2019
DOI: 10.1049/iet-sen.2018.5293
|View full text |Cite
|
Sign up to set email alerts
|

Service level agreement‐based GDPR compliance and security assurance in(multi)Cloud‐based systems

Abstract: Compliance with the new European General Data Protection Regulation (Regulation (EU) 2016/679) and security assurance are currently two major challenges of Cloud-based systems. GDPR compliance implies both privacy and security mechanisms definition, enforcement and control, including evidence collection. This paper presents a novel DevOps framework aimed at supporting Cloud consumers in designing, deploying and operating (multi)Cloud systems that include the necessary privacy and security controls for ensuring… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
5
0

Year Published

2020
2020
2023
2023

Publication Types

Select...
6
3
1

Relationship

1
9

Authors

Journals

citations
Cited by 28 publications
(10 citation statements)
references
References 11 publications
0
5
0
Order By: Relevance
“…It enables the production of an audit trail for cloud providers through a fully distributed, secure and consensus-based approach [23]. A framework for supporting cloud users in designing and deploying multi-cloud systems was presented in [25]. Although the framework made use of GDPR rules for ensuring data privacy of cloud users, it lacked a Blockchain-based technique to automatically verify such rules on processing activities carried out by providers on user data.…”
Section: Related Workmentioning
confidence: 99%
“…It enables the production of an audit trail for cloud providers through a fully distributed, secure and consensus-based approach [23]. A framework for supporting cloud users in designing and deploying multi-cloud systems was presented in [25]. Although the framework made use of GDPR rules for ensuring data privacy of cloud users, it lacked a Blockchain-based technique to automatically verify such rules on processing activities carried out by providers on user data.…”
Section: Related Workmentioning
confidence: 99%
“…Blockchain has also been considered as a technology to facilitate GDPR compliance by Aujla et al (2020) , who propose an architecture for compliance provisioning, monitoring, verification, and enforcement. For GDPR compliance, as well as security assurance, Rios et al (2019) present the DevOps framework to support the design, deployment and operation of cloud systems. The framework considers the privacy and security controls necessary to ensure transparency to end-users, third parties involved in service provision, and authorities.…”
Section: Related Workmentioning
confidence: 99%
“…Rios et al [19] proposed a new DevOps architecture intended at assisting Cloud consumer in deploying, designing and functioning (multi) Cloud systems which contain the required security and privacy controls to ensure law enforcement authorities, transparency for end users and third-party in service provisions. The architecture is based on the risk driven requirement at implementation time of security and privacy levels objective in the continuous enforcement and service level agreement and observing at run-time.…”
Section: Review Of Existing Security Related Solutions For Multi-cloud Architecturesmentioning
confidence: 99%