Risk-Driven Compliant Access Controls for Clouds

نویسندگان

  • Hanene Boussi Rahmouni
  • Kamran Munir
  • Mohammed Odeh
  • Richard McClatchey
چکیده

There is widespread agreement that Cloud computing has proven cost cutting and agility benefits. However, security and regulatory compliance issues are continuing to challenge the wide acceptance of such technology both from social and commercial stakeholders. An important factor behind this is the fact that Clouds, and in particular public Clouds, are usually deployed and used within broad geographical or even international domains. This implies that the exchange of private and other protected data within the Cloud environment would be governed by multiple jurisdictions. These jurisdictions have a great degree of harmonisation, however, they present possible conflicts that are difficult to negotiate at run time. So far, important efforts have been taken in order to deal with regulatory compliance management for large distributed systems. However, measurable solutions are required for the context of Cloud. In this position paper, we propose an approach that starts with a conceptual model of explicit regulatory requirements for exchanging private data on a multijurisdictional environment and build on it in order to define metrics for noncompliance or risks to compliance. These metrics will be integrated within usual data access-control policies and will be checked at policy analysis time before a decision to allow/deny the data access is made.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Effect of long-term low dose prednisolone administration on bone mineral density: Relating to non-compliant women with rheumatoid arthritis

Background: Long-term treatment of rheumatoid arthritis (RA) with prednisolone (PRED) is associated with bone mineral density (BMD) loss. This study aimed to determine the status of BMD in non-compliant women who used PRED alone for RA. Methods: Non-adherent RA taking < 7.5 mg daily PRED without DMARDs for > 6 months, and RA patients taking methotrexate +PRED (RA control) were compared with ag...

متن کامل

Let’s Take it to the Clouds: The Potential of Educational Innovations, Including Blended Learning, for Capacity Building in Developing Countries

In modern decentralised health systems, district and local managers are increasingly responsible for financing, managing, and delivering healthcare. However, their lack of adequate skills and competencies are a critical barrier to improved performance of health systems. Given the financial and human resource, constraints of relying on traditional face-to-face training to upskill a large and dis...

متن کامل

A Pattern-Based and Tool-Supported Risk Analysis Method Compliant to ISO 27001 for Cloud Systems

To benefit from cloud computing and the advantages it offers, obstacles regarding the usage and acceptance of clouds have to be cleared. For cloud providers, one way to obtain customers’ confidence is to establish security mechanisms when using clouds. The ISO 27001 standard provides general concepts for establishing information security in an organization. Risk analysis is an essential part in...

متن کامل

بررسی ورتبه بندی عوامل مؤثربرریسک عملیاتی بانکداری الکترونیکی در بانک مسکن (مطالعه موردی: شعب بانک مسکن در استان لرستان)

One of the essential tools for achieving the expansion of e-commerce is e-banking system. One of the major risks identified in the field of electronic banking, is operational risks. Accurate understanding of banks about the concept of operational risk to monitor and manage this specific category of risk effectively is vital. This study aimed to identify and rank the six factors, outsourcing, an...

متن کامل

Does Participation in Farmer Field School Extension Program Improve Crop Yields? Evidence from Smallholder Tea Production Systems in Kenya

Agricultural Extension services are among the most important rural services in developing countries. The services are considered to be a key driver of technological change and productivity growth in agriculture. In Kenya, like in the rest of the developing economies, agricultural extension has largely been delivered through supply–driven approaches. Due to perceived low impact of agricultural e...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • CoRR

دوره abs/1202.5482  شماره 

صفحات  -

تاریخ انتشار 2011