The typical implementation process for Cloudaware:
Typical Implementation Steps:
Assessment and Planning:
Evaluate the organization's cloud infrastructure and security requirements.
Define objectives and success criteria for the Cloudaware deployment.
Develop a detailed implementation roadmap.
Platform Deployment:
Deploy the Cloudaware Configuration Management Database (CMDB) module to enable comprehensive discovery and provide a detailed, up-to-date inventory of cloud resources.
Integrate Cloudaware with existing security and IT management tools.
Configuration and Customization:
Configure custom policies and workflows to align with the organization's security requirements.
Set up approval processes and change management protocols as needed.
Training and Onboarding:
Conduct training sessions for IT and security teams to ensure effective use of the Cloudaware platform.
Provide documentation and support resources to facilitate user adoption.
Monitoring and Optimization:
Perform ongoing monitoring of the cloud environment using Cloudaware's tools.
Cloudaware is designed to be highly customizable to meet specific business needs. The platform offers a range of features that allow organizations to tailor its functionalities to their unique requirements:
Custom Fields and Objects:
Adding Custom Fields: Users can enhance existing cloud objects by adding custom fields to store additional information pertinent to their operations.
Creating Custom Objects: Beyond predefined objects, Cloudaware allows the creation of entirely new custom objects to represent unique entities within an organization's infrastructure.
Formula and Derived Fields: The platform supports the creation of formula fields, enabling users to define calculations or derive values based on other fields. This is useful for estimating costs or assessing performance metrics.
Compliance Engine Customization:
Policy Development: Cloudaware Compliance Engine comes with over 450 pre-engineered policies and supports the development of custom policies using standard programming languages. This allows businesses to enforce security, reliability, and performance standards tailored to their specific needs.
Exception Handling: Advanced exception handling processes enable users to manage policy violations effectively, accommodating unique operational scenarios.
Workflow Automation: Users can define custom workflows to automate actions triggered by specific events, such as sending notifications, creating tasks, or enforcing policies. This enhances operational efficiency by aligning the platform's behavior with business processes.
Tag Management and Normalization: Cloudaware provides tools to manage and normalize tags across cloud resources, ensuring consistency and aiding in resource organization. This is particularly beneficial for enforcing tagging standards and improving resource tracking.
Integration Capabilities: The platform integrates with over 50 additional source types, including monitoring systems, ticketing tools, and security scanners, allowing businesses to consolidate data from various systems into a unified view.
Cloudaware offers a comprehensive support framework to assist new users in effectively utilizing their platform:
Training and Onboarding
Customized Training Sessions: Cloudaware provides tailored training sessions to meet the specific needs of organizations. For instance, during the implementation with Coca-Cola, Cloudaware conducted training focused on effectively leveraging the CMDB, Change Management, and Compliance Engine modules.
Documentation and Resources
Extensive Documentation: Cloudaware maintains a detailed documentation portal that covers various aspects of the platform, including supported objects, integrations, and configuration guides. This resource is invaluable for new users seeking to understand and navigate the platform's capabilities.
Customer Support:
Cloudaware implements a set of security measures to protect user data and ensure the integrity of its cloud management platform:
Data Encryption:
Salesforce Shield Platform Encryption: Cloudaware leverages the Salesforce Shield Platform to encrypt sensitive data within its Configuration Management Database (CMDB). This includes field- and record-level encryption using customer-managed keys, providing an additional layer of data confidentiality.
Vulnerability Management:
Integration with Qualys: Cloudaware integrates with Qualys, a cloud-based solution that detects vulnerabilities across networked assets. This integration enhances the CMDB by providing data on vulnerability statuses, scan dates, and criticality levels, enabling proactive security management.
Configuration Management:
Automated Discovery and Mapping: Utilizing tools like Discovery and Dependency Mapping, Cloudaware automates the tracking of infrastructure changes. This ensures that configuration data is accurate and up-to-date, reducing the risk of misconfigurations that could lead to security vulnerabilities.
Compliance and Governance:
Policy Enforcement: Cloudaware Compliance Engine supports the development and enforcement of custom policies using standard programming languages. This allows businesses to maintain adherence to internal security requirements and regulatory standards.
Access Control:
Cloudaware policies on data ownership and portability are designed to ensure that customers retain control over their data within the platform.
Data Ownership:
Customer Data Control: Cloudaware operates as a container application within Salesforce's App Cloud environment. The platform's role is limited to updating, deleting, and inserting data into the Configuration Management Database CMDB within the customer's Salesforce instance. There are no automated processes that export customer data outside of this environment. Additionally, Cloudaware's internal security policy explicitly prohibits exporting customer data beyond the customer's Salesforce instance.
Data Portability:
Cloudaware Master Subscription Agreement outlines specific terms regarding contract renewal and cancellation:
Contract Renewal:
Automatic Renewal: The agreement is set for an initial term of one year and will automatically renew for successive one-year periods unless either party provides written notice of non-renewal at least 30 days before the current term ends.
Contract Cancellation:
Termination for Cause: Either party may terminate the agreement for cause under the following conditions:
Providing 30 days' written notice to the other party in the event of a material breach, if such breach remains uncured at the end of this period.
If the other party becomes the subject of bankruptcy proceedings or any other proceedings related to insolvency, receivership, liquidation, or assignment for the benefit of creditors.
Refunds Upon Termination: If the agreement is terminated for cause by the customer, Cloudaware will refund any prepaid fees covering the remainder of the subscription term after the termination date.
Cloudaware Compliance Engine is designed to help organizations adhere to a variety of industry standards and regulatory frameworks. It offers over 550 pre-built policies and benchmarks that align with best practices and requirements from several key standards, including:
CIS (Center for Internet Security) Benchmarks
ISO (International Organization for Standardization)
HIPAA (Health Insurance Portability and Accountability Act)
PCI (Payment Card Industry Data Security Standard)
GDPR (General Data Protection Regulation)
SOC 2 (Service Organization Control 2)
NIST (National Institute of Standards and Technology)
FedRAMP (Federal Risk and Authorization Management Program)