首页> 外文会议>IFIP WG 11.11 international conference on trust management >Investigating Security Capabilities in Service Level Agreements as Trust-Enhancing Instruments
【24h】

Investigating Security Capabilities in Service Level Agreements as Trust-Enhancing Instruments

机译:调查服务水平协议中的安全能力作为信任增强仪器

获取原文

摘要

Many government agencies (GAs) increasingly rely on external computing, communications and storage services supplied by service providers (SPs) to process, store or transmit sensitive data to increase scalability and decrease the costs of maintaining services. The relationships with external SPs are usually established through service level agreements (SLAs) as trust-enhancing instruments. However, there is a concern that existing SLAs are mainly focused on the system availability and performance aspects, but overlook security in SLAs. In this paper, we investigated 'real world' SLAs in terms of security guarantees between GAs and external SPs, using Indonesia as a case study. This paper develops a grounded adaptive Delphi method to clarify the current and potential attributes of security-related SLAs that are common among external service offerings. To this end, we conducted a longitudinal study of the Indonesian government auctions of 59 e-procurement services from 2010-2016 to find 'auction winners'. Further, we contacted five selected major SPs (n = 15 participants) to participate in a three-round Delphi study. Using a grounded theory analysis, we examined the Delphi study data to categorise and generalise the extracted statements in the process of developing propositions. We observed that most of the GAs placed significant importance on service availability, but security capabilities of the SPs were not explicitly expressed in SLAs. Additionally, the GAs often use the provision of service availability to demand additional security capabilities supplied by the SPs. We also observed that most of the SPs found difficulties in addressing data confidentiality and integrity in SLAs. Overall, our findings call for a proposition-driven analysis of the Delphi study data to establish the foundation for incorporating security capabilities into security-related SLAs.
机译:许多政府机构(天然气)越来越依赖服务提供商(SPS)提供的外部计算,通信和存储服务来处理,存储或传输敏感数据以提高可扩展性并降低维护服务的成本。与外部SPS的关系通常通过服务级别协议(SLA)作为信任增强仪器建立。但是,担心现有的SLA主要集中在系统可用性和性能方面,而是忽略了SLA中的安全性。在本文中,我们在使用印度尼西亚作为案例研究中调查了天然气和外部SPS之间的安全保障的“真实世界”的SLA。本文开发了一个接地的自适应Delphi方法,以阐明外部服务提供的安全相关的SLA的当前和潜在属性。为此,我们对2010 - 2016年从2010 - 2016年的印度尼西亚政府拍卖进行了纵向研究,以查找“拍卖获奖者”。此外,我们联系了五个选定的主要SPS(N = 15名参与者),参与了三往返Delphi研究。使用接地的理论分析,我们检查了Delphi研究数据,在制定命题过程中分类和概括提取的陈述。我们观察到,大多数天然气对服务可用性具有重要意义,但SPS的安全能力在SLA中没有明确表达。此外,气体通常使用提供服务可用性来要求SPS提供的额外安全功能。我们还观察到,大多数SPS在解决SLA中解决数据机密性和完整性方面发现了困难。总的来说,我们的调查结果要求Delphi研究数据的命题驱动分析,为将安全功能纳入与安全相关的SLA来建立基础。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号