Enabling Secure Cloud Governance using Policy as Code
dc.contributor.author | Jothimani, Arun Prakash | |
dc.contributor.department | Chalmers tekniska högskola / Institutionen för data och informationsteknik | sv |
dc.contributor.department | Chalmers University of Technology / Department of Computer Science and Engineering | en |
dc.contributor.examiner | Olovsson, Tomas | |
dc.contributor.supervisor | Ali-Eldin Hassan, Ahmed | |
dc.date.accessioned | 2022-11-30T10:01:51Z | |
dc.date.available | 2022-11-30T10:01:51Z | |
dc.date.issued | 2022 | |
dc.date.submitted | 2020 | |
dc.description.abstract | Cloud infrastructures are evolving at a rapid rate. Thus, it is important to ensure the stability and reliability of the cloud services [1] as they support many of today’s critical systems. The Cloud Security Governance Deployment Framework [2] describes the critical security issues that must be considered and analyzed by the developer to ensure a secure cloud environment. With the rapid growth in the data and users, there is a need for solid rules to handle data storage and Identity Access Management(IAM). Lack of proper authentication management [3], user management, authorization management, access management, data management and monitoring can easily open doors for attackers to exploit the system [4]. The initiation, development, implementation, operation, and destruction phase has to be studied based on the cloud security critical domain guidelines, and risk considerations [2][5]. Policy-driven governance can be used to control the provisioning and consumption of cloud services. As discussed in [6], It is a challenging task to identify and implement scalable monitoring for different types of metrics [7] relevant to the Cloud infrastructure of the organization. The industrial state of the art in policy-based governance [8] has to meet the dynamic needs of the organization that changes throughout the period of time. The policy definition and evaluation are tightly coupled in one component via imperative languages, which hinders the easy evolution. This tightly coupled approach gives an opportunity to introduce policy-as-code [9] to modularize and decouple the policy environment for easy governance adoption. The policy based strategy will also provide a better solution to manage user credentials, user authentication and authorization [10]. | |
dc.identifier.coursecode | DATX05 | |
dc.identifier.uri | https://odr.chalmers.se/handle/20.500.12380/305845 | |
dc.language.iso | eng | |
dc.setspec.uppsok | Technology | |
dc.subject | Cloud Governance | |
dc.subject | Policy | |
dc.subject | Infrastructure as code | |
dc.subject | Configuration Management | |
dc.subject | Automation | |
dc.title | Enabling Secure Cloud Governance using Policy as Code | |
dc.type.degree | Examensarbete för masterexamen | sv |
dc.type.degree | Master's Thesis | en |
dc.type.uppsok | H | |
local.programme | Computer systems and networks (MPCSN), MSc |