As an Amex customer I'm glad to know they have strict requirements but the fact is, they're shunning a massive cloud infrastructure service like AWS over a piddly little local co-locted hosting company.
As an Amex customer I'm glad to know they have strict requirements but the fact is, they're shunning a massive cloud infrastructure service like AWS over a piddly little local co-locted hosting company.
So while for the developer, moving things to AWS is a no-brainer, a time-saver, and a money-saver to the company, the amount of politics, and change, is so large these behemoths of companies are the last to consider it.
Security is a valid piece, but also a political move to keep the money from changing hands too rapidly.
http://www.prweb.com/releases/2016/10/prweb13764156.htm
"But where labor efficiency is greater than [400 VMs per engineer], OpenStack becomes more financially attractive. In fact, past this tipping point, all private cloud options are cheaper than both public cloud and managed private cloud options."
This study does ignore the services supplied on top of basic compute, however.
Are any cloud providers UIs good? OpenStack provides decent APIs, and a usable UI. and I much prefer the CLIs OpenStack has to AWSs.
Also, in AWS' defense, you won't hear stories about startups using them and having expensive developers sitting on their hands waiting for hardware. Probably a lot of startups only start (or get funding) because of the low barrier to entry AWS provides.
Here it is: https://aws.amazon.com/govcloud-us/
http://fortune.com/2015/06/29/intelligence-community-loves-i...
Often, it seems like the only defence is that skiddies don't have a clue about mainframes that's saving these idiots.
I agree, as long as fines are lower than the CEOs salary + bonuses, these "fines" remain laughable. But based on these other cases, it's unlikely that the ICO would or could do anything to severely impact how a bank operates, which makes them toothless.
As for telling the ICO, well the deputy director of the National Cyber Security Centre (NCSC, part of GCHQ) explicitly said he won't tell ICO if people report breaches to him... so I wouldn't cross my fingers.
Unfortunately, even though my department are more than happy to budget any money for AWS, IT, Internal Security, Risk etc. are all blocking the path saying they haven't vetted or onboarded Amazon, and that they're working on their own internal cloud so that we can do similar things (I've tried this "internal cloud", it's beyond useless. Slow and locked down more than guantanamo so you can't actually do anything with it).
That "piddly little local co-locted hosting company" (whoever they are) is subject to some pretty intense level of scrutiny and has to pass gazillions of tests outside of your normal hosting SLA stuff just to claim that they are compliant.
From my dealings with pharma companies, I will point out one thing.
For things where they have to follow regulations around privacy, they won't let you host your software on AWS for them to use.
They will have their in house team set up your software on AWS for them to use.
Setting it up themselves allows them to guarantee all the regulatory requirements are being met. The CIA isn't using Joe Schmoe's amazon instance, they spin up their own machines and install the software there.