Security framework to achieve a continuous audit-based certificationn in compliance with the EU-wide cloud security certification scheme

Acronym

MEDINA

Description of the granted funding

Despite the evident benefits of cloud computing, its adoption is still limited partially because of EU customers’ perceived lack of security and transparency in this technology. Cloud service providers (CSPs) usually rely on security certifications as a mean to improve transparency and trustworthiness, however European CSPs still face multiple challenges for certifying their services (e.g., fragmentation in the certification market, and lack of mutual recognition). In this context, the new EU Cybersecurity Act (EU CSA) proposes improving customer's trust in the European ICT market through a European certification scheme. The proposed EU CSA’s cloud security certification scheme conveys new technological challenges due to its notion of “levels of assurance” (e.g., high-assurance through continuous certification for the whole supply chain), which need to be solved in order to bring all of EU CAS’s expected benefits to EU cloud providers and customers. In this context, MEDINA proposes a framework for achieving a continuous audit-based certification for CSPs based on EU CSA’s scheme for cloud security certification. MEDINA will tackle challenges in areas like security validation/testing, machine-readable certification language, cloud security performance, and audit evidence management. The MEDINA consortium is composed of academic and industrial partners, which play key roles in the EU cloud security certification ecosystem (e.g., research, cloud providers/customers, and auditors). MEDINA will provide and empirically validate sustainable outcomes in order to benefit EU adopters.
Show more

Starting year

2020

End year

2023

Granted funding

NIXU CERTIFICATION OY
68 125 €
Third party
NIXU OYJ
118 875 €
Participant
HEWLETT-PACKARD CUSTOMER DELIVERY SERVICES ITALIA SRL (IT)
45 000 €
Third party
FABASOFT R&D GMBH (AT)
454 875 €
Participant
FUNDACION TECNALIA RESEARCH & INNOVATION (ES)
814 875 €
Coordinator
XLAB RAZVOJ PROGRAMSKE OPREME IN SVETOVANJE DOO (SI)
405 875 €
Participant
ROBERT BOSCH GMBH (DE)
685 683.75 €
Participant
HEWLETT PACKARD ITALIANA SRL (IT)
616 125 €
Participant
CONSIGLIO NAZIONALE DELLE RICERCHE (IT)
560 875 €
Participant
FRAUNHOFER GESELLSCHAFT ZUR FOERDERUNG DER ANGEWANDTEN FORSCHUNG E.V. (DE)
710 000 €
Participant

Amount granted

4 480 309 €

Funder

European Union

Funding instrument

Research and Innovation action

Framework programme

Horizon 2020 Framework Programme

Call

Programme part
INDUSTRIAL LEADERSHIP - Leadership in enabling and industrial technologies - Information and Communication Technologies (ICT) (5239)
Topic
Building blocks for resilience in evolving ICT systems (SU-ICT-02-2020)
Call ID
H2020-SU-ICT-2019

Other information

Funding decision number

952633

Identified topics

security, privacy, cybersecurity