SlideShare une entreprise Scribd logo
1  sur  36
Télécharger pour lire hors ligne
PCI for Cloud Applications
Securing the Subscription Economy
Rand Wacker
VP of Products
@randwacker | #subscribed13
CloudPassage	
  Overview	
  
CloudPassage	
  provides	
  
security	
  and	
  compliance	
  	
  
for	
  your	
  cloud,	
  	
  
so9ware-­‐defined,	
  and	
  
tradi<onal	
  data	
  center	
  
infrastructure	
  
Our	
  PCI	
  Story	
  
1.  We	
  use	
  Zuora	
  for	
  metered	
  usage	
  billing	
  
2.  Since	
  we	
  accept	
  CCs	
  in	
  mul;ple	
  ways,	
  had	
  to	
  do	
  a	
  full	
  PCI	
  cert	
  
for	
  ourselves	
  
3.  We	
  also	
  provide	
  PCI	
  security	
  controls	
  to	
  our	
  customers	
  
4.  Here’s	
  what	
  we	
  learned…	
  
	
  
I T S 	
   N E V E R 	
   J U S T 	
   T H A T 	
   S I M P L E 	
  
Your	
  Architecture	
  Drives	
  PCI	
  Scope	
  
1.  PCI	
  “in-­‐scope”	
  systems	
  are	
  anything	
  that	
  accept,	
  store,	
  process,	
  
or	
  transmit	
  CC	
  info	
  
2.  Zuora	
  can	
  handle	
  much	
  (maybe	
  all?)	
  of	
  this,	
  depending	
  on	
  
architecture/features	
  you’re	
  using	
  
3.  If	
  (like	
  us)	
  you	
  take	
  CCs	
  in	
  your	
  app	
  (or	
  by	
  other	
  means),	
  then	
  
you’re	
  responsible	
  for	
  PCI	
  for	
  those	
  in-­‐scope	
  systems	
  
	
  
E V E R Y O N E 	
   H E R E 	
   L I K E L Y 	
   P C I 	
   L I A B L E 	
  
Its	
  Not	
  All	
  Doom	
  and	
  Gloom	
  
1.  Yes,	
  you	
  can	
  be	
  PCI	
  compliant	
  using	
  cloud!	
  
2.  You	
  will	
  likely	
  need	
  some	
  different	
  tools	
  and	
  
processes	
  
3.  Not	
  all	
  stacks/providers	
  are	
  created	
  equal!	
  
4.  There	
  is	
  no	
  “silver	
  bullet”	
  –	
  but	
  the	
  
responsibility	
  is	
  s;ll	
  yours	
  
P L E N T Y 	
   O F 	
   F . U . D . 	
   R E 	
   P C I 	
   A N D 	
   C L O U D 	
  
YES	
  IT	
  IS	
  POSSIBLE	
  
P C I 	
   I N 	
   T H E 	
   C L O U D 	
  
•  CloudPassage	
  is	
  Cer;fied	
  Level	
  1	
  Service	
  Provider	
  
–  First	
  en;rely	
  cloud-­‐based	
  vendor	
  cer;fied	
  across	
  mul;ple	
  CSPs	
  
–  Hosted	
  in	
  Rackspace	
  Cloud	
  &	
  AWS,	
  with	
  full	
  DevOps	
  automa;on	
  
•  Mul;ple	
  customers	
  have	
  successfully	
  cleared	
  QSA	
  audits	
  
PCI	
  Responsbility	
  
Cloud	
  Responsibility	
  Model	
  
Y O U ’ R E 	
   O N 	
   T H E 	
   H O O K , 	
   W H E R E V E R 	
   H O S T E D 	
  
Physical	
  Facili;es	
  
Hypervisor	
  
Compute	
  &	
  Storage	
  
Shared	
  Network	
  
Virtual	
  Machine	
  
Data	
  
App	
  Code	
  
App	
  Framework	
  
Opera;ng	
  System	
  
Physical	
  Facili;es	
  
Hypervisor	
  
Compute	
  &	
  Storage	
  
Shared	
  Network	
  
Virtual	
  Machine	
  
Data	
  
App	
  Code	
  
App	
  Framework	
  
Opera;ng	
  System	
  
Private	
  Cloud	
   Public	
  IaaS	
  Provider	
  
Customer	
  
Responsibility	
  
Provider	
  
Responsibility	
  
Recent	
  Guidance	
  Changes	
  
1.  Use	
  VM-­‐to-­‐VM	
  firewalling	
  (host-­‐based)	
  in	
  cloud/virtual	
  
environments	
  
2.  Ensure	
  integrity	
  of	
  VM	
  OS,	
  Apps,	
  and	
  Data	
  to	
  isolate	
  from	
  
hypervisor-­‐based	
  access	
  
3.  CSP	
  (Cloud	
  Service	
  Provider)	
  PCI	
  compliance	
  helps,	
  but	
  is	
  not	
  
mandatory	
  
4.  If	
  you’re	
  in	
  a	
  private	
  data	
  center,	
  all	
  your	
  stack	
  is	
  in-­‐scope	
  
	
  
P C I 	
   C L O U D 	
   S I G 	
   C L A R I F I E S 	
   R U L E S 	
  
PCI	
  Shared	
  Responsibility	
  
PCI	
  in	
  any	
  Cloud/Infrastructure	
  
•  Security	
  (if	
  done	
  correctly)	
  begets	
  compliance	
  
–  Not	
  the	
  other	
  way	
  around	
  
•  What	
  worked	
  in	
  your	
  datacenter	
  might	
  not	
  work	
  in	
  cloud	
  
environments	
  
•  Need	
  technical	
  controls	
  that	
  work	
  like	
  the	
  cloud	
  does	
  
–  Dynamic,	
  elas;c,	
  scalable	
  
Compliance	
  Design	
  
Cloud	
  PCI	
  Founda<ons	
  
Cloud	
  Stack/Provider	
  
	
  
Assessor	
  
	
  
Applica;on	
  design	
  
	
  
Harden	
  the	
  systems	
  
!
!
!
Assessor	
  
•  Find	
  one	
  …	
  that	
  knows	
  cloud	
  technology	
  
–  A	
  good	
  default	
  choice	
  is	
  the	
  QSA	
  who	
  did	
  the	
  assessment	
  for	
  your	
  CSP	
  
•  If	
  you	
  don’t	
  want/need	
  to	
  use	
  an	
  external	
  auditor,	
  then	
  …
determine	
  if	
  you	
  have	
  the	
  knowledge	
  internally	
  
–  You	
  need	
  to	
  make	
  sure	
  you	
  have	
  the	
  depth	
  of	
  knowledge	
  on	
  the	
  PCI	
  DSS,	
  as	
  
you	
  will	
  likely	
  get	
  it	
  wrong	
  if	
  not	
  
Applica<on	
  Design	
  
!
!
!
MASTER DB SLAVE DB!
•  Ability	
  to	
  achieve	
  PCI	
  compliance	
  is	
  primarily	
  based	
  on	
  
forethought	
  given	
  to	
  applica;on	
  design	
  
•  Most	
  providers,	
  and	
  all	
  cloud-­‐based	
  OS’s	
  can	
  be	
  PCI	
  
compliant*	
  
•  Ask:	
  
–  What	
  data	
  am	
  I	
  storing?	
  Why?	
  
–  What	
  is	
  communica;on	
  flow	
  of	
  the	
  applica;on?	
  Is	
  it	
  restricted?	
  
–  Is	
  my	
  crypto	
  public	
  veled	
  standards?	
  
This	
  is	
  where	
  Zuora	
  can	
  help	
  limit	
  your	
  systems	
  “in-­‐scope”	
  
Harden	
  the	
  Systems	
  
•  Protect	
  the	
  system	
  
–  Firewalls	
  (remember	
  ingress	
  and	
  egress)	
  
–  Change	
  defaults	
  
–  Install	
  patches	
  
–  Watch	
  the	
  system	
  for	
  odd	
  behavior	
  or	
  changes	
  
•  You	
  need	
  to	
  automate	
  this.	
  Trying	
  to	
  do	
  this	
  by	
  hand	
  in	
  a	
  cloud	
  
environment	
  is	
  error-­‐prone.	
  
Summary	
  
How	
  Zuora	
  Can	
  Help	
  
L I M I T I N G 	
   P C I 	
   S C O P E 	
  
•  Zuora	
  is	
  a	
  PCI	
  Level	
  1	
  cer;fied	
  vendor	
  
•  Your	
  applica;on	
  architecture	
  determines	
  how	
  much	
  PCI	
  you’ll	
  
be	
  exposed	
  to	
  
•  Inves;gate	
  Zuora	
  HPM	
  (iFrames,	
  etc),	
  APIs,	
  and	
  other	
  
mechanisms	
  to	
  accept/handle	
  CC	
  info	
  
•  Scrub	
  everywhere	
  else	
  in	
  your	
  business	
  process	
  for	
  ways	
  CCs	
  
are	
  managed	
  (ie	
  faxes,	
  POs,	
  sales	
  emails)	
  
Best	
  Prac<ces	
  
•  Read	
  and	
  understand	
  what	
  your	
  provider	
  does,	
  and	
  what	
  you	
  are	
  responsible	
  
for,	
  with	
  regards	
  to	
  PCI	
  
•  When	
  moving	
  servers	
  outside	
  your	
  data	
  center,	
  ensure	
  that	
  they	
  are	
  hardened	
  
and	
  compliant	
  before	
  they	
  are	
  exposed	
  to	
  the	
  public	
  
•  Start	
  with	
  public	
  cloud,	
  PCI	
  everywhere	
  else	
  is	
  rela;vely	
  easy!	
  
•  Focus	
  on	
  securing	
  the	
  tenets	
  of	
  PCI	
  that	
  you	
  can	
  control	
  –	
  partners	
  (CSPs,	
  
vendors)	
  are	
  key	
  to	
  success	
  
!
Cloud	
  Security	
  Resources	
  
cloudpassage.com/pci-­‐kit	
  
cloudpassage.com	
  
Q&A	
  
Thank	
  You!	
  
rand@cloudpassage.com	
  
	
  
cloudpassage.com/pci-­‐kit	
  
Winston Morton
Vice President, Technology
Enabling Usage Based Metering
Cloud Services
Agenda	
  
1.  LinkBermuda	
  Company	
  Introduc<on	
  
2.  Business	
  Model	
  and	
  Metered	
  Cloud	
  Services	
  
3.  Cloud	
  Services	
  Billing	
  and	
  Challenges	
  
4.  Drivers	
  to	
  use	
  a	
  cloud	
  based	
  Recurring	
  	
  
5.  How	
  Zuora	
  Helped	
  ?	
  
6.  Lessons	
  Learned	
  
7.  Wrap	
  Up	
  &	
  QA	
  
LinkBermuda	
  -­‐	
  Introduc<on	
  
LinkBermuda	
  Service	
  Por^olio	
  
LinkBermuda	
  Network	
  Facili<es	
  
§  On-­‐net	
  connec;vity	
  in	
  mul;ple	
  
undersea	
  and	
  terrestrial	
  cable	
  
systems	
  	
  
§  Direct	
  ownership	
  of	
  undersea	
  cable	
  
landing	
  sta;ons	
  
§  Extensive	
  Bermuda	
  domes;c	
  fiber	
  
network	
  
§  Mul;ple	
  interconnects	
  with	
  network	
  
providers	
  for	
  global	
  reach	
  
§  7x24	
  redundant	
  network	
  opera;ons	
  
centers	
  
LinkBermuda	
  Data	
  Center	
  Facili<es	
  
§  Bermuda’s	
  largest	
  data	
  center	
  
complex	
  
§  Hos;ng	
  many	
  of	
  the	
  largest	
  compute	
  
nodes	
  in	
  Bermuda	
  
§  Designated	
  as	
  a	
  Cri%cal	
  
Infrastructure	
  by	
  the	
  Bermudian	
  
Government	
  (Keypoint-­‐1)	
  for	
  priority	
  
security	
  and	
  fuel	
  delivery.	
  
§  7x24	
  Network	
  Opera;ons	
  Center	
  
§  SSAE	
  16	
  SOC	
  2	
  Cer;fica;on	
  (in	
  
Process)	
  
§  Strategic	
  na;onal	
  and	
  interna;onal	
  
network	
  connec;vity	
  
Key	
  Specifica;ons:	
  
§ Site	
  is	
  deployed	
  on	
  one	
  of	
  the	
  highest	
  eleva;ons	
  in	
  
Bermuda	
  to	
  military	
  specifica;ons	
  
§ 	
  Designed	
  to	
  withstand	
  hurricane	
  force	
  winds	
  	
  	
  
§ 	
  Fully	
  Redundant	
  4160V	
  U;lity	
  Feeds	
  
§ 	
  N+1	
  Redundant	
  Diesel	
  Generators	
  (3x1000kW)	
  
§ 	
  N+1	
  UPS	
  (2x1000kW)	
  
§ 	
  N+1	
  Cooling	
  (2x300	
  Ton	
  Air	
  Cooled	
  Chillers)	
  
Understanding	
  Metered	
  Cloud	
  Services	
  
and	
  Design	
  
I N F R A S T R U C T U R E 	
   A S 	
   A 	
   S E R V I C E 	
  
§  Bundled	
  Virtual	
  Servers,	
  Storage,	
  
Security,	
  and	
  Network	
  Connec;vity	
  
§  Flexible	
  On-­‐Demand	
  Self	
  Service	
  
§  Geographically	
  Aware	
  
-­‐  Customers	
  can	
  select	
  as	
  well	
  as	
  
guarantee	
  primary	
  and	
  secondary	
  VDC	
  
loca;ons	
  (Bermuda	
  and/or	
  Canada	
  
today)	
  
IaaS	
  High	
  Level	
  Features	
  
§  Predictable	
  Performance	
  
-­‐  IaaS	
  bundled	
  with	
  Interna;onal	
  
MPLS	
  QOS	
  features.	
  	
  
-­‐  Broadband	
  local	
  loop	
  
-­‐  SLA	
  guarantees	
  
§  Highly	
  Secure	
  
-­‐  Embedded	
  VLAN	
  Security	
  
-­‐  Embedded	
  offsite	
  D/R	
  	
  
§  Ease	
  of	
  Management	
  
-­‐  Customer	
  Self	
  Service	
  Module	
  
Metered	
  Cloud	
  Services	
  
• 	
  Communica<on	
  as	
  a	
  Service	
  
• 	
  Value	
  Added	
  Apps	
  
• 	
  $$/Mth	
  Fixed	
  +	
  Usage	
  
• 	
  Backup	
  as	
  a	
  Service	
  
• 	
  Value	
  Added	
  Apps	
  
• 	
  $$/Mb/Mth	
  
• 	
  Infrastructure	
  as	
  a	
  Service	
  	
  
• 	
  Virtual	
  Servers	
  
• 	
  Value	
  Added	
  Apps	
  
• 	
  $$/Server/Hr	
  
Cloud	
  Services	
  Billing	
  
H i g h 	
   L e v e l 	
   D e s i g n 	
  
Cloud	
  
Management	
  
Pla^orm	
  (IaaS)	
  
Exported	
  
Cumula<ve	
  Usage	
  
Report	
  
Cloud	
  
Management	
  
Pla^orm	
  (BaaS)	
  
Cloud	
  
Management	
  
Pla^orm	
  (CaaS)	
  
Billing	
  Pla^orm	
  
IaaS	
  Product	
  
Catalogue	
  
Product	
  
Catalogue	
  
Exported	
  
Cumula<ve	
  Usage	
  
Report	
  
BaaS	
  Product	
  
Catalogue	
  
Product	
  
Catalogue	
  
Exported	
  
Cumula<ve	
  Usage	
  
Report	
  
CaaS	
  Product	
  
Catalogue	
  
Product	
  
Catalogue	
  
Cloud	
  Services	
  Billing	
  
F u n c ; o n a l 	
   A p p r o a c h 	
  
§ 	
  Ini;al	
  launched	
  with	
  a	
  IaaS	
  model	
  with	
  
interfaces	
  as	
  straight	
  forward	
  as	
  possible.	
  
§ 	
  Most	
  of	
  our	
  cloud	
  systems	
  have	
  their	
  own	
  
sophis;cated	
  self	
  service	
  provisioning	
  
interface.	
  
§ 	
  We	
  choose	
  to	
  leverage	
  the	
  provisioning	
  
systems	
  embedded	
  in	
  each	
  cloud	
  system	
  to	
  
minimized	
  development	
  
	
  
Upside:	
  	
  	
  
One	
  way	
  usage	
  based	
  interfaces	
  are	
  more	
  
cost	
  effect	
  and	
  quicker	
  to	
  launch	
  
Downside:	
  	
  	
  
Mul;ple	
  product	
  catalogues	
  need	
  to	
  be	
  
synchronized	
  
Cloud	
  
Management	
  
Pla^orm	
  
Product	
  
Catalogue	
  
Billing	
  
Pla^orm	
  
Product	
  
Catalogue	
  
Usage	
  
Report	
  
Customer	
  
Portal	
  
Business	
  Drivers	
  to	
  use	
  Recurring	
  Billing	
  Solu<on	
  
§ LinkBermuda	
  was	
  looking	
  to	
  out-­‐source	
  billing,	
  we	
  did	
  not	
  want	
  to	
  build	
  our	
  own	
  
system	
  because	
  of	
  the	
  complexity	
  involved	
  in	
  recurring	
  billing.	
  
	
  
§ 	
  We	
  evaluated	
  several	
  different	
  recurring	
  billing	
  systems	
  –	
  Zuora	
  was	
  the	
  quickest	
  
to	
  deploy	
  and	
  most	
  cost	
  effec;ve.	
  
§ We	
  needed	
  a	
  system	
  which	
  would	
  enable	
  to	
  Price	
  and	
  Package	
  our	
  services	
  
efficiently	
  and	
  be	
  able	
  to	
  rapidly	
  iterate	
  on	
  Pricing	
  when	
  needed.	
  
Why	
  Zuora	
  ?	
  
§ The	
  Ra;ng	
  and	
  Billing	
  Engine	
  in	
  Zuora	
  understands	
  our	
  subscrip;on	
  business	
  
model	
  and	
  is	
  ideally	
  suited	
  to	
  do	
  the	
  job.	
  
	
  
§ 	
  Zuora	
  provided	
  out	
  of	
  box	
  solu;on	
  (Zforce)	
  for	
  integra;ng	
  with	
  our	
  CRM	
  system	
  
(Salesforce).	
  We	
  took	
  advantage	
  of	
  both	
  ZQuotes	
  and	
  Z360.	
  
§ Looking	
  forward	
  to	
  u;lize	
  Zuora	
  Billing	
  and	
  Financial	
  Reports	
  and	
  Forward	
  
Looking	
  Metrics	
  like	
  MRR,	
  ARR	
  etc.	
  
	
  
§ 	
  As	
  LinkBermuda	
  grows	
  we	
  are	
  confident	
  that	
  Zuora	
  can	
  scale	
  and	
  accommodate	
  
our	
  business	
  growth.	
  
How	
  LinkBermuda	
  Uses	
  Zuora	
  
Background	
  
Business	
  Model	
  
The	
  Challenge	
  
Moving	
  from	
  tradi;onal	
  Telco	
  services	
  
to	
  cloud	
  services	
  for	
  interna;onal	
  financial,	
  
insurance	
  and	
  eCommerce	
  markets	
  
	
  
B2B	
  +	
  B2C	
  =	
  B2Any	
  
Direct:	
  Self-­‐service	
  and	
  sales	
  assisted	
  
Channels:	
  Cloud	
  Marketplace,	
  Resellers	
  
We	
  needed	
  to	
  develop	
  a	
  self	
  service	
  cloud	
  capability	
  with	
  usage	
  based	
  
billing.	
  Legacy	
  billing	
  system	
  limited	
  customiza;on	
  and	
  product	
  
catalogue	
  capabili;es.	
  
Lessons	
  Learned	
  
Plan.	
  Plan.	
  Plan	
  
B E S T 	
   P R A C T I C E S 	
  
Limit	
  Ini<al	
  Scope	
  
Learn.	
  Launch.	
  Repeat	
  
Business	
  strategy	
  changes	
  during	
  market	
  launch	
  	
  
Best	
  Prac;ce:	
   	
  -­‐	
  Clear	
  defini;on	
  of	
  business	
  goals.	
  	
  
	
   	
  -­‐	
  Phase	
  1	
  launch	
  should	
  be	
  limited	
  to	
  base	
   	
  
	
  	
  	
  	
  services,	
  add	
  func;onality	
  as	
  use	
  cases	
   	
   	
  	
  	
  	
  
become	
  more	
  evident	
  
	
  Avoid	
  big	
  bang	
  cutovers	
  	
  
Best	
  Prac;ce:	
  	
  	
  	
  -­‐	
  Flexible	
  architecture	
  
	
   	
  	
  -­‐	
  Repeatable	
  Interfaces	
  (If	
  possible)	
  
	
  
Deploy,	
  measure,	
  iterate	
  	
  
Best	
  Prac;ce:	
  	
  	
  	
  	
  -­‐	
  Be	
  data	
  driven	
  
	
  
Q&A	
  
Thank	
  You!	
  

Contenu connexe

Tendances

Aruba Rightsizing Your Network
Aruba Rightsizing Your NetworkAruba Rightsizing Your Network
Aruba Rightsizing Your Networkhypknight
 
Wp ipam infoblox
Wp ipam infobloxWp ipam infoblox
Wp ipam infobloxislamet
 
The Inside Story: How OPC UA and DDS Can Work Together in Industrial Systems
The Inside Story: How OPC UA and DDS Can Work Together in Industrial SystemsThe Inside Story: How OPC UA and DDS Can Work Together in Industrial Systems
The Inside Story: How OPC UA and DDS Can Work Together in Industrial SystemsReal-Time Innovations (RTI)
 
System integration in offshore supply vessels – how we applied DDS and redefi...
System integration in offshore supply vessels – how we applied DDS and redefi...System integration in offshore supply vessels – how we applied DDS and redefi...
System integration in offshore supply vessels – how we applied DDS and redefi...Real-Time Innovations (RTI)
 
Speed Hybrid WAN Deployment with the New Cisco Intelligent WAN Design Guide -...
Speed Hybrid WAN Deployment with the New Cisco Intelligent WAN Design Guide -...Speed Hybrid WAN Deployment with the New Cisco Intelligent WAN Design Guide -...
Speed Hybrid WAN Deployment with the New Cisco Intelligent WAN Design Guide -...Cisco Enterprise Networks
 
Palo Alto Networks: Protection for Security & Compliance
Palo Alto Networks: Protection for Security & CompliancePalo Alto Networks: Protection for Security & Compliance
Palo Alto Networks: Protection for Security & ComplianceAmazon Web Services
 
BIG-IP Data Center Firewall Solution
BIG-IP Data Center Firewall SolutionBIG-IP Data Center Firewall Solution
BIG-IP Data Center Firewall SolutionF5 Networks
 
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)Cisco Canada
 
Yes, you can be pci compliant using a public iaas cloud a case study by phi...
Yes, you can be pci compliant using a public iaas cloud   a case study by phi...Yes, you can be pci compliant using a public iaas cloud   a case study by phi...
Yes, you can be pci compliant using a public iaas cloud a case study by phi...Khazret Sapenov
 
Sdwan webinar
Sdwan webinarSdwan webinar
Sdwan webinarpmohapat
 
Introduction to Software Defined WANs
Introduction to Software Defined WANsIntroduction to Software Defined WANs
Introduction to Software Defined WANsAPNIC
 
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...ThousandEyes
 
Capstone Presentation For Five Rivers Medical Centers
Capstone Presentation For Five Rivers Medical CentersCapstone Presentation For Five Rivers Medical Centers
Capstone Presentation For Five Rivers Medical Centersdjackson134
 

Tendances (20)

Best Practices Using RTI Connext DDS
Best Practices Using RTI Connext DDSBest Practices Using RTI Connext DDS
Best Practices Using RTI Connext DDS
 
Aruba Rightsizing Your Network
Aruba Rightsizing Your NetworkAruba Rightsizing Your Network
Aruba Rightsizing Your Network
 
Wp ipam infoblox
Wp ipam infobloxWp ipam infoblox
Wp ipam infoblox
 
Juniper Services and Support
Juniper Services and SupportJuniper Services and Support
Juniper Services and Support
 
The Inside Story: How OPC UA and DDS Can Work Together in Industrial Systems
The Inside Story: How OPC UA and DDS Can Work Together in Industrial SystemsThe Inside Story: How OPC UA and DDS Can Work Together in Industrial Systems
The Inside Story: How OPC UA and DDS Can Work Together in Industrial Systems
 
System integration in offshore supply vessels – how we applied DDS and redefi...
System integration in offshore supply vessels – how we applied DDS and redefi...System integration in offshore supply vessels – how we applied DDS and redefi...
System integration in offshore supply vessels – how we applied DDS and redefi...
 
Speed Hybrid WAN Deployment with the New Cisco Intelligent WAN Design Guide -...
Speed Hybrid WAN Deployment with the New Cisco Intelligent WAN Design Guide -...Speed Hybrid WAN Deployment with the New Cisco Intelligent WAN Design Guide -...
Speed Hybrid WAN Deployment with the New Cisco Intelligent WAN Design Guide -...
 
Jvvnl 071108
Jvvnl 071108Jvvnl 071108
Jvvnl 071108
 
Palo Alto Networks: Protection for Security & Compliance
Palo Alto Networks: Protection for Security & CompliancePalo Alto Networks: Protection for Security & Compliance
Palo Alto Networks: Protection for Security & Compliance
 
F5 beyond load balancer (nov 2009)
F5 beyond load balancer (nov 2009)F5 beyond load balancer (nov 2009)
F5 beyond load balancer (nov 2009)
 
SD WAN
SD WANSD WAN
SD WAN
 
BIG-IP Data Center Firewall Solution
BIG-IP Data Center Firewall SolutionBIG-IP Data Center Firewall Solution
BIG-IP Data Center Firewall Solution
 
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
 
Yes, you can be pci compliant using a public iaas cloud a case study by phi...
Yes, you can be pci compliant using a public iaas cloud   a case study by phi...Yes, you can be pci compliant using a public iaas cloud   a case study by phi...
Yes, you can be pci compliant using a public iaas cloud a case study by phi...
 
Sdwan webinar
Sdwan webinarSdwan webinar
Sdwan webinar
 
Introduction to Software Defined WANs
Introduction to Software Defined WANsIntroduction to Software Defined WANs
Introduction to Software Defined WANs
 
Citrix NetScaler SD-WAN - What’s New, What’s Hot?
Citrix NetScaler SD-WAN - What’s New, What’s Hot?Citrix NetScaler SD-WAN - What’s New, What’s Hot?
Citrix NetScaler SD-WAN - What’s New, What’s Hot?
 
A series presentation
A series presentationA series presentation
A series presentation
 
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
 
Capstone Presentation For Five Rivers Medical Centers
Capstone Presentation For Five Rivers Medical CentersCapstone Presentation For Five Rivers Medical Centers
Capstone Presentation For Five Rivers Medical Centers
 

Similaire à Usage Based Metering in the Cloud (Subscribed13)

45 Minutes to PCI Compliance in the Cloud
45 Minutes to PCI Compliance in the Cloud45 Minutes to PCI Compliance in the Cloud
45 Minutes to PCI Compliance in the CloudCloudPassage
 
Customer Case Study: Achieving PCI Compliance in AWS
Customer Case Study: Achieving PCI Compliance in AWSCustomer Case Study: Achieving PCI Compliance in AWS
Customer Case Study: Achieving PCI Compliance in AWSAmazon Web Services
 
MX Deep Dive PPT
MX Deep Dive PPTMX Deep Dive PPT
MX Deep Dive PPTomar awad
 
Compliance in the Cloud
Compliance in the CloudCompliance in the Cloud
Compliance in the CloudRapidScale
 
AWS Cloud Security From the Point of View of the Compliance
AWS Cloud Security From the Point of View of the ComplianceAWS Cloud Security From the Point of View of the Compliance
AWS Cloud Security From the Point of View of the ComplianceYury Chemerkin
 
Building Cloud capability for startups
Building Cloud capability for startupsBuilding Cloud capability for startups
Building Cloud capability for startupsSekhar Mohanty
 
Cloud computing ppt
Cloud computing pptCloud computing ppt
Cloud computing pptA
 
Lect15 cloud
Lect15 cloudLect15 cloud
Lect15 cloudVan Pham
 
Lect15 cloud
Lect15 cloudLect15 cloud
Lect15 cloudsree raj
 
Introduction to cloud computing
Introduction to cloud computingIntroduction to cloud computing
Introduction to cloud computingRevathi Ram
 
Cloud computing ppt
Cloud computing pptCloud computing ppt
Cloud computing pptA
 
Webinar: Overcoming the Top Challenges of Recovery to the Cloud
Webinar: Overcoming the Top Challenges of Recovery to the CloudWebinar: Overcoming the Top Challenges of Recovery to the Cloud
Webinar: Overcoming the Top Challenges of Recovery to the Cloudiland Cloud
 

Similaire à Usage Based Metering in the Cloud (Subscribed13) (20)

45 Minutes to PCI Compliance in the Cloud
45 Minutes to PCI Compliance in the Cloud45 Minutes to PCI Compliance in the Cloud
45 Minutes to PCI Compliance in the Cloud
 
Customer Case Study: Achieving PCI Compliance in AWS
Customer Case Study: Achieving PCI Compliance in AWSCustomer Case Study: Achieving PCI Compliance in AWS
Customer Case Study: Achieving PCI Compliance in AWS
 
MX Deep Dive PPT
MX Deep Dive PPTMX Deep Dive PPT
MX Deep Dive PPT
 
Compliance in the Cloud
Compliance in the CloudCompliance in the Cloud
Compliance in the Cloud
 
AWS Cloud Security From the Point of View of the Compliance
AWS Cloud Security From the Point of View of the ComplianceAWS Cloud Security From the Point of View of the Compliance
AWS Cloud Security From the Point of View of the Compliance
 
CLOUD
CLOUDCLOUD
CLOUD
 
Building Cloud capability for startups
Building Cloud capability for startupsBuilding Cloud capability for startups
Building Cloud capability for startups
 
Lect15 cloud
Lect15 cloudLect15 cloud
Lect15 cloud
 
Cloud
CloudCloud
Cloud
 
Cloud computing ppt
Cloud computing pptCloud computing ppt
Cloud computing ppt
 
Cloud Computing
Cloud ComputingCloud Computing
Cloud Computing
 
Cloud
CloudCloud
Cloud
 
Lect15 cloud
Lect15 cloudLect15 cloud
Lect15 cloud
 
Lect15 cloud
Lect15 cloudLect15 cloud
Lect15 cloud
 
Lect15 cloud
Lect15 cloudLect15 cloud
Lect15 cloud
 
Introduction to cloud computing
Introduction to cloud computingIntroduction to cloud computing
Introduction to cloud computing
 
Cloud computing ppt
Cloud computing pptCloud computing ppt
Cloud computing ppt
 
Lect15 cloud
Lect15 cloudLect15 cloud
Lect15 cloud
 
Cloud Computing Strategy and Architecture
Cloud Computing Strategy and ArchitectureCloud Computing Strategy and Architecture
Cloud Computing Strategy and Architecture
 
Webinar: Overcoming the Top Challenges of Recovery to the Cloud
Webinar: Overcoming the Top Challenges of Recovery to the CloudWebinar: Overcoming the Top Challenges of Recovery to the Cloud
Webinar: Overcoming the Top Challenges of Recovery to the Cloud
 

Plus de Zuora, Inc.

SSP Your New Strategic Growth Weapon
SSP  Your New Strategic Growth Weapon SSP  Your New Strategic Growth Weapon
SSP Your New Strategic Growth Weapon Zuora, Inc.
 
Subscribed 2019 - CPQ X: The Future of CPQ
Subscribed 2019 - CPQ X: The Future of CPQSubscribed 2019 - CPQ X: The Future of CPQ
Subscribed 2019 - CPQ X: The Future of CPQZuora, Inc.
 
Subscribed 2019 - Going Global: Demystifying International Payments
Subscribed 2019 - Going Global: Demystifying International PaymentsSubscribed 2019 - Going Global: Demystifying International Payments
Subscribed 2019 - Going Global: Demystifying International PaymentsZuora, Inc.
 
Subscribed 2019 - Fraud Management Strategies: Reducing Collection Friction t...
Subscribed 2019 - Fraud Management Strategies: Reducing Collection Friction t...Subscribed 2019 - Fraud Management Strategies: Reducing Collection Friction t...
Subscribed 2019 - Fraud Management Strategies: Reducing Collection Friction t...Zuora, Inc.
 
Subscribed 2019 - Optimizing Recurring Collections at Scale
Subscribed 2019 - Optimizing Recurring Collections at ScaleSubscribed 2019 - Optimizing Recurring Collections at Scale
Subscribed 2019 - Optimizing Recurring Collections at ScaleZuora, Inc.
 
Subscribed 2019 - Regulations and What Lies Ahead with Zuora Payments and Col...
Subscribed 2019 - Regulations and What Lies Ahead with Zuora Payments and Col...Subscribed 2019 - Regulations and What Lies Ahead with Zuora Payments and Col...
Subscribed 2019 - Regulations and What Lies Ahead with Zuora Payments and Col...Zuora, Inc.
 
Subscribed 2019 - Collection Strategies: Recovering Critical Revenue to Drive...
Subscribed 2019 - Collection Strategies: Recovering Critical Revenue to Drive...Subscribed 2019 - Collection Strategies: Recovering Critical Revenue to Drive...
Subscribed 2019 - Collection Strategies: Recovering Critical Revenue to Drive...Zuora, Inc.
 
Subscribed 2019 - Why Digital Transformation Should Drive Business Model Tran...
Subscribed 2019 - Why Digital Transformation Should Drive Business Model Tran...Subscribed 2019 - Why Digital Transformation Should Drive Business Model Tran...
Subscribed 2019 - Why Digital Transformation Should Drive Business Model Tran...Zuora, Inc.
 
Subscribed 2019 - Business Transformation: Architecting the Launch for Success
Subscribed 2019 - Business Transformation: Architecting the Launch for SuccessSubscribed 2019 - Business Transformation: Architecting the Launch for Success
Subscribed 2019 - Business Transformation: Architecting the Launch for SuccessZuora, Inc.
 
Subscribed 2019 - Deliver Growth Without Breaking Your Back Office
Subscribed 2019 - Deliver Growth Without Breaking Your Back OfficeSubscribed 2019 - Deliver Growth Without Breaking Your Back Office
Subscribed 2019 - Deliver Growth Without Breaking Your Back OfficeZuora, Inc.
 
Subscribed 2019 - Customer First Approach to Pricing
Subscribed 2019  - Customer First Approach to Pricing Subscribed 2019  - Customer First Approach to Pricing
Subscribed 2019 - Customer First Approach to Pricing Zuora, Inc.
 
Subscribed 2019 - Empower Sales Operations
Subscribed 2019 -  Empower Sales Operations Subscribed 2019 -  Empower Sales Operations
Subscribed 2019 - Empower Sales Operations Zuora, Inc.
 
Subscribed 2019 - Best Practices for Realizing Optimal Value from Zuora
Subscribed 2019 -  Best Practices for Realizing Optimal Value from ZuoraSubscribed 2019 -  Best Practices for Realizing Optimal Value from Zuora
Subscribed 2019 - Best Practices for Realizing Optimal Value from ZuoraZuora, Inc.
 
Subscribed 2019 - Omni-Channel Customer Acquisition and Retention
Subscribed 2019 - Omni-Channel Customer Acquisition and RetentionSubscribed 2019 - Omni-Channel Customer Acquisition and Retention
Subscribed 2019 - Omni-Channel Customer Acquisition and RetentionZuora, Inc.
 
Subscribed 2019 - Quote Smarter, Faster and Get Products to Market Quicker wi...
Subscribed 2019 - Quote Smarter, Faster and Get Products to Market Quicker wi...Subscribed 2019 - Quote Smarter, Faster and Get Products to Market Quicker wi...
Subscribed 2019 - Quote Smarter, Faster and Get Products to Market Quicker wi...Zuora, Inc.
 
Subscribed 2019 - Empower Sales Operations with Zuora CPQ
Subscribed 2019 - Empower Sales Operations with Zuora CPQSubscribed 2019 - Empower Sales Operations with Zuora CPQ
Subscribed 2019 - Empower Sales Operations with Zuora CPQZuora, Inc.
 
Subscribed 2019 - Implementing a Consumption-Based Pricing Strategy
Subscribed 2019 - Implementing a Consumption-Based Pricing StrategySubscribed 2019 - Implementing a Consumption-Based Pricing Strategy
Subscribed 2019 - Implementing a Consumption-Based Pricing StrategyZuora, Inc.
 
Subscribed 2019 - Proration: Why Getting it Right Matters
Subscribed 2019 - 	Proration: Why Getting it Right MattersSubscribed 2019 - 	Proration: Why Getting it Right Matters
Subscribed 2019 - Proration: Why Getting it Right MattersZuora, Inc.
 
Subscribed 2019 - Beyond reporting analytics for growth
Subscribed 2019 - Beyond reporting analytics for growthSubscribed 2019 - Beyond reporting analytics for growth
Subscribed 2019 - Beyond reporting analytics for growthZuora, Inc.
 
Subscribed 2019 - The Future of Orders
Subscribed 2019 - The Future of Orders Subscribed 2019 - The Future of Orders
Subscribed 2019 - The Future of Orders Zuora, Inc.
 

Plus de Zuora, Inc. (20)

SSP Your New Strategic Growth Weapon
SSP  Your New Strategic Growth Weapon SSP  Your New Strategic Growth Weapon
SSP Your New Strategic Growth Weapon
 
Subscribed 2019 - CPQ X: The Future of CPQ
Subscribed 2019 - CPQ X: The Future of CPQSubscribed 2019 - CPQ X: The Future of CPQ
Subscribed 2019 - CPQ X: The Future of CPQ
 
Subscribed 2019 - Going Global: Demystifying International Payments
Subscribed 2019 - Going Global: Demystifying International PaymentsSubscribed 2019 - Going Global: Demystifying International Payments
Subscribed 2019 - Going Global: Demystifying International Payments
 
Subscribed 2019 - Fraud Management Strategies: Reducing Collection Friction t...
Subscribed 2019 - Fraud Management Strategies: Reducing Collection Friction t...Subscribed 2019 - Fraud Management Strategies: Reducing Collection Friction t...
Subscribed 2019 - Fraud Management Strategies: Reducing Collection Friction t...
 
Subscribed 2019 - Optimizing Recurring Collections at Scale
Subscribed 2019 - Optimizing Recurring Collections at ScaleSubscribed 2019 - Optimizing Recurring Collections at Scale
Subscribed 2019 - Optimizing Recurring Collections at Scale
 
Subscribed 2019 - Regulations and What Lies Ahead with Zuora Payments and Col...
Subscribed 2019 - Regulations and What Lies Ahead with Zuora Payments and Col...Subscribed 2019 - Regulations and What Lies Ahead with Zuora Payments and Col...
Subscribed 2019 - Regulations and What Lies Ahead with Zuora Payments and Col...
 
Subscribed 2019 - Collection Strategies: Recovering Critical Revenue to Drive...
Subscribed 2019 - Collection Strategies: Recovering Critical Revenue to Drive...Subscribed 2019 - Collection Strategies: Recovering Critical Revenue to Drive...
Subscribed 2019 - Collection Strategies: Recovering Critical Revenue to Drive...
 
Subscribed 2019 - Why Digital Transformation Should Drive Business Model Tran...
Subscribed 2019 - Why Digital Transformation Should Drive Business Model Tran...Subscribed 2019 - Why Digital Transformation Should Drive Business Model Tran...
Subscribed 2019 - Why Digital Transformation Should Drive Business Model Tran...
 
Subscribed 2019 - Business Transformation: Architecting the Launch for Success
Subscribed 2019 - Business Transformation: Architecting the Launch for SuccessSubscribed 2019 - Business Transformation: Architecting the Launch for Success
Subscribed 2019 - Business Transformation: Architecting the Launch for Success
 
Subscribed 2019 - Deliver Growth Without Breaking Your Back Office
Subscribed 2019 - Deliver Growth Without Breaking Your Back OfficeSubscribed 2019 - Deliver Growth Without Breaking Your Back Office
Subscribed 2019 - Deliver Growth Without Breaking Your Back Office
 
Subscribed 2019 - Customer First Approach to Pricing
Subscribed 2019  - Customer First Approach to Pricing Subscribed 2019  - Customer First Approach to Pricing
Subscribed 2019 - Customer First Approach to Pricing
 
Subscribed 2019 - Empower Sales Operations
Subscribed 2019 -  Empower Sales Operations Subscribed 2019 -  Empower Sales Operations
Subscribed 2019 - Empower Sales Operations
 
Subscribed 2019 - Best Practices for Realizing Optimal Value from Zuora
Subscribed 2019 -  Best Practices for Realizing Optimal Value from ZuoraSubscribed 2019 -  Best Practices for Realizing Optimal Value from Zuora
Subscribed 2019 - Best Practices for Realizing Optimal Value from Zuora
 
Subscribed 2019 - Omni-Channel Customer Acquisition and Retention
Subscribed 2019 - Omni-Channel Customer Acquisition and RetentionSubscribed 2019 - Omni-Channel Customer Acquisition and Retention
Subscribed 2019 - Omni-Channel Customer Acquisition and Retention
 
Subscribed 2019 - Quote Smarter, Faster and Get Products to Market Quicker wi...
Subscribed 2019 - Quote Smarter, Faster and Get Products to Market Quicker wi...Subscribed 2019 - Quote Smarter, Faster and Get Products to Market Quicker wi...
Subscribed 2019 - Quote Smarter, Faster and Get Products to Market Quicker wi...
 
Subscribed 2019 - Empower Sales Operations with Zuora CPQ
Subscribed 2019 - Empower Sales Operations with Zuora CPQSubscribed 2019 - Empower Sales Operations with Zuora CPQ
Subscribed 2019 - Empower Sales Operations with Zuora CPQ
 
Subscribed 2019 - Implementing a Consumption-Based Pricing Strategy
Subscribed 2019 - Implementing a Consumption-Based Pricing StrategySubscribed 2019 - Implementing a Consumption-Based Pricing Strategy
Subscribed 2019 - Implementing a Consumption-Based Pricing Strategy
 
Subscribed 2019 - Proration: Why Getting it Right Matters
Subscribed 2019 - 	Proration: Why Getting it Right MattersSubscribed 2019 - 	Proration: Why Getting it Right Matters
Subscribed 2019 - Proration: Why Getting it Right Matters
 
Subscribed 2019 - Beyond reporting analytics for growth
Subscribed 2019 - Beyond reporting analytics for growthSubscribed 2019 - Beyond reporting analytics for growth
Subscribed 2019 - Beyond reporting analytics for growth
 
Subscribed 2019 - The Future of Orders
Subscribed 2019 - The Future of Orders Subscribed 2019 - The Future of Orders
Subscribed 2019 - The Future of Orders
 

Dernier

Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 

Dernier (20)

Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 

Usage Based Metering in the Cloud (Subscribed13)

  • 1. PCI for Cloud Applications Securing the Subscription Economy Rand Wacker VP of Products @randwacker | #subscribed13
  • 2. CloudPassage  Overview   CloudPassage  provides   security  and  compliance     for  your  cloud,     so9ware-­‐defined,  and   tradi<onal  data  center   infrastructure  
  • 3. Our  PCI  Story   1.  We  use  Zuora  for  metered  usage  billing   2.  Since  we  accept  CCs  in  mul;ple  ways,  had  to  do  a  full  PCI  cert   for  ourselves   3.  We  also  provide  PCI  security  controls  to  our  customers   4.  Here’s  what  we  learned…     I T S   N E V E R   J U S T   T H A T   S I M P L E  
  • 4. Your  Architecture  Drives  PCI  Scope   1.  PCI  “in-­‐scope”  systems  are  anything  that  accept,  store,  process,   or  transmit  CC  info   2.  Zuora  can  handle  much  (maybe  all?)  of  this,  depending  on   architecture/features  you’re  using   3.  If  (like  us)  you  take  CCs  in  your  app  (or  by  other  means),  then   you’re  responsible  for  PCI  for  those  in-­‐scope  systems     E V E R Y O N E   H E R E   L I K E L Y   P C I   L I A B L E  
  • 5. Its  Not  All  Doom  and  Gloom   1.  Yes,  you  can  be  PCI  compliant  using  cloud!   2.  You  will  likely  need  some  different  tools  and   processes   3.  Not  all  stacks/providers  are  created  equal!   4.  There  is  no  “silver  bullet”  –  but  the   responsibility  is  s;ll  yours   P L E N T Y   O F   F . U . D .   R E   P C I   A N D   C L O U D  
  • 6. YES  IT  IS  POSSIBLE   P C I   I N   T H E   C L O U D   •  CloudPassage  is  Cer;fied  Level  1  Service  Provider   –  First  en;rely  cloud-­‐based  vendor  cer;fied  across  mul;ple  CSPs   –  Hosted  in  Rackspace  Cloud  &  AWS,  with  full  DevOps  automa;on   •  Mul;ple  customers  have  successfully  cleared  QSA  audits  
  • 8. Cloud  Responsibility  Model   Y O U ’ R E   O N   T H E   H O O K ,   W H E R E V E R   H O S T E D   Physical  Facili;es   Hypervisor   Compute  &  Storage   Shared  Network   Virtual  Machine   Data   App  Code   App  Framework   Opera;ng  System   Physical  Facili;es   Hypervisor   Compute  &  Storage   Shared  Network   Virtual  Machine   Data   App  Code   App  Framework   Opera;ng  System   Private  Cloud   Public  IaaS  Provider   Customer   Responsibility   Provider   Responsibility  
  • 9. Recent  Guidance  Changes   1.  Use  VM-­‐to-­‐VM  firewalling  (host-­‐based)  in  cloud/virtual   environments   2.  Ensure  integrity  of  VM  OS,  Apps,  and  Data  to  isolate  from   hypervisor-­‐based  access   3.  CSP  (Cloud  Service  Provider)  PCI  compliance  helps,  but  is  not   mandatory   4.  If  you’re  in  a  private  data  center,  all  your  stack  is  in-­‐scope     P C I   C L O U D   S I G   C L A R I F I E S   R U L E S  
  • 11. PCI  in  any  Cloud/Infrastructure   •  Security  (if  done  correctly)  begets  compliance   –  Not  the  other  way  around   •  What  worked  in  your  datacenter  might  not  work  in  cloud   environments   •  Need  technical  controls  that  work  like  the  cloud  does   –  Dynamic,  elas;c,  scalable  
  • 13. Cloud  PCI  Founda<ons   Cloud  Stack/Provider     Assessor     Applica;on  design     Harden  the  systems   ! ! !
  • 14. Assessor   •  Find  one  …  that  knows  cloud  technology   –  A  good  default  choice  is  the  QSA  who  did  the  assessment  for  your  CSP   •  If  you  don’t  want/need  to  use  an  external  auditor,  then  … determine  if  you  have  the  knowledge  internally   –  You  need  to  make  sure  you  have  the  depth  of  knowledge  on  the  PCI  DSS,  as   you  will  likely  get  it  wrong  if  not  
  • 15. Applica<on  Design   ! ! ! MASTER DB SLAVE DB! •  Ability  to  achieve  PCI  compliance  is  primarily  based  on   forethought  given  to  applica;on  design   •  Most  providers,  and  all  cloud-­‐based  OS’s  can  be  PCI   compliant*   •  Ask:   –  What  data  am  I  storing?  Why?   –  What  is  communica;on  flow  of  the  applica;on?  Is  it  restricted?   –  Is  my  crypto  public  veled  standards?   This  is  where  Zuora  can  help  limit  your  systems  “in-­‐scope”  
  • 16. Harden  the  Systems   •  Protect  the  system   –  Firewalls  (remember  ingress  and  egress)   –  Change  defaults   –  Install  patches   –  Watch  the  system  for  odd  behavior  or  changes   •  You  need  to  automate  this.  Trying  to  do  this  by  hand  in  a  cloud   environment  is  error-­‐prone.  
  • 18. How  Zuora  Can  Help   L I M I T I N G   P C I   S C O P E   •  Zuora  is  a  PCI  Level  1  cer;fied  vendor   •  Your  applica;on  architecture  determines  how  much  PCI  you’ll   be  exposed  to   •  Inves;gate  Zuora  HPM  (iFrames,  etc),  APIs,  and  other   mechanisms  to  accept/handle  CC  info   •  Scrub  everywhere  else  in  your  business  process  for  ways  CCs   are  managed  (ie  faxes,  POs,  sales  emails)  
  • 19. Best  Prac<ces   •  Read  and  understand  what  your  provider  does,  and  what  you  are  responsible   for,  with  regards  to  PCI   •  When  moving  servers  outside  your  data  center,  ensure  that  they  are  hardened   and  compliant  before  they  are  exposed  to  the  public   •  Start  with  public  cloud,  PCI  everywhere  else  is  rela;vely  easy!   •  Focus  on  securing  the  tenets  of  PCI  that  you  can  control  –  partners  (CSPs,   vendors)  are  key  to  success   !
  • 20. Cloud  Security  Resources   cloudpassage.com/pci-­‐kit   cloudpassage.com  
  • 21. Q&A   Thank  You!   rand@cloudpassage.com     cloudpassage.com/pci-­‐kit  
  • 22. Winston Morton Vice President, Technology Enabling Usage Based Metering Cloud Services
  • 23. Agenda   1.  LinkBermuda  Company  Introduc<on   2.  Business  Model  and  Metered  Cloud  Services   3.  Cloud  Services  Billing  and  Challenges   4.  Drivers  to  use  a  cloud  based  Recurring     5.  How  Zuora  Helped  ?   6.  Lessons  Learned   7.  Wrap  Up  &  QA  
  • 26. LinkBermuda  Network  Facili<es   §  On-­‐net  connec;vity  in  mul;ple   undersea  and  terrestrial  cable   systems     §  Direct  ownership  of  undersea  cable   landing  sta;ons   §  Extensive  Bermuda  domes;c  fiber   network   §  Mul;ple  interconnects  with  network   providers  for  global  reach   §  7x24  redundant  network  opera;ons   centers  
  • 27. LinkBermuda  Data  Center  Facili<es   §  Bermuda’s  largest  data  center   complex   §  Hos;ng  many  of  the  largest  compute   nodes  in  Bermuda   §  Designated  as  a  Cri%cal   Infrastructure  by  the  Bermudian   Government  (Keypoint-­‐1)  for  priority   security  and  fuel  delivery.   §  7x24  Network  Opera;ons  Center   §  SSAE  16  SOC  2  Cer;fica;on  (in   Process)   §  Strategic  na;onal  and  interna;onal   network  connec;vity   Key  Specifica;ons:   § Site  is  deployed  on  one  of  the  highest  eleva;ons  in   Bermuda  to  military  specifica;ons   §   Designed  to  withstand  hurricane  force  winds       §   Fully  Redundant  4160V  U;lity  Feeds   §   N+1  Redundant  Diesel  Generators  (3x1000kW)   §   N+1  UPS  (2x1000kW)   §   N+1  Cooling  (2x300  Ton  Air  Cooled  Chillers)  
  • 28. Understanding  Metered  Cloud  Services   and  Design  
  • 29. I N F R A S T R U C T U R E   A S   A   S E R V I C E   §  Bundled  Virtual  Servers,  Storage,   Security,  and  Network  Connec;vity   §  Flexible  On-­‐Demand  Self  Service   §  Geographically  Aware   -­‐  Customers  can  select  as  well  as   guarantee  primary  and  secondary  VDC   loca;ons  (Bermuda  and/or  Canada   today)   IaaS  High  Level  Features   §  Predictable  Performance   -­‐  IaaS  bundled  with  Interna;onal   MPLS  QOS  features.     -­‐  Broadband  local  loop   -­‐  SLA  guarantees   §  Highly  Secure   -­‐  Embedded  VLAN  Security   -­‐  Embedded  offsite  D/R     §  Ease  of  Management   -­‐  Customer  Self  Service  Module   Metered  Cloud  Services  
  • 30. •   Communica<on  as  a  Service   •   Value  Added  Apps   •   $$/Mth  Fixed  +  Usage   •   Backup  as  a  Service   •   Value  Added  Apps   •   $$/Mb/Mth   •   Infrastructure  as  a  Service     •   Virtual  Servers   •   Value  Added  Apps   •   $$/Server/Hr   Cloud  Services  Billing   H i g h   L e v e l   D e s i g n   Cloud   Management   Pla^orm  (IaaS)   Exported   Cumula<ve  Usage   Report   Cloud   Management   Pla^orm  (BaaS)   Cloud   Management   Pla^orm  (CaaS)   Billing  Pla^orm   IaaS  Product   Catalogue   Product   Catalogue   Exported   Cumula<ve  Usage   Report   BaaS  Product   Catalogue   Product   Catalogue   Exported   Cumula<ve  Usage   Report   CaaS  Product   Catalogue   Product   Catalogue  
  • 31. Cloud  Services  Billing   F u n c ; o n a l   A p p r o a c h   §   Ini;al  launched  with  a  IaaS  model  with   interfaces  as  straight  forward  as  possible.   §   Most  of  our  cloud  systems  have  their  own   sophis;cated  self  service  provisioning   interface.   §   We  choose  to  leverage  the  provisioning   systems  embedded  in  each  cloud  system  to   minimized  development     Upside:       One  way  usage  based  interfaces  are  more   cost  effect  and  quicker  to  launch   Downside:       Mul;ple  product  catalogues  need  to  be   synchronized   Cloud   Management   Pla^orm   Product   Catalogue   Billing   Pla^orm   Product   Catalogue   Usage   Report   Customer   Portal  
  • 32. Business  Drivers  to  use  Recurring  Billing  Solu<on   § LinkBermuda  was  looking  to  out-­‐source  billing,  we  did  not  want  to  build  our  own   system  because  of  the  complexity  involved  in  recurring  billing.     §   We  evaluated  several  different  recurring  billing  systems  –  Zuora  was  the  quickest   to  deploy  and  most  cost  effec;ve.   § We  needed  a  system  which  would  enable  to  Price  and  Package  our  services   efficiently  and  be  able  to  rapidly  iterate  on  Pricing  when  needed.  
  • 33. Why  Zuora  ?   § The  Ra;ng  and  Billing  Engine  in  Zuora  understands  our  subscrip;on  business   model  and  is  ideally  suited  to  do  the  job.     §   Zuora  provided  out  of  box  solu;on  (Zforce)  for  integra;ng  with  our  CRM  system   (Salesforce).  We  took  advantage  of  both  ZQuotes  and  Z360.   § Looking  forward  to  u;lize  Zuora  Billing  and  Financial  Reports  and  Forward   Looking  Metrics  like  MRR,  ARR  etc.     §   As  LinkBermuda  grows  we  are  confident  that  Zuora  can  scale  and  accommodate   our  business  growth.  
  • 34. How  LinkBermuda  Uses  Zuora   Background   Business  Model   The  Challenge   Moving  from  tradi;onal  Telco  services   to  cloud  services  for  interna;onal  financial,   insurance  and  eCommerce  markets     B2B  +  B2C  =  B2Any   Direct:  Self-­‐service  and  sales  assisted   Channels:  Cloud  Marketplace,  Resellers   We  needed  to  develop  a  self  service  cloud  capability  with  usage  based   billing.  Legacy  billing  system  limited  customiza;on  and  product   catalogue  capabili;es.  
  • 35. Lessons  Learned   Plan.  Plan.  Plan   B E S T   P R A C T I C E S   Limit  Ini<al  Scope   Learn.  Launch.  Repeat   Business  strategy  changes  during  market  launch     Best  Prac;ce:    -­‐  Clear  defini;on  of  business  goals.        -­‐  Phase  1  launch  should  be  limited  to  base            services,  add  func;onality  as  use  cases             become  more  evident    Avoid  big  bang  cutovers     Best  Prac;ce:        -­‐  Flexible  architecture        -­‐  Repeatable  Interfaces  (If  possible)     Deploy,  measure,  iterate     Best  Prac;ce:          -­‐  Be  data  driven