Abstract
Compliance with the new European General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and security assurance are currently two major challenges of Cloud-based systems. GDPR compliance implies both privacy and security mechanisms definition, enforcement and control, including evidence collection. This study presents a novel DevOps framework aimed at supporting Cloud consumers in designing, deploying and operating (multi)Cloud systems that include the necessary privacy and security controls for ensuring transparency to end-users, third parties in service provision (if any) and law enforcement authorities. The framework relies on the risk-driven specification at design time of privacy and security level objectives in the system service level agreement and in their continuous monitoring and enforcement at runtime.
Cite
CITATION STYLE
Rios, E., Iturbe, E., Larrucea, X., Rak, M., Mallouli, W., Dominiak, J., … Gonzalez, L. (2019). Service level agreement-based GDPR compliance and security assurance in (multi)Cloud-based systems. IET Software, 13(3), 213–222. https://doi.org/10.1049/iet-sen.2018.5293
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.