AMOE: a Tool to Automatically Extract and Assess Organizational Evidence for Continuous Cloud Audit

07/31/2023
by   Franz Deimling, et al.
0

The recent spread of cloud services has enabled many companies to take advantage of them. Nevertheless, the main concern about the adoption of cloud services remains the lack of transparency perceived by customers regarding security and privacy. To overcome this issue, Cloud Service Certifications (CSCs) have emerged as an effective solution to increase the level of trust in cloud services, possibly based on continuous auditing to monitor and evaluate the security of cloud services on an ongoing basis. Continuous auditing can be easily implemented for technical aspects, while organizational aspects can be challenging due to their generic nature and varying policies between service providers. In this paper, we propose an approach to facilitate the automatic assessment of organizational evidence, such as that extracted from security policy documents. The evidence extraction process is based on Natural Language Processing (NLP) techniques, in particular on Question Answering (QA). The implemented prototype provides promising results on an annotated dataset, since it is capable to retrieve the correct answer for more than half of the tested metrics. This prototype can be helpful for Cloud Service Providers (CSPs) to automate the auditing of textual policy documents and to help in reducing the time required by auditors to check policy documents.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/03/2019

An Automated Security Analysis Framework and Implementation for Cloud

Cloud service providers offer their customers with on-demand and cost-ef...
research
04/12/2018

QRES: Quantitative Reasoning on Encrypted Security SLAs

While regulators advocate for higher cloud transparency, many Cloud Serv...
research
07/13/2019

Dogfooding: use IBM Cloud services to monitor IBM Cloud infrastructure

The stability and performance of Cloud platforms are essential as they d...
research
05/15/2019

Towards a Security Baseline for IaaS-Cloud Back-Ends in Industry 4.0

The popularity of cloud based Infrastructure-as-a- Service (IaaS) soluti...
research
03/04/2022

Network Services Anomalies in NFV: Survey, Taxonomy, and Verification Methods

Network Function Virtualization (NFV) has emerged as a disruptive networ...
research
04/02/2018

Database as a Service - Current Issues and Its Future

With the prevalence of applications in cloud, Database as a Service (DBa...
research
01/16/2022

PolicyCLOUD: A prototype of a Cloud Serverless Ecosystem for Policy Analytics

We present PolicyCLOUD, a prototype for an extensible, serverless cloud-...

Please sign up or login with your details

Forgot password? Click here to reset