Cloud paradigm is currently one of the most remunerative segments of Information Technology. It has gained the interest of a very large number of corporates and organizations. However, despite the promising features, security is the major concern for businesses that want to shift their services to the cloud. On the other hand, business critical systems must be certified against a set of security controls to be compliant to security standards, as well as to mitigate potential security incidents. Therefore, cloud service providers must employ adequate security measures that conform to security controls expected by the information systems they host; moreover, they should be able to grant the correct application of such controls to their customers. Security service level agreements (SLAs) are a way to face such issues, through the definition of contracts among cloud service providers and customers that clearly state the security grants applied to the offered cloud services. This chapter illustrates a case study that describes how it is possible to implement such security SLAs on a concrete cloud service, which offers Apache Hadoop services over public cloud providers. The chapter outlines how to write and assess security SLAs on such services.

Security SLAs for cloud services: Hadoop case study

FICCO, Massimo;
2017-01-01

Abstract

Cloud paradigm is currently one of the most remunerative segments of Information Technology. It has gained the interest of a very large number of corporates and organizations. However, despite the promising features, security is the major concern for businesses that want to shift their services to the cloud. On the other hand, business critical systems must be certified against a set of security controls to be compliant to security standards, as well as to mitigate potential security incidents. Therefore, cloud service providers must employ adequate security measures that conform to security controls expected by the information systems they host; moreover, they should be able to grant the correct application of such controls to their customers. Security service level agreements (SLAs) are a way to face such issues, through the definition of contracts among cloud service providers and customers that clearly state the security grants applied to the offered cloud services. This chapter illustrates a case study that describes how it is possible to implement such security SLAs on a concrete cloud service, which offers Apache Hadoop services over public cloud providers. The chapter outlines how to write and assess security SLAs on such services.
2017
978-3-319-49537-8
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11386/4776151
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? 0
social impact