Jump to content

Cloud, SaaS and SoSaas - Same old Software, as a Service


Recommended Posts

Posted
I thought this topic was forked from the data migration\integration topic to discuss cloudy things? Do I have to get a mod to slap you back over to your own topic? lol

 

No, check the first few replies which mention APIs still... :roll:

Posted
No, check the first few replies which mention APIs still... :roll:

 

Ahh, you're referring to the naughty @PhilNeal who's using his salesman skills to distract us whilst the Capita developers finish of SIMS 8 so we don't badge Capita with rainy clouds. Didn't your mother warning you about following other people?

Posted
We totally agree with matt40k on scalability.

 

What infrastructure are you using for Bromcom's cloud backend - are you using someone else's servers (Amazon, RackSpace, Microsoft Azure) with your software on top, or are you hosting your own hardware? If its your own hardware, are you running a cloud system of some kind, i.e. OpenStack or similar, or have you written all you software from scratch?

Posted
They shouldn't really tell you for security, but an educated guess...

 

They list two cloud providers on their site:

Bromcom Computers Plc - Partners

 

Colocation Cloud Hosting & UK Datacentre Provider | Pulsant

and

Managed Hosting | Dedicated Servers & Cloud Hosting | UKFast

 

So I would guess they have a private cloud using something like vmware.

 

I would suggest a customer MUST know where and how their data is being stored... no?

Posted
Ahh, you're referring to the naughty @PhilNeal who's using his salesman skills to distract us whilst the Capita developers finish of SIMS 8 so we don't badge Capita with rainy clouds. Didn't your mother warning you about following other people?

 

Not really as we are talking about Cloud MIS and how this interaction happens with API.

 

Stop looking for naughtiness... I can see right through you! :mad: :D

Posted
I would suggest a customer MUST know where and how their data is being stored... no?

 

Agree to a certain point. Normally you know where the primary site is but you never know where the backup site is, you just a get legal document confirming that it is in the UK and it is signed off by an independent company or you'd have to sign a NDA all depending on the level of security we're talking.

 

I can tell you that Azure has a DC in Ireland, not sure I can tell you the exact location. Could be wrong. I just wouldn't think you'd want to be able to find a data center with 22,000 schools MIS systems on Google Maps.

 

Personally I'd like to know it's in England and no backups, regards of if they are encrypted or not*, leave England. Not too fussed about exact locations so long as they have a primary and secondary and they're not next door to each other (ideally something like Manchester and London). I'm sure Ireland would be fine, its just, well if its within the same country I'd assume it would be easier to deal with issues that might occur. I just assume it might get a bit sticky trying to comply with two sets of government legislation, ones bad enough.

 

All boils down to trust. End of the day even if you get a guided tour of a data center in England, doesn't mean the data isn't forwarding to China or USA.

 

 

* I'm just saying this as we know the NSA can break most encryption and surely having a database full of all the UK children with behaviour reports and critical life events kinda makes for a good platform for making predictions about the future adult population of the UK. Paranoid I know.

Posted (edited)
I would suggest a customer MUST know where and how their data is being stored... no?

 

Usually schools question whether data is in within UK, EU or elsewhere. Yes, Bromcom's data is within UK.

 

LA's in tenders even ask to inspect the data-centres. Yes, they are welcome to inspect.

Edited by Bromcom-PR
typo
Posted
I agree @matt40k @Bromcom-PR In the UK is acceptable under DPA, although I would want to know where backups are too, not just a random signed agreement. A customer should know themselves, it is their responsibility too not just suppliers in telling them. Potentially, yes a school should be able to visit the site.
Posted
I agree @matt40k @Bromcom-PR In the UK is acceptable under DPA, although I would want to know where backups are too, not just a random signed agreement. A customer should know themselves, it is their responsibility too not just suppliers in telling them. Potentially, yes a school should be able to visit the site.

 

But the buyer can sort that with the vendor, it doesn't need to be revealed here for the world.

Posted

Other one is data erasing. How would you ensure that once your end the contract that they securely destroy the data.

 

Thing is, if they give you a legal document saying the data never leaves the UK and when you leave they securely destroy the data along with any backups - they're only ever going to get it wrong once, the fines and penalties are ridiculous. Pretty sure if it's an individuals fault they can be liable for life imprisonment. Personally I think I can trust a company when the MD signs his life away - literally.

Posted
But the buyer can sort that with the vendor, it doesn't need to be revealed here for the world.

 

Why does it need to be secretive? If all customers know, the data is out there. I'm saying that in the UK is fine publicly, not sure where the confusion is? I'm saying that the buyer individually should know.

Posted (edited)
Personally I think I can trust a company when the MD signs his life away - literally.

 

So bank bosses that were fiddling numbers into the billions? That means nothing at all! having MD sign anything. All that means is who you are blame after the event, not safeguard in the first place!

 

I'm not making trouble if you read my posts carefully, I promise you. I'm just saying that information should be available if requested, there needs to get away from this secretive hush hush side, and more from the customer side they should be actively aware!

Edited by GREED
Posted

Fair point but like I said. Having something on your site saying UK only DC and letting people visit the DC and signing a document confirming this - it still comes down to trust. They could move the servers the day after, or forward your data outside of Europe. You of course build the trust by visiting the DC and checking out what they telling you.

 

One day @GREED we'll get to a point where we don't have any of these dark spots where information is hidden behind a NDA or the maze that is SupportNet ;)

  • Thanks 1
Posted
Fair point but like I said. Having something on your site saying UK only DC and letting people visit the DC and signing a document confirming this - it still comes down to trust. They could move the servers the day after, or forward your data outside of Europe. You of course build the trust by visiting the DC and checking out what they telling you.

 

One day @GREED we'll get to a point where we don't have any of these dark spots where information is hidden behind a NDA or the maze that is SupportNet ;)

 

Yes we basically agree :D

 

If I were being picky I would suggest that the more expensive or difficult it is to make such changes as you suggest the greater the trust you build.

Posted
I would suggest that the more expensive or difficult it is to make such changes as you suggest the greater the trust you build.

 

If by greater trust, you mean increase the chances that I would hunt you down and break your legs if you should break that trust :D

Posted

Not just that, but fundamentally the more difficult or expensive it would be to say change the location of the data center overnight, the less likely it is a bona fide company would do that. ..

 

Checks legs :D

Posted
Ahh good point. Be worth sending the dc onsite guys some goodies at xmas to keep them on side in case they decide to move away without telling you.

 

Lol always tip your IT team!

 

Anyways back to the OP...

Posted

So the guys at @Bromcom-PR told me about this thread about my SoSaaS definition (among other things) and they challenged me to sharpen up the definition as requested by GREED below.

 

...Software as a Service seems to be bounded about without a full understanding of the meaning too.

 

It might be nice to have a definitive definition, because my understanding is that SaaS is software you use you do not manage. So Microsoft when they brought out 365 apps, Word became a Software as a Service you use then switch off. You don't install, update, troubleshoot and fix, that is handled elsewhere. Just as you would with a SaaS MIS. Ok you then have the grey area with the storage, but you could argue this is a service you are paying for too (like OneDrive).

Given that, does SoSaaS actually exist (I personally don't like the term, but as @vikpaw will testify that is probably because I didn't think of it!). I would argue not, because any software could be used as SaaS under that definition.

 

To Cloud, my interpretation has always been that Cloudy applications are ones that are hosted on several disparate and distributed servers, like Google servers and services are. Ones simply presented via a web browser and hosted on a server not on site does not make it cloud(y).

 

I also liked @matt40k's notion of grey and white clouds - yes there are definitely both types.

 

The problem with the grey versions of cloud and SaaS is that people have taken existing client-server software and just put them in the cloud but they haven't adapted them for it. You may call it SaaS - "software you use you do not manage" per GREED - but it's only SoSaaS, not true/white cloud according to the widely accepted NIST definition (which the UK government uses to define its 'Cloud First' policy).

 

The nub of the NIST definition is that cloud is a "shared pool" of dynamically allocated resources. If you don't change the software to behave like this internally then you may be putting it on top of a cloud, but it doesn't become cloud software unless you change it on the inside as well.

 

Does that work as a definition or do I need to expand on it do you think?

Posted

Interoperability is a huge benefit of SaaS. Third party software developers can manage MIS integration from their end, rather than having to support software on some school computer that's subject to constant environmental changes.

 

As someone that has integrated software with a number of cloud-based MIS solutions, I can say that it took me less time to write that integration than I spend solving SIMS integration problems every week, and it never fails.

 

There are difficulties associated with SaaS, but it's such a common software model now that all of these have been addressed long ago. You have to be security conscious with any application that deals with this kind of data. In my experience, you're actually improving security by moving in-house to cloud-based, as the software vendor can apply it's vigorously tested security to all customers alike, removing a lot of the potential for client-side security lapses.

Posted

I've read this thread with interest, and obviously I'm speaking from the point of view of a software supplier rather than consumer, but I think that many people are overloading the basic Software as a Service definiton with a lot of additional concepts (all of them progressive) but which doesn't really get delivered by SaaS. For instance the Gartner definition of SaaS (Gartner IT Glossary - Software as a Service (SaaS)) says "software that is owned, delivered and managed remotely by one or more providers". It doesn't incorporate any concepts of elasticity, cost, integration or technology. It doesn't even have to be run remotely - just delivered and managed remotely.

 

The definition crucially talks about how a customer pays for the service delivered by software; which seems to be an important move away from "owning software in perpetuity" to "paying to use a service delivered via software". As an extreme example Adobe delivers its Photoshop application on-demand with updates remotely managed and delivered, on a subscription basis. This qualifies under the Gartner definition as a SaaS model of delivery. Its not browser based or "integrated" any further than the "perpetually owned" version, so I guess this would be your "SosaaS" example.

 

The NIST definition defines the Cloud Software as a Service in similar terms "The capability provided to the consumer is to use the provider’s applications running on a cloud infrastructure" - how the provider provides elasticity (or even whether it does so efficiently) isn't a consideration. The NIST does say "Note: Cloud software takes full advantage of the cloud paradigm by being service oriented with a focus on statelessness, low coupling, modularity, and semantic interoperability." but doesn't define why the "Cloud Paradigm" delivers any of this within its own definition of Cloud - I suspect what they wanted to say was "HTML REST" rather than Cloud. I'm guessing that everyone here's expectation of a cloud delivered MIS would be HTML + REST (which would be a sensible assumption).

 

I would be very interested in the groups weighted shopping list of capabilities above and beyond "remotely managed and delivered, and subscription based payment" that would attract you to a "true cloud" application rather than, say, a Browser Terminal Services hosted existing MIS (which fulfills the definition of SaaS) ?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...