Medina: Improving cloud services trustworthiness through continuous audit-based certification

dc.contributor.authorOrue-Echevarria, Leire
dc.contributor.authorGarcia, Jesus Luna
dc.contributor.authorBanse, Christian
dc.contributor.authorAlonso, Juncal
dc.contributor.institutionTecnalia Research & Innovation
dc.contributor.institutionHPA
dc.date.accessioned2024-07-24T12:05:04Z
dc.date.available2024-07-24T12:05:04Z
dc.date.issued2021
dc.descriptionPublisher Copyright: © 2021 CEUR-WS. All rights reserved.
dc.description.abstractOne of the reasons of the still limited adoption of Cloud Computing in the EU is the EU customers' perceived lack of security and transparency in this technology. Cloud service providers (CSPs) usually rely on security certifications as a mean to improve transparency and trustworthiness, however European CSPs still face multiple challenges for certifying their services (e.g., fragmentation in the certification market, and lack of mutual recognition). In this context, the EU Cybersecurity Act (EU CSA) proposes improving customer's trust in the European ICT market through a European certification scheme (EUCS). The proposed cloud security certification scheme conveys new technological challenges including the notion of automated monitoring for the whole supply chain, which needs to be solved in order to bring all the expected benefits to EU cloud providers and customers. In this context, MEDINA proposes a framework for supporting a continuous audit-based certification for CSPs based on EU CSA's scheme for cloud security certification. MEDINA will tackle challenges in areas like security validation/ testing, machine-readable certification language, cloud security performance, and audit evidence management. MEDINA will provide and empirically validate sustainable outcomes in order to benefit EU adopters.en
dc.description.sponsorshipThis work has been partially funded by the European project MEDINA (Horizon 2020 research and innovation Programme, under grant agreement no 952633).
dc.description.statusPeer reviewed
dc.format.extent8
dc.identifier.citationOrue-Echevarria , L , Garcia , J L , Banse , C & Alonso , J 2021 , ' Medina : Improving cloud services trustworthiness through continuous audit-based certification ' , CEUR Workshop Proceedings , vol. 2878 , pp. 16-23 .
dc.identifier.issn1613-0073
dc.identifier.urihttps://hdl.handle.net/11556/3518
dc.identifier.urlhttp://www.scopus.com/inward/record.url?scp=85108024296&partnerID=8YFLogxK
dc.language.isoeng
dc.relation.ispartofCEUR Workshop Proceedings
dc.relation.projectIDHorizon 2020, 952633
dc.rightsinfo:eu-repo/semantics/restrictedAccess
dc.subject.keywordscertification language
dc.subject.keywordscloud certification scheme
dc.subject.keywordscontinuous auditing
dc.subject.keywordscontinuous certification
dc.subject.keywordsCybersecurity Act
dc.subject.keywordssmart contracts
dc.subject.keywordsGeneral Computer Science
dc.subject.keywordsSDG 12 - Responsible Consumption and Production
dc.titleMedina: Improving cloud services trustworthiness through continuous audit-based certificationen
dc.typeconference output
Files