RT Conference Proceedings T1 Methodology to obtain the security controls in multi-cloud applications A1 Afolaranmi, Samuel Olaiya A1 Gonzalez Moctezuma, Luis E. A1 Rak, Massimiliano A1 Casola, Valentina A1 Rios, Erkuden A1 Martinez Lastra, Jose L. A2 Cardoso, Jorge A2 Cardoso, Jorge A2 Ferguson, Donald A2 Munoz, Victor Mendez A2 Helfert, Markus AB What controls should be used to ensure adequate security level during operation is a non-trivial subject in complex software systems and applications. The problem becomes even more challenging when the application uses multiple cloud services which security measures are beyond the control of the application provider. In this paper, a methodology that enables the identification of the best security controls for multicloud applications which components are deployed in heterogeneous cloud providers is presented. The methodology is based on application decomposition and modelling of threats over the components, followed by the analysis of the risks together with the capture of cloud business and security requirements. The methodology has been applied in the MUSA EU H2020 project use cases as the first step for building up the multi-cloud applications’ security-aware Service Level Agreements (SLA). The identified security controls will be included in the applications’ SLAs for their monitoring and fulfilment assurance at operation. PB SCITEPRESS Digital Library SN 978-989-758-182-3 SN 9789897581823 YR 2016 FD 2016 LA eng NO Afolaranmi , S O , Gonzalez Moctezuma , L E , Rak , M , Casola , V , Rios , E & Martinez Lastra , J L 2016 , Methodology to obtain the security controls in multi-cloud applications . in J Cardoso , J Cardoso , D Ferguson , V M Munoz & M Helfert (eds) , unknown . 1 , SCITEPRESS Digital Library , pp. 327-332 , 6th International Conference on Cloud Computing and Services Science, CLOSER 2016 , Rome , Italy , 23/04/16 . https://doi.org/10.5220/0005912603270332 NO conference NO Publisher Copyright: Copyright © 2016 by SCITEPRESS-Science and Technology Publications, Lda. All rights reserved. DS TECNALIA Publications RD 3 jul 2024