Journal article icon

Journal article

Towards a framework for trustworthy data security level agreement in cloud procurement

Abstract:
After the post-Snowden upheavals, there is a growing concern about preserving the confidentiality of sensitive data across government agencies when using global cloud service providers, such as Amazon Web Services and Microsoft Azure. The use of certification schemes is becoming more critical to assure the security of services offered. This situation is problematic because many certification schemes aim to demonstrate compliance with a security standard rather than achieve a specified security level. Despite the benefits of security certification schemes like Common Criteria (CC), an assurance-based certification process does not scale well to service provision. To this end, this paper aims to investigate the concept of system assurance and trustworthiness in service provisioning, especially when government agencies procure cloud-based services. By using work on the Indonesian Government’s data confidentiality requirements, this work develops principles as foundations for a trustworthy data security level agreement (TDSLA) capability framework as a new assurance mechanism for service provisioning based on discrete levels of security assurance incorporated into the formulation of a service level agreement (SLA). The principles which have emerged from the empirical qualitative data collection were evaluated and validated using four approaches, namely: 1) reflection against related work; 2) testimonial validity through participants’ feedback; 3) use cases, and 4) application of transferability using cases from the UK Government Cloud (G-Cloud) and the US Federal Risk and Authorization Management Program (FedRAMP). The TDSLA capability framework can form the basis for constructing a legal language in contracts or SLAs.
Publication status:
Published
Peer review status:
Peer reviewed

Actions


Access Document


Files:
Publisher copy:
10.1016/j.cose.2021.102266

Authors


More by this author
Institution:
University of Oxford
Role:
Author


Publisher:
Elsevier
Journal:
Computers and Security More from this journal
Volume:
106
Issue:
July 2021
Article number:
102266
Publication date:
2021-04-20
Acceptance date:
2021-03-01
DOI:
ISSN:
0167-4048


Language:
English
Keywords:
Pubs id:
1166882
Local pid:
pubs:1166882
Deposit date:
2021-03-11

Terms of use



Views and Downloads






If you are the owner of this record, you can report an update to it here: Report update to this record

TO TOP