Aus Aifbportal
Wechseln zu:Navigation, Suche
News of November 13, 2018

New Research Article Accepted for Publication in Communications of the AIS

The new research article bya Sebastian Lins, Stephan Schneider and Ali Sunyaev together with Jakub Szefer (Yale University) with the title “Designing Monitoring Systems for Continuous Certification of Cloud Services: Deriving Meta-Requirements and Design Guidelines” was accepted in the journal Communications of the AIS.

The articles derives requirements and design guidelines for the implementation of continuous certification processes. Particularly, it focuses on monitoring-based certification processes.

Continuous service certification (CSC) involves the consistent gathering and assessing of certification-relevant information about cloud service operation to validate ongoing certification criteria adherence. Previous research has proposed test-based CSC methodologies that directly assess components of the cloud service infrastructure. However, test-based certification requires access to the cloud infrastructure by certification authorities, which may be limited due to various issues. To address these challenges, cloud service providers have to monitor their cloud service infrastructure to gather certification-relevant data by themselves, and then provide these data to certification authorities, which is referred to monitoring-based CSC. Nevertheless, we require a better understanding of how to design monitoring systems to enable monitoring-based CSC of cloud services. By taking a design science perspective, we derive universal meta-requirements and design guidelines for CSC monitoring systems based on findings from five expert focus group interviews with 33 cloud experts and 10 one-to-one interviews with cloud customers. With this study, we have expanded the current knowledge base regarding CSC and monitoring-based CSC. Our derived design guidelines contribute to the development of CSC monitoring systems and enable monitoring-based CSC that overcomes issues of prior test-based approaches.

More info at: Designing Monitoring Systems for Continuous Certification of Cloud Services Deriving Meta-Requirements and Design Guidelines

From the research group Critical Information Infrastructures