Service level agreement-based GDPR compliance and security assurance in (multi)Cloud-based systems

33Citations
Citations of this article
95Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Compliance with the new European General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and security assurance are currently two major challenges of Cloud-based systems. GDPR compliance implies both privacy and security mechanisms definition, enforcement and control, including evidence collection. This study presents a novel DevOps framework aimed at supporting Cloud consumers in designing, deploying and operating (multi)Cloud systems that include the necessary privacy and security controls for ensuring transparency to end-users, third parties in service provision (if any) and law enforcement authorities. The framework relies on the risk-driven specification at design time of privacy and security level objectives in the system service level agreement and in their continuous monitoring and enforcement at runtime.

Cite

CITATION STYLE

APA

Rios, E., Iturbe, E., Larrucea, X., Rak, M., Mallouli, W., Dominiak, J., … Gonzalez, L. (2019). Service level agreement-based GDPR compliance and security assurance in (multi)Cloud-based systems. IET Software, 13(3), 213–222. https://doi.org/10.1049/iet-sen.2018.5293

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free