SlideShare ist ein Scribd-Unternehmen logo
1 von 19
Downloaden Sie, um offline zu lesen
Yes, Clouds Can Be Secure

 Peter Coffee
 Director of Platform Research
 salesforce.com
Safe Harbor Statement

“Safe harbor” statement under the Private Securities Litigation Reform Act of 1995: This presentation may contain forward-
looking statements including but not limited to statements concerning the potential market for our existing service offerings
and future offerings. All of our forward looking statements involve risks, uncertainties and assumptions. If any such risks or
uncertainties materialize or if any of the assumptions proves incorrect, our results could differ materially from the results
expressed or implied by the forward-looking statements we make.

The risks and uncertainties referred to above include - but are not limited to - risks associated with possible fluctuations in
our operating results and cash flows, rate of growth and anticipated revenue run rate, errors, interruptions or delays in our
service or our Web hosting, our new business model, our history of operating losses, the possibility that we will not remain
profitable, breach of our security measures, the emerging market in which we operate, our relatively limited operating
history, our ability to hire, retain and motivate our employees and manage our growth, competition, our ability to continue to
release and gain customer acceptance of new and improved versions of our service, customer and partner acceptance of
the AppExchange, successful customer deployment and utilization of our services, unanticipated changes in our effective
tax rate, fluctuations in the number of shares outstanding, the price of such shares, foreign currency exchange rates and
interest rates.

Further information on these and other factors that could affect our financial results is included in reports on Forms 10-K,
10-Q and 8-K and in other filings we make with the Securities and Exchange Commission from time to time. These
documents are available in the SEC Filings section under Investor Information at www.salesforce.com/investor.
Salesforce.com, inc. assumes no obligation and does not intend to update these forward-looking statements, except as
required by law.
What is “secure”?
The Nouns and Verbs of Security



   Preserve integrity, availability & access
   Permit authentication and authorization
   Assure confidentiality & control
   Promote awareness and accountability
   Perform inspection; maintain protection;
   afford detection; enable reaction; build on
   reflection
The Nouns and Verbs of Security



   Preserve integrity, availability & access
   Permit authentication and authorization
   Assure confidentiality & control
   Promote awareness and accountability
   Perform inspection; maintain protection;
   afford detection; enable reaction; build on
   reflection
The Nouns and Verbs of Security


   If all you want is data protection, put it on
   tape and store it in a Kansas cavern
   The point of security is to maximize the
   risk-adjusted value of the asset: money in
   a bank, not under a mattress
   Infosec is therefore a process, not a
   product; a mode of travel, not a destination
“Secure” against what?
“Who” Matters So Much More than “Where”



                          "There are five common factors that lead
                          to the compromise of database
                          information":
                               • ignorance
                               • poor password management
                               • rampant account sharing
                               • unfettered access to data
                               • excessive portability of data


                                       DarkReading.com, October 2009
Clouds Can Be
Usefully Secure
Single-Tenant vs. Multi-Tenant Clouds

                                                                        Shared infrastructure

                                               Other apps
                    App 2
      App 1        App Server
                                  App 3
     App Server     Database     App Server
      Database        OS          Database
        OS           Server          OS
       Server       Storage         Server
      Storage       Network        Storage
      Network                      Network




Single tenancy entails creation of multiple        In a multi-tenant environment, all
software stacks, whether real or virtual:          applications run under a common trust
each layer in each stack represents a              model: more manageable, more consistent,
distinct opportunity for misconfiguration or       more subject to rigorous scrutiny by trained
other sources of security risk                     specialists (internal & customer)
Every Act an Invocation: Granular Privilege
Bottom-Up Design to be “Shared and Secure”
                                Apply Data
  Login…        Authenticate…   Security Rules…   View Filtered Content




Password security policies
Rich Sharing Rules
User Profiles
SSO/2-factor solutions
Governance: More Eyes, More Agendas

   Expanding legislation, regulation, mainstream mind share
   Rising standard of due diligence
   Desktop/laptop systems carry far too much “state”
   – More data than people actually use
   – Far too much data that user may easily lose
   – More than one version of what should be one shared truth
   Cloud’s Solutions:
   – Logical view of exactly one database
   – Profile definitions manage privilege sets
   – Activity logs precisely record actions
Common Controls + Customer Choices
 Strong Session Management

 Every row in the database contains an ORG_ID - Unique encoded string

 Session Tokens – user unique, non-predictable long random value generated for
 each session combined with a routing “hint” and checksum, base64 encoded

 Contains no user-identifiable information

 Session Timeout – 15 Mins to 8 Hrs

 Lock Sessions to IP – prevent hijacking and replay attacks

 SSLv3/TLS used to prevent token capture / session hijacking

 Session Logout – Explicitly expire and destroy the session
Put What You Want, Where You Want
“This is process lite. It gives my business users what they want,
a unique app for each sales team, fundamentally reflecting their own personality.
“And yes, I get a single standard SAP integration. It’s a terrific success.”
           –CIO, Fortune 500 Firm
                                                                                     Deployments


                                                                       Sales
                                                                       Sales         4 Months
                                                                    Distributors    (Oct ’06- Feb ’07)
                                                                    Distributors


                                                                        EMEA        1 Month
                                                                        EMEA
                                                                                    (Dec ’06)
                                                                    Inside Sales
                                                                     Inside Sales

                                                                    AFS Global      5 Months
                                                                    AFS Global
                                                                                    (Dec ’06 – May ’07)
                                                                      Sales
                                                                      Sales

    SAP back-end                                                    FLPR Field
                                                                    FLPR Field      2Q07
     integration                                                      Sales
                                                                      Sales

                                                                Customized for
                                                             Diverse Sales Groups
World-Class Defense in Depth




    Facility Security                  Network Security                       Platform Security
•   24x365 on site security        • Fault tolerant external firewall      • SSL data encryption
•   Biometric readers, man traps   • Intrusion detection systems           • Optional strict password policies
•   Anonymous exterior             • Best practices secure systems mgmt    • SAS 70 Type II & SysTrust Certification
•   Silent alarm                   • 3rd party vulnerability assessments   • Security certifications from Fortune 50
•   CCTV                                                                     financial services customers
•   Motion detection                                                       • May 2008: ISO 27001 Certification
•   N+1 infrastructure

                      “There are some strong technical security arguments in favor of Cloud
                      Computing… (Craig Balding, Fortune 500 security practitioner)
Trust is a Product of Transparency
How salesforce.com Achieves Trust

  Robust infrastructure security
  Rigorous operational security
  Granular customer controls
   – Role-based privilege sets
   – Convenient access control & audit
  “Sum of all fears” scrutiny and response
   – Multi-tenancy reduces opportunities for error
   – The most demanding customer sets the bar
Peter Coffee
Director of Platform Research
     pcoffee@salesforce.com      Next?
   facebook.com/peter.coffee
       twitter.com/petercoffee

Weitere ähnliche Inhalte

Andere mochten auch

Reliablity vs Authority, IAMCR Paper
Reliablity vs Authority, IAMCR PaperReliablity vs Authority, IAMCR Paper
Reliablity vs Authority, IAMCR PaperAxel Maireder
 
20110514 PMI San Diego Keynote
20110514 PMI San Diego Keynote20110514 PMI San Diego Keynote
20110514 PMI San Diego KeynotePeter Coffee
 
Sustainability in Multi-Tenant Clouds
Sustainability in Multi-Tenant CloudsSustainability in Multi-Tenant Clouds
Sustainability in Multi-Tenant CloudsPeter Coffee
 
From Valleys to Clouds
From Valleys to CloudsFrom Valleys to Clouds
From Valleys to CloudsPeter Coffee
 
Possible; Inevitable; Essential: The Social and Mobile Cloud
Possible; Inevitable; Essential: The Social and Mobile Cloud Possible; Inevitable; Essential: The Social and Mobile Cloud
Possible; Inevitable; Essential: The Social and Mobile Cloud Peter Coffee
 
Traction Group Twitter
Traction Group TwitterTraction Group Twitter
Traction Group TwitterSally Witzky
 
Meeting of the Preserve Graydon Coalition, March 23, 2010
Meeting of the Preserve Graydon Coalition, March 23, 2010Meeting of the Preserve Graydon Coalition, March 23, 2010
Meeting of the Preserve Graydon Coalition, March 23, 2010Alan Seiden
 
Common Core Presentation - Moms Club of Roxbury- September 8, 2014
Common Core Presentation - Moms Club of Roxbury- September 8, 2014Common Core Presentation - Moms Club of Roxbury- September 8, 2014
Common Core Presentation - Moms Club of Roxbury- September 8, 2014Ameerah Palacios, APR, MBA
 
Social Models and Innovation Ecosystems
Social Models and Innovation EcosystemsSocial Models and Innovation Ecosystems
Social Models and Innovation EcosystemsPeter Coffee
 
Flash on Tap slides
Flash on Tap slidesFlash on Tap slides
Flash on Tap slidesjkosoy
 
Clouds of connection sept2011 acm aitp
Clouds of connection sept2011 acm aitpClouds of connection sept2011 acm aitp
Clouds of connection sept2011 acm aitpPeter Coffee
 
Remember the 21st Century?
Remember the 21st Century?Remember the 21st Century?
Remember the 21st Century?Peter Coffee
 
Ancient Olympic Games 2015
Ancient Olympic Games 2015Ancient Olympic Games 2015
Ancient Olympic Games 2015Ciclos Formativos
 

Andere mochten auch (17)

Reliablity vs Authority, IAMCR Paper
Reliablity vs Authority, IAMCR PaperReliablity vs Authority, IAMCR Paper
Reliablity vs Authority, IAMCR Paper
 
20110514 PMI San Diego Keynote
20110514 PMI San Diego Keynote20110514 PMI San Diego Keynote
20110514 PMI San Diego Keynote
 
Sustainability in Multi-Tenant Clouds
Sustainability in Multi-Tenant CloudsSustainability in Multi-Tenant Clouds
Sustainability in Multi-Tenant Clouds
 
From Valleys to Clouds
From Valleys to CloudsFrom Valleys to Clouds
From Valleys to Clouds
 
Possible; Inevitable; Essential: The Social and Mobile Cloud
Possible; Inevitable; Essential: The Social and Mobile Cloud Possible; Inevitable; Essential: The Social and Mobile Cloud
Possible; Inevitable; Essential: The Social and Mobile Cloud
 
Pr news seo_report
Pr news seo_reportPr news seo_report
Pr news seo_report
 
Traction Group Twitter
Traction Group TwitterTraction Group Twitter
Traction Group Twitter
 
Prsa international 2011_2
Prsa international 2011_2Prsa international 2011_2
Prsa international 2011_2
 
Meeting of the Preserve Graydon Coalition, March 23, 2010
Meeting of the Preserve Graydon Coalition, March 23, 2010Meeting of the Preserve Graydon Coalition, March 23, 2010
Meeting of the Preserve Graydon Coalition, March 23, 2010
 
The Media's Role in the Innovation Ecosystem
The Media's Role in the Innovation EcosystemThe Media's Role in the Innovation Ecosystem
The Media's Role in the Innovation Ecosystem
 
Common Core Presentation - Moms Club of Roxbury- September 8, 2014
Common Core Presentation - Moms Club of Roxbury- September 8, 2014Common Core Presentation - Moms Club of Roxbury- September 8, 2014
Common Core Presentation - Moms Club of Roxbury- September 8, 2014
 
Social Models and Innovation Ecosystems
Social Models and Innovation EcosystemsSocial Models and Innovation Ecosystems
Social Models and Innovation Ecosystems
 
Stams accomplishments final
Stams accomplishments finalStams accomplishments final
Stams accomplishments final
 
Flash on Tap slides
Flash on Tap slidesFlash on Tap slides
Flash on Tap slides
 
Clouds of connection sept2011 acm aitp
Clouds of connection sept2011 acm aitpClouds of connection sept2011 acm aitp
Clouds of connection sept2011 acm aitp
 
Remember the 21st Century?
Remember the 21st Century?Remember the 21st Century?
Remember the 21st Century?
 
Ancient Olympic Games 2015
Ancient Olympic Games 2015Ancient Olympic Games 2015
Ancient Olympic Games 2015
 

Ähnlich wie Peter Coffee Open Group Cloud Security Debate Seattle 2010/02/03

ALTITUDE 2019 | Enabling Productivity with Agile Security
ALTITUDE 2019 | Enabling Productivity with Agile SecurityALTITUDE 2019 | Enabling Productivity with Agile Security
ALTITUDE 2019 | Enabling Productivity with Agile SecurityBetterCloud
 
Closing Compliance Gap
Closing Compliance GapClosing Compliance Gap
Closing Compliance GapSEEBURGER
 
Platform Encryption for ISVs (February 23, 2016)
Platform Encryption for ISVs (February 23, 2016)Platform Encryption for ISVs (February 23, 2016)
Platform Encryption for ISVs (February 23, 2016)Salesforce Partners
 
Security Best Practices for Mobile Development @ Dreamforce 2013
Security Best Practices for Mobile Development @ Dreamforce 2013Security Best Practices for Mobile Development @ Dreamforce 2013
Security Best Practices for Mobile Development @ Dreamforce 2013Tom Gersic
 
2012-01 How to Secure a Cloud Identity Roadmap
2012-01 How to Secure a Cloud Identity Roadmap2012-01 How to Secure a Cloud Identity Roadmap
2012-01 How to Secure a Cloud Identity RoadmapRaleigh ISSA
 
CloudOps evening presentation from Salesforce.com
CloudOps evening presentation from Salesforce.comCloudOps evening presentation from Salesforce.com
CloudOps evening presentation from Salesforce.comAlistair Croll
 
Power the Connected Enterprise with Cloud Integration and Master Data Managem...
Power the Connected Enterprise with Cloud Integration and Master Data Managem...Power the Connected Enterprise with Cloud Integration and Master Data Managem...
Power the Connected Enterprise with Cloud Integration and Master Data Managem...Darren Cunningham
 
Data Insights OEP interim submission
Data Insights OEP interim submissionData Insights OEP interim submission
Data Insights OEP interim submissionSandeep Rao
 
Building Elastic into security operations
Building Elastic into security operationsBuilding Elastic into security operations
Building Elastic into security operationsElasticsearch
 
Oracle Sales Cloud: Selling Complex Defense Sector Deals
Oracle Sales Cloud: Selling Complex Defense Sector DealsOracle Sales Cloud: Selling Complex Defense Sector Deals
Oracle Sales Cloud: Selling Complex Defense Sector DealsCapgemini
 
Joint Oracle-cVidya Cloud webinar - SaaS Market Growth & Opportunities
Joint Oracle-cVidya Cloud webinar - SaaS Market Growth & OpportunitiesJoint Oracle-cVidya Cloud webinar - SaaS Market Growth & Opportunities
Joint Oracle-cVidya Cloud webinar - SaaS Market Growth & OpportunitiescVidya Networks
 
Getting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseSplunk
 
Security Best Practices for Mobile Development
Security Best Practices for Mobile DevelopmentSecurity Best Practices for Mobile Development
Security Best Practices for Mobile DevelopmentSalesforce Developers
 
Perfect Storm: HR in the Cloud
Perfect Storm: HR in the CloudPerfect Storm: HR in the Cloud
Perfect Storm: HR in the CloudStanton Jones
 
Bring Your Own Device - Key Steps for an effective program
Bring Your Own Device - Key Steps for an effective programBring Your Own Device - Key Steps for an effective program
Bring Your Own Device - Key Steps for an effective programBrent Spencer
 
Architect and Design Your App for Commercial Success
Architect and Design Your App for Commercial SuccessArchitect and Design Your App for Commercial Success
Architect and Design Your App for Commercial SuccessSalesforce Partners
 
Clextra platform
Clextra platformClextra platform
Clextra platformEdgevalue
 
[Srijan Wednesday Webinars] 11 Things You Don't Know About Cloud
[Srijan Wednesday Webinars] 11 Things You Don't Know About Cloud[Srijan Wednesday Webinars] 11 Things You Don't Know About Cloud
[Srijan Wednesday Webinars] 11 Things You Don't Know About CloudSrijan Technologies
 
Secure HR Platform for Utilities
Secure HR Platform for Utilities Secure HR Platform for Utilities
Secure HR Platform for Utilities Bhupesh Chaurasia
 

Ähnlich wie Peter Coffee Open Group Cloud Security Debate Seattle 2010/02/03 (20)

ALTITUDE 2019 | Enabling Productivity with Agile Security
ALTITUDE 2019 | Enabling Productivity with Agile SecurityALTITUDE 2019 | Enabling Productivity with Agile Security
ALTITUDE 2019 | Enabling Productivity with Agile Security
 
Closing Compliance Gap
Closing Compliance GapClosing Compliance Gap
Closing Compliance Gap
 
Platform Encryption for ISVs (February 23, 2016)
Platform Encryption for ISVs (February 23, 2016)Platform Encryption for ISVs (February 23, 2016)
Platform Encryption for ISVs (February 23, 2016)
 
Security Best Practices for Mobile Development @ Dreamforce 2013
Security Best Practices for Mobile Development @ Dreamforce 2013Security Best Practices for Mobile Development @ Dreamforce 2013
Security Best Practices for Mobile Development @ Dreamforce 2013
 
2012-01 How to Secure a Cloud Identity Roadmap
2012-01 How to Secure a Cloud Identity Roadmap2012-01 How to Secure a Cloud Identity Roadmap
2012-01 How to Secure a Cloud Identity Roadmap
 
CloudOps evening presentation from Salesforce.com
CloudOps evening presentation from Salesforce.comCloudOps evening presentation from Salesforce.com
CloudOps evening presentation from Salesforce.com
 
Power the Connected Enterprise with Cloud Integration and Master Data Managem...
Power the Connected Enterprise with Cloud Integration and Master Data Managem...Power the Connected Enterprise with Cloud Integration and Master Data Managem...
Power the Connected Enterprise with Cloud Integration and Master Data Managem...
 
Data Insights OEP interim submission
Data Insights OEP interim submissionData Insights OEP interim submission
Data Insights OEP interim submission
 
Building Elastic into security operations
Building Elastic into security operationsBuilding Elastic into security operations
Building Elastic into security operations
 
Oracle Sales Cloud: Selling Complex Defense Sector Deals
Oracle Sales Cloud: Selling Complex Defense Sector DealsOracle Sales Cloud: Selling Complex Defense Sector Deals
Oracle Sales Cloud: Selling Complex Defense Sector Deals
 
Joint Oracle-cVidya Cloud webinar - SaaS Market Growth & Opportunities
Joint Oracle-cVidya Cloud webinar - SaaS Market Growth & OpportunitiesJoint Oracle-cVidya Cloud webinar - SaaS Market Growth & Opportunities
Joint Oracle-cVidya Cloud webinar - SaaS Market Growth & Opportunities
 
Getting Started with Splunk Enterprise
Getting Started with Splunk EnterpriseGetting Started with Splunk Enterprise
Getting Started with Splunk Enterprise
 
Security Best Practices for Mobile Development
Security Best Practices for Mobile DevelopmentSecurity Best Practices for Mobile Development
Security Best Practices for Mobile Development
 
Perfect Storm: HR in the Cloud
Perfect Storm: HR in the CloudPerfect Storm: HR in the Cloud
Perfect Storm: HR in the Cloud
 
Bring Your Own Device - Key Steps for an effective program
Bring Your Own Device - Key Steps for an effective programBring Your Own Device - Key Steps for an effective program
Bring Your Own Device - Key Steps for an effective program
 
Architect and Design Your App for Commercial Success
Architect and Design Your App for Commercial SuccessArchitect and Design Your App for Commercial Success
Architect and Design Your App for Commercial Success
 
Clextra platform
Clextra platformClextra platform
Clextra platform
 
[Srijan Wednesday Webinars] 11 Things You Don't Know About Cloud
[Srijan Wednesday Webinars] 11 Things You Don't Know About Cloud[Srijan Wednesday Webinars] 11 Things You Don't Know About Cloud
[Srijan Wednesday Webinars] 11 Things You Don't Know About Cloud
 
Secure HR Platform for Utilities
Secure HR Platform for Utilities Secure HR Platform for Utilities
Secure HR Platform for Utilities
 
Erp slides
Erp slidesErp slides
Erp slides
 

Mehr von Peter Coffee

Create And Keep a Customer
Create And Keep a CustomerCreate And Keep a Customer
Create And Keep a CustomerPeter Coffee
 
Snowforce 2017 Keynote - Peter Coffee
Snowforce 2017 Keynote - Peter CoffeeSnowforce 2017 Keynote - Peter Coffee
Snowforce 2017 Keynote - Peter CoffeePeter Coffee
 
#PaveItForward 2016 - Peter Coffee
#PaveItForward 2016 - Peter Coffee#PaveItForward 2016 - Peter Coffee
#PaveItForward 2016 - Peter CoffeePeter Coffee
 
Game of Phones - Becoming the Architects of Connection (Midwest Dreamin' Clos...
Game of Phones - Becoming the Architects of Connection (Midwest Dreamin' Clos...Game of Phones - Becoming the Architects of Connection (Midwest Dreamin' Clos...
Game of Phones - Becoming the Architects of Connection (Midwest Dreamin' Clos...Peter Coffee
 
Inside Out and Upside Down - FOO Camp 2016 - Peter Coffee
Inside Out and Upside Down - FOO Camp 2016 - Peter CoffeeInside Out and Upside Down - FOO Camp 2016 - Peter Coffee
Inside Out and Upside Down - FOO Camp 2016 - Peter CoffeePeter Coffee
 
Big Data Goes to Work - Liberating Latent Value in a Connected World - P.Coffee
Big Data Goes to Work - Liberating Latent Value in a Connected World - P.CoffeeBig Data Goes to Work - Liberating Latent Value in a Connected World - P.Coffee
Big Data Goes to Work - Liberating Latent Value in a Connected World - P.CoffeePeter Coffee
 
Forcing Functions: Reconceiving Everything - Peter Coffee at AITP San Diego C...
Forcing Functions: Reconceiving Everything - Peter Coffee at AITP San Diego C...Forcing Functions: Reconceiving Everything - Peter Coffee at AITP San Diego C...
Forcing Functions: Reconceiving Everything - Peter Coffee at AITP San Diego C...Peter Coffee
 
Forces of the Future That's Now - Peter Coffee at SoTeC 2015
Forces of the Future That's Now - Peter Coffee at SoTeC 2015Forces of the Future That's Now - Peter Coffee at SoTeC 2015
Forces of the Future That's Now - Peter Coffee at SoTeC 2015Peter Coffee
 
Fusion Trumps Confusion - 2015
Fusion Trumps Confusion - 2015Fusion Trumps Confusion - 2015
Fusion Trumps Confusion - 2015Peter Coffee
 
Unleash innovation on the Customer Success Platform
Unleash innovation on the Customer Success PlatformUnleash innovation on the Customer Success Platform
Unleash innovation on the Customer Success PlatformPeter Coffee
 
It's About The Citizen - Changing Needs and Rising Expectations
It's About The Citizen - Changing Needs and Rising ExpectationsIt's About The Citizen - Changing Needs and Rising Expectations
It's About The Citizen - Changing Needs and Rising ExpectationsPeter Coffee
 
Busting Silos, Boosting Communities
Busting Silos, Boosting CommunitiesBusting Silos, Boosting Communities
Busting Silos, Boosting CommunitiesPeter Coffee
 
What Is "Secure"?
What Is "Secure"?What Is "Secure"?
What Is "Secure"?Peter Coffee
 
Governing The Connected Everything
Governing The Connected EverythingGoverning The Connected Everything
Governing The Connected EverythingPeter Coffee
 
The Rising Floor of Platform - MIT Platform Summit 2014
The Rising Floor of Platform - MIT Platform Summit 2014The Rising Floor of Platform - MIT Platform Summit 2014
The Rising Floor of Platform - MIT Platform Summit 2014Peter Coffee
 
New Services, No Silos: The Next 15 Years
New Services, No Silos: The Next 15 YearsNew Services, No Silos: The Next 15 Years
New Services, No Silos: The Next 15 YearsPeter Coffee
 
How To Thrive In A World of Connected Customers
How To Thrive In A World of Connected CustomersHow To Thrive In A World of Connected Customers
How To Thrive In A World of Connected CustomersPeter Coffee
 
Looking Back at the Next Ten Years - Fusion Symposium 2024
Looking Back at the Next Ten Years - Fusion Symposium 2024Looking Back at the Next Ten Years - Fusion Symposium 2024
Looking Back at the Next Ten Years - Fusion Symposium 2024Peter Coffee
 
Delighting the Customer - The New Business Normal
Delighting the Customer - The New Business NormalDelighting the Customer - The New Business Normal
Delighting the Customer - The New Business NormalPeter Coffee
 
Redefining "Clean IT": Rejecting Incremental Improvement
Redefining "Clean IT": Rejecting Incremental ImprovementRedefining "Clean IT": Rejecting Incremental Improvement
Redefining "Clean IT": Rejecting Incremental ImprovementPeter Coffee
 

Mehr von Peter Coffee (20)

Create And Keep a Customer
Create And Keep a CustomerCreate And Keep a Customer
Create And Keep a Customer
 
Snowforce 2017 Keynote - Peter Coffee
Snowforce 2017 Keynote - Peter CoffeeSnowforce 2017 Keynote - Peter Coffee
Snowforce 2017 Keynote - Peter Coffee
 
#PaveItForward 2016 - Peter Coffee
#PaveItForward 2016 - Peter Coffee#PaveItForward 2016 - Peter Coffee
#PaveItForward 2016 - Peter Coffee
 
Game of Phones - Becoming the Architects of Connection (Midwest Dreamin' Clos...
Game of Phones - Becoming the Architects of Connection (Midwest Dreamin' Clos...Game of Phones - Becoming the Architects of Connection (Midwest Dreamin' Clos...
Game of Phones - Becoming the Architects of Connection (Midwest Dreamin' Clos...
 
Inside Out and Upside Down - FOO Camp 2016 - Peter Coffee
Inside Out and Upside Down - FOO Camp 2016 - Peter CoffeeInside Out and Upside Down - FOO Camp 2016 - Peter Coffee
Inside Out and Upside Down - FOO Camp 2016 - Peter Coffee
 
Big Data Goes to Work - Liberating Latent Value in a Connected World - P.Coffee
Big Data Goes to Work - Liberating Latent Value in a Connected World - P.CoffeeBig Data Goes to Work - Liberating Latent Value in a Connected World - P.Coffee
Big Data Goes to Work - Liberating Latent Value in a Connected World - P.Coffee
 
Forcing Functions: Reconceiving Everything - Peter Coffee at AITP San Diego C...
Forcing Functions: Reconceiving Everything - Peter Coffee at AITP San Diego C...Forcing Functions: Reconceiving Everything - Peter Coffee at AITP San Diego C...
Forcing Functions: Reconceiving Everything - Peter Coffee at AITP San Diego C...
 
Forces of the Future That's Now - Peter Coffee at SoTeC 2015
Forces of the Future That's Now - Peter Coffee at SoTeC 2015Forces of the Future That's Now - Peter Coffee at SoTeC 2015
Forces of the Future That's Now - Peter Coffee at SoTeC 2015
 
Fusion Trumps Confusion - 2015
Fusion Trumps Confusion - 2015Fusion Trumps Confusion - 2015
Fusion Trumps Confusion - 2015
 
Unleash innovation on the Customer Success Platform
Unleash innovation on the Customer Success PlatformUnleash innovation on the Customer Success Platform
Unleash innovation on the Customer Success Platform
 
It's About The Citizen - Changing Needs and Rising Expectations
It's About The Citizen - Changing Needs and Rising ExpectationsIt's About The Citizen - Changing Needs and Rising Expectations
It's About The Citizen - Changing Needs and Rising Expectations
 
Busting Silos, Boosting Communities
Busting Silos, Boosting CommunitiesBusting Silos, Boosting Communities
Busting Silos, Boosting Communities
 
What Is "Secure"?
What Is "Secure"?What Is "Secure"?
What Is "Secure"?
 
Governing The Connected Everything
Governing The Connected EverythingGoverning The Connected Everything
Governing The Connected Everything
 
The Rising Floor of Platform - MIT Platform Summit 2014
The Rising Floor of Platform - MIT Platform Summit 2014The Rising Floor of Platform - MIT Platform Summit 2014
The Rising Floor of Platform - MIT Platform Summit 2014
 
New Services, No Silos: The Next 15 Years
New Services, No Silos: The Next 15 YearsNew Services, No Silos: The Next 15 Years
New Services, No Silos: The Next 15 Years
 
How To Thrive In A World of Connected Customers
How To Thrive In A World of Connected CustomersHow To Thrive In A World of Connected Customers
How To Thrive In A World of Connected Customers
 
Looking Back at the Next Ten Years - Fusion Symposium 2024
Looking Back at the Next Ten Years - Fusion Symposium 2024Looking Back at the Next Ten Years - Fusion Symposium 2024
Looking Back at the Next Ten Years - Fusion Symposium 2024
 
Delighting the Customer - The New Business Normal
Delighting the Customer - The New Business NormalDelighting the Customer - The New Business Normal
Delighting the Customer - The New Business Normal
 
Redefining "Clean IT": Rejecting Incremental Improvement
Redefining "Clean IT": Rejecting Incremental ImprovementRedefining "Clean IT": Rejecting Incremental Improvement
Redefining "Clean IT": Rejecting Incremental Improvement
 

KĂźrzlich hochgeladen

Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth MarketingShawn Pang
 
Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaShree Krishna Exports
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesDipal Arora
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
 
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetCreating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetDenis GagnĂŠ
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Lviv Startup Club
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communicationskarancommunications
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsP&CO
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 DelhiCall Girls in Delhi
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Delhi Call girls
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
HONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsHONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsMichael W. Hawkins
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Roland Driesen
 

KĂźrzlich hochgeladen (20)

Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
 
Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in India
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetCreating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
HONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsHONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael Hawkins
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...
 

Peter Coffee Open Group Cloud Security Debate Seattle 2010/02/03

  • 1. Yes, Clouds Can Be Secure Peter Coffee Director of Platform Research salesforce.com
  • 2. Safe Harbor Statement “Safe harbor” statement under the Private Securities Litigation Reform Act of 1995: This presentation may contain forward- looking statements including but not limited to statements concerning the potential market for our existing service offerings and future offerings. All of our forward looking statements involve risks, uncertainties and assumptions. If any such risks or uncertainties materialize or if any of the assumptions proves incorrect, our results could differ materially from the results expressed or implied by the forward-looking statements we make. The risks and uncertainties referred to above include - but are not limited to - risks associated with possible fluctuations in our operating results and cash flows, rate of growth and anticipated revenue run rate, errors, interruptions or delays in our service or our Web hosting, our new business model, our history of operating losses, the possibility that we will not remain profitable, breach of our security measures, the emerging market in which we operate, our relatively limited operating history, our ability to hire, retain and motivate our employees and manage our growth, competition, our ability to continue to release and gain customer acceptance of new and improved versions of our service, customer and partner acceptance of the AppExchange, successful customer deployment and utilization of our services, unanticipated changes in our effective tax rate, fluctuations in the number of shares outstanding, the price of such shares, foreign currency exchange rates and interest rates. Further information on these and other factors that could affect our financial results is included in reports on Forms 10-K, 10-Q and 8-K and in other filings we make with the Securities and Exchange Commission from time to time. These documents are available in the SEC Filings section under Investor Information at www.salesforce.com/investor. Salesforce.com, inc. assumes no obligation and does not intend to update these forward-looking statements, except as required by law.
  • 4. The Nouns and Verbs of Security Preserve integrity, availability & access Permit authentication and authorization Assure confidentiality & control Promote awareness and accountability Perform inspection; maintain protection; afford detection; enable reaction; build on reflection
  • 5. The Nouns and Verbs of Security Preserve integrity, availability & access Permit authentication and authorization Assure confidentiality & control Promote awareness and accountability Perform inspection; maintain protection; afford detection; enable reaction; build on reflection
  • 6. The Nouns and Verbs of Security If all you want is data protection, put it on tape and store it in a Kansas cavern The point of security is to maximize the risk-adjusted value of the asset: money in a bank, not under a mattress Infosec is therefore a process, not a product; a mode of travel, not a destination
  • 8. “Who” Matters So Much More than “Where” "There are five common factors that lead to the compromise of database information": • ignorance • poor password management • rampant account sharing • unfettered access to data • excessive portability of data DarkReading.com, October 2009
  • 10. Single-Tenant vs. Multi-Tenant Clouds Shared infrastructure Other apps App 2 App 1 App Server App 3 App Server Database App Server Database OS Database OS Server OS Server Storage Server Storage Network Storage Network Network Single tenancy entails creation of multiple In a multi-tenant environment, all software stacks, whether real or virtual: applications run under a common trust each layer in each stack represents a model: more manageable, more consistent, distinct opportunity for misconfiguration or more subject to rigorous scrutiny by trained other sources of security risk specialists (internal & customer)
  • 11. Every Act an Invocation: Granular Privilege
  • 12. Bottom-Up Design to be “Shared and Secure” Apply Data Login… Authenticate… Security Rules… View Filtered Content Password security policies Rich Sharing Rules User Profiles SSO/2-factor solutions
  • 13. Governance: More Eyes, More Agendas Expanding legislation, regulation, mainstream mind share Rising standard of due diligence Desktop/laptop systems carry far too much “state” – More data than people actually use – Far too much data that user may easily lose – More than one version of what should be one shared truth Cloud’s Solutions: – Logical view of exactly one database – Profile definitions manage privilege sets – Activity logs precisely record actions
  • 14. Common Controls + Customer Choices Strong Session Management Every row in the database contains an ORG_ID - Unique encoded string Session Tokens – user unique, non-predictable long random value generated for each session combined with a routing “hint” and checksum, base64 encoded Contains no user-identifiable information Session Timeout – 15 Mins to 8 Hrs Lock Sessions to IP – prevent hijacking and replay attacks SSLv3/TLS used to prevent token capture / session hijacking Session Logout – Explicitly expire and destroy the session
  • 15. Put What You Want, Where You Want “This is process lite. It gives my business users what they want, a unique app for each sales team, fundamentally reflecting their own personality. “And yes, I get a single standard SAP integration. It’s a terrific success.” –CIO, Fortune 500 Firm Deployments Sales Sales 4 Months Distributors (Oct ’06- Feb ’07) Distributors EMEA 1 Month EMEA (Dec ’06) Inside Sales Inside Sales AFS Global 5 Months AFS Global (Dec ’06 – May ’07) Sales Sales SAP back-end FLPR Field FLPR Field 2Q07 integration Sales Sales Customized for Diverse Sales Groups
  • 16. World-Class Defense in Depth Facility Security Network Security Platform Security • 24x365 on site security • Fault tolerant external firewall • SSL data encryption • Biometric readers, man traps • Intrusion detection systems • Optional strict password policies • Anonymous exterior • Best practices secure systems mgmt • SAS 70 Type II & SysTrust Certification • Silent alarm • 3rd party vulnerability assessments • Security certifications from Fortune 50 • CCTV financial services customers • Motion detection • May 2008: ISO 27001 Certification • N+1 infrastructure “There are some strong technical security arguments in favor of Cloud Computing… (Craig Balding, Fortune 500 security practitioner)
  • 17. Trust is a Product of Transparency
  • 18. How salesforce.com Achieves Trust Robust infrastructure security Rigorous operational security Granular customer controls – Role-based privilege sets – Convenient access control & audit “Sum of all fears” scrutiny and response – Multi-tenancy reduces opportunities for error – The most demanding customer sets the bar
  • 19. Peter Coffee Director of Platform Research pcoffee@salesforce.com Next? facebook.com/peter.coffee twitter.com/petercoffee