首页> 外文会议>IFIP WG 11.11 international conference on trust management >Investigating Security Capabilities in Service Level Agreements as Trust-Enhancing Instruments
【24h】

Investigating Security Capabilities in Service Level Agreements as Trust-Enhancing Instruments

机译:调查服务级别协议中的安全功能作为增强信任的工具

获取原文

摘要

Many government agencies (GAs) increasingly rely on external computing, communications and storage services supplied by service providers (SPs) to process, store or transmit sensitive data to increase scalability and decrease the costs of maintaining services. The relationships with external SPs are usually established through service level agreements (SLAs) as trust-enhancing instruments. However, there is a concern that existing SLAs are mainly focused on the system availability and performance aspects, but overlook security in SLAs. In this paper, we investigated 'real world' SLAs in terms of security guarantees between GAs and external SPs, using Indonesia as a case study. This paper develops a grounded adaptive Delphi method to clarify the current and potential attributes of security-related SLAs that are common among external service offerings. To this end, we conducted a longitudinal study of the Indonesian government auctions of 59 e-procurement services from 2010-2016 to find 'auction winners'. Further, we contacted five selected major SPs (n = 15 participants) to participate in a three-round Delphi study. Using a grounded theory analysis, we examined the Delphi study data to categorise and generalise the extracted statements in the process of developing propositions. We observed that most of the GAs placed significant importance on service availability, but security capabilities of the SPs were not explicitly expressed in SLAs. Additionally, the GAs often use the provision of service availability to demand additional security capabilities supplied by the SPs. We also observed that most of the SPs found difficulties in addressing data confidentiality and integrity in SLAs. Overall, our findings call for a proposition-driven analysis of the Delphi study data to establish the foundation for incorporating security capabilities into security-related SLAs.
机译:许多政府机构(GA)越来越依赖服务提供商(SP)提供的外部计算,通信和存储服务来处理,存储或传输敏感数据,以提高可伸缩性并降低维护服务的成本。与外部SP的关系通常是通过服务级别协议(SLA)建立的,作为增强信任的工具。但是,存在一个担忧,即现有的SLA主要集中在系统可用性和性能方面,而忽略了SLA中的安全性。在本文中,我们以印度尼西亚为例研究了GA与外部SP之间的安全保障方面的“现实世界” SLA。本文开发了一种扎根的自适应Delphi方法,以阐明在外部服务产品中常见的与安全相关的SLA的当前和潜在属性。为此,我们对印度尼西亚政府在2010-2016年间拍卖的59种电子采购服务进行了纵向研究,以寻找“拍卖优胜者”。此外,我们联系了五个选定的主要SP(n = 15名参与者)以参加为期三轮的Delphi研究。使用扎根的理论分析,我们研究了Delphi研究数据,以在提出命题的过程中对提取的陈述进行分类和归纳。我们观察到,大多数GA都非常重视服务的可用性,但是SP的安全功能并未在SLA中明确表达。另外,GA经常使用服务可用性的提供来要求SP提供的其他安全功能。我们还观察到,大多数SP都在解决SLA中的数据机密性和完整性方面遇到困难。总体而言,我们的发现要求对Delphi研究数据进行以命题驱动的分析,从而为将安全功能纳入与安全相关的SLA中奠定基础。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号