More and more organizations are today using the cloud for their business as a convenient alternative to in-house solutions for storing, processing, and managing data. Cloud-based solutions are then permeating almost all aspects of business organizations, resulting appealing also for sensitive or security critical applications, whose enforcement in the cloud requires however particular care. In this article, we provide an approach for securely relying on cloud-based services for the enforcement of Internal Controls and Audit (ICA) functions for corporate governance. Our approach builds on a formalization of the ICA process and its requirements and on the consideration of the protection guarantees to be provided when outsourcing the process to external cloud services. The enforcement of the requirements leverages the use of selective encryption providing a self-protection layer on the data and on ICA reports, the hierarchical organization of keys based on the organizational structure, and compact tags for regulating write operations. Our solution enables the management of the ICA process with cloud-based services, while ensuring satisfaction of the protection requirements.

Enforcing Corporate Governance Controls with Cloud-based Services / S. De Capitani di Vimercati, S. Foresti, S. Paraboschi, P. Samarati. - In: IEEE TRANSACTIONS ON SERVICES COMPUTING. - ISSN 1939-1374. - 17:6(2024 Dec), pp. 3583-3596. [10.1109/TSC.2024.3451179]

Enforcing Corporate Governance Controls with Cloud-based Services

S. De Capitani di Vimercati
Primo
;
S. Foresti
Secondo
;
P. Samarati
Ultimo
2024

Abstract

More and more organizations are today using the cloud for their business as a convenient alternative to in-house solutions for storing, processing, and managing data. Cloud-based solutions are then permeating almost all aspects of business organizations, resulting appealing also for sensitive or security critical applications, whose enforcement in the cloud requires however particular care. In this article, we provide an approach for securely relying on cloud-based services for the enforcement of Internal Controls and Audit (ICA) functions for corporate governance. Our approach builds on a formalization of the ICA process and its requirements and on the consideration of the protection guarantees to be provided when outsourcing the process to external cloud services. The enforcement of the requirements leverages the use of selective encryption providing a self-protection layer on the data and on ICA reports, the hierarchical organization of keys based on the organizational structure, and compact tags for regulating write operations. Our solution enables the management of the ICA process with cloud-based services, while ensuring satisfaction of the protection requirements.
No
English
access control; Cloud-based services; internal controls and audit process; outsourcing; selective encryption
Settore INFO-01/A - Informatica
Articolo
Esperti anonimi
Ricerca di base
Pubblicazione scientifica
   Edge AI Technologies for Optimised Performance Embedded Processing (EdgeAI)
   EdgeAI
   MINISTERO DELLO SVILUPPO ECONOMICO
   101097300

   Green responsibLe privACy preservIng dAta operaTIONs
   GLACIATION
   EUROPEAN COMMISSION
   101070141

   SEcurity and RIghts in the CyberSpace (SERICS)
   SERICS
   MINISTERO DELL'UNIVERSITA' E DELLA RICERCA
   codice identificativo PE00000014

   POLAR: POLicy specificAtion and enfoRcement for privacy-enhanced data management
   POLAR
   MINISTERO DELL'UNIVERSITA' E DELLA RICERCA
   2022LA8XBH_001
dic-2024
28-ago-2024
Institute of Electrical and Electronics Engineers Inc.
17
6
3583
3596
14
Pubblicato
Periodico con rilevanza internazionale
scopus
Aderisco
info:eu-repo/semantics/article
Enforcing Corporate Governance Controls with Cloud-based Services / S. De Capitani di Vimercati, S. Foresti, S. Paraboschi, P. Samarati. - In: IEEE TRANSACTIONS ON SERVICES COMPUTING. - ISSN 1939-1374. - 17:6(2024 Dec), pp. 3583-3596. [10.1109/TSC.2024.3451179]
open
Prodotti della ricerca::01 - Articolo su periodico
4
262
Article (author)
Periodico con Impact Factor
S. De Capitani di Vimercati, S. Foresti, S. Paraboschi, P. Samarati
File in questo prodotto:
File Dimensione Formato  
Enforcing_Corporate_Governance_Controls_With_Cloud-Based_Services.pdf

accesso aperto

Descrizione: Article
Tipologia: Publisher's version/PDF
Dimensione 1.64 MB
Formato Adobe PDF
1.64 MB Adobe PDF Visualizza/Apri
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/2434/1128716
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 1
  • ???jsp.display-item.citation.isi??? 1
  • OpenAlex ND
social impact