Dr. Jesus Luna Garcia
|
|
|
- Kelly Goodwin
- 10 years ago
- Views:
Transcription
1 Cloud Accountability and SLAs: research challenges and opportunities Dr. Jesus Luna Garcia
2 Outline Cloud SLA s one year ago Open Research Challenges: Standardization/certification Accountability SLA management Final remarks
3 One year ago: CCSW 12 Specifying security parameters in Cloud Service Level Agreements (SLA). A promising approach for cloud security assurance. SLA s in action: ENISA EU FP7 projects Cloud Security Alliance How to quantitatively reason about Cloud SLA s? CSPs specifying security in SLAs (source: ENISA)
4 CHALLENGES
5 European Cloud Initiative The specific objectives of the SIG SLA are to create: Baseline and recommendations for SLA specifications, languages & modelling. Baseline and recommendations for SLA Management. Baseline and recommendations for SLA enforcement supporting mechanisms. European Cloud Initiative
6 ETSI CSC: cloud standardization gaps Focus on SLA, SEC and IOP. Preliminaries Use cases (UCs) elicitation. Create list with relevant cloud standards/specifications/others. UCs activities Choose representative UCs. For each UC, create activities from 3 perspectives: acquisition, operation, termination. Where applicable, identify generic activities (i.e., apply to all UCs). Gap analysis Map listed standards/specifications to UCs activities (either generic or specific). Add related work (i.e., documents identified as other ). If no applicable standard/specification exists, this activity becomes a gap.
7 ETSI CSC: lessons learned No jungle of standards, but jungle of forums: Standards and specifications vs. related works (including scientific papers). Gap analysis: Lack of standards vs. lack of cloud standards. Do identified standards really fill the gap?
8 ETSI CSC: lessons learned Gap on SLA models that support common metrics and vocabularies. (Semi-)Automated SLA management: Reality or fiction? Public review of CSC report started Nov-7 th.
9 Standardization and certification EU project CIRRUS: Brings together different stakeholders views, including research community. Surveys emerging and future challenges for building the chain of trust. Identified Cloud SLA challenges: SLA s Monitoring-as-a-Service. Cloud federations and cloud brokers, open new SLA-related challenges e.g., composition, is it time for an SLA algebra? Security assurance!
10 Cloud accountability Accountability-based approaches for trust and assurance EU FP7 A4Cloud.
11 Conceptual accountability framework Can SLA s be used to manage accountability in the cloud?
12 SLA management Create, promote and exploit an open source PaaS to offer and manage security features through SLAs.
13 SPECS PaaS model 1 Use Case: Added-value cloud broker End-user negotiates security with broker Integrates required/new cloud security services into CSP Continuous SLA monitoring to offer best available CSP
14 SPECS PaaS model 2 Use Case: CSP-managed Flexible SLAs offered to the end user Security is adapted to end user requirements SLA constantly monitored to react against e.g., cyber incidents
15 SPECS PaaS model 3 Use Case: User-managed (possibly a community cloud) User s services benefit from PaaS security services User dashboard to monitor achieved security levels
16 Open Challenges SLA (security) Negotiation: Security Aggregation = QoSec (cf., CCSW 12 paper) Quantitative vs. Qualitative vs. Probabilistic security metrics User-centric, trade-offs evaluation Continuous SLA Monitoring: Once again, security assurance. Don t reinvent the wheel e.g., extend Cloud Trust Protocol Critical factors: performance, intrusiveness,
17 Open Challenges Automated SLA enforcement: Guarantee a negotiated SLA/sustained QoSec SLA-based incident management. Real-world validation!
18 Final remarks Standardization (SLAs, vocabularies, metrics). Composition in the cloud of public services: Cloud brokers everywhere (Secure) SLA composition
19 Final remarks Bridging the (cloud security) gap between academic and industrial research Hopefully you ll leave with new ideas for CCSW 14
Making SLA s Useful for Security
Making SLA s Useful for Security Neeraj Suri www.deeds.informatik.tu-darmstadt.de 11/15/2013 Suri/CIRRUS 1 Service Level Agreement (SLA) Contract which describes the Service, the associated quality levels
Leveraging the Potential of Cloud Security Service Level Agreements through Standards
1 Leveraging the Potential of Cloud Security Service Level Agreements through Standards Jesus Luna, Neeraj Suri, Michaela Iorga and Anil Karmel Abstract: Despite the undisputed advantages of Cloud computing,
European Cloud. Computing Strategy. State of play: 1-2014. Ken Ducatel DG CONNECT
European Cloud State of play: 1-2014 Computing Strategy Ken Ducatel DG CONNECT What is at stake? Cloud as a growth engine Boost GDP : 940 bn cumulative impact for 2015-2020 250bn in 2020 Boosts productivity
Preliminary Design of a Platform-as-a-Service to Provide Security in Cloud
Preliminary Design of a Platform-as-a-Service to Provide Security in Valentina Casola 1, Alessandra De Benedictis 1, Massimiliano Rak 2 and Umberto Villano 3 1 Università Federico II di Napoli, Dipartimento
Federal Aviation Administration. efast. Cloud Computing Services. 25 October 2012. Federal Aviation Administration
efast Cloud Computing Services 25 October 2012 1 Bottom Line Up Front The FAA Cloud Computing Vision released in 2012 identified the agency's road map to meet the Cloud First Policy efast must provide
Helix Nebula: Secure Brokering of Cloud Resources for escience. Dr. Jesus Luna Garcia
Helix Nebula: Secure Brokering of Cloud Resources for escience Dr. Jesus Luna Garcia Outline Background The Blue-Box architecture Security Goals and Requirements Let s imagine Why a Public-Private Partnership
Accelerating Cloud adoption with Security Level Agreements automation, monitoring and industry standards compliance
Accelerating Cloud adoption with Security Level Agreements automation, monitoring and industry standards compliance Cirrus Workshop, Vienna, Austria, November 19, 2013 Dr. Said Tabet Senior Technologist
ENISA s Study on the Evolving Threat Landscape. European Network and Information Security Agency
ENISA s Study on the Evolving Threat Landscape European Network and Information Security Agency Agenda Introduction to ENISA Preliminary remarks The ENISA report Major findings Conclusions 2 ENISA The
Cloud and Critical Information Infrastructures
Cloud and Critical Information Infrastructures Cloud computing in ENISA Dr. Evangelos Ouzounis Head of Infrastructure & Services Unit www.enisa.europa.eu About ENISA The European Union Network and Information
Cloud Computing Best Practices. Creating Effective Cloud Computing Contracts for the Federal Government: Best Practices for Acquiring IT as a Service
Cloud Computing Best Practices Cloud Computing Best Practices Creating Effective Cloud Computing Contracts for the Federal Government: Best Practices for Acquiring IT as a Service Overview Cloud Computing
Cloud Standards Coordination Final Report November 2013 VERSION 1.0
November 2013 VERSION 1.0 Executive Summary The European Commission Communication on the European Cloud strategy identifies a key action for standardisation in this context: Key action 1: Cutting through
The problem of cloud data governance
The problem of cloud data governance Vasilis Tountopoulos, Athens Technology Center S.A. (ATC) CSP EU Forum 2014 - Thursday, 22 nd May, 2014 Focus on data protection in the cloud Why data governance in
European Cloud Computing. Strategy. Cloud standards. Ken Ducatel DG CONNECT
European Cloud Computing Cloud standards Strategy Ken Ducatel DG CONNECT The Cloud Computing Strategy The European Commission's strategy 'Unleashing the potential of cloud computing in Europe' Adopted
ENISA and Cloud Security
ENISA and Cloud Security Dimitra Liveri NIS Expert EuroCloud Forum 2015 Barcelona 07-10-2015 European Union Agency for Network and Information Security Securing Europe s Information Society Operational
The Next Generation Data Centers: SPECS and The 3 rd Platform.
The Next Generation Data Centers: SPECS and The 3 rd Platform. Dr. Silvio La Porta Senior Research Scientist EMC Research Europe Dr. Said Tabet Senior Technology Strategist Corporate CTO Office, EMC 1
A Model for Accomplishing and Managing Dynamic Cloud Federations
A Model for Accomplishing and Managing Dynamic Cloud Federations London, CFM workshop 2014, December 8 th Giuseppe Andronico, INFN CT Marco Fargetta (INFN CT), Maurizio Paone (INFN CT), Salvatore Monforte
ENISA What s On? ENISA as facilitator for enhanced Network and Information Security in Europe. CENTR General Assembly, Brussels October 4, 2012
ENISA What s On? ENISA as facilitator for enhanced Network and Information Security in Europe CENTR General Assembly, Brussels October 4, 2012 [email protected] 1 Who we are ENISA was
Cloud Standardization, Compliance and Certification. Class 2012 event 25.rd of October 2012 Dalibor Baskovc, CEO Zavod e-oblak
Cloud Standardization, Compliance and Certification Class 2012 event 25.rd of October 2012 Dalibor Baskovc, CEO Zavod e-oblak Todays Agenda IT Resourcing with Cloud Computing and related challenges Landscape
Concurrent Technologies Corporation (CTC) is an independent, nonprofit, applied scientific research and development professional services
Concurrent Technologies Corporation (CTC) is an independent, nonprofit, applied scientific research and development professional services organization providing innovative management and technology-based
Standardised SLAs: how far can we go? DIHC, Euro-Par 2013, Aachan John Kennedy Intel Labs Europe
Standardised SLAs: how far can we go? DIHC, Euro-Par 2013, Aachan John Kennedy Intel Labs Europe Before we begin AMD AT&T Microelectronics Digital Equipment Harris Semiconductor Hewlett-Packard IBM Intel
A CLOUD ADOPTION RISK ASSESSMENT MODEL
A CLOUD ADOPTION RISK ASSESSMENT MODEL Erdal Cayirci Electrical and Computer Engineering Department University of Stavanger Stavanger, Norway [email protected] Alexandr Garaga, Anderson Santana de Oliveira
Self-protecting multi-cloud applications
Self-protecting multi-cloud applications Antonio M. Ortiz 1, Erkuden Rios 2, Wissam Mallouli 1, Eider Iturbe 2, Edgardo Montes de Oca 1 1 Montimage R&D. Paris, France Email: {antonio.ortiz, wissam.mallouli,
CLOUD SERVICE LEVEL AGREEMENTS Meeting Customer and Provider needs
CLOUD SERVICE LEVEL AGREEMENTS Meeting Customer and Provider needs Eric Simmon January 28 th, 2014 BACKGROUND Federal Cloud Computing Strategy Efficiency improvements will shift resources towards higher-value
TECHNICAL SPECIFICATION: ABBREVIATIONS AND GLOSSARY
REALIZATION OF A RESEARCH AND DEVELOPMENT PROJECT (PRE-COMMERCIAL PROCUREMENT) ON CLOUD FOR EUROPE TECHNICAL SPECIFICATION: ABBREVIATIONS AND GLOSSARY ANNEX IV (E) TO THE CONTRACT NOTICE TENDER NUMBER
Accountability in Cloud Computing An Introduction to the Issues, Approaches, and Tools
Accountability in Cloud Computing An Introduction to the Issues, Approaches, and Tools Nick Papanikolaou, Cloud and Security Lab, HP Labs Europe [email protected] With special thanks to Nick Wainwright and Siani
Public Cloud Workshop Offerings
Cloud Perspectives a division of Woodward Systems Inc. Public Cloud Workshop Offerings Cloud Computing Measurement and Governance in the Cloud Duration: 1 Day Purpose: This workshop will benefit those
Allison Stanton, Director of E-Discovery U.S. Department of Justice, Civil Division. U.S. Department of Agriculture
Allison Stanton, Director of E-Discovery U.S. Department of Justice, Civil Division Benjamin Young, Assistant General Counsel U.S. Department of Agriculture 1 Disclaimer The views expressed in this presentation
Cloud computing and personal data protection. Gwendal LE GRAND Director of technology and innovation CNIL
Cloud computing and personal data protection Gwendal LE GRAND Director of technology and innovation CNIL 1 Data protection in Europe Directive 95/46/EC Loi 78-17 du 6 janvier 1978 amended in 2004 (France)
Cloud Computing Standards: Overview and ITU-T positioning
ITU Workshop on Cloud Computing (Tunis, Tunisia, 18-19 June 2012) Cloud Computing Standards: Overview and ITU-T positioning Dr France Telecom, Orange Labs Networks & Carriers / R&D Chairman ITU-T Working
Cloud Computing in a GxP Environment: The Promise, the Reality and the Path to Clarity
Reprinted from PHARMACEUTICAL ENGINEERING THE OFFICIAL TECHNICAL MAGAZINE OF ISPE JANUARY/FEBRUARY 2014, VOL 34, NO 1 Copyright ISPE 2014 www.pharmaceuticalengineering.org information systems in a GxP
THE BUSINESS OF CLOUD
THE BUSINESS OF CLOUD THE BUSINESS OF CLOUD Introduction Chapter 1: Chapter 2: Chapter 3: Chapter 4: Chapter 5: Chapter 6: Choose the Right Model Overcome Procurement Barriers to Cloud Adoption Meet Complex
Agenda. What is Service Level Agreement (SLA)? Why using ONE tool for SLA management? What s New on the Market? Oblicore Guarantee.
SLA Management Agenda What is Service Level Agreement (SLA)? Why using ONE tool for SLA management? What s New on the Market? Oblicore Guarantee Overview Architecture Why Sytel Reply What s Next 2 Definition
What REALLY matters in Cloud Security? RE: Internet of things sensors, data, security and beyond!
What REALLY matters in Cloud Security? RE: Internet of things sensors, data, security and beyond! HOW to best integrate security into the office AND the cloud? And what is a thing is that MORE we have
Alliance Scorecarding and Performance Management at TechCo. A Vantage Partners Case Study
Alliance Scorecarding and Performance Management at TechCo A Vantage Partners Case Study With the assistance of Vantage Partners, TechCo, a microelectronics company based in California, developed and implemented
IMPLEMENTING SERVICE LEVEL MANAGEMENT
IMPLEMENTING SERVICE LEVEL MANAGEMENT Author : Gary Case Version : 1.0 Date : August 2011 Implementing Service Level Management Page 1 of 8 Table Of Contents 1 EXECUTIVE SUMMARY... 3 2 SERVICE LEVEL MANAGEMENT
Incident Management. Verdis Spearman [email protected] 703.235.5443
Incident Management Verdis Spearman [email protected] 703.235.5443 Agenda Overview Governance Stakeholders Responsibilities Trusted Internet Connection Initiative Incident Response Requirements
Federation of Cloud Computing Infrastructure
IJSTE International Journal of Science Technology & Engineering Vol. 1, Issue 1, July 2014 ISSN(online): 2349 784X Federation of Cloud Computing Infrastructure Riddhi Solani Kavita Singh Rathore B. Tech.
BRIDGE. the gaps between IT, cloud service providers, and the business. IT service management for the cloud. Business white paper
BRIDGE the gaps between IT, cloud service providers, and the business. IT service management for the cloud Business white paper Executive summary Today, with more and more cloud services materializing,
The Cloud Computing Revolution: Beyond the Hype
The Cloud Computing Revolution: Beyond the Hype KEN ADLER Partner and Chair, Technology and Outsourcing Practice Group Loeb & Loeb LLP Outsourcing in Financial Services Program October 19, 2010 Overview
ITSM 101. Patrick Connelly and Sandeep Narang. Gartner. www.it.ufl.edu
ITSM 101 Patrick Connelly and Sandeep Narang Gartner 1 IT Service Management 101 Agenda What is IT Service Management? Why is IT Service Management Important? Speaking a Common Language: Overview of Key
Service Performance Aspects for Cloud Service Level Agreements
Service Performance Aspects for Cloud Service Level Agreements Dr. Craig A. Lee, Senior Scientist, [email protected] Computer Systems Research Department The Aerospace Corporation NITRD SLA Workshop Arlington,
September 17, 1:00 PM. Dean Sorensen, Founder, IBP Collaborative
BUSINESS FORECASTING AND INNOVATION FORUM 2015 September 17-18, 2015 Boston, MA September 17, 1:00 PM Track A Session: Transforming FP&A via Strategic, Financial & Operational Integration Improve forecast
Prof. Udo Helmbrecht
Prof. Udo Helmbrecht Guiding EU Cybersecurity from Policy to Implementation Udo Helmbrecht Executive Director Information Security for the Public Sector 2015 Stockholm 02/09/15 European Union Agency for
On the Adoption of Security SLAs in the Cloud
On the Adoption of Security SLAs in the Cloud Valentina Casola 1(B), Alessandra De Benedictis 1, and Massimiliano Rak 2 1 Universita di Napoli Federico II, Naples, Italy {valentina.casola,alessandra.debenedictis}@unina.it
Cloud Service Broker Portal: Main entry point for multi-cloud service providers and consumers
Cloud Service Broker Portal: Main entry point for multi-cloud service providers and consumers Jihyun Lee*, Jinmee Kim*, Dong-Jae Kang*, Namwoo Kim*, Sungin Jung* *Cloud Research Department, ETRI, 161 Gajungdong
Audit of the CFPB s Acquisition and Contract Management of Select Cloud Computing Services
O F F I C E O F IN S P E C TO R GENERAL Audit Report 2014-IT-C-016 Audit of the CFPB s Acquisition and Contract Management of Select Cloud Computing Services September 30, 2014 B O A R D O F G O V E R
Blend Approach of IT Service Management and PMBOK for Application Support Project
Blend Approach of IT Service and PMBOK for Application Support Project Introduction: This paper addresses the process area, phases and documentation to be done for Support Project using Project and ITSM
CRISIS MANAGEMENT AND FIRST AID: WHEN GOVERNMENT CONTRACTORS ARE THE HEADLINERS WELCOME
CRISIS MANAGEMENT AND FIRST AID: WHEN GOVERNMENT CONTRACTORS ARE THE HEADLINERS WELCOME CYBER CRISIS MANAGEMENT: ARE YOU PREPARED? Evan Wolff David Bodenheimer Kelly Currie Kate Growley Overview Cybersecurity
BMC Software Consulting Services. Fermilab Computing Division Service Catalog & Communications: Process and Procedures
BMC Software Consulting Services Service Catalog & Communications: Process and Procedures Policies, Client: Date : Version : Fermilab 02/12/2009 1.0 GENERAL Description Purpose This document establishes
FLEXIANT. Utility Computing on Demand
FLEXIANT Utility Computing on Demand Flexiant Flexiant is a software and services company, one of the world's first public/private Cloud providers. We provide cloud infrastructure software and services
IT Security Risk Management Model for Cloud Computing: A Need for a New Escalation Approach.
IT Security Risk Management Model for Cloud Computing: A Need for a New Escalation Approach. Gunnar Wahlgren 1, Stewart Kowalski 2 Stockholm University 1: ([email protected]), 2: ([email protected]) ABSTRACT
CForum: A Community Driven Solution to Cybersecurity Challenges
SESSION ID: AST3-R01 CForum: A Community Driven Solution to Cybersecurity Challenges Tom Conkle Cybersecurity Engineer G2, Inc. @TomConkle Greg Witte Sr. Security Engineer G2, Inc. @thenetworkguy Organizations
D4.1 Cloud certification guidelines and recommendations
Ref. Ares(2015)444655-04/02/2015 www.cloudwatchhub.eu D4.1 Cloud certification guidelines and recommendations Revised Version www.cloudwatchhub.eu [email protected] @CloudWatchHub Security and privacy
A Framework to Improve Communication and Reliability Between Cloud Consumer and Provider in the Cloud
A Framework to Improve Communication and Reliability Between Cloud Consumer and Provider in the Cloud Vivek Sridhar Rational Software Group (India Software Labs) IBM India Bangalore, India Abstract Cloud
ITIL Foundation for IT Service Management 2011 Edition
ITIL Foundation for IT Service Management 2011 Edition ITIL Rev 03.12 3 days Description ITIL (IT Infrastructure Library) provides a practical, no-nonsense framework for identifying, planning, delivering
European Cloud Computing Strategy
European Cloud Computing Strategy Key actions and state of play Jorge GASOS DG Connect, European Commission [email protected] Impact on providers and users Cloud services: market forecast Supply
Highlights & Next Steps
USG Cloud Computing Technology Roadmap Highlights & Next Steps NIST Mission: To promote U.S. innovation and industrial competitiveness by advancing measurement science, standards, and technology in ways
Module 1: Supply Chain Design
Module 1: Supply Chain Design Module 1 Introduction Section A: Develop the Supply Chain Strategy Chapter 1: Inputs to Supply Chain Strategy o Topic 1: Business Model o Topic 2: External Inputs to Supply
Role of contracts in Cloud Computing an Overview. Kevin McGillivray Doctoral Candidate (NRCCL)
Role of contracts in Cloud Computing an Overview Kevin McGillivray Doctoral Candidate (NRCCL) Barriers/Challenges to Cloud Transparency Compliance Legal Shared infrastructure Subcontractors (and their
The Cloud Security Alliance
The Cloud Security Alliance Daniele Catteddu, Managing Director EMEA & OCF-STAR Program Director Cloud Security Alliance ABOUT THE CLOUD SECURITY ALLIANCE To promote the use of best practices for providing
Aternity Virtual Desktop Monitoring. Complete Visibility Ensures Successful VDI Outcomes
Aternity Virtual Desktop Monitoring Complete Visibility Ensures Successful VDI Outcomes Realizing the Benefits of VDI Requires Illuminating Four Performance Blind Spots Without comprehensive visibility
A Comparison of IT Governance & Control Frameworks in Cloud Computing. Jack D. Becker ITDS Department, UNT & Elana Bailey
A Comparison of IT Governance & Control Frameworks in Cloud Computing Jack D. Becker ITDS Department, UNT & Elana Bailey ITDS Department, UNT MS in IS AMCIS 2014 August, 2014 Savannah, GA Presentation
Cloud Computing and Security Risk Analysis Qing Liu Technology Architect STREAM Technology Lab [email protected]
Cloud Computing and Security Risk Analysis Qing Liu Technology Architect STREAM Technology Lab [email protected] 1 Disclaimers This presentation provides education on Cloud Computing and its security
Virginia Government Finance Officers Association Spring Conference May 28, 2014. Cloud Security 101
Virginia Government Finance Officers Association Spring Conference May 28, 2014 Cloud Security 101 Presenters: John Montoro, RealTime Accounting Solutions Ted Brown, Network Alliance Presenters John Montoro
ENISA and Cloud Security
Click icon to add picture Click icon to add picture ENISA and Cloud Security Dimitra Liveri NIS Expert EuroCloud Forum 2015 Barcelona 07-10-2015 European Union Agency for Network and Informaton Security
COMMISSION STAFF WORKING DOCUMENT. Report on the Implementation of the Communication 'Unleashing the Potential of Cloud Computing in Europe'
EUROPEAN COMMISSION Brussels, 2.7.2014 SWD(2014) 214 final COMMISSION STAFF WORKING DOCUMENT Report on the Implementation of the Communication 'Unleashing the Potential of Cloud Computing in Europe' Accompanying
SLA Model Terms and Specifications: SLALOM Project Overview and Request for Feedback
SLA Model Terms and Specifications: SLALOM Project Overview and Request for Feedback SLALOM is an initiative aligned with the European Cloud Strategy [1]. The first phase of the initiative is an 18 month,
Cloud Federations in Contrail
Cloud Federations in Contrail Emanuele Carlini 1,3, Massimo Coppola 1, Patrizio Dazzi 1, Laura Ricci 1,2, GiacomoRighetti 1,2 " 1 - CNR - ISTI, Pisa, Italy" 2 - University of Pisa, C.S. Dept" 3 - IMT Lucca,
Shared Services Canada (SSC)
Shared Services Canada (SSC) Cloud Computing Architecture Identity, Credential & Access Architecture Framework Advisory Committee Transformation, Service Strategy and Design August 29, 2013 1 Agenda TIME
