NIST Cloud Computing Reference Architecture

Page 1 sur 35Lecteur de document UniversityLib

NIST Cloud Computing Reference Architecture

Cloud Computing · notes

Voir tous les documents en systèmes d'exploitation et cloud

Special Publication 500-292

NIST Cloud Computing

Reference Architecture

Recommendations of the National

Institute of Standards and

Technology

Fang Liu, Jin Tong, Jian Mao, Robert Bohn,

John Messina, Lee Badger and Dawn Leaf

NIST Special Publication 500-292

NIST Cloud Computing Reference

Architecture

Recommendations of the National

Institute of Standards and Technology

Fang Liu, Jin Tong, Jian Mao, Robert

Bohn, John Messina, Lee Badger and

Dawn Leaf

Information Techonology Laboratory

Cloud Computing Program

Information Technology Laboratory

National Institute of Standards and Technology

Gaithersburg, MD 20899-8930

September 2011

U.S. Department of Commerce

Rebecca M. Blank, Acting Secretary

National Institute of Standards and Technology

Patrick D. Gallagher, Under Secretary for Standards

and Technology and Director

i

NIST SP 500-292

NIST Cloud Computing Reference Architecture

Reports on Computer Systems Technology

The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology

(NIST) promotes the U.S. economy and public welfare by providing technical leadership for the nation‟s

measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of

concept implementations, and technical analysis to advance the development and productive use of

information technology. ITL‟s responsibilities include the development of technical, physical,

administrative, and management standards and guidelines for the cost-effective security and privacy of

sensitive unclassified information in Federal computer systems. This Special Publication 800-series

reports on ITL‟s research, guidance, and outreach efforts in computer security and its collaborative

activities with industry, government, and academic organizations.

National Institute of Standards and Technology Special Publication 500-292

Natl. Inst. Stand. Technol. Spec. Publ. 500-292, 35 pages (September 2011)

Certain commercial entities, equipment, or materials may be identified in this

document in order to describe an experimental procedure or concept adequately.

Such identification is not intended to imply recommendation or endorsement by the

National Institute of Standards and Technology, nor is it intended to imply that the

entities, materials, or equipment are necessarily the best available for the purpose.

ii

NIST SP 500-292

NIST Cloud Computing Reference Architecture

Acknowledgments

The authors, Fang Liu, Jin Tong, Jian Mao of Knowcean Consulting Inc. (services acquired via US

NAVY SPAWAR contract), Robert Bohn, John Messina, Lee Badger, Dawn Leaf of the National

Institute of Standards and Technology (NIST), wish to thank their colleagues who reviewed drafts of this

document and contributed to its technical content. The authors gratefully acknowledge and appreciate the

broad contributions from members of the NIST Cloud Computing Reference Architecture and Taxonomy

Working Group and the Reference Architecture Analysis Team.

All names are trademarks or registered trademarks of their respective owners.

Trademark Information

iii

NIST SP 500-292

NIST Cloud Computing Reference Architecture

Table of Contents

Executive Summary ............................................................................................................................. vi

1.

Introduction .................................................................................................................................... 1

1.1

Background ............................................................................................................................................ 1

1.2 Objectives ................................................................................................................................................ 1

1.3 How This Report Was Produced ..................................................................................................... 2

1.4

Structure of This Report .................................................................................................................... 2

2. Cloud Computing Reference Architecture: An Overview ................................................ 3

2.1

2.2

2.3

2.4

2.5

2.6

2.7

The Conceptual Reference Model ................................................................................................... 3

Cloud Consumer.................................................................................................................................... 5

Cloud Provider ...................................................................................................................................... 7

Cloud Auditor ........................................................................................................................................ 8

Cloud Broker .......................................................................................................................................... 8

Cloud Carrier ......................................................................................................................................... 8

Scope of Control between Provider and Consumer ................................................................. 9

3. Cloud Computing Reference Architecture: Architectural Components ................... 10

3.1

3.2

3.3

Service Deployment ......................................................................................................................... 10

Publicité

Service Orchestration ...................................................................................................................... 12

Cloud Service Management ........................................................................................................... 14

3.3.1

3.3.2

3.3.3

Business Support ...................................................................................................................................... 14

Provisioning and Configuration .......................................................................................................... 15

Portability and Interoperability ......................................................................................................... 15

3.4

Security ................................................................................................................................................. 15

3.4.1

3.4.2

3.4.3

Cloud Service Model Perspectives ..................................................................................................... 16

Implications of Cloud Deployment Models .................................................................................... 16

Shared Security Responsibilities ........................................................................................................ 16

3.5

Privacy .................................................................................................................................................. 17

4. Cloud Taxonomy .......................................................................................................................... 18

Appendix A: Cloud Taxonomy Terms and Definitions ........................................................... 20

Appendix B: Examples of Cloud Services .................................................................................... 24

Appendix C: Acronyms ...................................................................................................................... 26

Appendix D: References .................................................................................................................... 27

iv

NIST SP 500-292

NIST Cloud Computing Reference Architecture

List of Figures

Figure 1: The Conceptual Reference Model ............................................................................... 3

Figure 2: Interactions between the Actors in Cloud Computing .................................................. 4

Figure 3: Usage Scenario for Cloud Brokers .............................................................................. 4

Figure 4: Usage Scenario for Cloud Carriers .............................................................................. 5

Figure 5: Usage Scenario for Cloud Auditors ............................................................................. 5

Figure 6: Example Services Available to a Cloud Consumer ...................................................... 6

Figure 7: Cloud Provider - Major Activities ................................................................................. 7

Figure 8: Scope of Controls between Provider and Consumer ................................................... 9

Figure 10: On-site Private Cloud ...............................................................................................10

Figure 11: Out-sourced Private Cloud .......................................................................................11

Figure 12: On-site Community Cloud ........................................................................................11

Figure 13: Outsourced Community Cloud .................................................................................12

Figure 14: Hybrid Cloud ............................................................................................................12

Figure 15: Cloud Provider - Service Orchestration ....................................................................13

Figure 16: Cloud Provider - Cloud Service Management ...........................................................14

Figure 17: Cloud Taxonomy ......................................................................................................19

Table 1: Actors in Cloud Computing ........................................................................................... 4

List of Tables

v

NIST SP 500-292

NIST Cloud Computing Reference Architecture

Executive Summary

The adoption of cloud computing into the US Government (USG) and its implementation depend upon a

variety of technical and non-technical factors. A fundamental reference point, based on the NIST

definition of Cloud Computing, is needed to describe an overall framework that can be used government-

wide. This document presents the NIST Cloud Computing Reference Architecture (RA) and Taxonomy

(Tax) that will accurately communicate the components and offerings of cloud computing. The guiding

principles used to create the RA were 1) develop a vendor-neutral architecture that is consistent with the

NIST definition and 2) develop a solution that does not stifle innovation by defining a prescribed

technical solution. This solution will create a level playing field for industry to discuss and compare their

cloud offerings with the US Government (USG). The resulting reference architecture and taxonomy for

cloud computing was developed as an Actor/Role based model that lays out the central elements of cloud

computing for Federal CIOs, Procurement Officials and IT Program Managers. The cloudscape is open

and diversified and the accompanying taxonomy provides a means to describe it in an unambiguous

manner. The RA is presented in two parts: a complete overview of the actors and their roles and the

necessary architectural components for managing and providing cloud services such as service

deployment, service orchestration, cloud service management, security and privacy. The Taxonomy is

presented in its own section and appendices are dedicated to terms and definitions and examples of cloud

services.

The Overview of the Reference Architecture describes five major actors with their roles & responsibilities

using the newly developed Cloud Computing Taxonomy. The five major participating actors are the

Cloud Consumer, Cloud Provider, Cloud Broker, Cloud Auditor and Cloud Carrier. These core

individuals have key roles in the realm of cloud computing. For example, a Cloud Consumer is an

individual or organization that acquires and uses cloud products and services. The purveyor of products

and services is the Cloud Provider. Because of the possible service offerings (Software, Platform or

Infrastructure) allowed for by the cloud provider, there will be a shift in the level of responsibilities for

some aspects of the scope of control, security and configuration. The Cloud Broker acts as the

intermediate between consumer and provider and will help consumers through the complexity of cloud

service offerings and may also create value-added cloud services as well. The Cloud Auditor provides a

valuable inherent function for the government by conducting the independent performance and security

monitoring of cloud services. The Cloud Carrier is the organization who has the responsibility of

transferring the data akin to the power distributor for the electric grid.

The Architectural Components of the Reference Architecture describes the important aspects of service

deployment and service orchestration. The overall service management of the cloud is acknowledged as

an important element in the scheme of the architecture. Business Support mechanisms are in place to

recognize customer management issues like contracts, accounting and pricing and are vital to cloud

computing. A discussion on Provisioning and Configuration points out the requirements for cloud

systems to be available as needed, metered and have proper SLA management in place. Portability and

Interoperability issues for data, systems and services are crucial factors facing consumers in adopting the

cloud are also undertaken here. Consumers need confidence in moving their data and services across

multiple cloud environments.

As a major architectural component of the cloud, Security and Privacy concerns need to be addressed and

there needs to be a level of confidence and trust in order to create an atmosphere of acceptance in the

cloud‟s ability to provide a trustworthy and reliable system. Security responsibilities, security

consideration for different cloud service models and deployment models are also discussed.

Publicité

vi

NIST SP 500-292

NIST Cloud Computing Reference Architecture

1.

Introduction

1.1 Background

The National Institute of Standards and Technology (NIST) has been designated by Federal Chief

Information Officer (CIO) Vivek Kundra with technical leadership for US government (USG) agency

efforts related to the adoption and development of cloud computing standards. The goal is to accelerate

the federal government‟s adoption of secure and effective cloud computing to reduce costs and improve

services. The NIST strategy is to build a USG Cloud Computing Technology Roadmap which focuses on

the highest priority USG cloud computing security, interoperability and portability requirements, and to

lead efforts to develop standards and guidelines in close consultation and collaboration with standards

bodies, the private sector, and other stakeholders.

The NIST cloud computing program was formally launched in November 2010 to support the federal

government effort to incorporate cloud computing as a replacement for, or enhancement to, traditional

information system and application models where appropriate. The NIST cloud computing program

operates in coordination with other USG-wide cloud computing efforts (CIO Council/ISIMC, etc.) and is

integrated with the Federal 25-point IT Management Reform Plan1 and Federal Cloud Computing

Strategy2. NIST has created the following working groups in order to provide a technically-oriented

strategy and standards-based guidance for the federal cloud computing implementation effort:

Cloud Computing Target Business Use Cases Working Group

Cloud Computing Reference Architecture and Taxonomy Working Group

Cloud Computing Standards Roadmap Working Group

Cloud Computing SAJACC Working Group

Cloud Computing Security Working Group

1.2 Objectives

The NIST cloud computing definition [1] is widely accepted as a valuable contribution toward providing

a clear understanding of cloud computing technologies and cloud services. It provides a simple and

unambiguous taxonomy of three service models available to cloud consumers: cloud software as a service

(SaaS), cloud platform as a service (PaaS), and cloud infrastructure as a service (IaaS). It also

summarizes four deployment models describing how the computing infrastructure that delivers these

services can be shared: private cloud, community cloud, public cloud, and hybrid cloud. Finally, the NIST

definition also provides a unifying view of five essential characteristics that all cloud services exhibit: on-

demand self-service, broad network access, resource pooling, rapid elasticity, and measured service.

These services and their delivery are at the core of cloud computing. In the cloud computing model, the

primary focus is a more economic method of providing higher quality and faster services at a lower cost

to the users. In the traditional IT service delivery model, there is a large emphasis on procuring,

maintaining and operating the necessary hardware and related infrastructure. The cloud computing model

enables CIOs, IT project managers and procurement officials to direct their attention to innovative service

creation for the customers.

In order to have successful service delivery, the USG needs to ensure the reliability in the delivery of

products and processes. By ensuring durable and proper standards in place for cloud computing in

security, data portability and service interoperability, the USG will have the additional confidence needed

1Office of Management and Budget, U.S. Chief Information Officer Vivek Kundra, “25 Point Implementation Plan to Reform

Federal Information Technology Management”, December 2010. http://www.cio.gov/documents/25-Point-Implementation-

Plan-to-Reform-Federal%20IT.pdf

2Office of Management and Budget, U.S. Chief Information Officer Vivek Kundra, “Federal Cloud Computing Strategy”,

February 2011. http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf

1

NIST SP 500-292

NIST Cloud Computing Reference Architecture

to move their applications into the cloud. The necessary standards will also promote an even playing field

among cloud service providers and give the cloud service consumers a number of different options in the

marketplace and the confidence that their data and applications will operate on any cloud.

Standards for cloud computing are the overall goal of the NIST cloud computing program; the logical step

to take after the formation of the NIST cloud computing definition is to create an intermediate reference

point from where one can frame the rest of the discussion about cloud computing and begin to identify

sections in the reference architecture in which standards are either required, useful or optional. The NIST

cloud computing reference architecture presented in this document is a logical extension to the NIST

cloud computing definition. It is a generic high-level conceptual model that is an effective tool for

discussing the requirements, structures, and operations of cloud computing. The model is not tied to any

specific vendor products, services or reference implementation, nor does it define prescriptive solutions

that inhibit innovation. It defines a set of actors, activities and functions that can be used in the process of

developing cloud computing architectures, and relates to a companion cloud computing taxonomy. The

reference architecture contains a set of views and descriptions that are the basis for discussing the

characteristics, uses and standards for cloud computing. This actor/role based model is intended to serve

the expectations of the stakeholders by allowing them to understand the overall view of roles and

responsibilities in order to assess and assign risk.

The NIST cloud computing reference architecture focuses on the requirements of “what” cloud services

provide, not a “how to” design solution and implementation. The reference architecture is intended to

facilitate the understanding of the operational intricacies in cloud computing. It does not represent the

system architecture of a specific cloud computing system; instead it is a tool for describing, discussing,

and developing a system-specific architecture using a common framework of reference.

The design of the NIST cloud computing reference architecture serves the following objectives: to

illustrate and understand the various cloud services in the context of an overall cloud computing

conceptual model; to provide a technical reference to USG agencies and other consumers to understand,

discuss, categorize and compare cloud services; and to facilitate the analysis of candidate standards for

security, interoperability, and portability and reference implementations.

1.3 How This Report Was Produced

The NIST cloud computing reference architecture project team has surveyed and completed an initial

analysis of existing cloud computing reference models proposed by cloud organizations, vendors and

federal agencies. Based on available information, the project team developed a strawman model of

architectural concepts. This effort has leveraged the collaborative process from the NIST cloud computing

reference architecture and taxonomy working group that was active between November 2010 and April

2011. This process involves broad participation from the industry, academic, standards development

organizations (SDOs), and private and public sector cloud adopters. The project team has iteratively

revised the reference model by incorporating comments and feedback received from the working group.

This document reports the first edition of the NIST cloud computing reference architecture and taxonomy.

1.4 Structure of This Report

The remainder of this document is organized as follows: Section 2 presents the overview of the NIST

cloud computing reference architecture, lists the major actors and discusses the interactions among the

Publicité

actors. Section 3 drills down the details of the architectural components in the reference model. Section 4

depicts the associated taxonomy. The document also includes supporting materials in the appendices.

Appendix A lists the terms and definitions appearing in the taxonomy. Appendix B includes some

examples of cloud services. Appendix C and D list the acronyms and references used in the document,

respectively.

2

NIST SP 500-292

NIST Cloud Computing Reference Architecture

2. Cloud Computing Reference Architecture: An Overview

2.1 The Conceptual Reference Model

Figure 1 presents an overview of the NIST cloud computing reference architecture, which identifies the

major actors, their activities and functions in cloud computing. The diagram depicts a generic high-level

architecture and is intended to facilitate the understanding of the requirements, uses, characteristics and

standards of cloud computing.

Figure 1: The Conceptual Reference Model

As shown in Figure 1, the NIST cloud computing reference architecture defines five major actors: cloud

consumer, cloud provider, cloud carrier, cloud auditor and cloud broker. Each actor is an entity (a person

or an organization) that participates in a transaction or process and/or performs tasks in cloud computing.

Table 1 briefly lists the actors defined in the NIST cloud computing reference architecture. The general

activities of the actors are discussed in the remainder of this section, while the details of the architectural

elements are discussed in Section 3.

Figure 2 illustrates the interactions among the actors. A cloud consumer may request cloud services from

a cloud provider directly or via a cloud broker. A cloud auditor conducts independent audits and may

contact the others to collect necessary information. The details will be discussed in the following sections

and presented in increasing level of details in successive diagrams.

3

NIST SP 500-292

NIST Cloud Computing Reference Architecture

Actor

Definition

Cloud Consumer A person or organization that maintains a business relationship with, and

uses service from, Cloud Providers.

Cloud Provider

A person, organization, or entity responsible for making a service

available to interested parties.

Cloud Auditor

Cloud Broker

A party that can conduct independent assessment of cloud services,

information system operations, performance and security of the cloud

implementation.

An entity that manages the use, performance and delivery of cloud

services, and negotiates relationships between Cloud Providers and

Cloud Consumers.

Cloud Carrier

An intermediary that provides connectivity and transport of cloud

services from Cloud Providers to Cloud Consumers.

Table 1: Actors in Cloud Computing

Figure 2: Interactions between the Actors in Cloud Computing

Example Usage Scenario 1: A cloud consumer may request service from a cloud broker instead

of contacting a cloud provider directly. The cloud broker may create a new service by combining

multiple services or by enhancing an existing service. In this example, the actual cloud providers

are invisible to the cloud consumer and the cloud consumer interacts directly with the cloud

broker.

Figure 3: Usage Scenario for Cloud Brokers

4

NIST SP 500-292

NIST Cloud Computing Reference Architecture

Example Usage Scenario 2: Cloud carriers provide the connectivity and transport of cloud

services from cloud providers to cloud consumers. As illustrated in Figure 4, a cloud provider

participates in and arranges for two unique service level agreements (SLAs), one with a cloud

carrier (e.g. SLA2) and one with a cloud consumer (e.g. SLA1). A cloud provider arranges

service level agreements (SLAs) with a cloud carrier and may request dedicated and encrypted

connections to ensure the cloud services are consumed at a consistent level according to the

contractual obligations with the cloud consumers. In this case, the provider may specify its

requirements on capability, flexibility and functionality in SLA2 in order to provide essential

requirements in SLA1.

Figure 4: Usage Scenario for Cloud Carriers

Example Usage Scenario 3: For a cloud service, a cloud auditor conducts independent

assessments of the operation and security of the cloud service implementation. The audit may

involve interactions with both the Cloud Consumer and the Cloud Provider.

Figure 5: Usage Scenario for Cloud Auditors

2.2 Cloud Consumer

The cloud consumer is the principal stakeholder for the cloud computing service. A cloud consumer

represents a person or organization that maintains a business relationship with, and uses the service from

a cloud provider. A cloud consumer browses the service catalog from a cloud provider, requests the

appropriate service, sets up service contracts with the cloud provider, and uses the service. The cloud

consumer may be billed for the service provisioned, and needs to arrange payments accordingly.

Cloud consumers need SLAs to specify the technical performance requirements fulfilled by a cloud

provider. SLAs can cover terms regarding the quality of service, security, remedies for performance

failures. A cloud provider may also list in the SLAs a set of promises explicitly not made to consumers,

i.e. limitations, and obligations that cloud consumers must accept. A cloud consumer can freely choose a

cloud provider with better pricing and more favorable terms. Typically a cloud provider‟s pricing policy

and SLAs are non-negotiable, unless the customer expects heavy usage and might be able to negotiate for

better contracts. [2].

Depending on the services requested, the activities and usage scenarios can be different among cloud

consumers. Figure 6 presents some example cloud services available to a cloud consumer (For details, see

Appendix B: Examples of Cloud Services) [13].

5

NIST SP 500-292

NIST Cloud Computing Reference Architecture

Figure 6: Example Services Available to a Cloud Consumer

SaaS applications in the cloud and made accessible via a network to the SaaS consumers. The consumers

Publicité

of SaaS can be organizations that provide their members with access to software applications, end users

who directly use software applications, or software application administrators who configure applications

for end users. SaaS consumers can be billed based on the number of end users, the time of use, the

network bandwidth consumed, the amount of data stored or duration of stored data.

Cloud consumers of PaaS can employ the tools and execution resources provided by cloud providers to

develop, test, deploy and manage the applications hosted in a cloud environment. PaaS consumers can be

application developers who design and implement application software, application testers who run and

test applications in cloud-based environments, application deployers who publish applications into the

cloud, and application administrators who configure and monitor application performance on a platform.

PaaS consumers can be billed according to, processing, database storage and network resources consumed

by the PaaS application, and the duration of the platform usage.

Consumers of IaaS have access to virtual computers, network-accessible storage, network infrastructure

components, and other fundamental computing resources on which they can deploy and run arbitrary

software. The consumers of IaaS can be system developers, system administrators and IT managers who

are interested in creating, installing, managing and monitoring services for IT infrastructure operations.

IaaS consumers are provisioned with the capabilities to access these computing resources, and are billed

according to the amount or duration of the resources consumed, such as CPU hours used by virtual

computers, volume and duration of data stored, network bandwidth consumed, number of IP addresses

used for certain intervals..

6

NIST SP 500-292

NIST Cloud Computing Reference Architecture

2.3 Cloud Provider

A cloud provider is a person, an organization; it is the entity responsible for making a service available to

interested parties. A Cloud Provider acquires and manages the computing infrastructure required for

providing the services, runs the cloud software that provides the services, and makes arrangement to

deliver the cloud services to the Cloud Consumers through network access.

For Software as a Service, the cloud provider deploys, configures, maintains and updates the operation of

the software applications on a cloud infrastructure so that the services are provisioned at the expected

service levels to cloud consumers. The provider of SaaS assumes most of the responsibilities in managing

and controlling the applications and the infrastructure, while the cloud consumers have limited

administrative control of the applications.

For PaaS, the Cloud Provider manages the computing infrastructure for the platform and runs the cloud

software that provides the components of the platform, such as runtime software execution stack,

databases, and other middleware components. The PaaS Cloud Provider typically also supports the

development, deployment and management process of the PaaS Cloud Consumer by providing tools such

as integrated development environments (IDEs), development version of cloud software, software

development kits (SDKs), deployment and management tools. The PaaS Cloud Consumer has control

over the applications and possibly some the hosting environment settings, but has no or limited access to

the infrastructure underlying the platform such as network, servers, operating systems (OS), or storage.

For IaaS, the Cloud Provider acquires the physical computing resources underlying the service, including

the servers, networks, storage and hosting infrastructure. The Cloud Provider runs the cloud software

necessary to makes computing resources available to the IaaS Cloud Consumer through a set of service

interfaces and computing resource abstractions, such as virtual machines and virtual network interfaces.

The IaaS Cloud Consumer in turn uses these computing resources, such as a virtual computer, for their

fundamental computing needs Compared to SaaS and PaaS Cloud Consumers, an IaaS Cloud Consumer

has access to more fundamental forms of computing resources and thus has more control over the more

software components in an application stack, including the OS and network. The IaaS Cloud Provider, on

the other hand, has control over the physical hardware and cloud software that makes the provisioning of

these infrastructure services possible, for example, the physical servers, network equipments, storage

devices, host OS and hypervisors for virtualization.

A Cloud Provider‟s activities can be described in five major areas, as shown in Figure 7, a cloud provider

conducts its activities in the areas of service deployment, service orchestration, cloud service

management, security, and privacy. The details are discussed in Section 3.

Figure 7: Cloud Provider - Major Activities

7

NIST SP 500-292

NIST Cloud Computing Reference Architecture

2.4 Cloud Auditor

A cloud auditor is a party that can perform an independent examination of cloud service controls with the

intent to express an opinion thereon. Audits are performed to verify conformance to standards through

review of objective evidence. A cloud auditor can evaluate the services provided by a cloud provider in

terms of security controls, privacy impact, performance, etc.

Auditing is especially important for federal agencies as “agencies should include a contractual clause

enabling third parties to assess security controls of cloud providers” [4] (by Vivek Kundra, Federal Cloud

Computing Strategy, Feb. 2011.). Security controls [3] are the management, operational, and technical

safeguards or countermeasures employed within an organizational information system to protect the

confidentiality, integrity, and availability of the system and its information. For security auditing, a cloud

auditor can make an assessment of the security controls in the information system to determine the extent

to which the controls are implemented correctly, operating as intended, and producing the desired

outcome with respect to the security requirements for the system. The security auditing should also

include the verification of the compliance with regulation and security policy. For example, an auditor

can be tasked with ensuring that the correct policies are applied to data retention according to relevant

rules for the jurisdiction. The auditor may ensure that fixed content has not been modified and that the

legal and business data archival requirements have been satisfied.

A privacy impact audit can help Federal agencies comply with applicable privacy laws and regulations

governing an individual‟s privacy, and to ensure confidentiality, integrity, and availability of an

individual‟s personal information at every stage of development and operation [5].

2.5 Cloud Broker

As cloud computing evolves, the integration of cloud services can be too complex for cloud consumers to

manage. A cloud consumer may request cloud services from a cloud broker, instead of contacting a cloud

provider directly. A cloud broker is an entity that manages the use, performance and delivery of cloud

services and negotiates relationships between cloud providers and cloud consumers.

In general, a cloud broker can provide services in three categories [9]:

Service Intermediation: A cloud broker enhances a given service by improving some specific

capability and providing value-added services to cloud consumers. The improvement can be

managing access to cloud services, identity management, performance reporting, enhanced

security, etc.

Service Aggregation: A cloud broker combines and integrates multiple services into one or more

new services. T...