Rule-enhanced domain models for cloud security governance, risk and compliance management

  • Authors:
  • Marcus Spies

  • Affiliations:
  • Knowledge Management, LMU University of Munich

  • Venue:
  • RuleML'11 Proceedings of the 5th international conference on Rule-based modeling and computing on the semantic web
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

As security is essential for the adoption of cloud computing, several standards defining security domains, related threats and controls are being established. The common goal is to enable cloud security specific IT governance for cloud providers and client enterprises alike. The ensuing mandatory control objectives and control processes must cover regulatory compliance and risk management in view of the growing public sector and industry demand for cloud computing services. As of today, most of these standards are represented in textual or semi-structured form. However, the growing adoption of cloud computing calls for tool-supported monitoring and auditing. This paper shows how this can be accomplished based on a domain modelling approach that includes definitions and processing components for rules corresponding to control objectives and various aspects of control processes.