Cloud paradigm is currently one of the most remunerative segments of Information Technology. It has gained the interest of a very large number of corporates and organizations. However, despite the promising features, security is the major concern for businesses that want to shift their services to the cloud. On the other hand, business critical systems must be certified against a set of security controls to be compliant to security standards, as well as to mitigate potential security incidents. Therefore, cloud service providers must employ adequate security measures that conform to security controls expected by the information systems they host; moreover, they should be able to grant the correct application of such controls to their customers. Security service level agreements (SLAs) are a way to face such issues, through the definition of contracts among cloud service providers and customers that clearly state the security grants applied to the offered cloud services. This chapter illustrates a case study that describes how it is possible to implement such security SLAs on a concrete cloud service, which offers Apache Hadoop services over public cloud providers. The chapter outlines how to write and assess security SLAs on such services.

Security SLAs for cloud services: Hadoop case study / Ficco, Massimo; Rak, Massimiliano. - 20:(2017), pp. 103-114. [10.1007/978-3-319-49538-5_7]

Security SLAs for cloud services: Hadoop case study

FICCO, Massimo;RAK, Massimiliano
2017

Abstract

Cloud paradigm is currently one of the most remunerative segments of Information Technology. It has gained the interest of a very large number of corporates and organizations. However, despite the promising features, security is the major concern for businesses that want to shift their services to the cloud. On the other hand, business critical systems must be certified against a set of security controls to be compliant to security standards, as well as to mitigate potential security incidents. Therefore, cloud service providers must employ adequate security measures that conform to security controls expected by the information systems they host; moreover, they should be able to grant the correct application of such controls to their customers. Security service level agreements (SLAs) are a way to face such issues, through the definition of contracts among cloud service providers and customers that clearly state the security grants applied to the offered cloud services. This chapter illustrates a case study that describes how it is possible to implement such security SLAs on a concrete cloud service, which offers Apache Hadoop services over public cloud providers. The chapter outlines how to write and assess security SLAs on such services.
2017
978-3-319-49537-8
Security SLAs for cloud services: Hadoop case study / Ficco, Massimo; Rak, Massimiliano. - 20:(2017), pp. 103-114. [10.1007/978-3-319-49538-5_7]
File in questo prodotto:
File Dimensione Formato  
Published.pdf

non disponibili

Licenza: Non specificato
Dimensione 223.92 kB
Formato Adobe PDF
223.92 kB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11588/986042
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact