首页> 外文期刊>Computers & Security >Towards a framework for trustworthy data security level agreement in cloud procurement
【24h】

Towards a framework for trustworthy data security level agreement in cloud procurement

机译:迈向云采购中值得信赖的数据安全级别协议的框架

获取原文
获取原文并翻译 | 示例
           

摘要

After the post-Snowden upheavals, there is a growing concern about preserving the confidentiality of sensitive data across government agencies when using global cloud service providers, such as Amazon Web Services and Microsoft Azure. The use of certification schemes is becoming more critical to assure the security of services offered. This situation is problematic because many certification schemes aim to demonstrate compliance with a security standard rather than achieve a specified security level. Despite the benefits of security certification schemes like Common Criteria (CC), an assurance-based certification process does not scale well to service provision. To this end, this paper aims to investigate the concept of system assurance and trustworthiness in service provisioning, especially when government agencies procure cloud-based services. By using work on the Indonesian Government's data confidentiality requirements, this work develops principles as foundations for a trustworthy data security level agreement (TDSLA) capability framework as a new assurance mechanism for service provisioning based on discrete levels of security assurance incorporated into the formulation of a service level agreement (SLA). The principles which have emerged from the empirical qualitative data collection were evaluated and validated using four approaches: 1) reflection against related work; 2) testimonial validity through participants' feedback; 3) use cases, and 4) application of transferability using cases from the UK Government Cloud (G-Cloud) and the US Federal Risk and Authorization Management Program (FedRAMP). The TDSLA capability framework can form the basis for constructing a legal language in contracts or SLAs.
机译:在雪地后的动荡之后,在使用全球云服务提供商(如亚马逊Web服务和Microsoft Azure)的情况下,在政府机构中保留敏感数据的机密性越来越担心。认证方案的使用越来越重要,以确保提供的服务安全。这种情况是有问题的,因为许多认证计划旨在证明遵守安全标准而不是实现指定的安全级别。尽管安全认证计划等常见标准(CC)等好处,但基于保证的认证过程并未缩放到服务提供。为此,本文旨在调查服务供应中的系统保障和可靠性的概念,特别是当政府机构采购基于云的服务时。通过在印度尼西亚政府的数据保密要求上使用工作,这项工作将原则制定为值得信赖的数据安全级别协议(TDSLA)能力框架的基础,作为基于离散水平的安全保障提供的服务供应的新保证机制,该框架服务级别协议(SLA)。使用四种方法评估和验证了从经验定性数据收集中出现的原则:1)反映相关工作; 2)通过参与者的反馈证明有效性; 3)用例和4)在英国政府云(G-Cloud)和美国联邦风险和授权管理方案(FEDRAMP)中使用案件的可转让性。 TDSLA能力框架可以在合同或SLA中构建法律语言构成基础。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号