standardisation, certification research & innovation...

18
1 14/06/2013 Research & Innovation Public Your business technologists. Powering progress 04-08-2011 Standardisation, Certification and International Issues in Cloud Security Aljosa Pasic, June 2013

Upload: others

Post on 23-Jan-2021

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

1

14/06/2013

Research & Innovation Public

Your business technologists. Powering progress

04-08-2011

Standardisation, Certification and International Issues in

Cloud Security

Aljosa Pasic,

June 2013

Page 2: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

2

14/06/2013

Research & Innovation Public

Unleashing the Potential of CC

▶ Communication from EC to the European Parliament

▶ Three cloud-specific actions

– Cutting through the Jungle of Standards

– Safe and Fair Contract Terms and Conditions

– Establishing a European Cloud Partnership to drive innovation and growth from the public sector

▶ Comments from European Economic and Social Committee

– Top down approach

▶ CIRRUS coordination and support action takes hybrid approach to support EU policy: top-down & bottom up mapping

Page 3: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

3

14/06/2013

Research & Innovation Public

Building the chain of trust

Page 4: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

4

14/06/2013

Research & Innovation Public

Five pillars of CIRRUS

▶ETSI – Cloud Standard Convergence

▶ENISA – Cloud Expert Group

▶ECP and SIG

▶EC FP7 – Research projects

▶Member States – Initatives and Projects

Page 5: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

5

14/06/2013

Research & Innovation Public

ETSI CSC

Page 6: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

6

14/06/2013

Research & Innovation Public

Which security standards?

Page 7: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

7

14/06/2013

Research & Innovation Public

When less is more

Page 8: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

8

14/06/2013

Research & Innovation Public

ENISA

▶ Single Cloud Security Expert Group

▶ Current focus on Incident Management

Page 9: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

9

14/06/2013

Research & Innovation Public

WHO did it?

Page 10: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

10

14/06/2013

Research & Innovation Public

European Cloud Partnership

▶ ECP Steering Board: Presidents, Ministers and CEOs

▶ Select Industry Group

▶ Budget for Pre-Commercial Procurement

Page 11: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

11

14/06/2013

Research & Innovation Public

Conclusions (1)

OK?

Use of

Standards

Certificatio

n

Contract

terms

Page 12: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

12

14/06/2013

Research & Innovation Public

Problem that remain

Page 13: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

13

14/06/2013

Research & Innovation Public

Research Projects

▶ Cloud Research with Security WP

▶ Security Research with Cloud use cases

Page 14: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

14

14/06/2013

Research & Innovation Public

And also…

Page 15: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

15

14/06/2013

Research & Innovation Public

Member States

▶ Initatives: EuroCloud

▶ Research Projects

Page 16: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

16

14/06/2013

Research & Innovation Public

What about nr. 6??

▶ International issues:

– Metrics

– Initatives

– Cultural aspects

Page 17: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

17

14/06/2013

Research & Innovation Public

Conclusions (2)

▶CSP tend to choose or even impose their standards, certificates and contract terms – supported by legislative environment of their choice

▶Customers should better negotiate e.g. SLA and other contract terms

▶Policy makers should take bottom-up opinions/status into account

▶Researchers should align with market and policy priorities

▶Standardization/agencies should synchronize and converge their efforts & recommendations

Page 18: Standardisation, Certification Research & Innovation ...dimacs.rutgers.edu/Workshops/TAFC/Slides/APasic.pdf · 1 14/06/2013 Research & Innovation Public Your business technologists

14/06/2013

Thank you Aljosa Pasic [email protected]

Atos, the Atos logo, Atos Consulting, Atos Worldline, Atos Sphere, Atos Cloud and Atos WorldGrid

are registered trademarks of Atos SA. June 2011

© 2011 Atos. Confidential information owned by Atos, to be used by the recipient only. This document, or any part of it, may not be reproduced, copied, circulated and/or distributed nor quoted without prior written approval from Atos.