Public-Private proposal for a European Cloud Security Certification Scheme
Berlin 2nd April 2019
Public-Private proposal for a European Cloud Security Certification - - PowerPoint PPT Presentation
Berlin 2 nd April 2019 Public-Private proposal for a European Cloud Security Certification Scheme C5 success story and the way forward to a European certification for cloud services Clemens Doubrava Head of Section of Information Security in
Berlin 2nd April 2019
Clemens Doubrava Head of Section of Information Security in the cloud
3
Sept 2017 April 2018 Jan 18 Dec 17
To explore the possibility of developing a European Cloud Certification Scheme in the context of the Cybersecurity Act and come up with a recommendation that will be presented to the European Commission and ENISA
4
4
CSP CERT WG
Balanced/Commitment/effectiveness
Observers
Transparency Relevant expertise & legitimate interest Public
Access Partnership, Bitkom/Deutsche Bundesdruckerei, CISCO, CISPE, CTO Security Networks AG, DINSIC, Danish Business Authority, Digital Europe, European Banking Federation, Google, Government of Ontario, HUAWEI, Microsoft, Nokia, OVH, Outscale, Palo Alto, PWC, Santander bank, SALESFORCE, Sistemas de Datos/Digital SME, SCOPE EUROPE, Swedish civil contingencies agency, Upcloud, VARAM, Virtustream (DELL), VdTuev, VMWare Accenture, AMAZON, ANSSI, BBVA/EBF, Bosch GmbH, BSI, CSA, CISCO, Danish Tax Authority, Deutsche Börse Group, Erasmus University, Eurocloud, Fabasoft, Google, HSBC, IBM, JPMorgan, LEET Security, LSEC, Norea, Oodrive, ORACLE, Orange, PWC, SAP , Secura, Securemailbox, TECNALIA, Trusted Cloud, UCIMU/Confindustria/Business Europe, UNINFO, Zeker Online
Co-chairs
Rapporteur
European Commision:
ENISA
32 Drafting members 28 Observers
Online Collaborative tool (Community site / Blog) Strong approved Governance document Comprehensive approved Rules of Procedure document Monitor attendance and relevant contribution Webinar formats by default every two weeks with actions and deliverables assigned to drafting members Quarterly rotating plenary sessions
www.cspcert.eu
6
6
Incomplete Very comprehensive Underlying Security Objectives / requirements / Implementation (Assurance Levels) High Independence, trust and/or expertise Conformity Assessment Methodologies Continuity & Robustness of:
Low Independence, trust and/or expertise
7
7
To explore the possibility of developing a European Cloud Certification Scheme in the context of the Cybersecurity Act and come up with a recommendation that will be presented to the European Commission and ENISA
Milestone 1 Milestone 2 Milestone 3 Open Consultation
Jan-Oct 2018 Oct-Dec 2018 Jan 2019 Jun 2019
8
☁︐Rome plenary (16th & 17th of October 2018)
we start milestone 2 ☁︐Vienna plenary (6th & 7th of December 2018)
Sept 2017 July 2019 April 18 Dec 18 Jan 18 July 18 Oct 18
Leire Orue-Echevarria Arrieta Project Manager Cloud technologies and security
https://ec.europa.eu/digital-single-market/en/news/regulating-cloud-computing-europe-new-study-considers-options-certification-schemes
ISO 17203 ISO 17789 ISO 19944 ISO 19941 ISO 19086 ISO 19099 ISO 22301 ISO/IEC 24760 Family of 27000 ISO/IEC 27000 , ISO/IEC 27001 & ISO /IEC 27002 ISOIEC 29100 ISO/IEC 29101 ISO/IEC 29115https://ec.europa.eu/digital-single-market/en/news/regulating-cloud-computing-europe-new-study-considers-options-certification-schemes
https://www.enisa.europa.eu/news/enisa-news/enisa-cloud-certification-schemes-metaframework
United Kingdom, Italy, Netherlands, Spain, Sweden, Germany, Finland, Austria, Slovakia, Greece and Denmark.
Bert Tuinsma MSc RA Chairman of Zeker-OnLine, Issuer of Trust Certificates for Cloud Services
to enhance the credibility (or confidence or trust) towards stakeholders
Conceptual Framework
Levels of provided assurance
○
Evidence-based conformity assessment
○ Based upon ISO defined approach ○ Based upon ISAE defined approach
CAMs in place
Reporting and validity
Elements of a CAM
Appendix analysis the first three Conformity methodologies
https://ec.europa.eu/eusurvey/runner/cspcertconsultation
Milestone 1 doc Milestone 2 doc
Launched 15th January 2019
Closed 3th February 2019
Aurelien Leteinturier Head of security products and services approval unit
SaaS Applet Cloud Computing platform Feared events
(lactose free vs regular) Certification strategy
and process ?
SaaS Applet Cloud Computing platform Feared events
(lactose free vs regular) Certification strategy
and process ?
CSA certification Product CSA certification Software / Cloud service CSA certification Cloud service CSA Software CSA certification Product
SaaS Cloud Computing platform Feared events
(lactose free vs regular) Certification strategy
and process ?
CSA Certification CSA certification Product
MiFEURG*
*Milk and Fridge European Union Regulation Group
Applet
CSA Certification CSA Certification CSA Certification CSA Certification
Cloud Computing platform Feared events
(lactose free vs regular) Certification strategy
and process ?
Applet SaaS
CSP certification perimeter
Baseline CSP service (SaaS, PaaS and Iaas), certified
Assurance level : Basic, High or Substantial Energy Automotive
Specific Requirements Specific Requirements
Specific sector
Specific Requirements
CSP certification perimeter
Control 1 Control 2 Control 3 Control 4 Control xxx
++ + + + + ++ ++
level and stringency
++ Depth
assessment
○ Requirements for the assurance level substantial ○ Requirements for the assurance level basic
level substantial fulfills as well :
○ Requirements for the assurance level basic
Articles Content CCAL CSAR SGOV 43, 43a and 43b General consideration regarding the cybersecurity certification framework. 44 and 44a Preparation, adoption and review of a European cybersecurity certification schemes, publication on a centralized website of schemes and certificates. part 45 Security objectives of European certification schemes X 46 and 46a Assurance level of European certification schemes, and conformity self-assessment X 47 and 47a Elements of European cybersecurity certification schemes and Cybersecurity information for certified products, process and services X 48 Cybersecurity certification, which indicates who is able to deliver certificates regarding a specific assurance level. X 49 National cybersecurity certification schemes and certificates, which give requirement regarding the transition period between legacy national and European certification scheme. X 50 and 50a National cybersecurity certification authorities, which describes roles and duties for the
X X 51 and 52 Conformity assessment body and their notification X 53 European Cybersecurity Certification Group X 53a, 53b and 54 Complaint, effective juridical remedy and penalties regarding a conformity assessment body
X X
XXX
36
36
cspcerteurope@gmail.com www.cspcert.eu