SlideShare a Scribd company logo
1 of 1
Download to read offline
SPACE
Security and Privacy Assurance Case Environment
Problem
• Cloud service provides have to comply with internal as well as external security and privacy policies
• Different security and privacy controls are deployed across cloud supply chains by cloud providers
• Limited support for operational alignment between policies and associated controls
• Current certification and auditing practices provide limited assurance to customers and third parties
Our Solution
For Cloud Service Providers
• An assurance case environment for mapping security and privacy policies to associated controls
• A software-defined storage solution for gathering evidence supporting assurance
• Structuring security and privacy policies in terms of arguments and supporting evidence gathered or
generated by specific controls and associated technical solutions deployed in the cloud
For Cloud Customers
• Evidence-based continuous assurance of the adopted cloud services and related supply chains
For Cloud Auditors
• A centralised cloud-native evidence repository for inspecting cloud supply chains
Innovation
Continuous Assurance Systemic support for continuous assurance
Evidence-Driven Assurance Linking evidence to policies
AssurOps Combining Assurance and Operations
Example of a structured
Security and Privacy Assurance Case

More Related Content

Similar to A4CLOUD SPACE Poster

Secure Cloud Hosting: Real Requirements to Protect your Data
Secure Cloud Hosting: Real Requirements to Protect your DataSecure Cloud Hosting: Real Requirements to Protect your Data
Secure Cloud Hosting: Real Requirements to Protect your DataGreat Wide Open
 
Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Security Standards: What to Expect and What to Negotiate V2.0Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Security Standards: What to Expect and What to Negotiate V2.0Cloud Standards Customer Council
 
Latest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and PrivacyLatest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and PrivacyCloud Standards Customer Council
 
Transforming cloud security into an advantage
Transforming cloud security into an advantageTransforming cloud security into an advantage
Transforming cloud security into an advantageMoshe Ferber
 
AWS Summit 2013 | Singapore - Security & Compliance and Integrated Security w...
AWS Summit 2013 | Singapore - Security & Compliance and Integrated Security w...AWS Summit 2013 | Singapore - Security & Compliance and Integrated Security w...
AWS Summit 2013 | Singapore - Security & Compliance and Integrated Security w...Amazon Web Services
 
navigating the cloud key considerations for cloud computing solutions.pdf
navigating the cloud key considerations for cloud computing solutions.pdfnavigating the cloud key considerations for cloud computing solutions.pdf
navigating the cloud key considerations for cloud computing solutions.pdfbasilmph
 
PPT For Cloud Solution Provider.pptx
PPT For Cloud Solution Provider.pptxPPT For Cloud Solution Provider.pptx
PPT For Cloud Solution Provider.pptxssusercd035f1
 
Cloud Security 101 by Madhav Chablani
Cloud Security 101 by Madhav ChablaniCloud Security 101 by Madhav Chablani
Cloud Security 101 by Madhav ChablaniOWASP Delhi
 
Cloud Governance & DevOps: Must-have Tools on Your Journey to Azure Cloud
Cloud Governance & DevOps: Must-have Tools on Your Journey to Azure CloudCloud Governance & DevOps: Must-have Tools on Your Journey to Azure Cloud
Cloud Governance & DevOps: Must-have Tools on Your Journey to Azure CloudPredica Group
 
NIST CCRA.pptx for cloud computing and virtualization
NIST CCRA.pptx for cloud computing and virtualizationNIST CCRA.pptx for cloud computing and virtualization
NIST CCRA.pptx for cloud computing and virtualizationgmgkigaocwmxvbipfw
 
AWS Shared Responsibility Model & Compliance Program Overview
AWS Shared Responsibility Model & Compliance Program OverviewAWS Shared Responsibility Model & Compliance Program Overview
AWS Shared Responsibility Model & Compliance Program OverviewAmazon Web Services
 
compliance made easy. pass your audits stress-free webinar
compliance made easy. pass your audits stress-free webinarcompliance made easy. pass your audits stress-free webinar
compliance made easy. pass your audits stress-free webinarAlgoSec
 
Integrated Compliance Webinar.pptx
Integrated Compliance Webinar.pptxIntegrated Compliance Webinar.pptx
Integrated Compliance Webinar.pptxControlCase
 
BALANCING PERFORMANCE,ACCURACY,AND PRECISION FOR SECURE CLOUD TRANSACTIONS
BALANCING PERFORMANCE,ACCURACY,AND PRECISION FOR SECURE CLOUD TRANSACTIONSBALANCING PERFORMANCE,ACCURACY,AND PRECISION FOR SECURE CLOUD TRANSACTIONS
BALANCING PERFORMANCE,ACCURACY,AND PRECISION FOR SECURE CLOUD TRANSACTIONSakhilkumarreddybanda
 
The Trouble with Cloud Forensics :Sharique M. Rizvi Head of IT Security & Fo...
The Trouble with Cloud Forensics :Sharique M. Rizvi Head of IT Security &  Fo...The Trouble with Cloud Forensics :Sharique M. Rizvi Head of IT Security &  Fo...
The Trouble with Cloud Forensics :Sharique M. Rizvi Head of IT Security & Fo...Sharique Rizvi
 
Cloud technology - V2Soft
Cloud technology - V2SoftCloud technology - V2Soft
Cloud technology - V2SoftV2Soft2
 
The Trouble with Cloud Forensics
The Trouble with Cloud ForensicsThe Trouble with Cloud Forensics
The Trouble with Cloud ForensicsSharique Rizvi
 

Similar to A4CLOUD SPACE Poster (20)

Secure Cloud Hosting: Real Requirements to Protect your Data
Secure Cloud Hosting: Real Requirements to Protect your DataSecure Cloud Hosting: Real Requirements to Protect your Data
Secure Cloud Hosting: Real Requirements to Protect your Data
 
Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Security Standards: What to Expect and What to Negotiate V2.0Cloud Security Standards: What to Expect and What to Negotiate V2.0
Cloud Security Standards: What to Expect and What to Negotiate V2.0
 
Latest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and PrivacyLatest Developments in Cloud Security Standards and Privacy
Latest Developments in Cloud Security Standards and Privacy
 
Transforming cloud security into an advantage
Transforming cloud security into an advantageTransforming cloud security into an advantage
Transforming cloud security into an advantage
 
AWS Summit 2013 | Singapore - Security & Compliance and Integrated Security w...
AWS Summit 2013 | Singapore - Security & Compliance and Integrated Security w...AWS Summit 2013 | Singapore - Security & Compliance and Integrated Security w...
AWS Summit 2013 | Singapore - Security & Compliance and Integrated Security w...
 
navigating the cloud key considerations for cloud computing solutions.pdf
navigating the cloud key considerations for cloud computing solutions.pdfnavigating the cloud key considerations for cloud computing solutions.pdf
navigating the cloud key considerations for cloud computing solutions.pdf
 
PPT For Cloud Solution Provider.pptx
PPT For Cloud Solution Provider.pptxPPT For Cloud Solution Provider.pptx
PPT For Cloud Solution Provider.pptx
 
Cloud Security 101 by Madhav Chablani
Cloud Security 101 by Madhav ChablaniCloud Security 101 by Madhav Chablani
Cloud Security 101 by Madhav Chablani
 
Cloud Governance & DevOps: Must-have Tools on Your Journey to Azure Cloud
Cloud Governance & DevOps: Must-have Tools on Your Journey to Azure CloudCloud Governance & DevOps: Must-have Tools on Your Journey to Azure Cloud
Cloud Governance & DevOps: Must-have Tools on Your Journey to Azure Cloud
 
NIST CCRA.pptx for cloud computing and virtualization
NIST CCRA.pptx for cloud computing and virtualizationNIST CCRA.pptx for cloud computing and virtualization
NIST CCRA.pptx for cloud computing and virtualization
 
AWS Shared Responsibility Model & Compliance Program Overview
AWS Shared Responsibility Model & Compliance Program OverviewAWS Shared Responsibility Model & Compliance Program Overview
AWS Shared Responsibility Model & Compliance Program Overview
 
compliance made easy. pass your audits stress-free webinar
compliance made easy. pass your audits stress-free webinarcompliance made easy. pass your audits stress-free webinar
compliance made easy. pass your audits stress-free webinar
 
Integrated Compliance Webinar.pptx
Integrated Compliance Webinar.pptxIntegrated Compliance Webinar.pptx
Integrated Compliance Webinar.pptx
 
C24 Sandbox Insert
C24 Sandbox InsertC24 Sandbox Insert
C24 Sandbox Insert
 
BALANCING PERFORMANCE,ACCURACY,AND PRECISION FOR SECURE CLOUD TRANSACTIONS
BALANCING PERFORMANCE,ACCURACY,AND PRECISION FOR SECURE CLOUD TRANSACTIONSBALANCING PERFORMANCE,ACCURACY,AND PRECISION FOR SECURE CLOUD TRANSACTIONS
BALANCING PERFORMANCE,ACCURACY,AND PRECISION FOR SECURE CLOUD TRANSACTIONS
 
The Trouble with Cloud Forensics :Sharique M. Rizvi Head of IT Security & Fo...
The Trouble with Cloud Forensics :Sharique M. Rizvi Head of IT Security &  Fo...The Trouble with Cloud Forensics :Sharique M. Rizvi Head of IT Security &  Fo...
The Trouble with Cloud Forensics :Sharique M. Rizvi Head of IT Security & Fo...
 
Cloud technology - V2Soft
Cloud technology - V2SoftCloud technology - V2Soft
Cloud technology - V2Soft
 
3.pptx
3.pptx3.pptx
3.pptx
 
Techowl- Wazuh.pdf
Techowl- Wazuh.pdfTechowl- Wazuh.pdf
Techowl- Wazuh.pdf
 
The Trouble with Cloud Forensics
The Trouble with Cloud ForensicsThe Trouble with Cloud Forensics
The Trouble with Cloud Forensics
 

More from Massimo Felici

Accountability for Data Governance in the Cloud
Accountability for Data Governance in the CloudAccountability for Data Governance in the Cloud
Accountability for Data Governance in the CloudMassimo Felici
 
Emerging Technological Risk
Emerging Technological RiskEmerging Technological Risk
Emerging Technological RiskMassimo Felici
 
SAFECOMP 2003 Springer LNCS 2788
SAFECOMP 2003 Springer LNCS 2788SAFECOMP 2003 Springer LNCS 2788
SAFECOMP 2003 Springer LNCS 2788Massimo Felici
 
SAFECOMP 2002 Springer LNCS 2434
SAFECOMP 2002 Springer LNCS 2434SAFECOMP 2002 Springer LNCS 2434
SAFECOMP 2002 Springer LNCS 2434Massimo Felici
 
SAFECOMP 1999 Springer LNCS 1698
SAFECOMP 1999 Springer LNCS 1698SAFECOMP 1999 Springer LNCS 1698
SAFECOMP 1999 Springer LNCS 1698Massimo Felici
 
CSP 2015 Springer CCIS 530
CSP 2015 Springer CCIS 530CSP 2015 Springer CCIS 530
CSP 2015 Springer CCIS 530Massimo Felici
 
CSP 2014 Springer CCIS 470
CSP 2014 Springer CCIS 470CSP 2014 Springer CCIS 470
CSP 2014 Springer CCIS 470Massimo Felici
 
CSP 2013 Springer CCIS 182
CSP 2013 Springer CCIS 182CSP 2013 Springer CCIS 182
CSP 2013 Springer CCIS 182Massimo Felici
 

More from Massimo Felici (10)

Accountability for Data Governance in the Cloud
Accountability for Data Governance in the CloudAccountability for Data Governance in the Cloud
Accountability for Data Governance in the Cloud
 
msp20160300c1
msp20160300c1msp20160300c1
msp20160300c1
 
Emerging Technological Risk
Emerging Technological RiskEmerging Technological Risk
Emerging Technological Risk
 
SAFECOMP 2003 Springer LNCS 2788
SAFECOMP 2003 Springer LNCS 2788SAFECOMP 2003 Springer LNCS 2788
SAFECOMP 2003 Springer LNCS 2788
 
SAFECOMP 2002 Springer LNCS 2434
SAFECOMP 2002 Springer LNCS 2434SAFECOMP 2002 Springer LNCS 2434
SAFECOMP 2002 Springer LNCS 2434
 
SAFECOMP 1999 Springer LNCS 1698
SAFECOMP 1999 Springer LNCS 1698SAFECOMP 1999 Springer LNCS 1698
SAFECOMP 1999 Springer LNCS 1698
 
CSP 2015 Springer CCIS 530
CSP 2015 Springer CCIS 530CSP 2015 Springer CCIS 530
CSP 2015 Springer CCIS 530
 
CSP 2014 Springer CCIS 470
CSP 2014 Springer CCIS 470CSP 2014 Springer CCIS 470
CSP 2014 Springer CCIS 470
 
CSP 2013 Springer CCIS 182
CSP 2013 Springer CCIS 182CSP 2013 Springer CCIS 182
CSP 2013 Springer CCIS 182
 
SEOC 2004-2011
SEOC 2004-2011SEOC 2004-2011
SEOC 2004-2011
 

A4CLOUD SPACE Poster

  • 1. SPACE Security and Privacy Assurance Case Environment Problem • Cloud service provides have to comply with internal as well as external security and privacy policies • Different security and privacy controls are deployed across cloud supply chains by cloud providers • Limited support for operational alignment between policies and associated controls • Current certification and auditing practices provide limited assurance to customers and third parties Our Solution For Cloud Service Providers • An assurance case environment for mapping security and privacy policies to associated controls • A software-defined storage solution for gathering evidence supporting assurance • Structuring security and privacy policies in terms of arguments and supporting evidence gathered or generated by specific controls and associated technical solutions deployed in the cloud For Cloud Customers • Evidence-based continuous assurance of the adopted cloud services and related supply chains For Cloud Auditors • A centralised cloud-native evidence repository for inspecting cloud supply chains Innovation Continuous Assurance Systemic support for continuous assurance Evidence-Driven Assurance Linking evidence to policies AssurOps Combining Assurance and Operations Example of a structured Security and Privacy Assurance Case