiefasafspells
 
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
Health
 

Último (20)

Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
 
AI & Machine Learning Presentation Template
AI & Machine Learning Presentation TemplateAI & Machine Learning Presentation Template
AI & Machine Learning Presentation Template
 
%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand
 
WSO2CON 2024 - WSO2's Digital Transformation Journey with Choreo: A Platforml...
WSO2CON 2024 - WSO2's Digital Transformation Journey with Choreo: A Platforml...WSO2CON 2024 - WSO2's Digital Transformation Journey with Choreo: A Platforml...
WSO2CON 2024 - WSO2's Digital Transformation Journey with Choreo: A Platforml...
 
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
 
Architecture decision records - How not to get lost in the past
Architecture decision records - How not to get lost in the pastArchitecture decision records - How not to get lost in the past
Architecture decision records - How not to get lost in the past
 
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
 
%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg
%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg
%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg
 
WSO2CON 2024 - Navigating API Complexity: REST, GraphQL, gRPC, Websocket, Web...
WSO2CON 2024 - Navigating API Complexity: REST, GraphQL, gRPC, Websocket, Web...WSO2CON 2024 - Navigating API Complexity: REST, GraphQL, gRPC, Websocket, Web...
WSO2CON 2024 - Navigating API Complexity: REST, GraphQL, gRPC, Websocket, Web...
 
WSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
WSO2Con2024 - Enabling Transactional System's Exponential Growth With SimplicityWSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
WSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
 
WSO2Con204 - Hard Rock Presentation - Keynote
WSO2Con204 - Hard Rock Presentation - KeynoteWSO2Con204 - Hard Rock Presentation - Keynote
WSO2Con204 - Hard Rock Presentation - Keynote
 
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
 
WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?
 
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
 
WSO2CON2024 - It's time to go Platformless
WSO2CON2024 - It's time to go PlatformlessWSO2CON2024 - It's time to go Platformless
WSO2CON2024 - It's time to go Platformless
 
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
 
%in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park %in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park
 
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
 

4. cloud procurement

  • 2. Cloud Procurement Best Practices for Public Sector Customers David DeBrandt, Business Development AWS Worldwide Public Sector
  • 3. Agenda – Cloud Procurement • Cloud Procurement Overview • Procurement Models • Solicitation Details • Budget and Pricing • Security and Cyber Controls • Legal and Legislative Issues
  • 5. Characteristics of Cloud Old World IT New World of Cloud Computing Price lock Low variable costs Vendor lock-in No required minimum commitments Rigid structure Rapid innovation CapEx OpEx Budget for tech refresh Cloud providers continually upgrading Months to plan and order Rapid deployments Design lock-in Agile architecture
  • 6. Successful Public Sector Adoption Has Several Steps Security and Compliance Procurement Culture Broad Adoption Business Uses/Definition Policy
  • 7. Government Organizations Should Plan Early • Involve all key stakeholders at an early stage: – Procurement – Legal – Budget/finance – Security – IT – Business leadership • Get comfortable with the cloud model
  • 8. Understand Different Cloud Models Networking Storage Servers Virtualization Operating System Middleware Runtime Data Applications Infrastructure (as a Service) Networking Storage Servers Virtualization Data Applications Platform (as a Service) Operating System Middleware Runtime Networking Storage Servers Virtualization Software (as a Service) Operating System Middleware Runtime Data Applications Provider Responsible Consumer Responsible
  • 9. Government Sponsor (CIO, etc.) Gov Cust 1 Gov Cust 2 Gov Cust 3 Gov Cust n AWS Training Strategy&Roadmap SolutionArch&Design TechReview&Audit ReqAnalysis AppDevlpSupt Professional Services ServiceDesk ProgramMgmt Billing&AccountMgt Program Support Implement/Migration ConfigMgt/COOP IT O&M Governance Security Controls Infrastructure Direct Providers Reselling Cloud Migration and Service Providers All-Inclusive System Integrators Cloud Brokers Packaging/Bundling of Cloud IaaS/PaaS Typical Project Packages Vendor/ Owner Types Cloud Service Provider Government Customer Array of Cloud Project/Program Services
  • 10. Cloud Governance • Ownership and sovereignty – Public Sector entity owns all data • No long term contracts or exclusivity – Public Sector entity can terminate at any time • Choose location of your data – E.g.; Region in Brazil
  • 11. Separate Infrastructure from Services/Labor • Separate the purchase of infrastructure from services (planning, development, implementation, and maintenance). • Results in maximum pricing efficiencies
  • 13. Procurement Approach • Indirect purchase: – Managed Service Provider (MSP) – Independent Software Vendor (ISV) – Consultant/System Integrator/Reseller • Direct purchase from CSP
  • 15. A marketplace for software in the Cloud Over 2,100 listings across 23 categories
  • 16. Procurement Models • Understand different procurement models to buy cloud: – Cloud catalogue procurements – Solution procurement – Immediate cloud needs
  • 17. Procurement Models – Cloud Catalogues A pre-approved catalogue that can be used by multiple purchasers – a ‘license to hunt’ • Commercial Item: a utility-type service with no custom-built deliverables • Flexible pricing models: cloud vendors have different approaches • Quantities: not known in advance
  • 18. Procurement Models – Solution Procurement • Traditional IT procurement – cloud infrastructure is only a component • Seek best value of cloud resources
  • 19. Procurement Models – Immediate Needs • On-demand infrastructure • Emergent or temporary needs • Use cloud catalogue, existing vendor contract
  • 21. Don’t Be Overly Prescriptive • Focus on overall performance • Do no dictate specific methods, hardware or equipment • Leverage commercial best practices
  • 22. New and Updated Services • Take advantage of new and improved services • Avoid including restrictions or consent requirements for CSPs ability to change/improve services (and related terms)
  • 23. Cloud Provider Evaluation Criteria Evaluation Question to Ask AWS Value Experience How long has the vendor been providing cloud related services? AWS has been building and managing its cloud services since 2006. Service Breadth and Depth Provide details on how deep and wide the set of services provided go? 40+ services to support any cloud computing workload Pace of Innovation How does the vendor continue to innovate its offerings? AWS has released over 1,100 new services or major features since 2008 (including 516 in 2014). Global Footprint How large is the vendor’s global footprint? AWS serves customers through our 11 Regions, 28 Availability Zones, and 52 Edge Locations. Pricing Philosophy and History How does the vendor offer its pricing? Is there a long- term lock in? What is the history of price reductions? For each AWS service, you pay for exactly the amount of resources you actually need in a utility-style pricing model. AWS has lowered prices 48 times in the last eight years. Total Cost of Ownership (TCO) Does the vendor provide a complete TCO analysis (not just an “apples to apples” approach measuring potential hardware expense alongside utility pricing)? AWS offers the following TCO tool: http://aws.amazon.com/tco- calculator/ Ecosystem How extensive is the ecosystem of vendors that work with the CSP? 8,000+ SIs and ISVs; 2,000+ AWS Marketplace products. Security and Audit Certifications Does the CSP have industry-acknowledged certifications and accreditations? AWS can cite many security frameworks, best practices, audit standards, and standardized controls, including: SOC 1, SOC 2, SOC 3, PCI DSS, ISO 27001, ISO 9001, and U.S. FedRAMP, Industry Analysis How is the provider assessed by independent analysts? AWS has been assessed by multiple independent analysts, including Gartner, Inc., Forrester Research, and IDC
  • 25. Flexible Pricing Model • Pay as you go model • Fluctuating/variable prices • Accept multiple pricing models from CSPs – Don’t compare ‘apples to apples’ • Transparency
  • 26. Supervising and Controlling Budget and Consumption • Utilizing Resellers/Solution Providers to manage consumption of CSP Infrastructure and Platforms • Create internal control organization to manage utilization • Explore existing contract models such buying electricity for models
  • 27. Security and Cyber Controls
  • 28. Certifications and accreditations for workloads that matter Architected for Government Security Requirements
  • 29. Leverage 3rd Party Accreditations for Security, Privacy, & Audit • Leverage industry best practices on security and audit • Avoid mandating your unique security protocols • Take into account levels of security required
  • 30. AWS Foundation Services Compute Storage Database Networking AWS Global Infrastructure Regions Availability Zones Edge Locations Identity Data Infrastructure Customer applications & content You You get to define your controls IN the Cloud AWS takes care of the security OF the Cloud Understand Security is a Shared Responsibility
  • 32. Terms & Conditions • Commercial item: an item sold, leased, licensed, or otherwise offered for sale to the general public • Evolving terms and conditions – Take advantage of continuous evolution of cloud’s enhanced features and efficiencies • Avoid unnecessary restrictions or change consent • Identify only relevant requirements and terms
  • 33. Service Level Agreements • Accept Commercial Cloud Provider SLAs – The scalability and low cost of the cloud is directly linked to a single model for all customers • If required, additional SLAs could be handled by reseller or solution partner
  • 34. Minimized Admin Burdens • Minimize needs for project requirements – If working with CSP directly, avoid, project meetings, customized reporting, non standard notifications – Rely on resellers/partners for add-on project requirements
  • 35. Legislative Issues • Understand how existing laws and policy can affect this approach: – Security standards; – Audits; – Pricing controls; – Inability to accept changing terms;
  • 37. Cloud Procurement Best Practices April 9, 2015 • CSPs provide foundational services to build solutions/house workloads. • Accept different vendor approaches – CSP offerings are not apples to apples. • Understand different ways to buy SaaS v. IaaS/PaaS. • Focus on application-level and performance-based requirements – not dictating specific methods, infrastructure or hardware. Ultimately, you are not buying a physical asset. • Embrace on-demand, utility-like, OpEx model cloud pricing. Traditional IT pricing approaches can reduce or eliminate benefits of cloud. • Accept different vendor pricing models – do not create single pricing model. • Shared security/compliance model between the CSP & end user. • Leverage industry best practices on security and audit. • View cloud as a commercial item and consider appropriate terms & conditions • A mechanism to incorporate CSP’s unique terms and conditions. • Leverage CSP’s commercial SLAs, i.e. uptime, durability, reliability etc. • A model to obtain cloud services directly from CSP and/or an indirect model in which cloud services are procured through partners or reseller. • Do not consider or treat CSPs as System Integrators (SIs). Cloud Models Performance Based Requirements Pricing Security/Assurance/Audit Terms & Conditions and SLAs Vendor Types and Partner Ecosystem • Separate purchase of cloud infrastructure from the purchase of services and labor for planning, developing, and executing, migrations & workloads. Services vs. Infrastructure
  • 38. Cloud Procurement Next Steps • Understand the cloud model, security and how it is different from traditional IT • Understand working with partners/resellers • Understand Cloud pricing and SLA constructs • Focus on requirements that are cloud specific – not traditional IT