<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Layer 7 - Blogs &#187; Cloud Security</title>
	<atom:link href="http://www.layer7tech.com/blogs/index.php/category/cloud-computing-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.layer7tech.com/blogs</link>
	<description>API Management &#124; SOA Governance &#124; Cloud Integration</description>
	<lastBuildDate>Fri, 24 May 2013 21:23:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Growing Your APIs in the Amazon Cloud</title>
		<link>http://www.layer7tech.com/blogs/index.php/growing-your-apis-in-the-amazon-cloud/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/growing-your-apis-in-the-amazon-cloud/#comments</comments>
		<pubDate>Mon, 28 Jan 2013 22:30:28 +0000</pubDate>
		<dc:creator>Steven Tait</dc:creator>
				<category><![CDATA[Amazon]]></category>
		<category><![CDATA[API Management]]></category>
		<category><![CDATA[Cloud Integration]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Tech Talks]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=3792</guid>
		<description><![CDATA[Putting applications in the cloud can reduce overall IT costs and deliver greater scalability. Cost considerations are always a concern in IT infrastructures but scalability may be the most important benefit of hosting applications in the cloud. Leveraging the elasticity of Amazon’s cloud infrastructure can allow you to scale your APIs to match market demand. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.layer7.com/live" target="_blank"><img class="alignleft size-full wp-image-3803" style="margin: 0px 15px;" title="Amazon Tech Talk" src="http://www.layer7tech.com/blogs/wp-content/uploads/2013/01/Amazon-Tech-Talk-v1.jpg" alt="Amazon Tech Talk" width="300" height="169" /></a>Putting applications in the cloud can reduce overall IT costs and deliver greater scalability. Cost considerations are always a concern in IT infrastructures but scalability may be the most important benefit of hosting applications in the cloud. Leveraging the elasticity of Amazon’s cloud infrastructure can allow you to scale your APIs to match market demand. Amazon Web Services provides tooling that can help you be quicker to market with your APIs.</p>
<p>But do interfaces hosted on AWS and exposed to third-party developers contain significant vulnerabilities? Cloud services allow third-party access to applications and data through APIs. Failing to properly secure that access can put the data and applications at risk. So, how do you safely expose APIs in a cloud environment?</p>
<p>Understanding the cloud API model isn’t always easy. So, on January 29, we&#8217;re having a live discussion about publishing APIs in the AWS cloud, which may help answer questions surrounding exposing APIs in cloud environments. I&#8217;m excited to welcome Layer 7 Technologies Senior Software Developer Hirbod (Rod) Moshfeghi as our special guest for this API Tech Talk. This is a great opportunity to have your questions answered and to discuss the implications of publishing cloud-based APIs.</p>
<p>Here&#8217;s how to join the live discussion&#8230;</p>
<p>On the day of the event, click here to join:</p>
<ul>
<li><a href="http://www.layer7.com/live" target="_blank">layer7.com/live</a></li>
</ul>
<p>Submit your questions:</p>
<ul>
<li>Tweet using the tag <a href="https://twitter.com/intent/tweet?source=webclient&amp;text=Question+for+upcoming+%40Layer7+tech+talk%3A%23layer7live" target="_blank">#Layer7Live</a></li>
<li>Email <a href="mailto:techtalk@layer7.com">techtalk@layer7.com</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/growing-your-apis-in-the-amazon-cloud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CES 2013 Panel: Privacy &amp; Security in the Cloud</title>
		<link>http://www.layer7tech.com/blogs/index.php/ces-2013-panel-privacy-security-in-the-cloud/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/ces-2013-panel-privacy-security-in-the-cloud/#comments</comments>
		<pubDate>Thu, 03 Jan 2013 22:30:25 +0000</pubDate>
		<dc:creator>Scott Morrison</dc:creator>
				<category><![CDATA[Cloud Integration]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Talks]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=3705</guid>
		<description><![CDATA[The Consumer Electronics Show (CES) 2013 is starting in Las Vegas next week and cloud computing is on the agenda. You can be sure that a technology has moved out of the hype cycle and into everyday use when it shows up at a show like CES, known more for the latest TVs and phones [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.cesweb.org/" target="_blank"><img class="alignleft size-full wp-image-3709" style="margin: 0px 10px;" title="CES 2013" src="http://www.layer7tech.com/blogs/wp-content/uploads/2013/01/CES-2013-v2.jpg" alt="CES 2013" width="300" height="230" /></a>The <a href="http://www.cesweb.org/" target="_blank">Consumer Electronics Show (CES)</a> 2013 is starting in Las Vegas next week and cloud computing is on the agenda. You can be sure that a technology has moved out of the hype cycle and into everyday use when it shows up at a show like CES, known more for the latest TVs and phones than computing infrastructure. People don’t really need to talk about cloud any more; it’s just there and we are using it.</p>
<p>Of course there will always be a place for a little more talking and I’ll be doing some of this myself as part of the CES panel <a href="http://ces13.mapyourshow.com/5_0/sessions/sessiondetails.cfm?ScheduledSessionID=1BABC9&amp;CFID=89719778&amp;CFTOKEN=937c04dd1b97aa1b-13EC8E9F-DAF4-E3A2-4422913830B018B5" target="_blank">Privacy &amp; Security in the Cloud</a>. This discussion will take place on Monday Jan 7, 11am-12pm, in LVCC, North Hall N259. The panel is chaired by my good friend <a href="http://jeremygeelan.sys-con.com/" target="_blank">Jeremy Geelan</a>, founder of <a href="http://cloudcomputingexpo.com/" target="_blank">Cloud Computing Expo</a>, who honed his considerable moderation skills at the BBC.</p>
<p>I’m planning on exploring the intersection between the cloud and our increasingly ubiquitous consumer devices. We will highlight the opportunities created by this technological convergence but we will also consider the implications this has for our personal privacy. I hope you can join us.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/ces-2013-panel-privacy-security-in-the-cloud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Break in the Clouds</title>
		<link>http://www.layer7tech.com/blogs/index.php/a-break-in-the-clouds/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/a-break-in-the-clouds/#comments</comments>
		<pubDate>Mon, 03 Dec 2012 22:00:23 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[Apps]]></category>
		<category><![CDATA[Cloud Integration]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Mobile Access]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=3433</guid>
		<description><![CDATA[A recent study by researchers at North Carolina State University and the University of Oregon describes a threat scenario that allows attackers to exploit cloud-based resources for malicious purposes like cracking passwords or launching denial-of-service attacks. The study has gotten a lot of attention, including articles in reputable sources like Dark Reading, Ars Technica and [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.layer7tech.com/blogs/wp-content/uploads/2012/12/A-Break-in-the-Clouds-Large.jpg"><img class="alignleft size-medium wp-image-3435" style="margin: 10px;" title="Click to see full-size" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/12/A-Break-in-the-Clouds-Large-300x230.jpg" alt="A Break in the Clouds" width="300" height="230" /></a>A <a href="http://adl.csie.ncu.edu.tw/~jhhe/doc/bmr.pdf" target="_blank">recent study</a> by researchers at North Carolina State University and the University of Oregon describes a threat scenario that allows attackers to exploit cloud-based resources for malicious purposes like cracking passwords or launching denial-of-service attacks. The study has gotten a lot of attention, including articles in reputable sources like <a href="http://www.darkreading.com/cloud-security/167901092/security/news/240142718/new-hack-abuses-cloud-based-browsers.html" target="_blank">Dark Reading</a>, <a href="http://arstechnica.com/security/2012/11/hack-could-let-browsers-use-cloud-to-carry-out-big-attacks-on-the-cheap/" target="_blank">Ars Technica</a> and <a href="http://www.networkworld.com/news/2012/112812-vulnerability-hackers-cloud-computing-264610.html" target="_blank">Network World</a>.</p>
<p>In order to optimize the performance of mobile apps or browsers, some computation-heavy functions have been offloaded to cloud-based resources, which in turn access backend resources and Web pages. This creates a middle ground in the cloud that is exploited in the attack, which the authors call “Browser Map Reduce (BMR)”. In reading the paper, it’s clear that this is a legitimate threat. The authors actually carried it out using free resources, although they limited the scope in order not to be abusive.</p>
<p>Aside from questions of curiosity around the mechanics of the vulnerability, the obvious question is this: How can we mitigate this threat? Here are a few perspectives here as well as a method for each.</p>
<p><strong>Apps</strong> – This “cloud offload” architecture has arisen because of the processing limitations of mobile devices. When a backend resource is requested by a mobile user, it makes sense to have the data returned in the most consumable format, in order to optimize user experience. Whenever possible, instead of doing this through “browser offload”, data should be returned as JSON objects. This API approach is a proven method that works for mobile devices and is not subject to the BMR threat.</p>
<p><strong>Cloud Services</strong> – This threat should not be viewed as a dismissal of the “cloud offload” approach. Cloud-based resources are necessary for handling caching, data indexing and other key functions in the mobile paradigm. However, it serves as a warning that these dedicated cloud-based resources cannot be considered part of a walled garden that includes the associated mobile app. The resource’s entry point must be protected against attackers. <a href="http://www.layer7tech.com/products/mobile-access-gateway" target="_blank">Layer 7’s SecureSpan Mobile Access Gateway</a> is an ideal choice for this access control, as it uses identity-based measures to ensure that only requests from legitimate sources are serviced.</p>
<p><strong>Web-Based Resources</strong> – Although the backend Web resource was not exploited in this scenario, the study is a reminder that the topology of the mobile Web is changing and increasing in complexity. P2P app-to-API connections cannot be assumed and therefore inbound API calls cannot be implicitly trusted. API access must be controlled and the <a href="http://www.layer7tech.com/products/api-proxy" target="_blank">SecureSpan API Proxy</a> is a leading solution for this purpose.</p>
<p>To sum up, this is a legitimate threat but not a reason to abandon the use of cloud-based resources for mobile app optimization. Be aware of the threats, employ the mitigations and then you can continue to enjoy the exciting growth of the mobile Web.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/a-break-in-the-clouds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Returning from #CIS2012</title>
		<link>http://www.layer7tech.com/blogs/index.php/returning-from-cis2012-2/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/returning-from-cis2012-2/#comments</comments>
		<pubDate>Fri, 20 Jul 2012 17:45:04 +0000</pubDate>
		<dc:creator>Francois Lascelles</dc:creator>
				<category><![CDATA[Cloud Access Control]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[OpenID Connect]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=2595</guid>
		<description><![CDATA[Cloud Identity Summit was definitely worth the trip. The talks were great, the audience was great and the venue was outstanding. Sign me up for next year in Napa! It’s beautiful and quiet at Vail Cascade this morning. As I stepped outside, I’m pretty sure I saw SAML scurrying away into the trees. This is [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.cloudidentitysummit.com/" target="_blank"><img class="alignleft size-full wp-image-2601" style="margin: 10px;" title="Francois Lascelles at Cloud Identity Summit" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/07/Francois-Lascelles-at-Cloud-Identity-Summit.jpg" alt="Francois Lascelles at Cloud Identity Summit" width="263" height="300" /></a>Cloud Identity Summit was definitely worth the trip. The talks were great, the audience was great and the venue was outstanding. Sign me up for next year in Napa!</p>
<p>It’s beautiful and quiet at <a href="http://www.vailcascade.com/" target="_blank">Vail Cascade</a> this morning. As I stepped outside, I’m pretty sure I saw SAML scurrying away into the trees. This is weird given this week’s proclamations that SAML was dead. Although we won&#8217;t be rid of SAML anytime soon, I do look forward to enterprise adoption of the new kid on the block: <a href="http://www.layer7tech.com/tutorials/openid-connect" target="_blank">OpenID Connect</a>. Easier federation, <a href="http://www.layer7tech.com/blogs/index.php/mobile-friendly-federated-identity-part-2-openid-connect/" target="_blank">OpenID Connect-style</a> is already common for consumer identity providers; enterprise identity providers should take note and follow suit. As a vendor of API Management infrastructure, it’s up to us to enable the enterprise to better reach out to its target audience. I see <a href="http://www.businesswire.com/news/home/20120716005274/en/Layer-7-Demonstrate-OpenID-Connect-Implementation-Cloud" target="_blank">support for OpenID Connect</a> as a key component in achieving this today.</p>
<p>My favorite proclamation of the week goes to Patrick Harding who declared in his talk titled “The Platformication of the Enterprise is Upon us Again and They Forgot Security (Again)” that API tokens are going to be “the currency of the API economy”. <a href="http://www.layer7tech.com/blogs/index.php/oauth-token-management-2/" target="_blank">The management of tokens and their lifecycle</a> is indeed a crucial component of API Management. Consider the case of a mobile application consuming an enterprise API using an OAuth token. Such tokens are associated with the API provider, the user (subscriber), the mobile application and the mobile device. Each live token is potentially associated with multiple parties and one of the challenges of API token management is to enable control of the right tokens by the right parties.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/returning-from-cis2012-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Layer 7 at Gartner Security &amp; Risk Management Summit</title>
		<link>http://www.layer7tech.com/blogs/index.php/layer-7-at-gartner-security-risk-management-summit/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/layer-7-at-gartner-security-risk-management-summit/#comments</comments>
		<pubDate>Fri, 08 Jun 2012 16:00:00 +0000</pubDate>
		<dc:creator>Jaime Ryan</dc:creator>
				<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Gartner]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Mobile Access]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=2236</guid>
		<description><![CDATA[Next week (June 11-14), Layer 7 will be exhibiting at the Gartner Security &#38; Risk Management Summit near Washington, DC (in National Harbor, MD). Speakers will run the gamut from Michael Dell to the Cybersecurity Coordinator for the White House, because enterprises and governmental organizations share a serious interest in securing data and applications. The [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.gartner.com/technology/summits/na/security/" target="_blank"><img class="alignleft size-full wp-image-2238" style="margin: 5px;" title="Gartner Security and Risk Management" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/06/Gartner-Security-Risk-Management-v2.jpg" alt="Gartner Security and Risk Management" width="300" height="130" /></a>Next week (June 11-14), Layer 7 will be exhibiting at the <a href="http://www.gartner.com/technology/summits/na/security/" target="_blank">Gartner Security &amp; Risk Management Summit</a> near Washington, DC (in National Harbor, MD). Speakers will run the gamut from Michael Dell to the Cybersecurity Coordinator for the White House, because enterprises and governmental organizations share a serious interest in securing data and applications.</p>
<p>The combination of security and risk management is particularly interesting these days, as rapid migration to Cloud and Mobile has introduced a new set of risks. These new platforms raise issues around compliance, information security and identity management, which can only be addressed with a comprehensive approach to security, using proven technology.</p>
<p>If you’re at the show, stop by and visit Layer 7 at Booth 92. We’d love to demonstrate how our SOA Governance and API Management solutions can counteract the risks involved with adopting these new technologies. Our solutions – flexibly deployed on-premise or in the Cloud – provide control over data and applications being exposed to partners, Cloud and Mobile.</p>
<p>And <a href="http://www.layer7tech.com/products/industry-leading-xml-gateway-overview" target="_blank">our industry-leading technology</a> has been certified at the highest levels for use in both corporate and governmental organizations – <a href="http://www.layer7tech.com/solutions/pci-compliance-for-apis" target="_blank">PCI-DSS compliance</a> for retail, STIG vulnerability testing for the DoD, FIPS 140-2 for cryptographic functionality and <a href="http://www.layer7tech.com/products/eal4-common-criteria-certified-soa-gateway" target="_blank">Common Criteria certification</a> for overall security.</p>
<p>Don’t let the risk outweigh the reward – come <a href="http://www.layer7tech.com/contactus" target="_blank">talk to us</a>!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/layer-7-at-gartner-security-risk-management-summit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Start Spreading the News… Cloud Expo, New York</title>
		<link>http://www.layer7tech.com/blogs/index.php/start-spreading-the-new-cloud-expo-new-york/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/start-spreading-the-new-cloud-expo-new-york/#comments</comments>
		<pubDate>Wed, 06 Jun 2012 18:45:49 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Integration]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Hybrid Clouds]]></category>
		<category><![CDATA[Talks]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=2195</guid>
		<description><![CDATA[Cloud Expo 2012 is almost here. This promises to be an incredible event, with thousands of attendees and over 100 speakers. As previously mentioned, I’m privileged to be presenting on Making Hybrid Cloud Safe &#38; Reliable. I’m particularly excited that I’ll be introducing attendees to the new concept of API-Aware Traffic Management. It will also [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://cloudexpo2012east.sys-con.com/" target="_blank"><img class="alignleft size-full wp-image-2199" style="margin: 10px;" title="Cloud Expo 2012" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/06/Cloud-Expo-2012.jpg" alt="Cloud Expo 2012" width="300" height="201" /></a><a href="http://cloudexpo2012east.sys-con.com/" target="_blank">Cloud Expo 2012</a> is almost here. This promises to be an incredible event, with thousands of attendees and over 100 speakers. As previously mentioned, I’m privileged to be presenting on <a href="http://www.layer7tech.com/blogs/index.php/cloud-clear/" target="_blank">Making Hybrid Cloud Safe &amp; Reliable</a>. I’m particularly excited that I’ll be introducing attendees to the new concept of <a href="http://www.layer7tech.com/blogs/index.php/api-aware-traffic-management/" target="_blank">API-Aware Traffic Management</a>. It will also be great to be back in New York City!</p>
<p>I recently read Daniel Kahneman’s book <a href="http://www.amazon.com/Thinking-Fast-Slow-Daniel-Kahneman/dp/0374275637" target="_blank"><em>Thinking Fast &amp; Slow</em></a>, a fascinating study of how the human mind works. With the new capabilities offered by big data and Cloud computing — the dual themes for next week’s event — and the increasing personalization of technology through Mobile devices, I think we have an opportunity to make our digital systems more human in their processing. What does that mean?  Well, more intuitive in user experience, more lateral through caching of unstructured data and more adaptive to changing conditions. API-Aware Traffic Management certainly reflects this potential.</p>
<p>If you are going to be (or hope to be) at the event, <a href="http://www.layer7tech.com/blogs/index.php/start-spreading-the-new-cloud-expo-new-york/#comments">add a response in the comments box</a> or tweet to <a href="https://twitter.com/#!/MattMcLartyBC" target="_blank">@MattMcLartyBC</a>. Hope to see you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/start-spreading-the-new-cloud-expo-new-york/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Where Did Siri Go?</title>
		<link>http://www.layer7tech.com/blogs/index.php/where-did-siri-go/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/where-did-siri-go/#comments</comments>
		<pubDate>Wed, 30 May 2012 18:00:05 +0000</pubDate>
		<dc:creator>Jaime Ryan</dc:creator>
				<category><![CDATA[API Management]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Mobile Access]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=2150</guid>
		<description><![CDATA[Recently, there’s been some media focus on the limits of BYOD, especially relating to businesses disallowing certain smartphone features. This article on IBM’s somewhat restrictive BYOD guidelines mentions outright bans on technologies like Dropbox and Siri. As an ex-IBM employee, a geek in a partner-facing technical role and a smartphone user, I’m particularly intrigued by [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.technologyreview.com/business/40324/" target="_blank"><img class="alignleft size-full wp-image-2152" style="margin: 10px;" title="IBM Versus Siri" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/05/IBM-Siri-v2.jpg" alt="IBM Versus Siri" width="300" height="93" /></a>Recently, there’s been some media focus on the limits of BYOD, especially relating to businesses disallowing certain smartphone features. <a href="http://www.technologyreview.com/business/40324/" target="_blank">This article on IBM’s somewhat restrictive BYOD guidelines</a> mentions outright bans on technologies like Dropbox and Siri. As an ex-IBM employee, a geek in a partner-facing technical role and a smartphone user, I’m particularly intrigued by the lines drawn by corporations in cases like this.</p>
<p>As the variety of available business apps and mobile devices continues to grow exponentially, enterprises will find it increasingly difficult to place such rigid limits on BYOD. Employees are already beginning to feel entitled to use apps that make them more efficient. In some case this may mean that employees will knowingly use banned apps. If businesses want to avoid this kind of insubordination, they will have to work with their employees, not against them.</p>
<p>One part of the solution is a focus on education rather than overly-strict technological bans. Another is embracing the concept of BYOD rather than fighting it. For instance, many of our customers provide their own apps to run on employee-owned devices. We focus on providing these customers with <a href="http://www.layer7tech.com/solutions/enterprise-mobile-access" target="_blank">solutions that allow them to make BYOD secure and manageable</a>, without having to ban apps or impose invasive mobile device management software.</p>
<p>The rest of the solution will come from Cloud and mobile vendors taking steps to make their technologies more enterprise-friendly. This means, for example:</p>
<ul>
<li>Apple will need to recognize its prevalence in the enterprise market and take steps to certify iCloud and Siri for business use.</li>
<li>Google Drive and Microsoft SkyDrive will need to deliver terms of service that assuage fears rather than <a href="http://news.cnet.com/8301-1023_3-57421406-93/google-drive-terms-of-service-a-toxic-brew/" target="_blank">fostering them</a>.</li>
</ul>
<p>No one has all of the answers yet and I suppose you can’t blame IBM for a cautious approach but the most successful BYOD initiatives are likely going to be those that are flexible enough to avoid alienating employees. How else will we know what happens when Siri is asked to <a href="http://www.pocket-lint.com/news/42519/siri-website-created-iphone-4s" target="_blank">open the pod bay doors</a>?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/where-did-siri-go/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>API-Aware Traffic Management</title>
		<link>http://www.layer7tech.com/blogs/index.php/api-aware-traffic-management/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/api-aware-traffic-management/#comments</comments>
		<pubDate>Tue, 15 May 2012 17:00:45 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[API]]></category>
		<category><![CDATA[Cloud Brokers]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Integration]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Hybrid Clouds]]></category>
		<category><![CDATA[Talks]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=2010</guid>
		<description><![CDATA[As I mentioned in my last blog post, the promise of cost reduction is compelling many enterprises to move their workloads into the Cloud but many IT leaders are reluctant to do so, for fear of compromising the security and availability of their services. These concerns are well-founded but the benefits of Cloud are too [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://cloudexpo2012east.sys-con.com/event/session/1598" target="_blank"><img class="alignleft size-full wp-image-2012" style="margin: 10px;" title="Cloud Expo" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/05/Cloud-Expo.jpg" alt="Cloud Expo" width="300" height="149" /></a>As I mentioned in <a href="http://www.layer7tech.com/blogs/index.php/cloud-clear/" target="_blank">my last blog post</a>, the promise of cost reduction is compelling many enterprises to move their workloads into the Cloud but many IT leaders are reluctant to do so, for fear of compromising the security and availability of their services. These concerns are well-founded but the benefits of Cloud are too great to ignore. To obtain these benefits, companies must adopt techniques that protect against the attendant risks, without compromise.</p>
<p>Many people are familiar with Layer 7’s <a href="http://www.layer7tech.com/Forrester-Wave/" target="_blank">industry-leading</a> security functionality, so it’s no surprise that I’d recommend using our Gateway technology to protect connections from on-premise infrastructure to off-premise Cloud services. The flexibility of deployment options we offer makes it possible to create a network of secure on- and off-premise endpoints to meet the most stringent requirements. This covers security but what about availability?</p>
<p>People seem to be less familiar with Layer 7’s routing capabilities. <a href="http://www.layer7tech.com/library/product-data-sheets/cloudspan-cloudconnect-gateway/1861" target="_blank">Our Gateway technology</a> is optimized to perform flexible, content-based routing with negligible impact on overall transaction times. In the context of the Cloud, this means that traffic proxied by a Layer 7 Gateway can be re-directed using intelligent algorithms and even dynamic, state-based awareness. This routing capability, which I call “API-aware traffic management”, brings huge benefits in ensuring availability when connecting to multiple API instances – on-premise, off-premise, in multiple Clouds… anywhere on the hybrid network.</p>
<p>I’ll be discussing this topic in detail at the upcoming <a href="http://cloudcomputingexpo.com/" target="_blank">Cloud Expo 2012</a>, June 11-14 in New York City. This promises to be a great event, so I hope you can make it and <a href="http://cloudexpo2012east.sys-con.com/event/session/1598" target="_blank">attend my discussion</a>!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/api-aware-traffic-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud &amp; Clear</title>
		<link>http://www.layer7tech.com/blogs/index.php/cloud-clear/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/cloud-clear/#comments</comments>
		<pubDate>Mon, 30 Apr 2012 16:00:31 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Integration]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Hybrid Clouds]]></category>
		<category><![CDATA[Talks]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=1919</guid>
		<description><![CDATA[It’s April in Vancouver, which got me thinking about clouds.  Although the IT buzz in 2012 has been dominated by mobile and big data, Cloud computing is still a hot topic, especially since it is an enabler for both. In the public Cloud space, Google just launched Drive in the same week that Microsoft updated [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://cloudexpo2012east.sys-con.com/event/session/1598" target="_blank"><img class="alignleft size-full wp-image-1921" style="margin: 10px;" title="Hybrid Cloud" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/04/Hybrid-Cloud-v2.jpg" alt="Hybrid Cloud" width="300" height="208" /></a>It’s April in Vancouver, which got me thinking about clouds.  Although the IT buzz in 2012 has been dominated by mobile and big data, Cloud computing is still a hot topic, especially since it is an enabler for both. In the public Cloud space, Google just launched <a href="http://www.computerworld.com/s/article/9226565/Google_Drive_review_Adding_cloud_storage_to_the_mix?taxonomyId=19" target="_blank">Drive</a> in the same week that Microsoft updated <a href="http://www.informationweek.com/byte/news/personal-tech/storage-memory/232900899" target="_blank">SkyDrive</a>. In the private Cloud domain, IBM recently announced its <a href="http://www.zdnet.com/blog/btl/ibm-launches-puresystems-touts-integration-flexibility/73564" target="_blank">PureSystems</a> platform, which falls along similar lines as the Exa- line from Oracle.</p>
<p>It will be interesting to see whether or not big enterprises buy into this <a href="http://www.dbta.com/Articles/Columns/Applications-Insight/Oracles-Exalogic-%E2%80%93-Private-Cloud-or-Modern-Mainframe-71234.aspx" target="_blank">“21st century mainframe”</a> concept but what’s clear is that enterprises now want to migrate critical workloads to the Cloud, en masse. To realize the true benefits of Cloud, many of these workloads will have to be running off-premise. But since many will remain on-premise, enterprises will be relying on hybrid Cloud infrastructure for their most significant IT services.</p>
<p>Security remains a major area of concern for organizations looking to leverage the Cloud. Increasingly, availability and reliability are also significant concerns, particularly since Amazon has had a few <a href="http://techcrunch.com/2011/08/08/amazon-ec2-outage/" target="_blank">outages</a> recently. In addition to addressing these concerns, enterprises are evaluating how they can optimize processing volumes to get maximum cost benefit from their Cloud deployments.</p>
<p>Please join me at the <a href="http://cloudcomputingexpo.com/" target="_blank">Cloud Expo</a>, June 11-14 in New York, where <a href="http://cloudexpo2012east.sys-con.com/event/session/1598" target="_blank">I’ll be discussing solutions for each of these considerations</a>. Hey, we should have blue skies by then!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/cloud-clear/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security in the Clouds: The IPT Swiss IT Challenge</title>
		<link>http://kscottmorrison.com/2012/02/03/security-in-the-clouds-the-ipt-swiss-it-challenge/</link>
		<comments>http://kscottmorrison.com/2012/02/03/security-in-the-clouds-the-ipt-swiss-it-challenge/#comments</comments>
		<pubDate>Sat, 04 Feb 2012 00:27:03 +0000</pubDate>
		<dc:creator>Scott Morrison</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Private Clouds]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://kscottmorrison.com/?p=1186</guid>
		<description><![CDATA[Probably the best part of my job as CTO of Layer 7 Technologies is having the opportunity to spend time with our customers. They challenge my assumptions, push me for commitments, and take me to task for any issues; but &#8230; <a href="http://kscottmorrison.com/2012/02/03/security-in-the-clouds-the-ipt-swiss-it-challenge/">Continue reading <span>&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kscottmorrison.com&#38;blog=7836481&#38;post=1186&#38;subd=kscottmorrison&#38;ref=&#38;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://kscottmorrison.com/2012/02/03/security-in-the-clouds-the-ipt-swiss-it-challenge/" target="_blank"><img class="alignleft size-medium wp-image-1187" style="margin-top: 10px; margin-bottom: 10px;" title="Scott Morrison in Gstaad" src="http://kscottmorrison.files.wordpress.com/2012/02/gstaad.jpg?w=300&amp;h=225" alt="Scott Morrison in Gstaad" width="300" height="225" /></a>Probably the best part of my job as CTO of <a href="http://www.layer7.com/" target="_blank">Layer 7 Technologies</a> is having the opportunity to spend time with our customers. They challenge my assumptions, push me for commitments and take me to task for any issues -  but they also flatter the whole Layer 7 team for the many things we do right as a company. And for every good idea I think I have, I probably get two or three great ones out of each and every meeting with the people who use SecureSpan to solve real problems on a daily basis.</p>

<p>All of that is good but I’ve learned that if you add skiing into the mix, it becomes even better. Layer 7 is fortunate to have an excellent partnership with <a href="http://www.ipt.ch/de/" target="_blank">IPT</a>, a very successful IT services company out of Zug, Switzerland. Each year, IPT holds a customer meeting up in Gstaad, which I think surely gives them an unfair advantage over their competitors in countries less naturally blessed. I finally managed to draw the long straw in our company and was able to join my colleagues from IPT at their annual event this January.</p>

<p>Growing up in Vancouver, with Whistler practically looming in my backyard, I learned to ski early and ski well. Or so I thought, until I had to try to keep up with a crew of Swiss who surely were born with skis on their feet. But being challenged is always good and I can say the same for what I learned from my Swiss friends about technology and its impact on the local market.</p>

<p>The Swiss IT market is much more diverse than people from outside of it may think. Yes, there are the famous banks but it is also an interesting microcosm of the greater European market — albeit run with a natural attention to detail and extraordinary efficiency. It’s the different local challenges that shape technology needs and lead to different emphasis.</p>

<p>SOA and Web services are very mature and indeed are pushed to their limits but the API market is still in its very early stages. The informal, wild west character of RESTful services doesn’t seem to resonate in the corridors of power in Zurich. Cloud appears in patches but it is hampered by very real privacy concerns and this, of course, represents a great opportunity. Secure private Clouds are made for this place.</p>

<p>I always find Switzerland very compelling and difficult to leave. Perhaps it’s the miniscule drop of Swiss <a href="http://www.biographi.ca/009004-119.01-e.php?&amp;id_nbr=2202&amp;&amp;PHPSESSID=ychzfqkvzape" target="_blank">ancestry</a> I can claim. But more likely it’s just that I think the Swiss have got this life thing all worked out.</p>

<p>Looking forward to going back.</p>

<a href="http://feeds.wordpress.com/1.0/gocomments/kscottmorrison.wordpress.com/1186/" rel="nofollow"><img src="http://feeds.wordpress.com/1.0/comments/kscottmorrison.wordpress.com/1186/" alt="" border="0" /></a> <a href="http://feeds.wordpress.com/1.0/godelicious/kscottmorrison.wordpress.com/1186/" rel="nofollow"><img src="http://feeds.wordpress.com/1.0/delicious/kscottmorrison.wordpress.com/1186/" alt="" border="0" /></a> <a href="http://feeds.wordpress.com/1.0/gofacebook/kscottmorrison.wordpress.com/1186/" rel="nofollow"><img src="http://feeds.wordpress.com/1.0/facebook/kscottmorrison.wordpress.com/1186/" alt="" border="0" /></a> <a href="http://feeds.wordpress.com/1.0/gotwitter/kscottmorrison.wordpress.com/1186/" rel="nofollow"><img src="http://feeds.wordpress.com/1.0/twitter/kscottmorrison.wordpress.com/1186/" alt="" border="0" /></a> <a href="http://feeds.wordpress.com/1.0/gostumble/kscottmorrison.wordpress.com/1186/" rel="nofollow"><img src="http://feeds.wordpress.com/1.0/stumble/kscottmorrison.wordpress.com/1186/" alt="" border="0" /></a> <a href="http://feeds.wordpress.com/1.0/godigg/kscottmorrison.wordpress.com/1186/" rel="nofollow"><img src="http://feeds.wordpress.com/1.0/digg/kscottmorrison.wordpress.com/1186/" alt="" border="0" /></a> <a href="http://feeds.wordpress.com/1.0/goreddit/kscottmorrison.wordpress.com/1186/" rel="nofollow"><img src="http://feeds.wordpress.com/1.0/reddit/kscottmorrison.wordpress.com/1186/" alt="" border="0" /></a> <img src="http://stats.wordpress.com/b.gif?host=kscottmorrison.com&amp;blog=7836481&amp;post=1186&amp;subd=kscottmorrison&amp;ref=&amp;feed=1" alt="" width="1" height="1" border="0" />]]></content:encoded>
			<wfw:commentRss>http://kscottmorrison.com/2012/02/03/security-in-the-clouds-the-ipt-swiss-it-challenge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
