Paper
Virtustream: Enterprise-Class Security
and Compliance in the Cloud
Virtustream is a global CSP that focuses
specically on hosting mission-critical
workloads for large businesses. Customers
vary in size from midsize enterprises to
Fortune 500 and Global 2000 companies,
and they represent a broad range of
industries, including nancial services,
healthcare, retail, manufacturing, and
many others. Virtustream currently hosts
production SAP landscapes for more than
100 businesses, including many that are
using SAP HANA for real-time analytics
and for supporting SAP Business Suite
applications.
With its global scale and mission-critical
focus, Virtustream has the resources and
expertise to provide levels of security and
compliance that are as good as or better
than many businesses are able to provide
in their own data centers. Some of the
key safeguards that Virtustream provide
include the following:
• Enterprise-class data center security,
including both physical and logical
safeguards. Customers access their
systems and applications through
VPNs, and advanced rewalls block
digital attacks and unauthorized users
at multiple levels throughout the data
center (see Figure 2).
Backup
Virtustream Architecture on SAP HANA*
Core Network
xStream Enterprise Platform
Vormetric
Transparent Encryption
SAP HANA Managed Service
DMZ Platform
Management Platform
• VS DC 1: Production
• VS DC 1: Non-Prod/DR
Firewall
Storage
Compute
Network Switch
VPN
Public Landing Zone
Internet
VPN
Secure Customer Landing Zone
Site-to-Site
VPN
MPLS
Customer
Figure 2. The Virtustream enterprise cloud provides multiple layers of security to protect customer applications and data, including continuous
monitoring and analysis of logs to identify sophisticated attacks, such as advanced persistent threats.
• Advanced data protection and
residency control, since Virtustream
maintains physical separation of
customer data, enabling strong, disk-
level security protections that are not
possible in many cloud environments.
Customers can also stipulate data
residency requirements, so that
their data is restricted to specied
geographies or data centers. Vormetric
Data Security adds to these protections
by extending encryption coverage to
transaction logging and access controls,
and by ensuring that only the customer
can access the data.
5
Security in the Cloud for SAP HANA*