Ir directamente a la navegación principal Ir directamente a la búsqueda Ir directamente al contenido principal

Methodology to obtain the security controls in multi-cloud applications

  • Samuel Olaiya Afolaranmi
  • , Luis E. Gonzalez Moctezuma
  • , Massimiliano Rak
  • , Valentina Casola
  • , Erkuden Rios
  • , Jose L. Martinez Lastra

Producción científica: Capítulo del libro/informe/acta de congresoContribución a la conferenciarevisión exhaustiva

9 Citas (Scopus)
21 Descargas (Pure)

Resumen

What controls should be used to ensure adequate security level during operation is a non-trivial subject in complex software systems and applications. The problem becomes even more challenging when the application uses multiple cloud services which security measures are beyond the control of the application provider. In this paper, a methodology that enables the identification of the best security controls for multicloud applications which components are deployed in heterogeneous cloud providers is presented. The methodology is based on application decomposition and modelling of threats over the components, followed by the analysis of the risks together with the capture of cloud business and security requirements. The methodology has been applied in the MUSA EU H2020 project use cases as the first step for building up the multi-cloud applications’ security-aware Service Level Agreements (SLA). The identified security controls will be included in the applications’ SLAs for their monitoring and fulfilment assurance at operation.
Idioma originalInglés
Título de la publicación alojadaunknown
EditoresJorge Cardoso, Jorge Cardoso, Donald Ferguson, Victor Mendez Munoz, Markus Helfert
EditorialSCITEPRESS Digital Library
Páginas327-332
Número de páginas6
ISBN (versión digital)9789897581823
ISBN (versión impresa)978-989-758-182-3
DOI
EstadoPublicada - 2016
Evento6th International Conference on Cloud Computing and Services Science, CLOSER 2016 - Rome, Italia
Duración: 23 abr 201625 abr 2016

Serie de la publicación

Nombre1

Conferencia

Conferencia6th International Conference on Cloud Computing and Services Science, CLOSER 2016
País/TerritorioItalia
CiudadRome
Período23/04/1625/04/16

Palabras clave

  • Multi-cloud
  • Security-by-design
  • Cyber-security methodologies
  • Threat modelling

Project and Funding Information

  • Project ID
  • info:eu-repo/grantAgreement/EC/H2020/644429/EU/MUlti-cloud Secure Applications/MUSA
  • Funding Info
  • European Commission's H2020

Huella

Profundice en los temas de investigación de 'Methodology to obtain the security controls in multi-cloud applications'. En conjunto forman una huella única.

Citar esto