首页> 外文学位 >A holistic approach to cloud security certification.
【24h】

A holistic approach to cloud security certification.

机译:云安全认证的整体方法。

获取原文
获取原文并翻译 | 示例

摘要

Companies and government organizations are increasingly compelled, if not required by law, to ensure that their information systems will comply with various federal and industry regulatory standards, such as the Health Insurance Portability and Accountability Act (HIPAA), the NIST Special Publication on Security Controls for Federal Information Systems (NIST SP-800-53), or the Common Criteria (ISO 15408-2). Such organizations operate business or mission critical systems where a lack of or lapse in security protections translates to serious confidentiality, integrity, and availability risks that, if exploited, could result in information disclosure, loss of money, or, at worst, loss of life. To mitigate these risks and ensure that their information systems meet regulatory standards, organizations must be able to a) contextualize regulatory documents in a way that extracts the relevant technical implications for their systems, b) formally represent their systems and demonstrate that they meet the extracted requirements following an accreditation process, and c) ensure that all third party systems, which may exist outside of the information system enclave as third-party web services in the cloud, also implement appropriate security measures consistent with organizational expectations.;Each part of this process has specific challenges associated with it. First, regulatory documents, originally designed with locally managed "in house" information systems in mind, are being interpreted and scaled to a cloud context without the formal underpinnings necessary for their common expression. Second, current system certification processes rely on a static system model that is not realistic for organizational systems on the cloud. Finally, organizations using third party web services cannot assess their regulatory compliance. They can neither inspect third party service designs nor replace a trusted service if it goes down, since there is no current method to assess vertical security compatibility. To resolve these issues, this work advocates a common expression methodology that consistently extracts technical requirements from regulatory documents in a way that is amenable to the cloud and facilitates both contextualization and reuse by other organizations following the same regulatory standard. A new formal design language, called Cloud X-UNITY, extends existing coordination language models to allow for reasoning over extracted regulatory requirements to prove a cloud's compliance with security expectations. Finally, a Service Level Agreement framework, called SecAgreement, and two accompanying matchmaking algorithms are developed for attaching compliance requirements and risk analysis information to cloud web services and automatically selecting the service that best meets consumer compliance requirements. Overall the combination forms a single compliance assessment approach.
机译:公司和政府组织越来越被迫(即使法律没有要求)确保其信息系统符合各种联邦和行业监管标准,例如《健康保险可移植性和责任法案》(HIPAA),NIST安全控制特别出版物适用于联邦信息系统(NIST SP-800-53)或通用标准(ISO 15408-2)。此类组织在业务或任务关键型系统上运行,其中缺乏安全保护或安全保护失效会导致严重的机密性,完整性和可用性风险,如果利用这些风险,可能会导致信息泄露,资金损失,或者最严重的是造成生命损失。为了减轻这些风险并确保其信息系统符合监管标准,组织必须能够a)以提取其系统相关技术含义的方式对监管文件进行背景处理,b)正式代表其系统并证明其符合提取的要求。认证过程后的要求;以及c)确保可能存在于信息系统外部的所有第三方系统(作为第三方网络服务存在于云中)也执行符合组织期望的适当安全措施;过程具有与之相关的特定挑战。首先,最初设计时会考虑本地管理的“内部”信息系统的监管文件正在被解释和扩展到云环境,而没有它们共同表达所必需的正式基础。其次,当前的系统认证过程依赖于静态系统模型,这对于云上的组织系统而言是不现实的。最后,使用第三方Web服务的组织无法评估其法规遵从性。他们无法检查第三方服务设计,也无法在发生故障时更换受信任的服务,因为目前尚无评估垂直安全兼容性的方法。为了解决这些问题,这项工作提倡一种通用的表达方法,该方法始终以一种适合云计算的方式从监管文档中不断提取技术要求,并促进其他组织遵循相同的监管标准进行上下文化和重用。一种称为Cloud X-UNITY的新的正式设计语言扩展了现有的协调语言模型,从而可以对提取的监管要求进行推理,以证明云符合安全期望。最后,开发了一个称为SecAgreement的服务水平协议框架和两个随附的配对算法,用于将合规性要求和风险分析信息附加到云Web服务,并自动选择最符合消费者合规性要求的服务。总体而言,合并形成了单一的合规性评估方法。

著录项

  • 作者

    Hale, Matthew Loutrelle.;

  • 作者单位

    The University of Tulsa.;

  • 授予单位 The University of Tulsa.;
  • 学科 Computer science.;Computer engineering.;Information technology.
  • 学位 Ph.D.
  • 年度 2014
  • 页码 266 p.
  • 总页数 266
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号