Continuous Compliance: Experiences, Challenges, and Opportunities

被引:6
|
作者
Filepp, Robert [1 ]
Adam, Constantin [1 ]
Hernandez, Milton [1 ]
Vukovic, Maja [1 ]
Anerousis, Nikos [2 ]
Zhang, Guan Qun [3 ]
机构
[1] IBM Corp, IBM TJ Watson Res Ctr, Yorktown Hts, NY 10562 USA
[2] IBM Corp, GTS Incubat Lab, San Jose, CA USA
[3] IBM Corp, IBM Res China, Beijing, Peoples R China
关键词
compliance; container; hybrid cloud; cloud computing; security; regulation;
D O I
10.1109/SERVICES.2018.00029
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
IT compliance is an area of increasing attention and capital spend in enterprise IT environments. We present "Continuous Compliance", a framework that allows a managed IT services provider to automate the overall process of keeping IT assets conformant with enterprise policies, regulatory frameworks, and other best practices. Our framework applies to all cloud layers and service models: Infrastructure-, Platform-, and Software-as-a-Service. We describe our framework design, its operation, and the post-process analytics and reporting. We also examine remediation reports gathered from over 2,000 servers for a seven month period, graph the incidence of repeated remediations, and explore some reasons for gradually subsiding remediations.
引用
收藏
页码:31 / 32
页数:2
相关论文
共 50 条