Service Level Agreement-based GDPR Compliance and Security assurance in (multi)Cloud-based systems
Autor: | Victor Muntes, Luis Gonzalez, Xabier Larrucea, Peter Matthews, Massimiliano Rak, Wissam Mallouli, Jacek Dominiak, Erkuden Rios, Eider Iturbe |
---|---|
Přispěvatelé: | Rios Velasco, Erkuden, Iturbe, Eider, Larrucea, Xabier, Rak, Massimiliano, Mallouli, Wissam, Dominiak, Jacek, Muntes, Victor, Matthews, Peter, Gonzalez Moctezuma, Luis |
Jazyk: | angličtina |
Rok vydání: | 2019 |
Předmět: |
Computer science
business.industry 020207 software engineering Cloud computing 02 engineering and technology Computer security computer.software_genre Computer Graphics and Computer-Aided Design Security controls Service-level agreement Cloud-based systems Software security assurance Privacy General Data Protection Regulation 0202 electrical engineering electronic engineering information engineering Security Data Protection Act 1998 020201 artificial intelligence & image processing DevOps GDPR SLA business Enforcement computer European General Data Protection Regulation |
Zdroj: | TECNALIA Publications Fundación Tecnalia Research & Innovation IET Software |
Popis: | Compliance with the new European General Data Protection Regulation (Regulation (EU) 2016/679) and security assurance are currently two major challenges of Cloud-based systems. GDPR compliance implies both privacy and security mechanisms definition, enforcement and control, including evidence collection. This paper presents a novel DevOps framework aimed at supporting Cloud consumers in designing, deploying and operating (multi)Cloud systems that include the necessary privacy and security controls for ensuring transparency to end-users, third parties in service provision (if any) and law enforcement authorities. The framework relies on the risk-driven specification at design time of privacy and security level objectives in the system Service Level Agreement (SLA) and in their continuous monitoring and enforcement at runtime. The research leading to these results has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 644429 and No 780351, MUSA project and ENACT project, respectively. We would also like to acknowledge all the members of the MUSA Consortium and ENACT Consortium for their valuable help. |
Databáze: | OpenAIRE |
Externí odkaz: |