Responsibility sharing for the Hosted Private Cloud by VMware service under the SecNumCloud qualification

View as Markdown

Responsibility sharing between OVHcloud and the customer for the use of the VMware on OVHcloud product under the SecNumCloud qualification

Objective

The RACI below details shared responsibilities between OVHcloud and the customer for the Hosted Private Cloud by VMware service under the SecNumCloud qualification. This model is designed to help the customer make the best use of the VMware on OVHcloud service.

Roles
R: Is in charge of carrying out the process
A: is Accountable for the successful completion of the process
C: Is Consulted during the process
I: Is Informed of the results of the process

1. Before subscription

1.1. Specify service as needed

ActivityCustomerOVHcloud
Choose the location of infrastructuresRAI
Size infrastructures as neededRAI
Choose options as neededRAI

2. Service availability

2.1. Install service

ActivityCustomerOVHcloud
Produce, route, deliver and maintain physical machines and hosting buildingsCIRA
Purchase and own the licences and rights of use for the OS purchased from OVHcloudRIRA
Purchase and own the licences and rights of use for softwares provided by OVHcloudIRA
Purchase and own the licences and rights of use for the VMware solution (Private Cloud)IRA
Purchase and own the licences and rights of use for the backup solutions provided by OVHcloudIRA
Deploy the initial service in compliance with the SecNumCloud frameworkIRA
Deploy the initial network configuration to devicesIRA

2.2. Reversibility

ActivityCustomerOVHcloud
Provide the technical documentation corresponding to the SecNumCloud offerIRA
Draft a business continuity and disaster recovery plan for the hosted IS, in line with the sensitivity of the hosted ISRA

2.3. Customer's IS installation

ActivityCustomerOVHcloud
Create / install / optimise new VMsRAI
Install and configure softwares and middlewares on the Infrastructure as a ServiceRA
Purchase and own the licences and rights of use for OS with Bring Your Own Licence modeRA
Configure virtual instances deployed on the IaaSRAI

3. Service Usage

3.1. Operations

3.1.1. Daily operations
ActivityCustomerOVHcloud
Operate all the virtual instances deployed in the IaaSRAI
Decide to add/remove resources on the virtual datacentreRAI
Add/remove resources on the virtual datacentreIRA
Add/remove resources on VMsRA
3.1.2. Access management
ActivityCustomerOVHcloud
Manage access and security policy of the Service usersRA
Manage physical and logical access of OVHcloud teams to the infrastructuresIRA
Manage access to the Control PanelRAI
Manage access to the virtualisation management interfaceRAI
3.1.3. Monitoring
ActivityCustomerOVHcloud
Monitor the proper functioning of physical devices (utilities) supporting the Infrastructure as a ServiceIRA
Monitor physical resource performancesRIA
Monitor VMs performancesRAI
Process and acknowledge alarms from managed devices of the Infrastructure as a ServiceIRA
Keep logs generated by the Infrastructure as a ServiceIRA
Keep logs of the information system hosted on the Infrastructure as a ServiceRAI
3.1.4. Storage
ActivityCustomerOVHcloud
Create, modify, control, restore, delete backup jobsRA
Manage content hosted on infrastructuresRA
Manage data continuity and integrityRA
Carry out maintenance on the storage and backup devices provided by OVHcloudCRA
3.1.5. Connectivity
ActivityCustomerOVHcloud
Manage the functioning of automatic network management systems (architecture, implementation, software and hardware maintenance for deployed public and private networks)IRA
Manage IP addressing planRAI
3.1.6. Management
ActivityCustomerOVHcloud
Maintain an inventory of devices provided by OVHcloudIRA
Maintain a complete inventory of all devicesRA
Draft and provide a monthly report on the handling of incidents, changes and requests handled by OVHcloudIRA
Maintain and provide the technical documentation corresponding to the SecNumCloud offerIRA
Manage security of the management infrastructures (API, SSL Gateway) of the IaaSIRA
Manage security of the hosted management infrastructures (API, bastion, etc.)RAI
Manage security of VMsRAI
Manage security of softwares and middlewares installed on VMsRAI
Manage security of data placed by the Customer on the IaaSRAI
Manage physical security of equipment and infrastructures hosted at OVHcloudIRA
Maintain the VMware managed solution and its extensionsCRA
Carry out the commercial and contractual follow-up of the Customer (quote, order, delivery and invoicing)IRA
Carry out the commercial and contractual follow-up of the service provided (quote, order, delivery and invoicing)RAI
Obtain expert support through the Technical Account ManagerAR
3.1.7. Business continuity
ActivityCustomerOVHcloud
Manage automatic management systems for the infrastructure providedIRA
Maintain a business continuity and disaster recovery plan for the hosted ISRAC

3.2. Event management

3.2.1. Incidents
ActivityCustomerOVHcloud
Replace the defective hardware elements in support of the IaaSIRA
Intervene on the managed elements of the IaaSCRA
Qualify incidents occurring on the managed elements of the IaaSCRA
Draft and provide a post-mortem analysisCRA
Cooperate with OVHcloud as part of incident resolutionRACI
Cooperate with the Customer as part of incident resolutionCIRA

3.2.2. Change

ActivityCustomerOVHcloud
Deploy patches, updates and configurations on softwares, middlewares and IS hosted on the IaaSRAC
Optimise VMsRAC
Validate the request for an infrastructure hardware change submitted by OVHcloudAR
Update the components embedded in the virtual instancesRAC
Plan changes requested by the customerCRA
Carry out the changes required to maintain the compliance of the IaaS with SecNumCloudIRA
Issue the acceptanceRAC
Deploy patches, updates and configurations on all the constituent elements of the Infrastructure as a ServiceIRA
Deploy patches, updates and configurations on all the constituent elements of the information system hosted on the IaaSRAC
Carry out preventive interventions on the managed elements of the IaaSAR
Update the hypervisorIRA
Update VMsRAI

4. Reversibility

4.1. Reversibility model

ActivityCustomerOVHcloud
Schedule reversibility operationsRAI
Choose fallback infrastructuresRA

4.2. Data recovery

ActivityCustomerOVHcloud
Manage reversibility operationsRAI
Migrate/transfer dataRA

5. End of service

5.1. Destroying configurations

ActivityCustomerOVHcloud
Request the end of all or part of the ServiceRAI
Uncommission the Private Cloud configurations and options associated with the customer following contract terminationIRA

5.2. Data destruction

ActivityCustomerOVHcloud
Securely destroy data on storage mediaRA
Destroy storage media that has reached their end of life or when the secure destruction processes are generating errorsRA
Provide a certificate of destruction (upon request)IRA
Was this page helpful?