An approach to security-SLA in cloud computing environment
Carlos Alberto Figueiredo da Silva, Paulo Lício de Geus · 2014
The lack of novel security controls for the cloud might arise from the fact that Cloud Computing is the convergence of many different technological areas, including Utility Computer, Computational Grid, Autonomous Computing, Virtualization and Service Oriented Architectures. These underlying areas have been independently addressed by existing general-purpose security controls, but we noticed that each current cloud security control was mapped to multiple controls from the existing, general-purpose control frameworks. We also noticed a great demand for not only patterns but also specification, monitoring and security management mechanisms for cloud environments. We reason that this scenario might require a different approach, one where the specification of security controls, geared to meet the needs of services users, may be achieved through the use of Security Service Level Agreement - Security-SLA. Security may then be improved by automating the Security-SLA.