Building a Security Aware Cloud by Extending Internal Control to Cloud

Building a Security Aware Cloud by Extending Internal Control to Cloud
复制标题

将内控延伸至云端,构建安全感知云

DOI:
10.1109/isads.2011.48
复制
发表时间:
2011
期刊:
Proceedings of 10th IEEE International Symposium on Autonomous Decentralized Systems (ISADS 2011)
影响因子:
--
通讯作者:
Tanimoto Shigeaki
Tanimoto Shigeaki
中科院分区:
--
文献类型:
--
作者:
SATO Hiroyuki;Kanai Atsushi;Tanimoto Shigeaki

文献摘要

相似文献

面对今天云技术的创新爆炸,我们被迫重建云服务。在重建过程中,考虑到云作为社会基础设施的一个方面,安全性是一个关键问题。云计算的不安全问题主要可以归纳为管理的不安全问题,分为多利益相关者问题和开放空间安全问题。为了解决这些问题,我们通过在IAM和密钥管理上实现安全的信任基础,将ISMS内部控制扩展到云。由于ISMS内部控制是信任的来源,因此将其扩展到云可以成为安全的重要解决方案。此外,通过合同控制服务质量和安全级别,我们可以优化委托给云的服务和安全成本。
Faced with today's innovative blow-up of cloud technologies, we are forced to rebuild services in terms of cloud. In the rebuilding, considering a facet of cloud as social infrastructure, security is a critical problem. Most of insecurity against clouds can be summarized as insecurity of management, which is classified into the multiple stakeholder problem, and the open space security problem. As a solution to these problems, we extend ISMS internal control to cloud by implementing trust base of security on IAM and key management. Because ISMS internal control is a source of trust, its extension to cloud can be an essential solution of security. Moreover, by controlling levels of quality of service and security by contract, we can optimize cost on service and security delegated to a cloud.