News
8/1/2011
10:38 AM
George Crump
George Crump
Commentary
Connect Directly
RSS
E-Mail
50%
50%

How to Choose A Cloud Storage Provider: Availability

Access varies across cloud storage providers. Here's how to make sure you get what you need, when you need it.

In a recent entry we discussed what security capabilities you should look for in a cloud storage provider. While security is important, being able to get to your data is equally imperative. To make matters worse, many cloud storage providers are somewhat sketchy in what level of availability they will commit to. Knowing what you can expect from your provider--and how you have to augment that--is critical.

Understanding the availability you need is important because in most cases the level of availability you get directly impacts the price you pay. Typically, the more copies of data that you store in different parts of the cloud, the more it's going to cost.

To a large extent, how available you need cloud storage to be depends on how you are going to use it. If you're using cloud storage as an offsite vault for your backups and you are also keeping some or most of your backups onsite, then 100% availability may not be that big of a concern. If you're using cloud storage as the primary destination for your backups, even with a local cache of some sort, then access to that data for recovery may be critical.

If you're going to use cloud storage for primary storage, then availability is more important, especially with block-based storage solutions. NAS or file-based solutions tend to keep the most recently accessed files in a local, on-premises cache. That means that if the cache is of adequate size you can still get to your most recently accessed files until the cloud service is backed up. Block is more random in nature, so it's harder to predict exactly where the next access will be and, if an old block of data can't be accessed, the application may crash.

The two situations where availability is critical are probably going to be: when you're counting on cloud storage as your primary backup storage area and when you're using cloud storage to store primary block-based storage. Cloud storage as a NAS storage area could be a close third.

Increased availability can come in two forms. The first can be to use the basic services from two different cloud suppliers. This gives you redundancy, not only in a cloud storage failure, but also protects you in case one of the organizations goes out of business. This means your cloud storage software or application needs to be able to support writing to two clouds simultaneously. For most organizations, though, the cost is not going to be practical to have two cloud storage providers.

The next option is to invest in a cloud storage provider that can provide some level of redundancy. This is not limited to just redundant copies of storage spread around the Internet, but also a redundant means of accessing that data. As stated above, extra copies will typically mean extra money. The pricing for these extra copies can vary greatly, so check out the details.

Many providers can deliver a multi-copy level of redundancy, but the key is to make sure that they will provide a service level agreement to stand behind that commitment. Beyond the SLA, make sure that the organization has the capabilities to fulfill the commitments in that SLA, otherwise they are just words on a page. Look to make sure they have quality storage systems, quality data centers, and quality network connections--and of course the financial wherewithal to stand behind all that.

Also understand exactly what is being committed to. Some providers offer a complete, full-service responsibility; others still put much of the burden on you. Several cloud vendors are now providing a turnkey service where they will manage the redundancy and connectivity for you. Of course there is a fee for this service, but it may be well worth it, especially if your IT resources are already stretched thin.

The final step in availability is to know what you will do when a failure occurs. Don't wait for a network or cloud storage failure to figure out your strategy. Plan for it. Make sure that you know how you will connect to the redundant copies or how you will switch to a local copy if you decide to go that route.

Follow Storage Switzerland on Twitter

George Crump is lead analyst of Storage Switzerland, an IT analyst firm focused on the storage and virtualization segments. Storage Switzerland's disclosure statement.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
AJ12345
50%
50%
AJ12345,
User Rank: Apprentice
12/4/2011 | 12:23:50 AM
re: How to Choose A Cloud Storage Provider: Availability
Cloud technology has come a long way! I think the most important things are

1. Security
2. Ease of use and integration
3. Cost savings potential

Here's a company doing it really well: bit.ly/cloudforhotels
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Threat Intel Today
Threat Intel Today
The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0485
Published: 2014-09-02
S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object in (1) common.py or (2) local.py in backends/.

CVE-2014-3861
Published: 2014-09-02
Cross-site scripting (XSS) vulnerability in CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted reference element within a nonXMLBody element.

CVE-2014-3862
Published: 2014-09-02
CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, leading to information disclosure in a Referer log.

CVE-2014-5076
Published: 2014-09-02
The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework.

CVE-2014-5136
Published: 2014-09-02
Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.