Recent models of software provisioning based on cloud architectures co-exist and interact with in-premises large and heterogeneous software ecosystems. In this increasingly complex landscape, organizations and users are striving to deal with assurance in all phases of software life cycle: acquisition, installation, use and maintenance. In this paper, we start by describing the notion of machine-readable security certificates, and discuss how they can be used for assurance-based software selection. Then, we introduce some models and tools for administrators for the automatic management of security policies, which include policy conflict detection. Finally, we discuss how these two approaches can be integrated for supporting organization to (semi-) automatically address the security requirements throughout the entire software life cycle.

Integrating advanced security certification and policy management

PARABOSCHI, Stefano;
2013-01-01

Abstract

Recent models of software provisioning based on cloud architectures co-exist and interact with in-premises large and heterogeneous software ecosystems. In this increasingly complex landscape, organizations and users are striving to deal with assurance in all phases of software life cycle: acquisition, installation, use and maintenance. In this paper, we start by describing the notion of machine-readable security certificates, and discuss how they can be used for assurance-based software selection. Then, we introduce some models and tools for administrators for the automatic management of security policies, which include policy conflict detection. Finally, we discuss how these two approaches can be integrated for supporting organization to (semi-) automatically address the security requirements throughout the entire software life cycle.
book chapter - capitolo di libro
scientifica
Inglese
2013
Cyber Security and Privacy: Trust in the Digital World and Cyber Security and Privacy EU Forum 2013, Brussels, Belgium, April 2013, Revised Selected Papers
Felici, Massimo
cartaceo
online
978-3-642-41204-2
978-3-642-41205-9
182
55
66
Germany
Berlin
Springer-Verlag Germany
Settore ING-INF/05 - Sistemi di Elaborazione delle Informazioni
Service assurance; security certification; security policy management;
info:eu-repo/semantics/bookPart
none
1.2 Contributi in volume - Book chapters::1.2.01 Contributi in volume (Capitoli o Saggi) - Book Chapters/Essays
no full text
Bezzi, Michele; Damiani, Ernesto; Paraboschi, Stefano; Plate, Henrik
4
268
File allegato/i alla scheda:
Non ci sono file allegati a questa scheda.
Pubblicazioni consigliate

Aisberg ©2008 Servizi bibliotecari, Università degli studi di Bergamo | Terms of use/Condizioni di utilizzo

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10446/30299
Citazioni
  • Scopus 1
  • ???jsp.display-item.citation.isi??? 1
social impact