<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>ORCID:</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>trustworthiness through continuous audit-based certification</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Leire Orue-Echevarria</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Jesus Luna Garcia</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Christian Banse</string-name>
          <email>christian.banse@aisec.fraunhofer.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Juncal Alonso</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>TECNALIA</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Basque Research</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Technology Alliance (BRTA)</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Parque Científico y Tecnológico de Bizkaia</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Astondo bidea</institution>
          ,
          <addr-line>700, E-48160 Derio</addr-line>
          ,
          <country country="ES">Spain</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Fraunhofer AISEC</institution>
          ,
          <addr-line>Lichtenbergstraße 11, 85748 Garching near Munich</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>ISO, Cloud Security Alliance</institution>
          ,
          <addr-line>...), Member States' schemes (e.g., Germany's BSI C5</addr-line>
          ,
          <country>Spain's Esquema</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>Robert Bosch GmbH</institution>
          ,
          <addr-line>Postfach 30 02 20 , 70442 Stuttgart</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
      </contrib-group>
      <volume>000</volume>
      <fpage>0</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>One of the reasons of the still limited adoption of Cloud Computing in the EU is the EU customers' perceived lack of security and transparency in this technology. Cloud service providers (CSPs) usually rely on security certifications as a mean to improve transparency and trustworthiness, however European CSPs still face multiple challenges for certifying their services (e.g., fragmentation in the certification market, and lack of mutual recognition). In this context, the EU Cybersecurity Act (EU CSA) proposes improving customer's trust in the European ICT market through a European certification scheme (EUCS). The proposed cloud security certification scheme conveys new technological challenges including the notion of automated monitoring for the whole supply chain, which needs to be solved in order to bring all the expected benefits to EU cloud providers and customers. In this context, MEDINA proposes a framework for supporting a continuous audit-based certification for CSPs based on EU CSA's scheme for cloud security certification. MEDINA will tackle challenges in areas like security validation/ testing, machine-readable certification language, cloud security performance, and audit evidence management. MEDINA will provide and empirically validate sustainable outcomes in order to benefit EU adopters. cloud certification scheme, Cybersecurity Act, continuous auditing, continuous certification,</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>smart contracts, certification language</p>
    </sec>
    <sec id="sec-2">
      <title>1. Introduction and motivation</title>
      <p>
        Despite the conspicuous benefits to customer’s trustworthiness in cloud services, which result from
leveraging recognized security certifications (just as evidenced by the EU Cybersecurity Act (EU
CSA)), it is also true that European cloud providers currently face multiple challenges to certify their
services. Take for example the European Commission’s study SMART 2016/0029 “Certification
schemes for cloud computing” led by TECNALIA [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], which shows that the market penetration of the
cloud security certification is rather uneven. ISO 27001-based certifications are leading the market,
despite being a generic IT systems management standard and not focusing solely on cloud services. The
above-mentioned study has analysed the market penetration of international certification schemes (e.g.,
Nacional de Seguridad – ENS), private initiatives (e.g., Zeker online, EuroCloud), public-private
initiatives (e.g. Trusted Cloud) and cross-border initiatives (e.g., ESCloud) in 50 Cloud Service
Providers (CSPs). The conclusions demonstrate a big fragmentation in the domain of existing
certification schemes.
      </p>
      <p>First workshop on trustworthy software and open source, March 23-25, 2021, Virtual Conference
EMAIL:</p>
      <p>Leire.Orue-echevarria@tecnalia.com
(L.Orue-Echevarria)
;</p>
      <p>Jesus.LunaGarcia@de.bosch.com
(J. Luna</p>
      <p>Garcia),</p>
      <p>2020 Copyright for this paper by its authors.</p>
      <p>In addition to the evident fragmentation in cloud security certification schemes, the EC study also
highlighted the diverse focus of the different security controls in current certification schemes.</p>
      <p>The final challenge that European cloud providers face when seeking a certification is the selection
of the conformity assessment method (CAM). Several different CAMs exist at the state of practice such
as self-assessment, evidence-based, ISO-based, and ISAE 3402. Each of these CAMs also have
different scopes. While ISO mainly assesses if security measures are defined and put in place at a certain
point of time, ISAE evaluates the efficiency of the implemented controls in a period of time, usually
six months.</p>
      <p>The conspicuous lack of cloud-specific security certifications, in addition to the existing market
fragmentation (scope, methodologies), hinder transparency and accountability in the provision of
European cloud services. Both issues ultimately reflect on the level of customer’s trustworthiness and
adoption of cloud services in Europe.</p>
      <p>In an effort to solve some of the challenges depicted above, the EU Cybersecurity Act (EU CSA,
approved in June 2019) in its Title III gives ENISA the mandate of defining and implementing a
European security certification scheme for ICT products, processes and services for three different
levels of assurance (low, substantial, and high). Being cloud computing one of the identified EU CSA
priorities, Articles 54 (j) and 57 (9) propose the possibility of deploying a high-assurance,
evidencebased and continuous certification of European cloud providers. Despite the evident benefits of EU
CSA’s principles for the European market and cloud customers, currently there are no concrete cloud
certification frameworks nor tools for implementing any of those proposals.</p>
      <p>
        To overcome this situation, the main objective of the MEDINA European research project [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] is to
provide a holistic framework that enhances cloud customers’ control and trust in consumed cloud
services, by supporting CSPs (IaaS, PaaS and SaaS providers) towards the successful achievement of a
continuous certification aligned to the EU Cybersecurity Act (EU CSA). Such certification should fulfill
the requirements of the EU cloud security certification scheme in their basic, substantial and high
assurance levels. The proposed framework will be comprised of tools, techniques, and processes
supporting the continuous auditing and certification of cloud services where security and accountability
are measurable by design. As the MEDINA framework is leveraged into a cloud supply chain, it will
support continuously assessing the efficiency and efficacy of security measures to ultimately achieve
and maintain a certification.
      </p>
      <p>The rest of this paper is structured in the following manner: Section 2 introduces an overview of the
related state of the art and the progress that MEDINA expect to provide to each topic. Section 3 details
the MEDINA approach for Cloud Security Continuous Certification and section 4 oversees the future
work in MEDINA.</p>
    </sec>
    <sec id="sec-3">
      <title>2. Introduction and motivation</title>
      <p>In the last years, several projects and initiatives have worked in research areas of interest for
continuous certification of security in Cloud Services. Table 1 shows an overview of the main
challenges identified after the analysis of the current state of the art per area of interest, considering
national and/or international initiatives, and highlighting the main scientific advances that MEDINA
will bring.</p>
      <p>
        Cloud security certification • Fragmented • MEDINA framework
schemes and conformity certification schemes. supports the homogenization of
assessments • Partial coverage of certification schemes, by
[26], [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] relevant cloud security controls. aligning to the EU CSA.
      </p>
      <p>• Wide variety of • Framework fully
conformity assessment covers security controls from
methods. relevant standards and good
practices.</p>
      <p>• MEDINA leverages
conformity assessment
methodologies proposed to EU
CSA</p>
      <p>
        Continuous assessment, • Static cloud security • Toolset supporting EU
audit and certification configurations, i.e., forced by CSA’s cloud certification
[
        <xref ref-type="bibr" rid="ref22">22</xref>
        ], [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ], [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ], [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] traditional audits, cannot adapt processes, including
to a changing threat landscape. automation (smart contracts),
      </p>
      <p>• Lack of KPIs and accountability and
techniques for measuring cloud trustworthiness.
security efficiency/efficacy. • Risk-based MEDINA’s</p>
      <p>• Trustworthiness of framework supports CSPs in
evidences, and automation are adapting security configuration
missing in current cloud at run-time/design-time, in a
certification processes. certifiable manner.</p>
      <p>• Non-technical • Contribution of a
measures are not quantifiable repository containing TOMs,
and thus currently hard to assess metrics and security KPIs
continuously derived from internationally
accepted control frameworks.</p>
      <p>• New techniques to
analyse the semantic of
documents and process
descriptions to address
nontechnical and organisational
controls</p>
      <p>
        Policies for certification • Limited scope of • Provision of a broad
language existing tools on new spectrum of evidence gathering
[27], [28], [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], [29], [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ] computing paradigms such as techniques for technical
serverless computing measures, such as security
      </p>
      <p>• Existing static code assessment of cloud workloads,
analysis techniques are not containers and serverless
adopted to the needs of functions
gathering evidences in a • Analysis of data flows
certification context of cloud applications using</p>
      <p>• Non-technical code property graphs on
measures are not quantifiable incomplete source code
and thus currently hard to assess • Machine-learning and
continuously NLP to analyse the semantic of</p>
      <p>• Auditors lack real- documents and process to
world experience on continuous address non-technical or
certification organisational measures</p>
      <p>• Validation of
techniques based on real-world
audit practices</p>
      <p>
        Economic and risk aspects • Lack of (economic) • MEDINA framework
of certification analysis for evaluating the cost- for quantitative risk-assessment
[
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ], [30], [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ], benefit of security for cloud security certification.
[31], [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] certifications, and related • Contribution of
cybersecurity risks. validated cost-benefit analysis
      </p>
      <p>• No CSP guidance for to ensure the cost-effectiveness
selecting risk-assessment of the selected
methodologies for purposes of countermeasures.
cloud certification. • The MEDINA</p>
      <p>• Entry barrier for small framework will also help to
EU CSPs, which face costly compare various security
setup of security configurations system configurations to
to achieve a certification. support CSPs in their
certification efforts.</p>
      <p>• Provide support
reevaluate the CSP security
configuration at run-time, thus
ensuring continuous
adaptability of the certification.</p>
    </sec>
    <sec id="sec-4">
      <title>3. MEDINA approach</title>
      <p>
        The MEDINA approach is depicted in Figure 1 MEDINA approach for continuous Cloud Services
certification against the EU Cloud Certification Scheme (EUCS). It describes the lifecycle of
continuous Cloud security certification, from the definition of the security controls and metrics to the
continuous auditing of the evidences. Such lifecycle can be summarized as follows:
1. Define a catalogue of metrics associated to technical and organizational measures out of the
MEDINA catalogue (e.g., based on EUCS [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]). This repository of metrics (Key result 1- [KR1]) and
measures entails a clear definition of the technical and organizational measures (TOMs) relevant for
cloud service providers. The repository also includes the corresponding security metrics (both
quantitative and qualitative) for security requirements/TOMs such as those related to system security
and integrity, operational security, business continuity and incident management.
2. Select controls: Taking into consideration the CSPs risk appetite following a risk-based
approach and the chosen assurance level, the CSP shall select the implementing TOMs and related
metrics for all security controls considering its risk appetite. MEDINA offers a tool-supported
riskbased approach [KR2] to select the appropriate controls aligned with the overall risk “appetite” of
the organisation. This will be based on a risk self-assessment tool and will help to identify the core
assets of the service (considering all involved stakeholders), help to value them and identify the
relevant threats. Furthermore, the framework will be improved to propose an (near) optimal security
configuration to ensure the optimal coverage of security risks. After that, assets of the cloud service
and relevant IT threats shall be identified, and additional implementing TOMs proposed [KR2].
MEDINA proposes a tool-supported methodology for the selection of additional controls and
associated TOMs, which address the concrete needs of a CSP taking into consideration both its risk
appetite and requested certification’s assurance level.
3. Specify the certification language: currently certification schemes are expressed using natural
language. MEDINA proposes to transform this certification language into a machine-readable
expression [KR3], by using NLP, including aspects such as scope of the certification, assurance level
and conformity assessment method. For a lean and seamless trait d'union between what is required
by official documents of the European Commission in terms of certification to the definition of the
machine-readable certification language [KR3] MEDINA intends to develop:
• A procedure to semi-automatically translate Natural Language (NL) certifications terms and
conditions, as they appear on official documents like, e.g., the Cybersecurity Act, into a Controlled
Natural Language (CNL) [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ];
• A tool to edit, tune and revise semi-automatically generated CNL, to manually improve the
translation and verify the generated statements;
• A component to map the CNL to a runtime-enforceable Domain-Specific Language (DSL) that
can be used by assessment tools to check the compliance status of the stated certification terms and
conditions.
4. Collect and evaluate evidences, continuously and automatically audit: Once the scope of the
certification scheme is established, the evidences need to be collected [KR4] at cloud service as well
as code level, both at design and at operation time, that is, during the whole lifecycle of the cloud
service. The collected evidences need to be ensured that no one has tampered with them and are
trustworthy. MEDINA refers to Distributed Ledger Technologies (DLT)-based that manage
evidence (e.g., on a private blockchain) based on additional information about the deployed or
tobe-deployed services. Moreover, these evidences are continuously evaluated [KR5] and the risks
continuously monitored and updated [KR6], in order to have a secure operational service certifiable
through the selected conformity assessment method.
5. Achieving continuous certification is the process of continuously evaluating whether
appropriate evidence is collected [KR4] that supports the fulfilment of individual controls of a
certification target. MEDINA aims to greatly reduce this effort by providing quantitative measures
for both the target as well as the evidence. Since evidence is collected as a set of measurable metrics
(e.g., by measuring the value 256 of the metric key-size, simple Boolean expressions such as
keysize =&gt; 128 in the certification target can be employed), MEDINA is able to validate whether a
measurement result fulfil the certifiable requirement or not [KR5].
      </p>
      <p>Summarizing from the table above (Table 1) and the approach presented here it can be concluded
that no initiative or commercial solution fully covers the objectives of MEDINA.</p>
    </sec>
    <sec id="sec-5">
      <title>4. Use cases</title>
      <p>The MEDINA framework will be validated in two use cases:
1. European Certification of Multi-cloud backends for IoT Solutions, provided a big industrial
player such as Bosch. This use case will deploy a set of IaaS and PaaS services, commonly used for IoT
backends, in at least three public CSPs (e.g., Microsoft Azure, AWS, and Fabasoft). This case includes
managed Kubernetes clusters, transactional SQL databases, raw virtual storage, virtual networks, virtual
machines (e.g., as jump hosts), and serverless PaaS (e.g., functions). Furthermore, widely used
“support” PaaS will be also deployed e.g., virtual hardware security modules (HSM), log repositories,
application gateways, and network security groups/firewalls-as-a-service. Those PaaS components will
be orchestrated to mock-up and IoT service based on the company’s industrial experience. Having a
measurable, holistic, and end-to-end view of the security measures (TOMs) implemented in such a
complex cloud ecosystem becomes essential for the certification process of the supply chain. Beyond
its usage for the European certification, the continuously achieved levels of security transparency bring
a huge benefit to the internal processes of the organization providing the IoT solution e.g., security
governance, security benchmarking, measurable efficiency and efficacy of implemented TOMs, and
enablement of secure DevOps.</p>
      <p>2. Continuous Audit of SaaS Solutions for the Public Sector: this use case provided by Fabasoft
aims to provide a high level of automation to the current audit process of a SaaS provider in alignment
to the EU CSA, with particular focus on continuous audit-based certification. At the state of practice,
for a good number of requirements in current certification schemes (e.g., BSI C5, SOC2, ISO 20017,
etc.), several CSPs already collect evidence automatically by using monitoring tools, log files, internal
versioning and the likes. However, this generated evidence cannot, to date, be evaluated and audited
automatically (continuously) due to the lack of standardized processes and tool chains. Furthermore,
there is no clear definition of what “real evidence” is (i.e., evidence that auditors consider trustworthy
for certification purposes), when it is automatically produced. The tools and techniques proposed by
MEDINA will be validated in this use case, taking into consideration the objectives and Key Results
expected from the project.</p>
    </sec>
    <sec id="sec-6">
      <title>5. Conclusions and future work</title>
      <p>This paper presented the proposed MEDINA approach to support current challenges in the
continuous security certification of Cloud Computing services. MEDINA proposes to increase the
trustworthiness of the Cloud Services and Cloud Service Providers through a framework of methods,
mechanism and tools supporting continuous cloud security certification, through trustworthy
evidencemanagement methods. The project started in November 2020 and will last 36 months. Currently the
reference architecture for the MEDINA framework is being designed, and the first versions of the
methods and prototypes will be ready during 2021.These initial versions will be validated by two
European Cloud Providers which are part of the MEDINA consortium, Robert Bosch GmbH and
Fabasoft.</p>
    </sec>
    <sec id="sec-7">
      <title>Acknowledgements References</title>
      <p>This work has been partially funded by the European project MEDINA (Horizon 2020 research and
innovation Programme, under grant agreement no 952633).
[26] “Unleashing the Potential of Cloud Computing in Europe,” EC, 2012.
[27] OSCAL, (n.d.).
[28] OWL - Semantic Web Standards, (n.d.).
[29] Natural Language Toolkit — NLTK 3.5 documentation, (n.d.).
[30] PAe - MAGERIT v.3 : Metodología de Análisis y Gestión de Riesgos de los Sistemas de</p>
      <p>Información, (n.d.).
[31] Self-Assessment Tools | CyberSecurity Observatory, (n.d.).</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>M.</given-names>
            <surname>Anisetti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.A.</given-names>
            <surname>Ardagna</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Damiani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N. El</given-names>
            <surname>Ioini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Gaudenzi</surname>
          </string-name>
          ,
          <article-title>Modeling time, probability, and configuration constraints for continuous cloud service certification</article-title>
          ,
          <source>Computers &amp; Security</source>
          .
          <volume>72</volume>
          (
          <year>2018</year>
          )
          <fpage>234</fpage>
          -
          <lpage>254</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>R.M.</given-names>
            <surname>Blank</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Secretary</surname>
          </string-name>
          ,
          <source>Guide for Conducting Risk Assessments</source>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>European</given-names>
            <surname>Commission</surname>
          </string-name>
          .
          <article-title>Directorate General for Communications Networks, Content and Technology</article-title>
          .,
          <string-name>
            <surname>Fundación</surname>
            <given-names>TECNALIA RESEARCH</given-names>
          </string-name>
          &amp; INNOVATION.,
          <article-title>Certification schemes for cloud computing: final report</article-title>
          .,
          <string-name>
            <surname>Publications</surname>
            <given-names>Office</given-names>
          </string-name>
          ,
          <string-name>
            <surname>LU</surname>
          </string-name>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>European</given-names>
            <surname>Union</surname>
          </string-name>
          <article-title>Agency for Cybersecurity</article-title>
          , EUCS - Cloud Services Scheme, n.d.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>A.</given-names>
            <surname>Fantechi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Ferrari</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Gnesi</surname>
          </string-name>
          , L. Semini, Requirement Engineering of Software Product Lines:
          <article-title>Extracting Variability Using NLP</article-title>
          , in: 2018 IEEE 26th International Requirements Engineering Conference (RE),
          <year>2018</year>
          : pp.
          <fpage>418</fpage>
          -
          <lpage>423</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>A.</given-names>
            <surname>Ferrari</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Gori</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Rosadini</surname>
          </string-name>
          , I. Trotta,
          <string-name>
            <given-names>S.</given-names>
            <surname>Bacherini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Fantechi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Gnesi</surname>
          </string-name>
          ,
          <article-title>Detecting requirements defects with NLP patterns: an industrial experience in the railway domain</article-title>
          ,
          <source>Empir Software Eng</source>
          .
          <volume>23</volume>
          (
          <year>2018</year>
          )
          <fpage>3684</fpage>
          -
          <lpage>3733</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>J.</given-names>
            <surname>Großmann</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Seehusen</surname>
          </string-name>
          ,
          <article-title>Combining Security Risk Assessment and Security Testing Based on Standards</article-title>
          , in: F. Seehusen,
          <string-name>
            <given-names>M.</given-names>
            <surname>Felderer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Großmann</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.-F. Wendland</surname>
            (Eds.),
            <given-names>Risk</given-names>
          </string-name>
          <string-name>
            <surname>Assessment</surname>
          </string-name>
          and
          <string-name>
            <surname>Risk-Driven</surname>
            <given-names>Testing</given-names>
          </string-name>
          , Springer International Publishing, Cham,
          <year>2015</year>
          : pp.
          <fpage>18</fpage>
          -
          <lpage>33</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>D.</given-names>
            <surname>Knoblauch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Banse</surname>
          </string-name>
          ,
          <article-title>Reducing Implementation Efforts in Continuous Auditing Certification Via an Audit API</article-title>
          , in: 2019 IEEE 28th International Conference on Enabling Technologies:
          <article-title>Infrastructure for Collaborative Enterprises (WETICE), IEEE</article-title>
          , Napoli, Italy,
          <year>2019</year>
          : pp.
          <fpage>88</fpage>
          -
          <lpage>92</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>T.</given-names>
            <surname>Kuhn</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A</given-names>
            <surname>Survey</surname>
          </string-name>
          and
          <article-title>Classification of Controlled Natural Languages</article-title>
          ,
          <source>Computational Linguistics</source>
          .
          <volume>40</volume>
          (
          <year>2014</year>
          )
          <fpage>121</fpage>
          -
          <lpage>170</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>I.</given-names>
            <surname>Kunz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Stephanow</surname>
          </string-name>
          ,
          <string-name>
            <surname>A Process</surname>
          </string-name>
          <article-title>Model to Support Continuous Certification of Cloud Services</article-title>
          ,
          <source>in: 2017 IEEE 31st International Conference on Advanced Information Networking and Applications (AINA)</source>
          , IEEE, Taipei, Taiwan,
          <year>2017</year>
          : pp.
          <fpage>986</fpage>
          -
          <lpage>993</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>M.S.</given-names>
            <surname>Lund</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Solhaug</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Stølen</surname>
          </string-name>
          ,
          <string-name>
            <surname>Model-Driven Risk</surname>
            <given-names>Analysis</given-names>
          </string-name>
          , Springer Berlin Heidelberg, Berlin, Heidelberg,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>S.N.</given-names>
            <surname>Matheu-García</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.L.</given-names>
            <surname>Hernández-Ramos</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.F.</given-names>
            <surname>Skarmeta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Baldini</surname>
          </string-name>
          ,
          <article-title>Risk-based automated assessment and testing for the cybersecurity certification and labelling of IoT devices</article-title>
          ,
          <source>Computer Standards &amp; Interfaces</source>
          .
          <volume>62</volume>
          (
          <year>2019</year>
          )
          <fpage>64</fpage>
          -
          <lpage>83</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>I.</given-names>
            <surname>Matteucci</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Petrocchi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.L.</given-names>
            <surname>Sbodio</surname>
          </string-name>
          ,
          <article-title>CNL4DSA: a controlled natural language for data sharing agreements</article-title>
          ,
          <source>in: Proceedings of the 2010 ACM Symposium on Applied Computing - SAC '10</source>
          , ACM Press, Sierre, Switzerland,
          <year>2010</year>
          : p.
          <fpage>616</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <article-title>MEDINA, MEDINA Security framework to achieve a continuous audit-based certification in compliance with the EU-wide cloud security certification scheme - Annex 1</article-title>
          ,
          <string-name>
            <surname>DoA Part</surname>
            <given-names>B</given-names>
          </string-name>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>T.</given-names>
            <surname>Mikolov</surname>
          </string-name>
          , I. Sutskever,
          <string-name>
            <given-names>K.</given-names>
            <surname>Chen</surname>
          </string-name>
          , G. s Corrado,
          <source>J. Dean, Distributed Representations of Words and Phrases and their Compositionality</source>
          ,
          <source>Advances in Neural Information Processing Systems</source>
          .
          <volume>26</volume>
          (
          <year>2013</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>N.M.</given-names>
            <surname>Müller</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Kowatsch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Debus</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Mirdita</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Böttinger</surname>
          </string-name>
          ,
          <article-title>On GDPR Compliance of Companies' Privacy Policies</article-title>
          , in: K. Ekštein (Ed.), Text, Speech, and Dialogue, Springer International Publishing, Cham,
          <year>2019</year>
          : pp.
          <fpage>151</fpage>
          -
          <lpage>159</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>E.</given-names>
            <surname>Schmieders</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Metzger</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Pohl</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A Runtime</given-names>
            <surname>Model</surname>
          </string-name>
          <article-title>Approach for Data Geo-location Checks of Cloud Services</article-title>
          , in: X.
          <string-name>
            <surname>Franch</surname>
            ,
            <given-names>A.K.</given-names>
          </string-name>
          <string-name>
            <surname>Ghose</surname>
            ,
            <given-names>G.A.</given-names>
          </string-name>
          <string-name>
            <surname>Lewis</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          Bhiri (Eds.),
          <string-name>
            <surname>Service-Oriented</surname>
            <given-names>Computing</given-names>
          </string-name>
          , Springer Berlin Heidelberg, Berlin, Heidelberg,
          <year>2014</year>
          : pp.
          <fpage>306</fpage>
          -
          <lpage>320</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>P.</given-names>
            <surname>Stephanow</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Fallenbeck</surname>
          </string-name>
          ,
          <article-title>Towards Continuous Certification of Infrastructure-as-a-Service Using Low-Level Metrics</article-title>
          ,
          <source>in: 2015 IEEE 12th Intl Conf on Ubiquitous Intelligence and Computing and 2015 IEEE 12th Intl Conf on Autonomic and Trusted Computing and 2015 IEEE 15th Intl Conf on Scalable Computing and Communications</source>
          and
          <string-name>
            <surname>Its Associated Workshops (UICATC-ScalCom</surname>
            <given-names>)</given-names>
          </string-name>
          , IEEE, Beijing,
          <year>2015</year>
          : pp.
          <fpage>1485</fpage>
          -
          <lpage>1492</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>P.</given-names>
            <surname>Stephanow</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Khajehmoogahi</surname>
          </string-name>
          ,
          <article-title>Towards Continuous Security Certification of Software-as-aService Applications Using Web Application Testing Techniques</article-title>
          ,
          <source>in: 2017 IEEE 31st International Conference on Advanced Information Networking and Applications (AINA)</source>
          , IEEE, Taipei, Taiwan,
          <year>2017</year>
          : pp.
          <fpage>931</fpage>
          -
          <lpage>938</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>P.</given-names>
            <surname>Stephanow</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Moein</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Banse</surname>
          </string-name>
          , Continuous Location Validation of Cloud Service Components, in: 2017
          <source>IEEE International Conference on Cloud Computing Technology and Science (CloudCom)</source>
          ,
          <year>2017</year>
          : pp.
          <fpage>255</fpage>
          -
          <lpage>262</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>I.K.</given-names>
            <surname>Tanoli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Petrocchi</surname>
          </string-name>
          , R. De Nicola,
          <article-title>Towards automatic translation of social network policies into controlled natural language</article-title>
          ,
          <source>in: 2018 12th International Conference on Research Challenges in Information Science (RCIS)</source>
          , IEEE, Nantes,
          <year>2018</year>
          : pp.
          <fpage>1</fpage>
          -
          <lpage>12</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>I.</given-names>
            <surname>Windhorst</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Sunyaev</surname>
          </string-name>
          , Dynamic Certification of Cloud Services, in: 2013 International Conference on Availability,
          <source>Reliability and Security</source>
          , IEEE, Regensburg, Germany,
          <year>2013</year>
          : pp.
          <fpage>412</fpage>
          -
          <lpage>417</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>F.</given-names>
            <surname>Yamaguchi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Golde</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Arp</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Rieck</surname>
          </string-name>
          ,
          <article-title>Modeling and Discovering Vulnerabilities with Code Property Graphs</article-title>
          ,
          <source>in: 2014 IEEE Symposium on Security and Privacy</source>
          ,
          <year>2014</year>
          : pp.
          <fpage>590</fpage>
          -
          <lpage>604</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24] [24]
          <string-name>
            <given-names>J.</given-names>
            <surname>Zhang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.M.</given-names>
            <surname>El-Gohary</surname>
          </string-name>
          ,
          <source>Semantic NLP-Based Information Extraction from Construction Regulatory Documents for Automated Compliance Checking, J. Comput. Civ. Eng</source>
          .
          <volume>30</volume>
          (
          <year>2016</year>
          )
          <fpage>04015014</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>P.</given-names>
            <surname>Zhou</surname>
          </string-name>
          ,
          <article-title>Ontology-based information extraction from environmental regulations for supporting environmental compliance checking</article-title>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>