<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Automated Conformity Verification Concept for Cloud Security</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Yevhenii Martseniuk</string-name>
          <email>yevhenii.v.martseniuk@lpnu.ua</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andrii Partyka</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oleh Harasymchuk</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nataliia Korshun</string-name>
          <email>n.korshun@kubg.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Borys Grinchenko Kyiv Metropolitan University</institution>
          ,
          <addr-line>18/2 Bulvarno-Kudriavska str., Kyiv, 04053</addr-line>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Lviv Polytechnic National University</institution>
          ,
          <addr-line>12 Stepana Bandery str., Lviv, 79000</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>25</fpage>
      <lpage>37</lpage>
      <abstract>
        <p>The primary objective of this research is to develop an advanced automated method for configuring and managing public cloud accounts and subscriptions on prominent platforms such as AWS, GCP, and Azure. This method involves the application of standardized configurations to ensure optimal performance and security compliance. A significant component of this methodology is the intermittent scanning of the infrastructure of these cloud accounts and subscriptions. This scanning is meticulously designed to identify and address any deviations or non-compliance issues with globally recognized security standards, including NIST 800-53, ISO 27001, HIPAA, and PCI DSS. The approach leverages cutting-edge automation technologies to streamline the deployment and management of cloud resources. By automating the application of configurations, the method aims to reduce manual effort, minimize the likelihood of human error, and enhance operational efficiency. This automation extends to the continuous monitoring and auditing processes, enabling real-time detection of configuration drifts or security vulnerabilities. Furthermore, the research delves into the development of a dynamic, responsive system capable of adapting to the evolving requirements of cloud security. The automated scanning component plays a pivotal role in this aspect, providing ongoing assurance that the cloud environments adhere to the strictest security protocols and standards. Continuous compliance monitoring is critical in today's ever-changing digital landscape, where threats to data security and privacy are increasingly sophisticated. By integrating these automated processes, the proposed method promises not only to bolster the security posture of cloud environments but also to offer a scalable, efficient solution for cloud infrastructure management. This automated approach is poised to set a new standard in cloud management, aligning with best practices in IT security and compliance, and paving the way for more secure, manageable, and efficient cloud computing practices.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Hosting</kwd>
        <kwd>security standards</kwd>
        <kwd>automation</kwd>
        <kwd>cloud technologies</kwd>
        <kwd>cloud service models</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Currently, most cloud environments require the
implementation of accounting mechanisms,
control of external security perimeter, cost
control, and monitoring by cybersecurity
specialists. In most cases, the process of applying
configurations to create a cloud environment is
the same and typical in the sequence of actions.</p>
      <sec id="sec-1-1">
        <title>Based on this, this process can be automated</title>
        <p>to save time and money on creating something
that has already been created more than once.</p>
        <p>
          The main task of this work is to create a
service for automatic application of
configurations to create a cloud environment,
its accounting in the internal accounting system
of the organization, user access accounting,
control by monitoring tools through logs for
finances spent by cloud environment services,
configurations of the external security
perimeter, and setting up the process of control
over critical vulnerabilities and
noncompliances with security standards by
cybersecurity specialists [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ].
        </p>
        <p>Cloud security is a critical aspect of modern
information technology infrastructure,
particularly in the context of the increasing
reliance on cloud computing for both business
and personal applications [2].</p>
        <p>The technologies in cloud computing have
their security solutions but these solutions are
provided only from the provider side, and this is
a drawback for the existing security system in
cloud computing. The customer or Organization
does not have any knowledge of where its data
is stored and also, it does not have access and
control to the status of data. Each transaction is
controlled by the server (or provider) side [3].</p>
        <p>Building IT services on public cloud
infrastructure highlights the necessity of
precise control and visibility over highly
dynamic environments.</p>
        <p>Cloud services that become a part of
business applications and development
processes cannot be managed in a legacy IT way
by restricting their usage to only predefined
configurations, network topologies, and
statically allocated resources.</p>
        <p>This paper focuses and proposes relies on
modern tools, purpose-built to process cloud
platform configuration and event streams, as
well as dynamically track the security
compliance, cloud configuration vulnerability,
and utilization state of resources. Extensive use
of orchestrated automation through platform
APIs ensures a consistent view of the cloud
resources and related services at any stage of
the environment life cycle.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>2. Research on Common Threats to Cloud Environment Security</title>
      <p>The main issue with security in the cloud
environment is that the responsibility for
security is shared between the provider and
the user. Most providers offer access to their
services without enabled security controls,
which is good for the process of service
development but creates vulnerabilities for
security and data leaks from cloud
environments [4].</p>
      <sec id="sec-2-1">
        <title>Data confidentiality also becomes</title>
        <p>
          increasingly important for users and
government institutions. According to the
General Data Protection Regulation (GDPR)
and the Health Insurance Portability and
Accountability Act (HIPAA), organizations
must collect information transparently and
implement policies that help prevent data theft
or misuse [
          <xref ref-type="bibr" rid="ref2">5–7</xref>
          ]. Non-compliance with these
requirements can lead to significant losses and
damage to the organization’s reputation [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ].
        </p>
        <p>Organizations use cloud computing and
cloud-based collaboration or messaging tools
to share files and information with colleagues
and partners. At the same time, they can put
regulated data and Intellectual Property (IP),
such as trade secrets, engineering designs, and
other sensitive corporate data, at risk.</p>
        <p>
          Cloud computing infrastructure requires
protection from cyber threats. Cloud security is
a branch of cybersecurity devoted to this task.
Not only is cloud security important for the
protection of data, but it also helps industries
and organizations meet compliance
requirements, safeguard against reputation
damages, establish business continuity in case
of disruptive events, and even provide a
competitive advantage in a highly cloud-based
landscape [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ].
        </p>
        <p>
          Cloud security is essential in helping
organizations address specific vulnerabilities
and threats. Employee negligence or lack of
training can create cloud security threats, such
as oversharing files via public links that anyone
can access. Data theft by insiders is also
common. For example, salespeople leaving
your company can steal data from cloud CRM
services [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ].
        </p>
        <p>Shadow IT refers to using cloud apps and
services without explicit IT approval. Users
typically use unapproved
Software-as-aService (SaaS) applications for file sharing,
social media, collaboration, and web
conferencing. Users who upload corporate data
to unapproved apps may violate data privacy
and residency regulations.</p>
        <p>
          And there’s another growing challenge:
third-party apps and scripts with OAuth
permissions. OAuth-connected third-party
apps access IT-approved cloud computing
services, such as Microsoft Office 365 and
Google G Suite. It is common to see a hundred,
if not a thousand, apps and scripts in an
organization’s cloud environment. Some pose
risks because of poor design, giving them
broader than necessary data permissions.
Some are malicious or easy to exploit [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ].
        </p>
        <p>
          What’s the danger of OAuth? Once an OAuth
token is authorized, access to enterprise data
and applications continues until revoked [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ].
        </p>
        <p>
          Based on this principle, the following key
steps can be identified for organizational
owners to control security:
• Identify all cloud environment providers
that the organization works with and
familiarize themselves with their
security and privacy obligations.
• Invest in tools that provide secure access
to the cloud, to monitor all applications
and data used by the organization
(Microsoft Azure Active Directory, AWS
Identity, Google Authenticator, Okta).
• Deploy tools to manage cloud security
that can detect and correct configuration
errors (Prisma Cloud, Vanta).
• Implement a cloud infrastructure
protection platform to integrate security
measures into the development process.
Regularly install updates and patches for
software and implement policies to keep
employee devices up to date (end-point
protection).
• Implement a training process and
assessment of employee awareness of
the organization’s security principles, so
that employees are aware of the latest
threats and phishing tactics [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ].
        </p>
        <p>Implement a protection strategy based on
the ‘zero trust’ model and use an identity and
access management system for critical
infrastructure nodes.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Development of the Approach</title>
      <p>of “Continuous Automated</p>
    </sec>
    <sec id="sec-4">
      <title>Scanning of Configurations” as</title>
      <p>an Element of Protection of</p>
    </sec>
    <sec id="sec-5">
      <title>Cloud Environments</title>
      <p>
        Despite the availability of numerous tools,
most organizations find it difficult to
effectively control access to their data and
implement security policies in constantly
changing cloud environments. In addition,
ensuring compliance when data is stored in
distributed environments creates a significant
burden on specialists and already limited
security teams [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
      </p>
      <sec id="sec-5-1">
        <title>3.1. What is Cloud and What Types of</title>
      </sec>
      <sec id="sec-5-2">
        <title>Offering We Have on a Market?</title>
        <p>IaaS, PaaS, and SaaS are the three most
popular types of cloud service offerings. They
are sometimes referred to as cloud service
models or cloud computing service models.
• IaaS, or infrastructure as a service, is
ondemand access to cloud-hosted physical
and virtual servers, storage, and
networking—the backend IT
infrastructure for running applications
and workloads in the cloud.
• PaaS, or platform as a service, is
ondemand access to a complete,
ready-touse, cloud-hosted platform for
developing, running, maintaining, and
managing applications.
• SaaS, or software as a service, is
ondemand access to ready-to-use,
cloudhosted application software.</p>
        <p>IaaS, PaaS, and SaaS are not mutually
exclusive. Many mid-sized businesses use more
than one, and most large enterprises use all
three (Fig. 1).</p>
        <p>‘As a service’ refers to the way IT assets are
consumed in these offerings—and to the
essential difference between cloud computing
and traditional IT. In traditional IT, an
organization consumes IT assets—hardware,
system software, development tools,
applications—by purchasing them, installing
them, managing them, and maintaining them in
its own on-premises data center. In cloud
computing, the cloud service provider owns,
manages, and maintains the assets; the
customer consumes them via an Internet
connection and pays for them on a subscription
or pay-as-you-go basis.</p>
        <p>
          So, the chief advantage of IaaS, PaaS, SaaS, or
any ‘as a service’ solution is economic: A
customer can access and scale the IT capabilities
it needs for a predictable cost, without the
expense and overhead of purchasing and
maintaining everything in its data center.
However, there are additional advantages
specific to each of these solutions [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ].
        </p>
      </sec>
      <sec id="sec-5-3">
        <title>3.2. Continuous Automated Scanning of</title>
      </sec>
      <sec id="sec-5-4">
        <title>Configurations</title>
        <p>
          The automated process uses a central
orchestrator facility that performs
provisioning and changes to the IaaS cloud and
supporting services. It is based on the Rundeck
platform and a library of scenarios composed
of a well-known IT automation toolset, Ansible
[
          <xref ref-type="bibr" rid="ref16">16</xref>
          ], and Python [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ]. The scenarios
themselves are maintained and developed
within the CI development process with code
control and testing.
        </p>
        <p>Orchestrator and scenario structure are
designed not to store any data about the cloud
environments they control. All needed data for
a job to perform and job status is
communicated to and from Rundeck via REST
API. This solution is used to ease scaling and
meet requirements for system availability and
security.</p>
        <p>
          Security of the orchestrator when assessing
cloud environments may be enhanced with
storage services for secret information such as
HashiCorp Vault [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ].
        </p>
        <p>
          Configuration scanning is the process of
detecting inconsistencies in the configuration
based on cloud environment logs (Audit logs,
Flow logs) and comparing the configuration
with the recommended cyber security
standards (NIST 800-53, HIPAA, PCI-DSS, SOC,
ISO) [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ].
        </p>
        <p>Using continuous integration through audit
and flow logging between cloud environments
and Prisma, the system ensures continuous
monitoring and compliance. This integration
facilitates real-time visibility into cloud
infrastructure, allowing for immediate
identification and rectification of any
deviations from established security standards
or operational benchmarks. The continuous
integration approach not only enhances
security but also ensures operational efficiency
and reliability.</p>
        <p>Furthermore, the system employs advanced
analytics to interpret log data, providing
insights into usage patterns and potential
vulnerabilities. This data-driven approach
enables proactive identification of security
risks and operational inefficiencies. By
leveraging machine learning algorithms, the
system can predict potential issues based on
historical data, facilitating preemptive actions
to mitigate risks.</p>
        <p>In addition to security and operational terms of financial loss but also in reputational
efficiency, the system’s design prioritizes damage. Early detection and remediation of
flexibility and adaptability. This is achieved vulnerabilities through automated scanning
through modular scenario architecture, can prevent these costly incidents, providing a
allowing for quick adjustments and significant return on investment.
customization to meet evolving business needs Optimization of Resource Usage:
and technological advancements. The use of Automated scanning helps in identifying
overAnsible and Python ensures that the system allocated or underutilized resources within the
remains at the forefront of automation cloud environment. By optimizing these
technology, benefiting from the wide support resources, organizations can achieve
and continuous updates these tools receive significant cost savings on their cloud
from their respective communities. expenditure. Efficient resource utilization not</p>
        <p>Using continuous integration through audit only reduces costs but also enhances the
and flow logging between cloud environments overall performance of cloud services.
and Prisma Cloud, continuous control over Compliance Cost Reduction:
Nonconfigurations, external perimeter, costs, compliance with regulatory standards can
change management, authorization, and result in hefty fines and legal repercussions.
reduction of these assets to appropriate Automated configuration scanning ensures
security standards was achieved (Fig. 2). continuous compliance with various industry
standards, thereby avoiding the costs
associated with non-compliance. This
continuous compliance is not only a
costsaving measure but also strengthens the
organization’s position in regulated industries.</p>
        <p>Increased System Uptime: By maintaining
optimal configuration settings, automated
scanning contributes to increased system
uptime and reliability. Downtime can be
incredibly costly for businesses, in terms of
both lost revenue and recovery expenses. The
stability provided by consistent configuration
Figure 2: Automated scanning of configurations scanning minimizes the risk of downtime, thus
process diagram protecting against these potential losses.</p>
      </sec>
      <sec id="sec-5-5">
        <title>Long-term Strategic Benefits: The adoption</title>
        <p>
          3.3. Cost-Benefit Analysis of Automated of automated configuration scanning aligns with
Configuration Scanning long-term strategic benefits. It fosters a culture of
efficiency, security, and compliance within the
Reduced Operational Costs: One of the most organization. These benefits, though not directly
significant benefits of automated configuration quantifiable in the short term, contribute to the
scanning is the reduction in operational costs. overall health and competitiveness of the
By automating routine checks and business in the long run [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ].
maintenance, organizations can significantly The cost-benefit analysis of automated
reduce the time and labor associated with configuration scanning reveals a compelling
manual configuration reviews. This case for its implementation. The upfront
automation translates into direct cost savings, investment in such systems is outweighed by
as less staff time is required for these tasks, the substantial savings in operational costs,
allowing personnel to focus on more strategic prevention of costly breaches, optimization of
initiatives. resources, reduction in compliance costs,
        </p>
        <p>Prevention of Costly Breaches: increased system uptime, and long-term
Automated configuration scanning plays a strategic benefits. This analysis underscores
critical role in identifying potential the importance of automated configuration
vulnerabilities before they can be exploited by scanning as a vital component in modern cloud
malicious actors. The cost of a data breach or management strategies.
security incident can be substantial, not just in</p>
      </sec>
      <sec id="sec-5-6">
        <title>3.4. The Benefits of the Automated</title>
      </sec>
      <sec id="sec-5-7">
        <title>Approach</title>
        <p>Detection of Inconsistencies: Configuration
scanning efficiently identifies discrepancies
and inconsistencies in cloud settings by
analyzing environment logs. This proactive
detection is crucial for maintaining the
integrity and security of cloud infrastructures.</p>
        <p>Compliance with Security Standards: By
comparing current configurations against
established cybersecurity standards like NIST
800-53, HIPAA, PCI DSS, SOC, and ISO,
configuration scanning ensures adherence to
these critical guidelines, enhancing overall
security compliance.</p>
        <p>Continuous Integration and Monitoring:
The integration of configuration scanning
within the Continuous Integration (CI) process,
using tools like Ansible, Python, and Prisma
Cloud, allows for ongoing monitoring and
control over cloud configurations. This
continuous approach is key to maintaining
secure and efficient cloud environments.</p>
        <p>Improved Security Posture: With the use
of advanced tools and techniques, including
audit and flow logging, the scanning process
contributes to a stronger security posture by
managing the external perimeter, monitoring
costs, and overseeing change management and
authorization processes.</p>
        <p>Enhanced Data Security: The use of
services like HashiCorp Vault for storing
sensitive information, and the design of
orchestrators to not store cloud environment
data directly, reinforces the security of the
configuration scanning process, ensuring that
sensitive data remains protected.</p>
        <p>Scalability and Reliability: The
configuration scanning system is designed for
scalability and high availability. The use of
REST API with Rundeck for communication
ensures that the system can scale effectively
while meeting stringent security and
availability requirements.</p>
      </sec>
      <sec id="sec-5-8">
        <title>3.5. Why is it Important?</title>
        <p>Configuration scanning plays a vital role in
cloud environment management by ensuring
adherence to critical cybersecurity standards,
detecting vulnerabilities and risks early for
prompt remediation, maintaining the overall
integrity and reliability of the system, providing
continuous monitoring in dynamic cloud
settings, facilitating thorough audit and
compliance processes, enhancing operational
efficiency through automation, reducing
associated manual checks and potential
downtime costs, and significantly bolstering
customer and stakeholder trust through a
demonstrable commitment to data security and
privacy. Moreover, in safeguarding against
evolving cyber threats. With the ever-changing
landscape of cybersecurity risks, proactive
scanning allows organizations to stay ahead of
potential threats by identifying and addressing
security gaps before they can be exploited. This
proactive stance is crucial at a time when
cyberattacks are becoming more sophisticated
and frequent.</p>
        <p>In addition to security benefits,
configuration scanning greatly aids in resource
optimization and cost management.
Continuously analyzing cloud environments,
helps identify underutilized or inefficiently
configured resources, enabling organizations to
optimize their cloud spend and resource
allocation. This financial prudence is especially
important in large-scale cloud deployments,
where unchecked resource usage can lead to
significant unnecessary expenses.</p>
        <p>Another key aspect is its role in ensuring
regulatory compliance. With increasing
regulatory demands, especially in industries
handling sensitive data, configuration scanning
ensures that cloud environments comply with
regulations such as GDPR, HIPAA, and others.
This compliance is not just a legal necessity but
also an ethical obligation to protect user data,
reinforcing the organization’s reputation in the
market. Furthermore, configuration scanning
contributes to a more streamlined and agile IT
workflow. By automating the detection and
reporting of configuration issues, IT teams can
focus on more strategic tasks rather than being
bogged down by routine checks. This shift
towards a more strategic focus is integral in
driving innovation and staying competitive in
the digital landscape.</p>
        <p>Lastly, configuration scanning enhances
disaster recovery preparedness. By regularly
checking and ensuring that cloud environments
are configured correctly, organizations can
ensure faster recovery times in the event of a
disaster. This preparedness is essential for
maintaining business continuity and
minimizing the impact of any unforeseen
events. In conclusion, configuration scanning is
not just a technical necessity but a strategic
asset in cloud environment management. It
plays a crucial role in cybersecurity, regulatory
compliance, cost management, operational
efficiency, and disaster recovery, making it an
indispensable tool for organizations leveraging
cloud technology.</p>
      </sec>
      <sec id="sec-5-9">
        <title>3.6. Components That Were Used</title>
        <p>Prisma Cloud™ is a PaloAlto Networks
product that allows you to monitor
configurations, compare them with security
standards, analyze the configuration of cloud
services, identify risks, and perform automatic
configuration corrections according to
established security policies.</p>
        <p>Automate scanning uses the specialized
service—Prisma Public Cloud—to
continuously inspect the configuration of cloud
environments, track asset history, and monitor
administrator actions. The compliance
management process implemented on Prisma
Public Cloud compares platform configuration
to the requirements of information security
standards and alerts the SIEM system about
out-of-compliance cases. It also provides
notifications regarding administrators’
insecure actions and optional reporting on
suspicious network connections that may
indicate attack attempts.</p>
        <p>Every cloud account selected for
compliance inspection is configured with an
access role for the Prisma Public Cloud service,
including appropriate configuration and event
exporting services. In this framework, a job on
the Rundeck orchestrator takes this account on
Prisma Public Cloud and correctly identifies it
for an appropriate inspection profile.</p>
        <p>To inspect code and processes, Prisma
Public Cloud functionality can also be
integrated with cloud environments on host
and container levels. This capability is
particularly useful in environments that
require controls for the secure development of
product code.</p>
        <p>Additionally, Prisma Cloud offers enhanced
visibility and control over multi-cloud
environments. Its comprehensive dashboard
provides a unified view of security and
compliance across various cloud platforms.
This holistic approach is critical for
organizations operating in hybrid or
multicloud infrastructures, where visibility can
often become fragmented. Prisma Cloud
features advanced threat detection
capabilities. By leveraging AI and machine
learning algorithms, it can detect anomalous
behaviors and potential threats in real-time.
This level of security intelligence is crucial for
preemptively identifying and mitigating
sophisticated cyber threats.</p>
        <p>
          Another critical aspect of Prisma Cloud is its
ability to automate remediation actions. When
a security risk or compliance issue is detected,
the system can automatically implement
predefined remediation steps or provide
recommendations for manual intervention.
This automation not only speeds up the
response time but also reduces the potential
for human error [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ].
        </p>
        <p>Prisma Cloud also supports custom policy
creation, allowing organizations to tailor
security and compliance checks to their
specific needs. This customization ensures that
the security measures are not just broad and
generic but are specifically aligned with the
organization’s unique requirements and risk
profile.</p>
        <p>Splunk is a company, the market leader in
SIEM (Security information and event
management)—a combination of two terms
denoting the scope of the software: SIM
(Security information management)—security
information management, and SEM (Security
event management)—event management
security.</p>
        <p>Every IaaS environment enrolled in an
automated scanning system is typically
configured to export platform events into
Splunk SIEM hosted. Enrollment operation
configures the appropriate access roles and
event notification services on the IaaS platform
side along with a dedicated Splunk index to
store and visualize the event data and
dashboards.</p>
        <p>Users who are entitled to appropriate
access roles within a given cloud environment
might be automatically provisioned with
access to Splunk dashboards for the relevant
environment.</p>
        <p>
          There is a data-level integration between
SIEM and the ITSM platform to export
Configuration Item objects that describe cloud
environments and all related incidents into
Splunk. This integration is aimed at enriching
events that are received from cloud platforms
with business-level and process-level
metadata. This capability is used to implement
dashboards that display incidents related to
environments, their processing speed, priority
classification, service impact, and more [
          <xref ref-type="bibr" rid="ref22">22</xref>
          ].
        </p>
        <p>Rundeck is a runbook automation platform
that significantly reduces and optimizes
operational workflows. What characterizes it
is the easy-to-use user interface that allows
technical or non-technical staff to administrate
and carry out complex tasks with no
requirement of special training. It’s this feature
in fact to be particularly efficient in
timecritical environments in which reduced time of
response and self-reliance are a must.</p>
        <p>The most outstanding characteristic of this
platform is its ability to introduce automation
into complex workflows. Designed to execute
operational tasks with consistency and
without errors, plays a crucial role in
maintaining operational integrity and efficacy.
The standardization brought into play by this
solution is critical across large organizations
where multiple teams working on multiple
processes can often pretty easily get
misaligned and lead to discrepancies.
Automating these routine, complex tasks frees
up valuable time for IT staff to concentrate on
more strategic initiatives. This is a game
changer that is done to enhance the overall
output and efficiency of the team by shifting
from manual, repeatable work to more
valueadded activities.</p>
        <p>
          Rundeck also performs well to give greater
control and governance of IT operations. It has
a tight detailed logging feature that ensures
transparency and accountability when issuing
operating processes to track as part of
governance. Moreover, integration with
several existing tools and systems allows
single operational centers to be created that
will improve operations with little change. In
the case of security and compliance, all
operational tasks are carried out according to
the set protocols and standards. Access control
as well as audit trail functionalities in the
platform play critical roles in maintaining an
operational secure environment where there
are no loopholes to any potential breaches as
well as fulfilling the regulatory requirements
placed on such systems [
          <xref ref-type="bibr" rid="ref23">23</xref>
          ].
        </p>
      </sec>
      <sec id="sec-5-10">
        <title>Runbook automation refers to the use of</title>
        <p>software to automate routine, repetitive, and
often complex operational tasks, and
procedures within an IT environment (Fig. 3).
Traditionally, a runbook is a compilation of
routine procedures and operations that the
system administrator or operator carries out.
Automation of these runbooks means using
software to execute these procedures
automatically or with minimal human
intervention.</p>
        <p>Rundeck, as a runbook automation tool,
enhances this process by providing a
comprehensive and user-friendly platform for
automating a wide array of IT tasks. It allows
IT teams to codify their operational
procedures into automated workflows. These
workflows can range from simple, routine
tasks to complex, multi-step processes. By
doing so, Rundeck not only reduces the time
and effort involved in executing these tasks but
also minimizes the potential for human error.</p>
        <p>
          One of the key features of Rundeck is its
ability to integrate with a wide variety of tools
and systems, making it a versatile option for
many IT environments. This integration
capability means that Rundeck can orchestrate
complex processes across different systems,
providing a cohesive operational experience
[
          <xref ref-type="bibr" rid="ref24">24</xref>
          ].
HashiCorp Vault is designed to help
organizations manage access to secrets and
transmit them safely within an organization.
Secrets are defined as any form of sensitive
credentials that need to be tightly controlled
and monitored and can be used to unlock
sensitive information. Secrets could be in the
form of passwords, API keys, SSH keys, RSA
tokens, or OTP. HashiCorp Vault makes it very
easy to control and manage access by providing
you with a unilateral interface to manage every
secret in your infrastructure. Not only that, but
you can also create detailed audit logs and keep
track of who accessed what [
          <xref ref-type="bibr" rid="ref25">25</xref>
          ].
        </p>
        <p>
          HashiCorp Vault is a secrets management
tool specifically designed to control access to
sensitive credentials in a low-trust
environment. It can be used to store sensitive
values and at the same time dynamically
generate access for specific
services/applications on lease. Plus, Vault can
be used to authenticate users (machines or
humans) to make sure they’re authorized to
access a particular file. Authentication can
either be via passwords or using dynamic
values to generate temporary tokens (which
can be generated by pseudo-random sequence
generators [
          <xref ref-type="bibr" rid="ref26 ref27 ref28">26–28</xref>
          ]) that allow you to access a
particular path. Policies written using
HashiCorp Configuration Language (HCL) are
used to determine who gets what access.
        </p>
        <p>Secret management: HashiCorp Vault can
be used to store any type of secrets, including
sensitive environment variables, database
credentials, API keys, and more, giving users
control over who has access and who does not.
Using Vault allows you to take full control of
any sensitive credentials with the ability to
rotate and revoke access at any time.</p>
        <p>With HashiCorp Vault, you can rest assured
that your credentials are secure, compared to
storing plaintext files in your configuration
management (for example).</p>
        <p>Instead of storing plaintext files for all the
world to see, you can have your application
query vault read or the HashiCorp API, which
protects the plaintext versions of those files.</p>
        <p>Secrets are also easy to rotate and revoke; if
an employee leaves your organization, you can
easily and securely revoke their access.</p>
      </sec>
      <sec id="sec-5-11">
        <title>Identity-based access: HashiCorp Vault</title>
        <p>uses identity-based access to broker access to
systems and secrets. When it comes to
authenticating via identity, there are two
major actors: humans and machines.</p>
        <p>Managing access for humans is done
through Role-Based Access Control (RBAC)
[29], granting permission and restricting
access to either create and manage secrets or
manage other users’ access based on the secret
value they are logged in with.</p>
        <p>Managing access for machines on the other
hand involves providing access to different
servers or secrets. With the dynamic nature of
HashiCorp Vault, you can create secrets that
work temporarily and revoke access in the
event of a breach. You can generate secrets
ondemand for a particular system like Sensu,
AWS, or Consul and generate a key pair with
valid permission. After usage, the dynamic
secrets generated will be automatically
revoked.</p>
        <p>Data encryption: Vault provides
“encryption as a service,” encrypting data in
transit (with TLS) and at rest (using AES
256bit CBC encryption). This protects sensitive
data from unauthorized access in two major
ways: as it travels across your network as well
as in storage in your cloud and data centers
[30].</p>
        <p>With centralized key management, it’s
straightforward to update and roll out new
keys across distributed infrastructure [31].</p>
        <p>ITSM System—a system of accounting for
the organization’s assets. Contains information
about assets, projects, cost distribution,
recorded changes, accounting of the
authorization system, and granted accesses
[32].</p>
        <p>Any service automation and orchestration
need a reliable source of records and metadata
store:
• Services which they contain.
• Identification and naming of the
components.
• Relation to organizational structure.
• Current state in the life cycle.
• Configuration items and dependencies
that are configured</p>
        <p>ITSM platform stores complex data
structures—Configuration Items (CIs)—for
every cloud account and related service
elements. In the process of managing the
environment life cycle, as CI records are
modified (enrolling a new account, changing
account ownership, or setting a monitoring
profile), changes are communicated to the
orchestration platform through API
transactions, and respective configuration
modifications are introduced to the cloud
services.</p>
        <p>Using the ITSM/CMDB system to centrally
store cloud environment metadata ensures
that all resources are provisioned consistently,
within the required pattern, and always have
actual connections to related entities.</p>
        <p>Moreover, this centralized approach to
managing cloud environment metadata via an
ITSM/CMDB system is instrumental in
enhancing the overall governance and control
over IT resources. It allows for a structured
and organized way of tracking the assets
throughout their lifecycle, from procurement
to decommissioning. This systematic tracking
is crucial for effective asset management,
ensuring that every asset is accounted for and
utilized efficiently [33].</p>
        <p>Additionally, the integration of ITSM
systems with cloud services facilitates better
risk management. By maintaining an
up-todate inventory of assets and their
configurations, organizations can quickly
identify and respond to potential security
vulnerabilities or compliance issues. This
proactive approach to risk management is
essential in minimizing the impact of security
threats and ensuring compliance with various
regulatory requirements. Another key benefit
of using an ITSM system in conjunction with
cloud services is the improvement in incident
and change management processes. With a
comprehensive view of all assets and their
configurations, IT teams can more effectively
diagnose and resolve incidents. Furthermore,
the system ensures that any changes to the IT
environment are properly documented and
implemented, reducing the likelihood of errors
or disruptions to services [34].</p>
        <p>The ITSM system also plays a critical role in
financial management and cost optimization.
By providing detailed insights into asset
utilization and costs, organizations can make
more informed decisions about their IT
investments. This financial transparency is
vital for optimizing IT spending and aligning IT
resources with business objectives. In
summary, the integration of ITSM systems
with cloud environments brings about
numerous advantages, including enhanced
governance and control, improved risk
management, more efficient incident and
change management, and better financial
oversight. These benefits underline the
importance of ITSM systems in modern IT
infrastructure management, especially in the
context of increasingly complex and dynamic
cloud environments.</p>
        <p>REST API is a set of definitions and
protocols for building and integrating
software. It is sometimes referred to as a
contract between an information provider and
an information consumer that establishes the
content requested by the consumer (the call)
and the content requested by the producer (the
response) [35].</p>
        <sec id="sec-5-11-1">
          <title>REST is a set of architectural constraints,</title>
          <p>not a protocol or a standard. API developers
can implement REST in a variety of ways.</p>
          <p>When a client request is made via a RESTful
API, it transfers a representation of the state of
the resource to the requester or endpoint. This
information, or representation, is delivered in
one of several formats via HTTP: JSON
(Javascript Object Notation), HTML, XLT,
Python, PHP, or plain text. JSON is the most
generally popular file format to use because,
despite its name, it’s language-agnostic, as well
as readable by both humans and machines [36].</p>
          <p>Something else to keep in mind: Headers and
parameters are also important in the HTTP
methods of a RESTful API HTTP request, as they
contain important identifier information as to
the request’s metadata, authorization, Uniform
Resource Identifier (URI), caching, cookies, and
more. There are request headers and response
headers, each with its own HTTP connection
information and status codes.</p>
          <p>For an API to be considered RESTful, it must
conform to these criteria:
• A client-server architecture made up of
clients, servers, and resources, with
requests managed through HTTP.
• Stateless client-server communication,
meaning no client information is stored
between get requests and each request is
separate and unconnected.
• Cacheable data that streamlines
clientserver interactions.
• A uniform interface between components
so that information is transferred in a
standard form. This requires that:
− resources requested are identifiable
and separate from the
representations sent to the client.
− resources can be manipulated by the
client via the representation they
receive because the representation
contains enough information to do so.
− self-descriptive messages returned to
the client have enough information to
describe how the client should
process it.
− hypertext/hypermedia is available,
meaning that after accessing a
resource the client should be able to
use hyperlinks to find all other
currently available actions they can
take.
• A layered system that organizes each
type of server (those responsible for
security, load-balancing, etc.) involves
the retrieval of requested information
into hierarchies, invisible to the client.
• Code-on-demand (optional): the ability
to send executable code from the server
to the client when requested, extending
client functionality.</p>
          <p>The testing phase of this research project
was comprehensively conducted using the
infrastructures of major cloud environments,
specifically Azure, AWS, and GCP. This diverse
selection of platforms was instrumental in
validating the versatility and effectiveness of
the automated configuration and scanning
method across different cloud ecosystems.
Each of these cloud environments presents
unique characteristics and challenges, making
them ideal for a thorough and robust testing
process.</p>
          <p>In Azure, the testing focused on assessing
how well the automated method integrates
with its native tools and services, particularly
in terms of configuration management and
compliance with security standards. AWS, with
its extensive service offerings and complex
infrastructure, provided a broad testing
ground for evaluating the scalability and
adaptability of the method. The testing in GCP
aimed to analyze the effectiveness of
automation in a Google-centric environment,
especially considering GCP's distinct security
and management tools.</p>
          <p>During the testing, various scenarios were
simulated to encompass a wide range of
possible configurations, security challenges,
and compliance requirements. This included
deploying different types of cloud resources,
applying varied configuration settings, and
then conducting intermittent scans to detect
any non-compliance with the specified global
security standards like NIST 800-53, ISO
27001, HIPAA, and PCI DSS.</p>
          <p>The testing also involved monitoring the
automated system’s response to induced
configuration changes and potential security
breaches. This provided valuable insights into
the system’s capacity to promptly identify and
rectify non-compliant configurations and
vulnerabilities, thereby ensuring continuous
adherence to the highest security standards.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>4. Conclusions</title>
      <p>In this work, a service was proposed and
designed that can be used as a mechanism for
continuous and automated control of
accounts/subscriptions in cloud environments
such as Azure (Microsoft), AWS (Amazon), and
GCP (Google). The service consists of the
following modules:
• Configuration Control Module: This
module is responsible for ensuring that
the cloud environments adhere to
predefined security standards. It
conducts basic checks for compliance
and maintains the necessary
configuration standards.
• Accounting and Audit Module: It
includes components for managing user
access, setting spending limits, tracking
changes, and monitoring the lifespan of
assets. This module is key for
maintaining accurate records and
ensuring financial and access-related
compliance.
• Reporting and Notification Module: This
module is designed to facilitate
communication with cybersecurity
professionals. It provides analytical tools
for a comprehensive overview of various
cloud environments, allowing for
centralized reporting and alerting.
• Continuous Integration Tools: These are
used for developing and testing
scenarios within the automation
approach. Tools like Ansible and Python
are typically involved, allowing for
flexible and efficient automation
scripting and orchestration.
• Orchestrator Tool (e.g., Rundeck):
Rundeck serves as the central
orchestrator, handling the provisioning
and management of cloud resources. It
coordinates the execution of tasks and
workflows as defined in the automation
scenarios.
• Secrets Management (e.g., HashiCorp
Vault): This module is used for securely
managing and storing sensitive
information like passwords, tokens, and
keys, essential for enhancing the security
of cloud assessments.
• Compliance and Security Standards
Scanning Tools (e.g., Prisma Cloud):</p>
      <sec id="sec-6-1">
        <title>These tools are used for continuous</title>
        <p>scanning of cloud configurations against
recommended cybersecurity standards
such as NIST 800-53, HIPAA, PCI DSS,
SOC, and ISO, ensuring ongoing
compliance.</p>
        <p>Audit and Flow Logging Tools: Integral for
tracking and monitoring the operations and
changes within cloud environments, these
tools provide the necessary data for
configuration scanning and compliance checks.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <source>[1] [2] [3] [4] [5] [6]</source>
          [7]
          <string-name>
            <given-names>A.</given-names>
            <surname>Hashmi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Ranjan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Anand</surname>
          </string-name>
          , Security and Compliance Management in Cloud Computing,
          <source>Int. J. Adv. Studies Comput.</source>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <source>Sci. Eng</source>
          .
          <volume>7</volume>
          (
          <issue>1</issue>
          ) (
          <year>2018</year>
          )
          <fpage>47</fpage>
          -
          <lpage>54</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <given-names>Enterprise</given-names>
            <surname>Technologies</surname>
          </string-name>
          ,
          <volume>5</volume>
          (
          <issue>9</issue>
          (
          <issue>89</issue>
          ) (
          <year>2017</year>
          )
          <fpage>36</fpage>
          -
          <lpage>42</lpage>
          . doi:
          <volume>10</volume>
          .15587/
          <fpage>1729</fpage>
          -
          <lpage>4061</lpage>
          .
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <given-names>V.</given-names>
            <surname>Susukailo</surname>
          </string-name>
          , I. Opirskyy,
          <string-name>
            <given-names>S.</given-names>
            <surname>Vasylyshyn</surname>
          </string-name>
          ,
          <article-title>Analysis of the Attack Vectors Used by Threat Actors During the Pandemic</article-title>
          ,
          <source>15th International Conference on Computer Sciences and Information Technologies</source>
          (
          <year>2020</year>
          )
          <fpage>261</fpage>
          -
          <lpage>264</lpage>
          . doi:
          <volume>10</volume>
          .1109/CSIT499 58.
          <year>2020</year>
          .
          <volume>9321897</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <article-title>What is cloud security? URL: https://www</article-title>
          .microsoft.com/uk-ua/ security/business/security-101/whatis-cloud-security
          <string-name>
            <given-names>Z. B.</given-names>
            <surname>Hu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Buriachok</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          ,
          <article-title>Deduplication Method for Ukrainian Last Names, Medicinal Names, and Toponyms Based on Metaphone Phonetic Algorithm, Advances in Computer Science for Engineering and Education III, vol</article-title>
          .
          <volume>1247</volume>
          (
          <year>2020</year>
          )
          <fpage>518</fpage>
          -
          <lpage>533</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>030</fpage>
          -55506-1_
          <fpage>47</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <surname>Enterp</surname>
          </string-name>
          . Technol.
          <volume>5</volume>
          , no.
          <volume>2</volume>
          (
          <issue>101</issue>
          ) (
          <year>2019</year>
          )
          <fpage>64</fpage>
          -
          <lpage>71</lpage>
          . doi:
          <volume>10</volume>
          .15587/
          <fpage>1729</fpage>
          -
          <lpage>4061</lpage>
          .
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <string-name>
            <given-names>S.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <source>Protection of Information in Telecommunication Medical Systems based on a RiskOriented Approach</source>
          , in: Workshop on Cybersecurity Providing in
          <source>Information and Telecommunication Systems</source>
          , vol.
          <volume>3421</volume>
          (
          <year>2023</year>
          )
          <fpage>158</fpage>
          -
          <lpage>167</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>O.</given-names>
            <surname>Vakhula</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I.</given-names>
            <surname>Opirskyy</surname>
          </string-name>
          ,
          <string-name>
            <surname>O. Mykhaylova,</surname>
          </string-name>
          <article-title>Research on Security Challenges in Cloud Environments and Solutions Based on the Security-As-Code Approach</article-title>
          , in: Cybersecurity
          <source>Providing in Information and Telecommunication Systems</source>
          II Vol.
          <volume>3550</volume>
          (
          <year>2023</year>
          )
          <fpage>55</fpage>
          -
          <lpage>69</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>S.</given-names>
            <surname>Kalra</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Atal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Jain</surname>
          </string-name>
          , Security Issues in Cloud Computing,
          <source>Int. J. Comput. Appl</source>
          .
          <volume>167</volume>
          (
          <year>2017</year>
          )
          <fpage>37</fpage>
          -
          <lpage>41</lpage>
          . doi:
          <volume>10</volume>
          .5120/ijca2017914190.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>S.</given-names>
            <surname>Sreedharan</surname>
          </string-name>
          ,
          <article-title>Security and Privacy Issues of Cloud Computing; Solutions and Secure Framework</article-title>
          ,
          <source>IOSR J. Comput. Eng</source>
          .
          <volume>10</volume>
          (
          <year>2013</year>
          )
          <fpage>33</fpage>
          -
          <lpage>37</lpage>
          . doi:
          <volume>10</volume>
          .9790/
          <fpage>0661</fpage>
          -
          <lpage>01043337</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>D.</given-names>
            <surname>Sharma</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Dhote</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Potey</surname>
          </string-name>
          ,
          <article-title>Securityas-a-Service from Clouds: A Comprehensive Analysis</article-title>
          ,
          <source>Int. J. Comput. Appl</source>
          .
          <volume>67</volume>
          (
          <year>2013</year>
          )
          <fpage>15</fpage>
          -
          <lpage>18</lpage>
          . doi:
          <volume>10</volume>
          .5120/
          <fpage>11374</fpage>
          -
          <lpage>6642</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>D.</given-names>
            <surname>Shevchuk</surname>
          </string-name>
          , et al.,
          <source>Designing Secured Services for Authentication</source>
          , Authorization, and Accounting of Users,
          <source>in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          II Vol.
          <volume>3550</volume>
          (
          <year>2023</year>
          )
          <fpage>217</fpage>
          -
          <lpage>225</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>R.</given-names>
            <surname>Marusenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Skladannyi</surname>
          </string-name>
          , Social Engineering Penetration Testing in Higher Education Institutions, Advances in Computer Science for Engineering and
          <string-name>
            <surname>Education</surname>
            <given-names>VI</given-names>
          </string-name>
          , vol.
          <volume>181</volume>
          (
          <year>2023</year>
          )
          <fpage>1132</fpage>
          -
          <lpage>1147</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>P.</given-names>
            <surname>Chirra</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kumar</surname>
          </string-name>
          ,
          <string-name>
            <surname>Multi-Cloud</surname>
            <given-names>Networking</given-names>
          </string-name>
          :
          <article-title>Investigating Strategies and Tools for Networking in Multi-Cloud Environments (</article-title>
          <year>2023</year>
          ).
          <source>doi: 10.13140/RG.2.2.11542.93768.</source>
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>K.</given-names>
            <surname>Parast</surname>
          </string-name>
          , et al.,
          <source>Cloud Computing Security: A Survey on Service-based Models, Comput. Secur</source>
          .
          <volume>114</volume>
          (
          <year>2021</year>
          ). doi:
          <volume>10</volume>
          .1016/j.cose.
          <year>2021</year>
          .
          <volume>102580</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>B.</given-names>
            <surname>Choi</surname>
          </string-name>
          , E. Medina,
          <article-title>Setting Up an Ansible Learning Environment</article-title>
          , Introd. Ansible Netw.
          <source>Automation</source>
          (
          <year>2023</year>
          ). doi:
          <volume>10</volume>
          .1007/978-1-
          <fpage>4842</fpage>
          -9624-
          <issue>0</issue>
          _
          <fpage>4</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>B.</given-names>
            <surname>Choi</surname>
          </string-name>
          ,
          <article-title>Introduction to Python Network Automation: The First Journey (</article-title>
          <year>2021</year>
          ). doi:
          <volume>10</volume>
          .1007/978-1-
          <fpage>4842</fpage>
          -6806-3.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>N.</given-names>
            <surname>Sabharwal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Pandey</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Pandey</surname>
          </string-name>
          ,
          <article-title>Improved Characteristics for CyberInfrastructure-As-Code Automation security Needs, Appl</article-title>
          . Sci.
          <volume>12</volume>
          (
          <issue>3</issue>
          ) (
          <year>2022</year>
          )
          <article-title>Using Terraform</article-title>
          , Packer, Vault, Nomad 1519. doi:
          <volume>10</volume>
          .3390/app12031519. and
          <string-name>
            <surname>Consul:</surname>
            Hands-on Deployment, [29]
            <given-names>T.</given-names>
          </string-name>
          <string-name>
            <surname>Baumer</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Mueller</surname>
            , G. Pernul,
            <given-names>System</given-names>
          </string-name>
          <string-name>
            <surname>Configuration</surname>
          </string-name>
          , and
          <string-name>
            <surname>Best Practices</surname>
          </string-name>
          (
          <year>2021</year>
          ).
          <source>for Cross-domain Identity Management doi: 10.1007/978-1-4842-7129-2</source>
          . (SCIM):
          <article-title>Survey and Enhancement with</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <article-title>National Institute of Standards and RBAC</article-title>
          , IEEE Access
          <volume>11</volume>
          (
          <year>2023</year>
          ). doi: Technology (NIST).
          <source>(Latest Update Year)</source>
          .
          <volume>10</volume>
          .1109/ACCESS.
          <year>2023</year>
          .
          <volume>3304270</volume>
          . “NIST Special Publication 800-53: [30]
          <string-name>
            <given-names>V.</given-names>
            <surname>Buriachok</surname>
          </string-name>
          , et al.,
          <article-title>Invasion Detection Security and Privacy Controls for Federal Model using Two-Stage Criterion of Information Systems</article-title>
          and Organizations.” Detection of Network Anomalies, in: URL: https://csrc.nist.gov/publications/ Workshop on Cybersecurity Providing in detail/sp/800-53/rev-5/final Information and Telecommunication
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>K.</given-names>
            <surname>Edwards</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Riis</surname>
          </string-name>
          ,
          <source>Expected and Systems</source>
          , vol.
          <volume>2746</volume>
          (
          <year>2020</year>
          )
          <fpage>23</fpage>
          -
          <lpage>32</lpage>
          . Realized Costs and Benefits from [31]
          <string-name>
            <given-names>P.</given-names>
            <surname>Riti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Flynn</surname>
          </string-name>
          ,
          <string-name>
            <surname>Vault</surname>
            <given-names>HCL</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Beginning Implementing Product Configuration HCL Programming</surname>
          </string-name>
          (
          <year>2021</year>
          )
          <fpage>129</fpage>
          -
          <lpage>155</lpage>
          . doi: Systems (
          <year>2004</year>
          )
          <fpage>216</fpage>
          -
          <lpage>231</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-1-
          <fpage>4842</fpage>
          -6634-
          <issue>2</issue>
          _
          <fpage>7</fpage>
          .
          <fpage>10</fpage>
          .4018/978-1-
          <fpage>60566</fpage>
          -260-2.
          <fpage>CH012</fpage>
          . [32]
          <string-name>
            <surname>ITSM-IT Service</surname>
          </string-name>
          Management Solution
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>J.</given-names>
            <surname>Dawson</surname>
          </string-name>
          , et al.,
          <source>PRISMA Archetype- of Your Business</source>
          . URL: https://www.
          <article-title>Based Systematic Literature Review of creatio.com/page/itsm-system Security Algorithms in the Cloud</article-title>
          , Secur. [33]
          <string-name>
            <given-names>S.</given-names>
            <surname>Niewiadomski</surname>
          </string-name>
          ,
          <string-name>
            <surname>G.</surname>
          </string-name>
          <article-title>Mzyk, ML Support Commun</article-title>
          . Netw. (
          <year>2023</year>
          )
          <fpage>1</fpage>
          -
          <lpage>17</lpage>
          . doi: for
          <source>Conformity Checks in CMDB-Like</source>
          <volume>10</volume>
          .1155/
          <year>2023</year>
          /9210803.
          <string-name>
            <surname>Databases</surname>
          </string-name>
          (
          <year>2023</year>
          ). doi:
          <volume>10</volume>
          .1007/978-3-
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>G.</given-names>
            <surname>Catescu</surname>
          </string-name>
          ,
          <source>Detecting Insider Threats 031-42508-0_33. Using Security Information and Event</source>
          [34]
          <string-name>
            <given-names>S.</given-names>
            <surname>Maes</surname>
          </string-name>
          ,
          <article-title>ITSM beyond IT. Take the service Management (SIEM</article-title>
          ) (
          <year>2018</year>
          ). doi: experience to new heights,
          <source>IFS</source>
          (
          <year>2023</year>
          ).
          <volume>10</volume>
          .13140/RG.2.2.11716.99200. [35]
          <article-title>What is a REST API? URL:</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>Spinellis</surname>
          </string-name>
          , Diomidis. Service https://www.redhat.com/en/topics/api Orchestration with Rundeck,
          <article-title>IEEE /what-is-a-rest-api Software 31(4) (</article-title>
          <year>2014</year>
          )
          <fpage>16</fpage>
          -
          <lpage>18</lpage>
          . doi: [36]
          <string-name>
            <given-names>B.</given-names>
            <surname>Williams</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Tadlock</surname>
          </string-name>
          , J. Jacoby, REST
          <volume>10</volume>
          .1109/MS.
          <year>2014</year>
          .92. API,
          <string-name>
            <surname>Professional</surname>
            <given-names>WordPress</given-names>
          </string-name>
          ® Plugin
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>H.</given-names>
            <surname>Rajavaram</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Rajula</surname>
          </string-name>
          , Development
          <volume>2</volume>
          (
          <issue>12</issue>
          ) (
          <year>2020</year>
          ). doi: T. Balasubramanian,
          <source>Automation of 10.1002/9781119666981</source>
          .ch12.
          <article-title>Microservices Application Deployment Made Easy by Rundeck</article-title>
          and Kubernetes, International Conference on Electronics, Computing and
          <string-name>
            <given-names>Communication</given-names>
            <surname>Technologies</surname>
          </string-name>
          (
          <year>2019</year>
          )
          <fpage>1</fpage>
          -
          <lpage>3</lpage>
          . doi:
          <volume>10</volume>
          .1109/CONECCT47791.
          <year>2019</year>
          .
          <volume>9012811</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <surname>HashiCorp. (Latest Update Year</surname>
          </string-name>
          <article-title>). “Vault by HashiCorp</article-title>
          .” URL: https://www. vaultproject.io/
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>V.</given-names>
            <surname>Maksymovych</surname>
          </string-name>
          , et al.,
          <source>Combined Pseudo-Random Sequence Generator for Cybersecurity, Sensors</source>
          <volume>22</volume>
          (
          <issue>24</issue>
          ) (
          <year>2022</year>
          )
          <article-title>9700</article-title>
          . doi:
          <volume>10</volume>
          .3390/s22249700.
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>V.</given-names>
            <surname>Maksymovych</surname>
          </string-name>
          , et al.,
          <source>Simulation of Authentication in InformationProcessing Electronic Devices Based on Poisson Pulse Sequence Generators, Electronics</source>
          <volume>11</volume>
          (
          <issue>13</issue>
          ) (
          <year>2022</year>
          )
          <year>2039</year>
          . doi:
          <volume>10</volume>
          .3390/electronics11132039.
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>V.</given-names>
            <surname>Maksymovych</surname>
          </string-name>
          , et al.,
          <source>Development of Additive Fibonacci Generators with</source>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>