For most companies the use of cloud services is initially often a step-by-step experiment. Based on individual accounts with one of the major cloud providers, various employees explore the possibilities and get an idea of what might be of interest to their company or department. Even these first explorations are usually subject to a fee. In order to keep an eye on where the journey is going financially, this initial option testing has to be tackled systematically. Such a plan is mandatory for a later widespread use of the cloud. Large providers such as AWS or Azure have usually planned the first steps for new customers diligently. With a Trusted Advisor, such as that found at AWS, the first steps are quickly and safely taken.

A TIERED AUTHORIZATION MODEL REDUCES THE ECONOMIC RISKS OF THE CLOUD TEST PHASE
The starting point for a company in the exploration phase is a base or root account for most providers, which has rights to everything. This account is especially secured – e. g. in addition to password protection with an RSA token. This is necessary, as the debit card is used here.

In the next step, a leading administration account is created. It has all authorizations, but no longer has access to the credit card data as an economic link between customer and provider. This account is also secured in detail.
This is where the user accounts for different employees come into play. With a larger group of people with their own access, the risk of generating costs uncontrollably and unintentionally increases. In the case of larger user groups, unlimited administrative full access cannot generally be granted to all users. By setting up billing alerts, undesired peaks in usage can be detected and reported at an early stage, but a graduated usage concept in advance and the corresponding assignment of rights to individual users provide more security.

First of all, the idea of not giving the "cloud pathfinders" in the company administrator rights, but rather sending them on an exploratory trip with largely unrighteous accounts and issuing authorizations if necessary, sounds sensible. In practice, however, this is almost impracticable, since the large cloud providers have set up the assignment of authorizations on an extremely small scale with a high degree of granularity. For the "Virtual Machines" area alone, AWS has over 230 different sub-permissions that can be assigned. With such an extraordinarily dense array of award policies and their interlinking, even the testing of cloud options becomes a science in itself, which tends to prevent quick discoveries.

The background to these complex procurement structures is that the large cloud providers have to meet the needs of large companies with often many hundreds of users and administrators. And this means that the division of work into small parts results in a correspondingly chiselled assignment of rights in cloud systems. Suitable for large usecases, this is often quite complicated and inflexible for smaller teams.

At the same time, it is also a great protection. Thousands of options and services in a global cloud computing network offer too many opportunities for waste or uncertainty from a data security and cost perspective.

KEEPING AN EYE ON STRATEGY AND IMPLEMENTATION WHEN DEVELOPING AN AUTHORIZATION CONCEPT
Documentation, experience reports, blog discussions and also the introductions of the large providers themselves together form a reservoir of important information that is often too large for the beginner to plan wisely into the cloud. The most important clues as to what needs to be considered, a guideline for your own first steps into the cloud, one often seeks in vain …

Read the complete article on novum online – the newsdesk of noventum consulting.

Über die noventum consulting GmbH

noventum consulting GmbH is an international IT management consultancy.

Founded in 1996 in Münster, today noventum is represented in Münster and Düsseldorf with more than 100 employees. Independent noventum partner companies work in Istanbul and Luxembourg.

The managing partner is Uwe Rotermund.

noventum consulting supports its customers in their IT challenges and in their efforts for a modern corporate culture.

Customers are predominantly DAX companies as well as medium-sized companies and organizations with a large IT infrastructure.

Firmenkontakt und Herausgeber der Meldung:

noventum consulting GmbH
Münsterstraße 111
48155 Münster
Telefon: +49 (2506) 9302-0
Telefax: +49 (2506) 9302-23
http://www.noventum.de

Ansprechpartner:
Dr. Matthias Rensing
Presse
Telefon: +49 (2506) 9302-0
E-Mail: matthias.rensing@noventum.de
Für die oben stehende Pressemitteilung ist allein der jeweils angegebene Herausgeber (siehe Firmenkontakt oben) verantwortlich. Dieser ist in der Regel auch Urheber des Pressetextes, sowie der angehängten Bild-, Ton-, Video-, Medien- und Informationsmaterialien. Die United News Network GmbH übernimmt keine Haftung für die Korrektheit oder Vollständigkeit der dargestellten Meldung. Auch bei Übertragungsfehlern oder anderen Störungen haftet sie nur im Fall von Vorsatz oder grober Fahrlässigkeit. Die Nutzung von hier archivierten Informationen zur Eigeninformation und redaktionellen Weiterverarbeitung ist in der Regel kostenfrei. Bitte klären Sie vor einer Weiterverwendung urheberrechtliche Fragen mit dem angegebenen Herausgeber. Eine systematische Speicherung dieser Daten sowie die Verwendung auch von Teilen dieses Datenbankwerks sind nur mit schriftlicher Genehmigung durch die United News Network GmbH gestattet.

counterpixel