• DocumentCode
    2099146
  • Title

    Building a Compliance Vocabulary to Embed Security Controls in Cloud SLAs

  • Author

    Hale, Matthew L. ; Gamble, Rose

  • Author_Institution
    Tandy Sch. of Comput. Sci., Univ. of Tulsa, Tulsa, OK, USA
  • fYear
    2013
  • fDate
    June 28 2013-July 3 2013
  • Firstpage
    118
  • Lastpage
    125
  • Abstract
    Mission critical information systems must be certified against a set of security controls to mitigate potential security incidents. Cloud service providers must in turn employ adequate security measures that conform to security controls expected by the organizational information systems they host. Since service implementation details are abstracted away by the cloud, organizations can only rely on service level agreements (SLAs) to assess the compliance of cloud security properties and processes. Various representation schema allow SLAs to embed service security terms, but are disconnected from documents regulating security controls. This paper demonstrates an extensible solution for building a compliance vocabulary that associates SLA terms with security controls. The terms allow services to express which security controls they comply with and enable at-a-glance comparison of security service offerings so organizations can distinguish among cloud service providers that best comply with security expectations. To exemplify the approach, we build a sample vocabulary of terms based on audit security controls from a standard set of governing documents and apply them to an SLA for an example cloud storage service. We assess the compatibility with existing SLAs and calculate the computational overhead associated with the use of our approach in service matchmaking.
  • Keywords
    cloud computing; contracts; information systems; security of data; cloud SLA; cloud security properties; cloud service providers; cloud storage service; compliance vocabulary; computational overhead; mission critical information systems; organizational information systems; security control embedding; security incidents; security service offerings; service level agreements; service matchmaking; service security terms; Certification; Measurement; Ontologies; Organizations; Security; Vocabulary; XML; certification; cloud; compliance; security; service level agreement; web services; xml;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Services (SERVICES), 2013 IEEE Ninth World Congress on
  • Conference_Location
    Santa Clara, CA
  • Print_ISBN
    978-0-7695-5024-4
  • Type

    conf

  • DOI
    10.1109/SERVICES.2013.27
  • Filename
    6655684