The Cloud Adoption Risk Assessment Model is designed to help cloud customers in assessing the risks that they face by selecting a specific cloud service provider. It evaluates background information obtained from cloud customers and cloud service providers to analyze various risk scenarios. This facilitates decision making an selecting the cloud service provider with the most preferable risk profile based on aggregated risks to security, privacy, and service delivery. Based on this model we developed a prototype using machine learning to automatically analyze the risks of representative cloud service providers from the Cloud Security Alliance Security, Trust & Assurance Registry.
We propose a data protection impact assessment (DPIA) method based on successive questionnaires for an initial screening and for a full screening for a given project. These were tailored to satisfy the needs of Small and Medium Enterprises (SMEs) that intend to process personal data in the cloud. The approach is based on legal and socio-economic analysis of privacy issues for cloud deployments and takes into consideration the new requirements for DPIAs within the European Union (EU) as put forward by the proposed General Data Protection Regulation (GDPR). The resultant features have been implemented within a tool.
Cloud Adoption Risk Assessment Model is designed for cloud customers to assess the risks that they face by selecting a specific cloud service provider. It is an expert system to evaluate various background information obtained from cloud customers, cloud service providers and other public external sources, and to analyze various risk scenarios. This would facilitate cloud customers in making informed decision to select the cloud service provider with the most preferable risk profile.
Component Design The component diagram (Figure 4.2) describes a part of the health care actors and their interactions. We have the data subject Kim and his relative Sandra. Sandra is a joint data controller. There are three cloud providers (named cloudX, cloudY and cloudZ). The data controller is the hospital and Leslie is the auditor. These entities are represented as components in the diagram offering and using some services. We consider only one way services to make more explicit the control and the communications. Note that the AccesRigthInterface is implemented by the three cloud providers and used by the two data subjects. This specific design can be improved, its purpose is mainly to make more concrete the AAL expressions we expect to write. B3-health-care-components-V2
Adequate trust and risk management are fundamental for governance in the cloud. Data controllers, processors, or more generally cloud customers must be aware of specific risks for business confidential, personal and other kinds of sensitive data subject to regulatory restrictions when using cloud services. In this deliverable we describe the progress in defining a representation of trust and risk for cloud service chains. We build on existing methodologies to create a high level approach to define risk in terms of the actors involved in a cloud service chain, possibly combining Software as a Service (SaaS), Platform as a Service (PaaS) and Infrastructure as a Service (IaaS), their responsibilities, obligations, and other accountability attributes, to finally determine how the trust assigned to each link in the chain will influence risk assessments. We reviewed extensively risk analysis methodologies, guidelines, models and standards to identify the gaps they have when applied to cloud computing, under the perspective of accountability. We propose a broad approach covering all risk categories mentioned in the literature, very close to the enumeration proposed by ENISA(ENISA, 2009). Establishing a level of trust about a cloud service is dependent on the degree of control an organization is able to exert on the provider to provision the security controls necessary to protect the organization’s data and applications, and also the evidence provided about the effectiveness of those controls. The majority of cloud computing agreements are offered in standard form, often drawn on traditional outsourcing or technology licensing models, but those types of agreements may not cover the particular risks associated with cloud computing. We provide an analysis of the impact of risks to the conclusion of cloud contracts, and how risk allocation affects the reliability of contracts as effective trust mechanisms - in particular, the security obligations allocated to data controllers -and data processors- established under the Data Protection Directive aim at mitigating risks, given that both entities are obliged to adopt appropriate security measures depending on the nature of processing. Trust also greatly influences the adoption of cloud services, shifting the cloud market. It is necessary to understand how social behaviour of (potential) cloud consumers will affect their choice to make use of cloud services. Aiming to integrate both the computer and social science perspectives on trust we investigate the social economic impact of changing roles, responsibilities and risks due to the use of cloud services by the different cloud consumers, as trust is shaped by the consumers’ perceptions of risk in cloud providers and their services. We depicted different perspectives on trust, in particular on how to make it measurable via the notion of reputation and other important elements for a risk and trust model. The deliverable also elaborates on the understanding of the relationships among accountability, risk, and trust and how this enables accountability governance. We present an analysis of stakeholder feedback (from the B2 – Stakeholder Elicitation workshop dedicated to risks) We created an abstract meta-model for cloud ecosystems, to which we mapped the A4Cloud conceptual framework of the work package C2. From this we can instantiate specific cloud service chains, following a structured approach in order to determine the trust and risk levels. In this deliverable, we set up the basis for modelling trust relationships and for enumerating risks in cloud ecosystems that will be the starting point for the privacy impact assessments. We also investigated how continuous risk monitoring of cloud services can be performed in an accountable and trustworthy setting, by creating a generic analytical model to understand how concrete events about the service operations, security and privacy will influence the risk and reputation levels for a given service composition. We confirmed the fitness of the model using numerical analysis using Monte Carlo simulations.