Continuous Auditing and Continuous Certification in MEDINA – Security Auditor's View
Authors/Creators
- 1. Nixu Certification Ltd, ESPOO, 02150, Finland
- 2. Fundacion Tecnalia Research & Innovation, San Sebastián, Basque Country, E-20009, Spain
Description
This paper discusses views on continuous auditing and continuous certification in the context of the MEDINA EU project and the security auditing industry. Based on an introduction of MEDINA, the notions of continuous auditing and continuous certification are introduced from a security auditor's perspective to discuss the opportunities and challenges related to these topics. The paper also discusses further actions beyond this project in order to provide feedback on how continuous auditing and certification can be developed and introduced to the market.
Files
openreseurope-3-18041.pdf
Files
(806.4 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:747615d6b97749e71e1ae5f16226f744
|
806.4 kB | Preview Download |
Additional details
Related works
- Cites
- 10.1016/j.protcy.2013.12.525 (DOI)
References
- Avram MG (2014). Advantages and challenges of adopting cloud computing from an enterprise perspective. Proc Technol. doi:10.1016/j.protcy.2013.12.525
- Kumar A (2015). Cloud Computing Challenges: A Survey. International Journal of Computer Science and Engineering Technology.
- (2023). Cybersecurity act.
- (2023). European cybersecurity certification scheme for cloud services.
- (2023). MEDINA web site.
- Etxaniz I, Leskinen M, Regueiro C (2022). An architecture proposal for the MEDINA framework.
- Etxaniz I, Alonso J (2023). MEDINA D2.2 continuously certifiable technical and organizational measures and catalogue of cloud security metrics-v2.
- Yautsiukhin A (2023). MEDINA D4.5 Methodology and tools for risk-based assessment and security control reconfiguration - v2.
- Petrocchi M, Fazzolari M (2023). MEDINA D2.5 specification of the cloud security certification language – v3.
- Ratkajec H (2023). MEDINA D3.6 tools and techniques for collecting evidence of technical and organisational measures – v3.
- Opara S, Leskinen M (2021). MEDINA D7.3 Market, Innovation and Applicability Analysis.
- (2015). ISO/IEC 17021-1: 2015(en). Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements.
- Benedetto D, Caimi C, Ibrahim A (2023). D5.5 MEDINA integrated solution-v3.
- Kunz I (2023). MEDINA D4.3 tools and techniques for the management and evaluation of cloud security certifications – v3.
- Luna J, Ruebsamen T, Weiss P (2021). MEDINA: First impressions on experimenting with automated monitoring requirements of the upcoming eu cybersecurity certification scheme for cloud services.