
Clouditor: Continuous Assurance of Cloud Services
Clouditor: Continuous Assurance of Cloud Services
Christian Banse (Head of Department „Service & Application Security (SAS)“ at Fraunhofer AISEC)
In this talk, we will present the open-source project Clouditor, developed at Fraunhofer AISEC. Its main goal is to continuously evaluate if a cloud-based application (built using either a hyperscaler, such as AWS, or based on open source approaches like OpenStack/Kubernetes) is configured in a secure way and thus complies with security requirements.
These requirements can stem from various sources that define the state-of-the art in cloud security. Examples includes the Cloud Computing Compliance Controls Catalogue (C5) issued by BSI or the upcoming European Cybersecurity Certification Scheme for Cloud Services (EUCS) by ENISA. Using an ontology-based approach that maps vendor-specific properties to a generic representation, new cloud services from other vendors can easily added to the open-source project.
ALASCA Tech-Talks
Die ALASCA Tech-Talks bieten eine Plattform, um Lösungen vorzustellen, die das Potenzial haben, die digitale Souveränität von Cloud-Infrastrukturen und -Diensten zu verbessern, sowie für Anwendungsfälle, die auf diese digital-souveränen Infrastrukturen und Dienste angewiesen sind.
Hier treffen Techies auf Techies. Sie verbindet die Überzeugung von Open-Source-Software für den Betrieb von Cloud-Anwendungen sowie das gemeinsame Ziel, digitale Souveränität in Deutschland und Europa herzustellen.
Die ALASCA Tech-Talks finden seit Januar 2023 einmal monatlich statt und erfreuen sich einer treuen Hörerschaft. Werde auch du Teil unserer ALASCA Tech-Talks – ob als Zuhörer, Mitdiskutierender oder als Speaker. Wir freuen uns auf dich!

