{"id":2475,"date":"2017-06-20T00:00:00","date_gmt":"2017-06-20T00:00:00","guid":{"rendered":""},"modified":"2018-05-09T12:21:24","modified_gmt":"2018-05-09T12:21:24","slug":"hadoop-cloud-security-fears","status":"publish","type":"post","link":"https:\/\/cazenasite.com\/?p=2475","title":{"rendered":"Don\u2019t Let Hadoop &#038; Cloud Security Fears Derail Your Path to Value"},"content":{"rendered":"<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2017\/06\/CloudSecurity.jpg\" style=\"float: right; max-width: 320px; margin-left: 10px;\"\/><\/p>\n<p><a href=\"https:\/\/www.sentierinformatics.com\" target=\"_blank\"><img decoding=\"async\" alt=\"Sentier Health Informatics\" src=\"\/wp-content\/uploads\/2017\/06\/64e320_c3da147686164600bfbba68478dc6d9c~mv2_1.png\" style=\"height: 84px; width: 536px;\" \/><\/a><br \/>\n<em>Guest blog from Rich Sokolosky&nbsp;&amp; Chael Christopher of <a href=\"http:\/\/sentierinformatics.com\" target=\"_blank\">Sentier Health Informatics<\/a>.<\/em><\/p>\n<hr \/>\n<p><strong>Don\u2019t Let Hadoop and Cloud Security Fears Derail Your Path to Value<\/strong><\/p>\n<p>As data practitioners, we have spent the last four years creating an enterprise data science environment for a life sciences client. We\u2019ve taken the project from an initial pilot on AWS (swiped a credit card!) to an analytic hub that houses 100TB of internally-owned data as well as data procured from syndicated data providers. &nbsp;The data sets are still growing, and they constitute the foundation of our client\u2019s analytics today. &nbsp;The toughest part of our big data journey was not standing up the different machines, dealing with the sources, generating the analytics, or running the updates. It was, and continues to be security.<\/p>\n<p>Hadoop from its inception was not designed with security as its primary mandate. To lock our environment up tight we needed to work fluently with AWS security groups and administration, Microsoft Active Directory, Cloudera Sentry, MIT Kerberos, encryption-at-rest, and transport layer security using SSL certificates. &nbsp;Oh, and we also had to do it all in an ecosystem of Amazon Workspaces that could communicate with the cluster.<\/p>\n<p>In a perfect world, the company\u2019s users would have accessed the environment from their own network but the challenges were too daunting. This means that all analytic tools (R, SAS, Tableau, etc.) and the Active Directory had to reside within the VPC, and have to integrate across all of the worker nodes. &nbsp;There are no external IPs\/firewalls into the environment, so we traded usability for security. &nbsp;While we solved all of the core security concerns from IT, we constrained the ways in which the environment can be used.<\/p>\n<p>We don\u2019t believe our experience accommodating all of the various security concerns was unusual. &nbsp;Yet, this security framework took two full-time Hadoop \/ network security engineers four months to design, setup, and test. It now takes one full time person to manage issues and grant\/change the permissions required for the growing user base and data.<\/p>\n<p>When thinking about a big data environment, security has to be addressed first. It has surpassed quality assurance as the number one concern. &nbsp;It is a tough, yet necessary nut to crack, and it will make or break a project given that all the patient level information these days has to pass rigorous compliance tests, and any hint of a breach will shut a project down indefinitely and immediately.<\/p>\n<p>There are many ways to address the compliance and end user needs and all will require a high degree of skill and experience. &nbsp;This begged us to ask this simple question: do we want to tolerate the lag and friction inherent to standing up a new Hadoop environment, or do we want to stay laser focused on delivering new insights and analytics to our clients vis-\u00e0-vis our data science sandboxes? &nbsp;We choose the latter \u2013 and we chose Cazena! &nbsp;<\/p>\n<table align=\"center\" bgcolor=\"CCCCCC\" border=\"1\" cellpadding=\"1\" cellspacing=\"1\" style=\"width:1010px;\">\n<tbody>\n<tr>\n<td class=\"rtecenter\" style=\"width: 1010px;\">\n<p><span style=\"font-size:16px;\"><br \/>\n\t\t\t<strong><em>Hear more true stories from the frontlines of life sciences analytics, direct from<br \/>\n\t\t\tRich and Chael in our joint webinar: <a href=\"http:\/\/go.cazena.com\/life-sci-cloud-analytics\" target=\"_blank\"><u>Watch the recording&nbsp;here<\/u><\/a>.<\/em><\/strong><\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>About Sentier Health Informatics:<\/strong><br \/>\nSentier Health Informatics is focused on one objective: &nbsp;getting healthcare information into the hands of analysts, data scientists, and decision makers in a timely and cost effective manner. We tackle information needs that fall outside traditional reporting and data warehousing. &nbsp;We provide adaptive services that utilize proven Big Data approaches and technologies to address the ever increasing speed at which information needs to be delivered. &nbsp;We believe \u201cconception to answer\u201d should be&nbsp;measured in hours and days not months and years and that follow up questions are the key to success. &nbsp;Sentier has decades of experience in healthcare and can anticipate client\u2019s analytic and&nbsp;information needs without any hand holding and we have a library of common analytics that can be deployed rapidly across our services. Learn more at <a href=\"http:\/\/www.sentierinformatics.com\/\" target=\"_blank\">www.sentierinformatics.com<\/a>.<\/p>\n<p><a href=\"http:\/\/www.cazena.com\/partners#tab_id_401\" target=\"_blank\">Read about more Cazena Consulting Partners here<\/a>.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cazena partner Sentier Health Informatics weighs in on their experiences navigating the complicated world of cloud security in a regulated industry. Sentier is focused on healthcare, life sciences, and insurance organizations who are quickly discovering that judicial use public cloud services is critical for competitive advantage in predictive analytics.<br \/>\n&nbsp;<\/p>\n","protected":false},"author":8,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[46],"class_list":["post-2475","post","type-post","status-publish","format-standard","hentry","category-blog","tag-technical"],"_links":{"self":[{"href":"https:\/\/cazenasite.com\/index.php?rest_route=\/wp\/v2\/posts\/2475","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cazenasite.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cazenasite.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cazenasite.com\/index.php?rest_route=\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/cazenasite.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2475"}],"version-history":[{"count":0,"href":"https:\/\/cazenasite.com\/index.php?rest_route=\/wp\/v2\/posts\/2475\/revisions"}],"wp:attachment":[{"href":"https:\/\/cazenasite.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2475"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cazenasite.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2475"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cazenasite.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2475"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}