Evidence Management for Continuous Certification as a Service in the Cloud
Akronym
EMERALD
Bidragets beskrivning
Cloud-based services have grown from basic computing services to complex ecosystems, comprising (virtual) infrastructure, business processes and application code. These advanced services also increasingly leverage the usage of Artificial Intelligence, including Machine Learning or Natural Language Processing techniques, raising the complexity even higher. Due to the cascade of dependencies among the different products and services, the need arose to bring more agility to the certification process of cloud-based services, e.g., using continuous monitoring and assessment, as evidenced by references to it in the certifications of the EU Cybersecurity Act (EU CSA). To transform the continuous assessment and certification concept into the complete realization of a Certification-as-a-Service (CaaS), several challenges need to be solved: 1) current proposed proofs of concepts for continuous monitoring lack interoperability at technology level, 2) the adoption of cloud and edge computing and the incorporation of regulations on specific topics or domains, such as AI, put significant strain on companies to comply with a multitude of different security schemes, 3) existing market fragmentation for continuous certification (scope, methodologies), hinder transparency and accountability in the provision of European cloud services, 4),smart tools and models need to be adopted to ease the agile application and implementation of the CaaS concept reducing complexity in the whole cloud certification value chain easing the adoption of CaaS by the different stakeholders. To overcome these challenges, the design and implementation of the EMERALD CaaS solution leverages the H2020 project MEDINA’s outcomes and advances them to TRL 7 in the EMERALD core. Two PoCs will be provided; one for composite certification and one for mapping requirements to upcoming AI certification schemes. EMERALD will pave the road towards CaaS for continuous certification of harmonized cybersecurity schemes.
Visa merStartår
2023
Slutår
2026
Beviljade finansiering
NIXU OYJ
196 350 €
Participant
IONOS SE (DE)
267 925 €
Participant
CLOUDFERRO SP ZOO (PL)
191 240 €
Participant
FABASOFT R&D GMBH (AT)
561 487.5 €
Participant
CAIXABANK SA (ES)
182 175 €
Participant
OPENNEBULA SYSTEMS SL (ES)
379 925 €
Participant
KNOW-CENTER GMBH RESEARCH CENTER FOR DATA-DRIVEN BUSINESS & BIG DATA ANALYTICS (AT)
478 250 €
Participant
FUNDACION TECNALIA RESEARCH & INNOVATION (ES)
738 375 €
Coordinator
SOFTWARE COMPETENCE CENTER HAGENBERG GMBH (AT)
573 500 €
Participant
CONSIGLIO NAZIONALE DELLE RICERCHE (IT)
308 200 €
Participant
FRAUNHOFER GESELLSCHAFT ZUR FOERDERUNG DER ANGEWANDTEN FORSCHUNG E.V. (DE)
859 000 €
Participant
Beviljat belopp
4 736 428 €
Finansiär
Europeiska unionen
Typ av finansiering
HORIZON Innovation Actions
Ramprogram
Horizon Europe (HORIZON)
Utlysning
Programdel
Civil Security for Society (11700 Cybersecurity (11703 )
Tema
Development and validation of processes and tools used for agile certification of ICT products, ICT services and ICT processes (HORIZON-CL3-2022-CS-01-04Utlysnings ID
HORIZON-CL3-2022-CS-01 Övriga uppgifter
Finansieringsbeslutets nummer
101120688