2016 IEEE International Conference on Cloud Engineering Workshop (IC2EW) 2016
DOI: 10.1109/ic2ew.2016.20
|View full text |Cite
|
Sign up to set email alerts
|

Harmonized Monitoring for High Assurance Clouds

Abstract: Due to a lack of transparency in cloud based services well-defined security levels cannot be assured within current cloud infrastructures. Hence sectors with stringent security requirements hesitate to migrate their services to the cloud. This applies especially when considering services where high security requirements are combined with legal constraints. To tackle this challenge this paper presents an extension to our existing work on assurance methodologies in cloud based environments by investigating how c… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
8
0

Year Published

2017
2017
2024
2024

Publication Types

Select...
3
2
1

Relationship

4
2

Authors

Journals

citations
Cited by 8 publications
(8 citation statements)
references
References 10 publications
0
8
0
Order By: Relevance
“…The monitoring and standard compliance framework, built on our previous work [7], uses an Evidence Gathering Mechanism (EGM) to collect evidence from a number of components in the target system based on a set of measurable indicator points (MIPs). The MIPs, categorized in measurable security indicators (MSI), measurable safety indicators (MSFI) and other organizational indicators related to legal (MSLI), are extracted from existing standards and guidelines to address target system specific requirements (e.g.…”
Section: Fig 1: High Level View Of Standard Compliance Verificationmentioning
confidence: 99%
“…The monitoring and standard compliance framework, built on our previous work [7], uses an Evidence Gathering Mechanism (EGM) to collect evidence from a number of components in the target system based on a set of measurable indicator points (MIPs). The MIPs, categorized in measurable security indicators (MSI), measurable safety indicators (MSFI) and other organizational indicators related to legal (MSLI), are extracted from existing standards and guidelines to address target system specific requirements (e.g.…”
Section: Fig 1: High Level View Of Standard Compliance Verificationmentioning
confidence: 99%
“…In order to provide adequate security and safety levels for such a framework to function properly, services such as, authorization, authentication, certificate distribution, security logging and service intrusion are considered as well. Even though the focus of the project is to provide interoperability between devices using the ARROWHEAD framework and to integrate automation systems in these devices, security and safety aspects are also 6 www.arrowhead.eu considered. However legal (e.g., SLAs) aspects are not in the focus of the project.…”
Section: Relevant Activities In Cppsmentioning
confidence: 99%
“…The goal of this work is to provide an approach towards CPPS transparency and trustworthiness by considering the cloud and the edge devices as highly networked systems, incorporating a large number of IT systems and automation components. We consider security as not independent from other issues such as legal and safety and we will enhance our previous work [6] to address security in the CPPS with a special focus on secure end-to-end communication in Industry 4.0.…”
Section: Relevant Activities In Cppsmentioning
confidence: 99%
See 1 more Smart Citation
“…The following list describes the proposed process steps in detail: 1) Define: the process starts by identifying and defining security risks for a cloud service. This can be achieved either by implementing a monitoring system [25] or by using any other method to identify security issues. In our use case the OWASP top 10 cloud security risks list was used and categorized by relevance and severity of consequences.…”
Section: Six Sigmamentioning
confidence: 99%