Cultural Considerations of Adopting Application Container Technology

The benefits of application containers have been shared across a variety of forums and to a diverse audience. The ability to have more application instances without a corresponding increase in hardware is probably the primary benefit that is used to persuade enterprises to adopt application containers. But if that is the primary benefit, meeting the objectives of the rapid deployment associated with DevOps is a close second.

Application containers allow developers to easily modify and test because applications are siloed in their own containers. So, the benefits are appealing from a cost savings perspective as well as support of DevOps deployment. Is there a downside, though?

Perhaps it is not a downside as much as a consideration, but as organizations adopt application containerization, some cultural shifts are necessary. These shifts relate to operational processes that organizations may already have in place; however, containerization requires doing those familiar processes differently. Because the change is for an existing process rather than the implementation of something new, the change is more cultural than operational. For example, in a traditional application environment, generally, there is a structured process for code review, which the time to deployment accommodates. As deployment time is shortened (as in a scenario involving DevOps and application containers), organizations may be challenged in how they perform formal, structured code reviews. So, a cultural shift to identify (and accept) solutions that provide assurance around secure coding in the containerized environment despite the rapid speed of deployment may be required.

Another area where a cultural shift may be required relates to access. Unless an organization develops a strategy around administrator access, it is possible for administrators to have access to multiple hosts, containers and images rather than the specific hosts, containers and images to which the administrator needs access to perform job responsibilities. Ensuring that a least privilege strategy is implemented would addresses this. Also, beyond internal expectations, several compliance initiatives, such as the Health Insurance Portability Accountability Act (HIPAA), the Payment Card Industry Data Security Standard (PCI DSS) and the General Data Protection Regulation (GDPR) rely on strong access controls.

Lastly, an organization’s approach to authentication may require a cultural shift. In administering workloads, orchestrators potentially place workloads that have varying levels of sensitivity on the same host. To address this, an orchestrator may have its own authentication directory. This directory, however, may be separate from other non-orchestrator authentication directories in use. As a result, the orchestrator’s authentication directory may have different authentication practices. A concerted effort to ensure alignment of authentication practices for all directories (orchestrator-related or not) may be necessary. These efforts may include, but are not limited to, restricting administrator authentication access to specific repositories rather than multiple repositories.

The benefits of adopting application containers are appealing. More application instances may be possible without incurring the cost of additional hardware and deployment time may be reduced. Effective adoption, however, depends on how organizations can modify existing protocols to accommodate the containerized environment. Code review, access and authentication are examples of areas for which organizations routinely have controls but where a cultural shift is necessary. Once these shifts have been made, the benefits or application containers can be fully realized.

Robin Lyons, Technical Research Manager, ISACA

[ISACA Now Blog]

Are You Google Cloud Ready?

Public Cloud Security Represents a Massive Opportunity for NextWave Partners

Organizations adopt public cloud solutions for greater network agility and scalability, higher performance and faster access to innovative technologies, but they need help keeping their data secure. 451 Group predicts that by 2018, 60 percent of all workloads will reside in the public cloud while 91 percent of cybersecurity professionals have concerns about cloud security*. The top three challenges they face include protecting against data loss and leakage (67%), threats to data privacy (61%), and breaches of confidentiality (53%). Helping our mutual customers move to the cloud while addressing these challenges represents a massive opportunity for NextWave partners to provide their security expertise and position the benefits of our Security Operating Platform, which supports all major public cloud services, including Amazon Web Services, Microsoft Azure and Google Cloud Platform, or GCP.

 

Become Familiar With Google Cloud Platform

Whether you are curious about GCP or want to dig into technical details, we have a starting place for you! The Google Cloud Platform Learning Guide is the latest addition to our Learning Guide series, providing info on how to get hands-on experience.

 

Start or Grow Your Knowledge

As organizations expand their adoption of GCP for big data, analytics and machine learning initiatives, protecting from threats and data loss becomes a top priority. This Learning Guide provides overviews and in-depth material on GCP, including GCP Launcher, Google Deployment Manager, Google Kubernetes Engine and networking concepts.

Palo Alto Networks VM-Series for GCP protects applications and data deployed on GCP with the same next-generation security that protects more than 51,000 networks around the world today. We provide training on GCP and Palo Alto Networks VM-Series virtualized firewalls, including deployment guidelines, architectures such as hybrid, scale-in and scale-out, and for technical roles, we have administrator guides.

 

Choose Your Own Learning Track

Either follow the learning guide step by step or simply skip ahead to specific topics based on your current knowledge.

Check out everything we can do now in the cloud with GCP. Get the Google Cloud Platform Learning Guide now.

 

* “Voice of the Enterprise: Cloud Transformation Survey of IT Buyers,” 451 Research, September 2016

[Palo Alto Networks Research Center]

English
Exit mobile version