Supporting highly regulated customers, such as pharmaceutical, financial and government, in the cloud come with a huge set of hurdles. These customers demand a quality offering from cloud providers including operational excellence, strong software development discipline and a solid security operation. OpenStack can be the foundation of such a cloud offering but requires additional layers of operational and security infrastructure to satisfy these customers.
Using real-world cloud providers as case studies, this session will examine the compliance issue identified, the specifics of the compliance requirements and present some solutions on how the issue could be resolved. These case studies are based upon (anonymized) historical audits and assessments of real-world cloud offerings.
The session will be wrapped up with some specific takeaways on how to build an OpenStack cloud environment to satisfy compliance and security requirements.