<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: sintetico82</title>
    <description>The latest articles on DEV Community by sintetico82 (@sintetico82).</description>
    <link>https://dev.to/sintetico82</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F735097%2F174b8cc8-9375-493f-9f3a-ff9cf21aa338.jpeg</url>
      <title>DEV Community: sintetico82</title>
      <link>https://dev.to/sintetico82</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/sintetico82"/>
    <language>en</language>
    <item>
      <title>Cloud Governance Management System</title>
      <dc:creator>sintetico82</dc:creator>
      <pubDate>Mon, 10 Jan 2022 11:40:36 +0000</pubDate>
      <link>https://dev.to/sintetico82/cloud-governance-management-system-57nl</link>
      <guid>https://dev.to/sintetico82/cloud-governance-management-system-57nl</guid>
      <description>&lt;p&gt;In this article, we will try to build a Cloud Governance Management System (CGMS), which is an integrated system consistent with Cloud services and allow to reach Cloud objectives. The main CGMS’s components are:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Principles;&lt;/li&gt;
&lt;li&gt;Reference models, policies, processes, procedures and tools;&lt;/li&gt;
&lt;li&gt;Organizational structure, roles and responsibilities;&lt;/li&gt;
&lt;li&gt;Monitoring and Key Performance Indicators (KPI).&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;We already discussed principles &lt;a href="https://dev.to/sintetico82/principles-of-cloud-computing-governance-1lhi"&gt;principles&lt;/a&gt;, so let see more details about reference models, policies and processes.&lt;/p&gt;

&lt;h2&gt;
  
  
  Reference models, policies, processes, procedures and tools
&lt;/h2&gt;

&lt;p&gt;Governance and management are activities based on processes. For creating a reference model we need to identify which are processes for the company that will use both for cloud governance than management.&lt;/p&gt;

&lt;p&gt;For each Cloud principle, it is defined a relative governance’s process. The process and his name should represent what is needed to realize the principle. In this way, a map that identifies the IT processes to follow is constructed, based on cloud governance principles. Of course, principles and processes can be already present in the company, and nowadays there are many well-established standards like COBIT 5 and ISO/IEC 38500. While the IS/IEC 38500 standard only defines IT governance principles, the COBIT 5 framework also defines activities and processes.&lt;/p&gt;

&lt;p&gt;So, we can use as a basis the COBIT 5 framework for processes. It subdivides the processes into two areas, governance and management. The two areas in total have 5 domains and 37 processes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Governance of Enterprise IT

&lt;ul&gt;
&lt;li&gt;Evaluate, Direct and Monitor (EDM) - 5 processes.&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;
&lt;li&gt;Management of Enterprise IT

&lt;ul&gt;
&lt;li&gt;Align, Plan and Organise (APO) - 13 processes;&lt;/li&gt;
&lt;li&gt;Build, Acquire and Implement (BAI) - 10 processes;&lt;/li&gt;
&lt;li&gt;Deliver, Service and Support (DSS) - 6 processes;&lt;/li&gt;
&lt;li&gt;Monitor, Evaluate and Assess (MEA) - 3 processes.&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If we consider the EDM area, we can make a link with Cloud services principles and the activities inside the EDM area. We define ti activities in Evaluate, Direct and Monitor area, associate processes to principles, and activity to processes.&lt;/p&gt;

&lt;p&gt;for exemple:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--Xcy7qbpH--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://sintetech.com/post/cloud-governance-management-system/cloud_principles_processes_activities_COBIT_5_mapping.png%23center" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--Xcy7qbpH--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://sintetech.com/post/cloud-governance-management-system/cloud_principles_processes_activities_COBIT_5_mapping.png%23center" alt="Cloud governance principles, processes and activities mapping with COBIT 5" title="Cloud governance principles, processes and activities mapping with COBIT 5" width="816" height="259"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Tools are extremely helpful for standardizing policies, processes and procedures. Using the right tools, the company can ensure the right execution of the processes. Of course, some tools can be “nice to have”, but other tools are mandatory for an effective CGMS. So, very important tools are a ticketing system to track and manage service requests and incidents, CMS to store documented processes and procedures, and collaboration tools to coordinate schedules and other shared information with Cloud service providers (CSPs) and stakeholders.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--m3CA_9nZ--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://sintetech.com/post/cloud-governance-management-system/CGMS.drawio.png%23center" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--m3CA_9nZ--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://sintetech.com/post/cloud-governance-management-system/CGMS.drawio.png%23center" alt="Example integrated Cloud Governance and Menagement reference model" title="Example integrated Cloud Governance and Menagement reference model" width="631" height="691"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In this example model principles is the main container, governance direct with plans and policies the management, evaluate their proposals and monitoring management performance and conformance fo continual improvement.&lt;/p&gt;

&lt;p&gt;Data, architecture and structure are a set of principles to support the privacy, confidentiality, availability, integrity and security of data on public and private clouds. Compliance and Risk Management are controls to manage, minimize and transfer risks.&lt;/p&gt;

&lt;p&gt;Management contains management and operations activity, for example:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cloud service provider management

&lt;ul&gt;
&lt;li&gt;Change management&lt;/li&gt;
&lt;li&gt;Cloud vendor management&lt;/li&gt;
&lt;li&gt;Monitoring and measurement&lt;/li&gt;
&lt;li&gt;Service level management&lt;/li&gt;
&lt;li&gt;Real-time alerting&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;
&lt;li&gt;Operations

&lt;ul&gt;
&lt;li&gt;Service management integration&lt;/li&gt;
&lt;li&gt;Availability management&lt;/li&gt;
&lt;li&gt;Capacity management and scalability&lt;/li&gt;
&lt;li&gt;Business continuity and disaster recovery&lt;/li&gt;
&lt;li&gt;Operations management&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;
&lt;li&gt;Finance management

&lt;ul&gt;
&lt;li&gt;Consumption model&lt;/li&gt;
&lt;li&gt;Total cost ownership model&lt;/li&gt;
&lt;li&gt;Benefits realization&lt;/li&gt;
&lt;li&gt;Adoption costs&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;
&lt;li&gt;Security

&lt;ul&gt;
&lt;li&gt;Identity and access management&lt;/li&gt;
&lt;li&gt;Data protection&lt;/li&gt;
&lt;li&gt;Security operations&lt;/li&gt;
&lt;li&gt;Platform security&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Tools support all areas (the icons are only an example of software tools to use, but of course, every company chooses their tools, both digital or physical like an old fashion paper).&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;Cloud Governance Management System can be hard to create and maintain, also the amount of plans, policies, controls, people to govern and manage everything highly depends on the company nature and its principles and goals.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Fulton, Lita. Cloud Governance and Management Made Simple: Practical Step-by-Step Guide for Small and Mid-Sized Organizations&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cloud</category>
      <category>governance</category>
      <category>digitaltransformation</category>
    </item>
    <item>
      <title>Align Cloud services with business goals</title>
      <dc:creator>sintetico82</dc:creator>
      <pubDate>Fri, 12 Nov 2021 14:29:08 +0000</pubDate>
      <link>https://dev.to/sintetico82/align-cloud-services-with-business-goals-46fe</link>
      <guid>https://dev.to/sintetico82/align-cloud-services-with-business-goals-46fe</guid>
      <description>&lt;p&gt;You know what are the &lt;a href="https://dev.to/sintetico82/introduction-to-cloud-computing-governance-59li"&gt;impacts of Cloud adoption on your governance&lt;/a&gt; and you start with &lt;a href="https://dev.to/sintetico82/principles-of-cloud-computing-governance-1lhi"&gt;building your Cloud principles&lt;/a&gt;, what next?&lt;/p&gt;

&lt;p&gt;An important phase at this point it’s the alignment of company business goals with Cloud services. If the Cloud objectives are not aligned with real company needs, Cloud service adoption can be a step backwards in terms of cost and efficiency rather than a qualitative advantage. Let better distingue the difference between goals and objectives.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Goals&lt;/strong&gt; are general guidelines that explain what you want to archives in your company. They are usually long-term and express global visions such as “give to the customers a better experience”, “security-first”, “reducing the time to market”, and others;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Objectives&lt;/strong&gt; define strategies or implementation steps to attain the identified goals. Objectives are specific, measurable, and have a completion date. So, from previous goals examples, we can have these objectives such as “design a new user interface”, “define security policies and controls”.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So, as we have seen, Cloud services objectives are specific and measurable and they must be followed to reach the strategic objectives of the company business. Cloud’s objectives are generally a subset of IT objectives.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--djgBp35t--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://sintetech.com/post/align-cloud-services-with-business-goals/relationship_between_goals_and_objectives.png%23center" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--djgBp35t--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://sintetech.com/post/align-cloud-services-with-business-goals/relationship_between_goals_and_objectives.png%23center" alt="Relationship between goals and objectives" title="Relationship between goals and objectives" width="880" height="440"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Align Cloud services with goals and objectives, and use or adapt them to respond to factors of strategy change, to respond to stakeholders, operational changes.&lt;/p&gt;

&lt;p&gt;Factors influencing strategy changes can be internal or external to the business organization. Some can be customer inputs, new technologies, new laws, or internal factors from teams new skills or dissatisfaction. Are we going in a good direction? should we change something?&lt;/p&gt;

&lt;p&gt;For example, the company doesn’t want to invest in IT CapEx, it’s not their core business to manage a CED infrastructure, so factors of change can be the need for cost reduction and the availability of newly available technology. So, a simplified example of the alignment can be the following:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Goals&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;Take advantage of new technology for cost reduction and management of CED infrastructure.&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Strategies&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;Migrate all services to a Public Cloud computing environment for taking advantage of the pay for use model.&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Strategic objectives&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;Organize the migration in two phases. The first objective is to migrate 30% of business services to the public Cloud in the first semester of this year;&lt;/li&gt;
&lt;li&gt;In the second phase, migrate the remaining services by the end of the year.&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Operational objectives&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;Configure the public cloud infrastructure by February;&lt;/li&gt;
&lt;li&gt;Prepare applications X, Y, Z for migration;&lt;/li&gt;
&lt;li&gt;Execute migration of X, Y, Z applications;&lt;/li&gt;
&lt;li&gt;and more.&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;What about factors of operational changes? These kinds of factors are generally connected to operational problems, events or anticipated risks. For example, customer users can encounter poor application performance, a security violation like a data breach or a simple down of servers, these are considerating factors of operational change.&lt;/p&gt;

&lt;p&gt;We can create a list of problems and risks known to the IT department and for these problems and risks define objectives for resolution and mitigation that satisfy the factors of changes. Of course, not all factors of change can be related to Cloud. Some examples can be the following:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A factor of operational change:&lt;/strong&gt; the business core application has a performance degrade during office time.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Objectives:&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;Change the application architecture for adopting a horizontal scaling model;&lt;/li&gt;
&lt;li&gt;Use CDN for static resources;&lt;/li&gt;
&lt;li&gt;Switch some synchronous operations to asynchronous.&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;Do not just start some virtual machine or fancy services on the Cloud. It’s ok for the experimentation period, but running business core services without a strategy, in the long run, can hurt in terms of cost and efficiency.&lt;/p&gt;

&lt;p&gt;Identify organization goals and strategic objectives, and align Cloud services to them. Technologies must serve the company business and not vice versa.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Fulton, Lita. Cloud Governance and Management Made Simple: Practical Step-by-Step Guide for Small and Mid-Sized Organizations&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cloud</category>
      <category>governance</category>
      <category>goals</category>
      <category>digitaltransformation</category>
    </item>
    <item>
      <title>Introduction to Cloud Computing governance</title>
      <dc:creator>sintetico82</dc:creator>
      <pubDate>Sun, 24 Oct 2021 10:00:00 +0000</pubDate>
      <link>https://dev.to/sintetico82/introduction-to-cloud-computing-governance-59li</link>
      <guid>https://dev.to/sintetico82/introduction-to-cloud-computing-governance-59li</guid>
      <description>&lt;p&gt;Every day, more and more new organizations decide to adopt the Cloud Computing paradigm. The adoption of this paradigm imposes some changes in company organizations, introducing new challenges and opportunities.&lt;/p&gt;

&lt;p&gt;In this article, I would like to discuss the Cloud computing definition, opportunities and impacts on IT governance. After, we will follow a path that conducts us to build a Cloud computing governance, putting in evidence the principal aspects to consider during the adoption of the Cloud computing paradigm.&lt;/p&gt;

&lt;h2&gt;
  
  
  Cloud computing
&lt;/h2&gt;

&lt;p&gt;Cloud computing, or Cloud, it’s a paradigm of on-demand services from a provider to a client through the internet web.&lt;/p&gt;

&lt;p&gt;This model allows to drastically simplify the management of the IT systems, transforming the physical infrastructure to virtual services available on needed consume.&lt;/p&gt;

&lt;p&gt;Today, we can identify these typologies of cloud computing:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Public cloud&lt;/strong&gt; : claimed and managed by specialized organizations in the cloud. They supply through the internet computing resources. Microsoft Azure, Amazon AWS, Google Cloud Platform, are examples of public cloud;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Private cloud&lt;/strong&gt; : a private cloud is referring to resources of cloud computing only from one company or association. A private cloud can be site in the company Data Center;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hybrid cloud&lt;/strong&gt; : these types o cloud, unify public and private cloud. They allow moving data and workloads from the private and public cloud.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  The opportunities of Cloud computing
&lt;/h2&gt;

&lt;p&gt;Cloud computing offers various advantages:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Cost calibration&lt;/strong&gt; : using service models like IaaS, PaaS and SaaS, the companies can adjust their cost on the resources used (pay for use). Furthermore, you can reduce the compressive cost connected to the physical Data Center location on-premises (rent, power, physical security and others);&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Security&lt;/strong&gt; : the main public Cloud provider offers a very high level of security for their system. They continuous make security updates on their platform (if you use the PaaS or SaaS model), guarantee the physical security of their Data Center, advance technologies for data protection, and usually, are compliant with the most important security standards;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Flexibility&lt;/strong&gt; : it’s one of the most strong features of the Cloud. The cloud allows you to scale up your resource theoretically infinitely when the resources demand are growing;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Reliability and availability&lt;/strong&gt; : the cloud enables the possibility to make services with a high level of reliability and business continuity;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Innovation&lt;/strong&gt; : it makes easy access to modern and innovative technologies to use within your services.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Features of cloud service
&lt;/h2&gt;

&lt;p&gt;To better understand what are the impacts on IT governance, we need to identify which are the features of Cloud computing services. The &lt;em&gt;National Institute of Standards and Technology&lt;/em&gt; (NIST) define six different features:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;On-demand self-service&lt;/strong&gt; : a user of services can, independently, carry out the procurement of resources of cloud computing, like example storage space and server time, as needed automatically without requiring human interaction with the service provider;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Broad network access&lt;/strong&gt; : capabilities are available over the internet, with standard API and with a different client (es smartphone, laptops, etc.);&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Resource pooling&lt;/strong&gt; : services and resources available on the provider, are organized in a multi-tenant model for serving different users, using both virtual than physical resources dynamically allocated to meet the needs of applications. The allocated resources are independent of physical location and users doesn’t have direct control over them but they can specify on a high level the geographical location;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rapid elasticity&lt;/strong&gt; : the resources can be elastic provisioned, often also automatically, to ensure high scalability both outward and inward. From the users perspective, the resources look infinite, and it is given to them the opportunity to buy at any time;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Measured service&lt;/strong&gt; : a Cloud system, automatic monitoring and optimizing resources to use based on the type of service (es. Storage, compute, network bandwidth). Used resources can be monitored, controlled and connected ensuring transparency between users and providers.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Impact on the IT governance
&lt;/h2&gt;

&lt;p&gt;Now that we know the features of cloud computing, what is the impact on IT governance? These features introduce some consideration about traditional service administration and management on-premises.&lt;/p&gt;

&lt;h3&gt;
  
  
  On-demand self-service
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The organization can accelerate the application deployment process.&lt;/li&gt;
&lt;li&gt;The easy access to the demand for new resources involves more control over cost budget, management and tracking of their use.&lt;/li&gt;
&lt;li&gt;The hardware lifecycle it demanded to the cloud service provider.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Broad network access
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Authentication and authorization impact.&lt;/li&gt;
&lt;li&gt;IAM management and integration with organization authorization.&lt;/li&gt;
&lt;li&gt;Communication between the cloud service provider and IT member of the organization.&lt;/li&gt;
&lt;li&gt;Operational Level Agreements (OLAs)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Resource pooling
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Security.&lt;/li&gt;
&lt;li&gt;Legal aspect to be compliant with local law.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Rapid elasticity
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;With the easy and virtual infinity possibility of resource demand, great attention is putting on cost budget.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Measured service
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Service Level Agreements (SLAs)&lt;/li&gt;
&lt;li&gt;Management billing of the consumed services.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Moreover, the level of the impact depends also on the Cloud model that is adopted like Infrastructure as a Service (IaaS), Platform as a Service (PaaS) or Software as a Service (SaaS).&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--ZaT_7Ol2--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://sintetech.com/post/introduction-to-cloud-computing-governance/users-manage-vs-csp.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--ZaT_7Ol2--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://sintetech.com/post/introduction-to-cloud-computing-governance/users-manage-vs-csp.png" alt="Users manage vs CSP manages" title="USers manage vs Cloud Service Provider" width="880" height="769"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;As we have seen, the introduction of cloud computing into the organization has an impact on roles, responsibilities, processes and measures. Without appropriate governance that provides guidelines for risks mitigation, delivering efficient services, the organizations can be in trouble and fail to achieve cost-saving and a good service offering level. The Cloud governance should operate and be integrated with the actual organization IT governance, extending this one with its characteristics.&lt;/p&gt;

&lt;p&gt;Now that we know what are the impacts on IT governance, we can try to understand how to build a Cloud computing governance. We will see how in the next articles.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;ISO/IEC 17788:2014: Information Technology – Cloud Computing – Overview and Vocabulary; (&lt;a href="http://www.iso.org/iso/catalogue_detail?csnumber=605455"&gt;www.iso.org/iso/catalogue_detail?csnumber=605455&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;ISO/IEC 17789:2014: Information Technology – Cloud Computing – Reference Architecture; (&lt;a href="http://www.iso.org/iso/catalogue_detail?csnumber=60545"&gt;www.iso.org/iso/catalogue_detail?csnumber=60545&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;National Institute of Standards and Technology (Special Publication 500‐291)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cloud</category>
      <category>governance</category>
    </item>
    <item>
      <title>Principles of Cloud Computing governance</title>
      <dc:creator>sintetico82</dc:creator>
      <pubDate>Fri, 22 Oct 2021 22:00:00 +0000</pubDate>
      <link>https://dev.to/sintetico82/principles-of-cloud-computing-governance-1lhi</link>
      <guid>https://dev.to/sintetico82/principles-of-cloud-computing-governance-1lhi</guid>
      <description>&lt;p&gt;From a high level, the governance goal is to ensure that we are doing the right things in the right way. The questions we are trying to ask are the following:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Are we doing the right thing?&lt;/li&gt;
&lt;li&gt;Are we doing it in the right way?&lt;/li&gt;
&lt;li&gt;How we can understand it?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Cloud computing governance it’s a comprehensive view of IT governance focused on responsibility, the definitions of the right decision and the balance between benefit/value. Risk and resources inside a Cloud ecosystem. The governance helps us to ensure that every expense relative to the Cloud are aligned with business objectives, it promotes data integrity, foster technology innovation and mitigate the risk of data loss or not compliance.&lt;/p&gt;

&lt;p&gt;We can say that Cloud governance it’s an extension of IT governance, something we need to integrate into the existing one inside the organization and not replace.&lt;/p&gt;

&lt;p&gt;We need to distingue between governance and management because sometimes we can confuse them. Governance defines the strategic direction and establishes an enabling system inside the organization. Management, use the governance enabling system to put in place the strategic direction of the governance.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--TA5f-obh--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://sintetech.com/post/principles-cloud-computing-governance/governance-vs-management.png%23center" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--TA5f-obh--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://sintetech.com/post/principles-cloud-computing-governance/governance-vs-management.png%23center" alt="Governance vs Management" title="Governance vs management" width="643" height="314"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Principles of IT governance, the bases for the Cloud governance
&lt;/h2&gt;

&lt;p&gt;Every governance starts from principles. Also for cloud governance is necessary to define adequate principles. One good start point is from the ISO/IEC standard 38500 (Information technology — Governance of IT for the organization); it shows six principles:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Responsibility: the responsibility of the use of the IT system, should be assigned clearly to individuals o groups;&lt;/li&gt;
&lt;li&gt;Strategy: the organization business strategy, from a high level, should consider and define the IT direction, given the base for a correct alignment of activities with the organization need;&lt;/li&gt;
&lt;li&gt;Acquisition: the decisions to invest and get IT assets should be taken considering valid reasons and success factors. These factors are not only for managing the ongoing business but they should consider future changes and challenges;&lt;/li&gt;
&lt;li&gt;Performance: the IT service demand and capacity both for day by day operation than for new system development should be balanced for ensuring a good level of performance;&lt;/li&gt;
&lt;li&gt;Conformance: all the policies and practices, internal or external, relative to the IT use must be formally identified, defined, clearly communicated, implemented and enforced;&lt;/li&gt;
&lt;li&gt;Human behaviour: people inside the process, IT policies, practices and decisions, must be always respected.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Nowadays, there are many IT governance frameworks, among which the most important are:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;TOGAF 9.1: it’s an Open Group standard. The framework provides guidelines of governance for enterprise architecture;&lt;/li&gt;
&lt;li&gt;COBIT 5: it’s a framework for IT governance;&lt;/li&gt;
&lt;li&gt;ITIL v3: it defines guidelines for governance of services management. It’s very important for cloud computing governance;&lt;/li&gt;
&lt;li&gt;The Open Group SOA Governance Framework: it provides guidelines of governance for service-oriented architecture.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--VHmrjiif--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://sintetech.com/post/principles-cloud-computing-governance/framework-landscape.jpg%23center" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--VHmrjiif--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://sintetech.com/post/principles-cloud-computing-governance/framework-landscape.jpg%23center" alt="Governance framework landscape" title="Governance framework landscape" width="573" height="308"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Cloud computing governance is intended as a subset of IT governance and Enterprise Architecture governance. It contains all the unique features that are essential for Cloud governance.&lt;/p&gt;

&lt;h2&gt;
  
  
  Principles of cloud governance
&lt;/h2&gt;

&lt;p&gt;The principles drive the design of the Cloud governance and define the behaviour. The principles, give a thread and a common theme for the decision relative to Cloud, providing a compass to the accountable people of all levels of the organization. Standard ISO 38500 Corporate Governance of Information Technology, as we have seen, defines six fundamental principles: responsibility, strategy, acquisition, performance, conformance, human behaviour. These principles are the best practices internationally recognized and they should be the constituent basis during the compilation of specific cloud governance principles for each company. Criteria for building efficient principles can be different for each organization because each organization can be very different, but there are principles that every organization that use Cloud services should strongly keep in mind: compliance with policies and standard, business goals must guide the Cloud strategy, contracts between the participating entities of the Cloud ecosystem, adopt well-defined change management processes, application of monitoring processes to achieve continuous improvement.&lt;/p&gt;

&lt;h3&gt;
  
  
  Compliance with policies and standard
&lt;/h3&gt;

&lt;p&gt;Cloud standards should be open, consistent and complementary to the main sector standard and adopted from the big company. The Cloud ecosystem has a broad range of services partners and suppliers. If you look at &lt;a href="https://landscape.cncf.io"&gt;https://landscape.cncf.io&lt;/a&gt; you can have an idea of the vast range. The compliance to standards and policies ensure a consistent approach, integrated and complete in the ecosystem for preventing, mitigate and dealing with a specific risk of cloud solutions (including security, business continuity, etc…). Using open standard give a great benefit in term of interoperability, often a fundamental need in a Cloud environment. This also allows to don’t lock with one single provider but they give the freedom to migrate or combine different providers.&lt;/p&gt;

&lt;h3&gt;
  
  
  Business goals must guide the Cloud strategy
&lt;/h3&gt;

&lt;p&gt;Cloud strategy should be integrated with organization and global IT strategy. Cloud enable a broad range of features to grow a company in an agile, flexible and cheap way. Thus, both business and IT objectives should drive the cloud transformation and be part of one global strategy.&lt;/p&gt;

&lt;h3&gt;
  
  
  Contracts between the participating entities of the Cloud ecosystem
&lt;/h3&gt;

&lt;p&gt;A clear ruleset of policies and agreements that define the interaction between the stakeholders is essential for guaranteeing a healthy coexistence in the Cloud ecosystem.&lt;/p&gt;

&lt;p&gt;The cloud ecosystem includes both external that internal stakeholders of the organization. Contracts provide clarity, responsibility, authority among stakeholders. So, it’s essential to have a work agreement among them. Fundamental is the service level agreement (SLA) for efficient use of the Cloud, especially for the high financial or another kind of impact and for this reason, should be formally declared.&lt;/p&gt;

&lt;h3&gt;
  
  
  Adopt well-defined change management processes
&lt;/h3&gt;

&lt;p&gt;Change should be practised and applied consistently and standardized on all components of the company’s cloud ecosystem.&lt;/p&gt;

&lt;p&gt;A Cloud ecosystem is composed of a vast component‘s network interconnected in which a single change to one of them can have an impact on all systems. This type of ecosystem needs a coherent operation model to better adapt to a different perspective. The lack of a well-defined change management process can compromise the end-to-end interoperability of the cloud ecosystem because of interruption derivated from unwanted change.&lt;/p&gt;

&lt;h3&gt;
  
  
  Application of monitoring processes to achieve continuous improvement
&lt;/h3&gt;

&lt;p&gt;The cloud governance process must monitor events and key factors that can be determined by continuous improvement. Companies are always changing because of the market demand and by the evolution of company targets. Therefore, the Cloud computing process will always need continuous change for aligning to them.&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;Principles are fundamentals for all kinds of governance, not only for the Cloud. Principles can be different from company to company, and it’s fine, but the lack of any principles it’s not.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;ISO/IEC 17788:2014: Information Technology – Cloud Computing – Overview and Vocabulary; (&lt;a href="http://www.iso.org/iso/catalogue_detail?csnumber=605455"&gt;www.iso.org/iso/catalogue_detail?csnumber=605455&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;ISO/IEC 17789:2014: Information Technology – Cloud Computing – Reference Architecture; (&lt;a href="http://www.iso.org/iso/catalogue_detail?csnumber=60545"&gt;www.iso.org/iso/catalogue_detail?csnumber=60545&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;National Institute of Standards and Technology (Special Publication 500‐291)&lt;/li&gt;
&lt;li&gt;The Open Group (&lt;a href="http://www.opengroup.org"&gt;http://www.opengroup.org&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fulton, Lita. Cloud Governance and Management Made Simple: Practical Step-by-Step Guide for Small and Mid-Sized Organizations&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cloud</category>
      <category>governance</category>
    </item>
  </channel>
</rss>
