Compliance, Security, Availability & Cost Requirements

Compliance, Security, Availability & Cost Requirements
Lesson 3 · Provisioning

Compliance, Security, Availability & Cost Requirements

Deploying a virtual machine or hyperconverged environment is only half the job. Every cloud deployment also has to satisfy a set of standing requirements — legal, security, uptime, and financial — that shape which decisions are even on the table.

3.11

Compliance Requirements

Businesses must understand and satisfy various compliance requirements. The specific regulations vary by information type, region, and industry. Click each criterion below to expand it.

INFO — Cloud service providers may limit services in some regions. Be sure to understand regional availability concerns for any data your cloud solution maintains.

3.12

Security Requirements

All businesses face cybersecurity challenges ranging from denial of service attacks to ransomware to identity theft. Many strategies used to protect on-premises resources also apply to cloud-based content.

๐Ÿข

Proprietary business information

Your company's internal workings — including data transfers, financial information, and business processes — must be secured.

๐Ÿ’ก

Intellectual property

The company's proprietary designs and applications require protection from outside exposure to competitors.

๐Ÿ›️

Customer privacy

Customers expect protection of names, contact information, purchase history, credit card data, health concerns, and more.

๐Ÿง‘‍๐Ÿ’ป

Employee privacy

Employees must also be protected from personal information leaks, phishing attacks, and social engineering.

How this shapes deployment — proprietary data and IP concerns may drive a decision toward a private or hybrid cloud, where the business retains greater control. Customer and employee privacy concerns may instead be addressed by choosing a provider with the right compliance certifications. Regional or national concerns can also govern which services or features a provider makes available.
INFO — Security is covered in-depth in a later module.

3.13

Availability Requirements

Today's information consumers expect virtually uninterrupted access to services. High availability comes with a cost, which may be justified depending on the resource.

Customer availability

Customers assume on-demand access to web, database, support, and other services. Cloud providers help ensure this using redundancy, scalability, and CDNs to deliver data.

Employee availability

Employees need access to organizational data to drive the business forward. Interruptions prevent employees from doing their jobs, greatly impacting the company.

Service availability

Microservices and web/database servers often require tight integration that assumes every component is available. Tools like server clusters help ensure this.

Cloud service providers continually update their offerings to maintain cutting-edge technologies — and deprecate features or retire outdated components as necessary. These changes can impact your deployment and management strategies. Utilities such as power and internet access do periodically fail, so disaster recovery and business continuity planning are critical to ensuring availability. Consider redundant methods of accessing resources in the event of an outage anywhere along the chain between employees, customers, and cloud services.

Disaster recovery
Business continuity
Redundant access paths
Feature deprecation risk
INFO — Availability is usually associated with security and performance concerns, so you may find related information within those parts of the requirements documents.

3.14

Cost Requirements

Like other aspects of IT, deployment and maintenance costs govern cloud services. What makes cloud computing different is that the cost structures for these services change — rather than purchasing expensive hardware or managing hundreds of licenses, cloud administrators manage resources on an as-needed subscription basis.

Optimized services

Optimization greatly impacts budgeting, allowing businesses to use their resources more efficiently rather than paying for idle capacity.

Reporting

Resource metering and auditing provide visibility into consumption and use, letting organizations understand exactly how their resources are spent.

INFO — Costs and billing are covered in-depth in a later module.
§ 3.11–3.14 · Compliance, Security, Availability & Cost Requirements