Published November 23, 2023 | Version 1

Continuous Auditing and Continuous Certification in MEDINA – Security Auditor's View

  • 1. Nixu Certification Ltd, ESPOO, 02150, Finland
  • 2. Fundacion Tecnalia Research & Innovation, San Sebastián, Basque Country, E-20009, Spain

Description

This paper discusses views on continuous auditing and continuous certification in the context of the MEDINA EU project and the security auditing industry. Based on an introduction of MEDINA, the notions of continuous auditing and continuous certification are introduced from a security auditor's perspective to discuss the opportunities and challenges related to these topics. The paper also discusses further actions beyond this project in order to provide feedback on how continuous auditing and certification can be developed and introduced to the market.

Files

openreseurope-3-18041.pdf

Files (806.4 kB)

Name Size Download all
md5:747615d6b97749e71e1ae5f16226f744
806.4 kB Preview Download

Additional details

Related works

References

  • Avram MG (2014). Advantages and challenges of adopting cloud computing from an enterprise perspective. Proc Technol. doi:10.1016/j.protcy.2013.12.525
  • Kumar A (2015). Cloud Computing Challenges: A Survey. International Journal of Computer Science and Engineering Technology.
  • (2023). Cybersecurity act.
  • (2023). European cybersecurity certification scheme for cloud services.
  • (2023). MEDINA web site.
  • Etxaniz I, Leskinen M, Regueiro C (2022). An architecture proposal for the MEDINA framework.
  • Etxaniz I, Alonso J (2023). MEDINA D2.2 continuously certifiable technical and organizational measures and catalogue of cloud security metrics-v2.
  • Yautsiukhin A (2023). MEDINA D4.5 Methodology and tools for risk-based assessment and security control reconfiguration - v2.
  • Petrocchi M, Fazzolari M (2023). MEDINA D2.5 specification of the cloud security certification language – v3.
  • Ratkajec H (2023). MEDINA D3.6 tools and techniques for collecting evidence of technical and organisational measures – v3.
  • Opara S, Leskinen M (2021). MEDINA D7.3 Market, Innovation and Applicability Analysis.
  • (2015). ISO/IEC 17021-1: 2015(en). Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements.
  • Benedetto D, Caimi C, Ibrahim A (2023). D5.5 MEDINA integrated solution-v3.
  • Kunz I (2023). MEDINA D4.3 tools and techniques for the management and evaluation of cloud security certifications – v3.
  • Luna J, Ruebsamen T, Weiss P (2021). MEDINA: First impressions on experimenting with automated monitoring requirements of the upcoming eu cybersecurity certification scheme for cloud services.