Enabling Secure Cloud Governance using Policy as Code

dc.contributor.authorJothimani, Arun Prakash
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.departmentChalmers University of Technology / Department of Computer Science and Engineeringen
dc.contributor.examinerOlovsson, Tomas
dc.contributor.supervisorAli-Eldin Hassan, Ahmed
dc.date.accessioned2022-11-30T10:01:51Z
dc.date.available2022-11-30T10:01:51Z
dc.date.issued2022
dc.date.submitted2020
dc.description.abstractCloud infrastructures are evolving at a rapid rate. Thus, it is important to ensure the stability and reliability of the cloud services [1] as they support many of today’s critical systems. The Cloud Security Governance Deployment Framework [2] describes the critical security issues that must be considered and analyzed by the developer to ensure a secure cloud environment. With the rapid growth in the data and users, there is a need for solid rules to handle data storage and Identity Access Management(IAM). Lack of proper authentication management [3], user management, authorization management, access management, data management and monitoring can easily open doors for attackers to exploit the system [4]. The initiation, development, implementation, operation, and destruction phase has to be studied based on the cloud security critical domain guidelines, and risk considerations [2][5]. Policy-driven governance can be used to control the provisioning and consumption of cloud services. As discussed in [6], It is a challenging task to identify and implement scalable monitoring for different types of metrics [7] relevant to the Cloud infrastructure of the organization. The industrial state of the art in policy-based governance [8] has to meet the dynamic needs of the organization that changes throughout the period of time. The policy definition and evaluation are tightly coupled in one component via imperative languages, which hinders the easy evolution. This tightly coupled approach gives an opportunity to introduce policy-as-code [9] to modularize and decouple the policy environment for easy governance adoption. The policy based strategy will also provide a better solution to manage user credentials, user authentication and authorization [10].
dc.identifier.coursecodeDATX05
dc.identifier.urihttps://odr.chalmers.se/handle/20.500.12380/305845
dc.language.isoeng
dc.setspec.uppsokTechnology
dc.subjectCloud Governance
dc.subjectPolicy
dc.subjectInfrastructure as code
dc.subjectConfiguration Management
dc.subjectAutomation
dc.titleEnabling Secure Cloud Governance using Policy as Code
dc.type.degreeExamensarbete för masterexamensv
dc.type.degreeMaster's Thesisen
dc.type.uppsokH
local.programmeComputer systems and networks (MPCSN), MSc
Ladda ner
Original bundle
Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
CSE 22-72 Jothimani.pdf
Storlek:
4.87 MB
Format:
Adobe Portable Document Format
Beskrivning:
License bundle
Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Storlek:
1.64 KB
Format:
Item-specific license agreed upon to submission
Beskrivning: