Journal article
Towards a framework for trustworthy data security level agreement in cloud procurement
- Abstract:
- After the post-Snowden upheavals, there is a growing concern about preserving the confidentiality of sensitive data across government agencies when using global cloud service providers, such as Amazon Web Services and Microsoft Azure. The use of certification schemes is becoming more critical to assure the security of services offered. This situation is problematic because many certification schemes aim to demonstrate compliance with a security standard rather than achieve a specified security level. Despite the benefits of security certification schemes like Common Criteria (CC), an assurance-based certification process does not scale well to service provision. To this end, this paper aims to investigate the concept of system assurance and trustworthiness in service provisioning, especially when government agencies procure cloud-based services. By using work on the Indonesian Government’s data confidentiality requirements, this work develops principles as foundations for a trustworthy data security level agreement (TDSLA) capability framework as a new assurance mechanism for service provisioning based on discrete levels of security assurance incorporated into the formulation of a service level agreement (SLA). The principles which have emerged from the empirical qualitative data collection were evaluated and validated using four approaches, namely: 1) reflection against related work; 2) testimonial validity through participants’ feedback; 3) use cases, and 4) application of transferability using cases from the UK Government Cloud (G-Cloud) and the US Federal Risk and Authorization Management Program (FedRAMP). The TDSLA capability framework can form the basis for constructing a legal language in contracts or SLAs.
- Publication status:
- Published
- Peer review status:
- Peer reviewed
Actions
Access Document
- Files:
-
-
(Preview, Accepted manuscript, 855.2KB, Terms of use)
-
- Publisher copy:
- 10.1016/j.cose.2021.102266
Authors
- Publisher:
- Elsevier
- Journal:
- Computers and Security More from this journal
- Volume:
- 106
- Issue:
- July 2021
- Article number:
- 102266
- Publication date:
- 2021-04-20
- Acceptance date:
- 2021-03-01
- DOI:
- ISSN:
-
0167-4048
- Language:
-
English
- Keywords:
- Pubs id:
-
1166882
- Local pid:
-
pubs:1166882
- Deposit date:
-
2021-03-11
Terms of use
- Copyright holder:
- Elsevier
- Copyright date:
- 2021
- Rights statement:
- © 2021 Elsevier Ltd. All rights reserved.
- Notes:
- This is the accepted manuscript version of the article. The final version is available online from Elsevier at: https://doi.org/10.1016/j.cose.2021.102266
If you are the owner of this record, you can report an update to it here: Report update to this record