Ir directamente a la navegación principal Ir directamente a la búsqueda Ir directamente al contenido principal

Medina: Improving cloud services trustworthiness through continuous audit-based certification: Improving cloud services trustworthiness through continuous audit-based certification

  • Leire Orue-Echevarria
  • , Jesus Luna Garcia
  • , Christian Banse
  • , Juncal Alonso
  • Robert Bosch GmbH
  • Fraunhofer Institute for Applied and Integrated Security

Producción científica: Contribución a una revistaArtículo de la conferenciarevisión exhaustiva

4 Citas (Scopus)
7 Descargas (Pure)

Resumen

One of the reasons of the still limited adoption of Cloud Computing in the EU is the EU customers' perceived lack of security and transparency in this technology. Cloud service providers (CSPs) usually rely on security certifications as a mean to improve transparency and trustworthiness, however European CSPs still face multiple challenges for certifying their services (e.g., fragmentation in the certification market, and lack of mutual recognition). In this context, the EU Cybersecurity Act (EU CSA) proposes improving customer's trust in the European ICT market through a European certification scheme (EUCS). The proposed cloud security certification scheme conveys new technological challenges including the notion of automated monitoring for the whole supply chain, which needs to be solved in order to bring all the expected benefits to EU cloud providers and customers. In this context, MEDINA proposes a framework for supporting a continuous audit-based certification for CSPs based on EU CSA's scheme for cloud security certification. MEDINA will tackle challenges in areas like security validation/ testing, machine-readable certification language, cloud security performance, and audit evidence management. MEDINA will provide and empirically validate sustainable outcomes in order to benefit EU adopters.

Idioma originalInglés
Páginas (desde-hasta)16-23
Número de páginas8
PublicaciónCEUR Workshop Proceedings
Volumen2878
EstadoPublicada - mar 2021
Evento1st SWForum Workshop on Trustworthy Software and Open Source, TSOS 2021 - Virtual, Online
Duración: 23 mar 202125 mar 2021

ODS de las Naciones Unidas

Este resultado contribuye a los siguientes Objetivos de Desarrollo Sostenible

  1. ODS 12: Producción y consumo responsables
    ODS 12: Producción y consumo responsables

Palabras clave

  • Cloud certification scheme
  • Cybersecurity Act
  • Continuous auditing
  • Continuous certification
  • Smart contracts
  • Certification language

Project and Funding Information

  • Project ID
  • info:eu-repo/grantAgreement/EC/H2020/952633/EU/Security framework to achieve a continuous audit-based certificationn in compliance with the EU-wide cloud security certification scheme/MEDINA
  • Funding Info
  • This work has been partially funded by the European project MEDINA (Horizon 2020 research and innovation Programme, under grant agreement no 952633).

Huella

Profundice en los temas de investigación de 'Medina: Improving cloud services trustworthiness through continuous audit-based certification: Improving cloud services trustworthiness through continuous audit-based certification'. En conjunto forman una huella única.

Citar esto