Skip to main content
Go to the home page of the European Commission (opens in new window)
English English
CORDIS - EU research results
CORDIS

Evidence Management for Continuous Certification as a Service in the Cloud

Project description

Advanced solutions for Continuous Cloud Certification-as-a-service

Cloud-based services make use of AI, including machine learning and natural language processing. This complicates the certification process for these services. As outlined by the EU Cybersecurity Act certifications, agility is important in facilitating monitoring and assessment. To achieve the full implementation of certification-as-a-service (CaaS), it is imperative to address issues like the absence of technology interoperability within proofs of concepts for continuous monitoring, the adoption of cloud and edge computing, the incorporation of regulations pertaining to domains, market fragmentation and the uptake of intelligent tools. The EU-funded EMERALD project will develop a CaaS solution consisting of two proofs of concepts: one involving composite certification and the other involving the mapping of requirements to upcoming AI certification schemes.

Objective

Cloud-based services have grown from basic computing services to complex ecosystems, comprising (virtual) infrastructure, business processes and application code. These advanced services also increasingly leverage the usage of Artificial Intelligence, including Machine Learning or Natural Language Processing techniques, raising the complexity even higher. Due to the cascade of dependencies among the different products and services, the need arose to bring more agility to the certification process of cloud-based services, e.g. using continuous monitoring and assessment, as evidenced by references to it in the certifications of the EU Cybersecurity Act (EU CSA). To transform the continuous assessment and certification concept into the complete realization of a Certification-as-a-Service (CaaS), several challenges need to be solved: 1) current proposed proofs of concepts for continuous monitoring lack interoperability at technology level, 2) the adoption of cloud and edge computing and the incorporation of regulations on specific topics or domains, such as AI, put significant strain on companies to comply with a multitude of different security schemes, 3) existing market fragmentation for continuous certification (scope, methodologies), hinder transparency and accountability in the provision of European cloud services, 4),smart tools and models need to be adopted to ease the agile application and implementation of the CaaS concept reducing complexity in the whole cloud certification value chain easing the adoption of CaaS by the different stakeholders. To overcome these challenges, the design and implementation of the EMERALD CaaS solution leverages the H2020 project MEDINA’s outcomes and advances them to TRL 7 in the EMERALD core. Two PoCs will be provided; one for composite certification and one for mapping requirements to upcoming AI certification schemes. EMERALD will pave the road towards CaaS for continuous certification of harmonized cybersecurity schemes.

Fields of science (EuroSciVoc)

CORDIS classifies projects with EuroSciVoc, a multilingual taxonomy of fields of science, through a semi-automatic process based on NLP techniques. See: The European Science Vocabulary.

You need to log in or register to use this function

Keywords

Project’s keywords as indicated by the project coordinator. Not to be confused with the EuroSciVoc taxonomy (Fields of science)

Programme(s)

Multi-annual funding programmes that define the EU’s priorities for research and innovation.

Topic(s)

Calls for proposals are divided into topics. A topic defines a specific subject or area for which applicants can submit proposals. The description of a topic comprises its specific scope and the expected impact of the funded project.

Funding Scheme

Funding scheme (or “Type of Action”) inside a programme with common features. It specifies: the scope of what is funded; the reimbursement rate; specific evaluation criteria to qualify for funding; and the use of simplified forms of costs like lump sums.

HORIZON-IA - HORIZON Innovation Actions

See all projects funded under this funding scheme

Call for proposal

Procedure for inviting applicants to submit project proposals, with the aim of receiving EU funding.

(opens in new window) HORIZON-CL3-2022-CS-01

See all projects funded under this call

Coordinator

FUNDACION TECNALIA RESEARCH & INNOVATION
Net EU contribution

Net EU financial contribution. The sum of money that the participant receives, deducted by the EU contribution to its linked third party. It considers the distribution of the EU financial contribution between direct beneficiaries of the project and other types of participants, like third-party participants.

€ 738 375,00
Address
PARQUE CIENTIFICO Y TECNOLOGICO DE BIZKAIA, ASTONDO BIDEA, EDIFICIO 700
48160 DERIO BIZKAIA
Spain

See on map

Region
Noreste País Vasco Gipuzkoa
Activity type
Research Organisations
Links
Total cost

The total costs incurred by this organisation to participate in the project, including direct and indirect costs. This amount is a subset of the overall project budget.

€ 738 375,00

Participants (10)

My booklet 0 0