Fraunhofer-Gesellschaft

Publica

Hier finden Sie wissenschaftliche Publikationen aus den Fraunhofer-Instituten.

A process model to support continuous certification of cloud services

 
: Kunz, I.; Stephanow, P.

:

Barolli, L. ; Institute of Electrical and Electronics Engineers -IEEE-; IEEE Computer Society, Technical Committee on Distributed Processing:
AINA 2017, 31st IEEE International Conference on Advanced Information Networking and Applications. Proceedings : 27-29 March 2017, Tamkang University, Taipei, Taiwan
Piscataway, NJ: IEEE, 2017
ISBN: 978-1-5090-6029-0
ISBN: 978-1-5090-6030-6
ISBN: 978-1-5090-6028-3
S.986-993
International Conference on Advanced Information Networking and Applications (AINA) <31, 2017, Taipei>
Bundesministerium für Bildung und Forschung BMBF
16KIS0075K; NGCert
European Commission EC
H2020; 731845; EU-SEC
The European Security Certification Framework
Englisch
Konferenzbeitrag
Fraunhofer AISEC ()

Abstract
Current research on cloud service certification is working on techniques to continuously, i.e. automatically and repeatedly, assess whether cloud services satisfy certification criteria. However, traditional certifications are conducted following static processes which are not designed to meet the requirements of continuous certification techniques. In this paper, we address this gap by redesigning the traditional certification process and adding suitable tooling to support continuous certification of cloud services. To that end, we analyze and generalize traditional certification processes and, on this basis, develop a novel, executable process model to detect ongoing changes of cloud services and adapt continuous certification techniques accordingly. We present our prototype which implements the process model and show how it allows us to automatically reconfigure continuous certification techniques according to changes observed in the target of certification as well as to continuously report certification results.

: http://publica.fraunhofer.de/dokumente/N-480977.html