Show simple item record

dc.contributor.advisorHiguero Aperribay, María Victoria ORCID
dc.contributor.advisorLarrucea Uriarte, Xabier
dc.contributor.authorRíos Velasco, Erkuden
dc.date.accessioned2021-02-19T15:39:43Z
dc.date.available2021-02-19T15:39:43Z
dc.date.issued2020-07-16
dc.date.submitted2020-07-16
dc.identifier.urihttp://hdl.handle.net/10810/50231
dc.descriptionx, 169 p.es_ES
dc.description.abstractThis Thesis studies research questions about how to design multiCloud applications taking into account security and privacy requirements to protect the system from potential risks and about how to decide which security and privacy protections to include in the system. In addition, solutions are needed to overcome the difficulties in assuring security and privacy properties defined at design time still hold all along the system life-cycle, from development to operation.In this Thesis an innovative DevOps integrated methodology and framework are presented, which help to rationalise and systematise security and privacy analyses in multiCloud to enable an informed decision-process for risk-cost balanced selection of the protections of the system components and the protections to request from Cloud Service Providers used. The focus of the work is on the Development phase of the analysis and creation of multiCloud applications.The main contributions of this Thesis for multiCloud applications are four: i) The integrated DevOps methodology for security and privacy assurance; and its integrating parts: ii) a security and privacy requirements modelling language, iii) a continuous risk assessment methodology and its complementary risk-based optimisation of defences, and iv) a Security and Privacy Service Level AgreementComposition method.The integrated DevOps methodology and its integrating Development methods have been validated in the case study of a real multiCloud application in the eHealth domain. The validation confirmed the feasibility and benefits of the solution with regards to the rationalisation and systematisation of security and privacy assurance in multiCloud systems.es_ES
dc.language.isoenges_ES
dc.rightsinfo:eu-repo/semantics/openAccesses_ES
dc.subjectdata transmission deviceses_ES
dc.titleAn Integrated Framework for the Methodological Assurance of Security and Privacy in the Development and Operation of MultiCloud Applicationses_ES
dc.typeinfo:eu-repo/semantics/doctoralThesises_ES
dc.rights.holder(c)2020 Erkuden Ríos Velasco
dc.identifier.studentID25957es_ES
dc.identifier.projectID17443es_ES
dc.departamentoesIngeniería de comunicacioneses_ES
dc.departamentoeuKomunikazioen ingeniaritzaes_ES


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record