3) Security Controls Implementation: Each stakeholder
implements the security controls under their responsibility
as stated in the security plan and the security controls
configurations as specified in the previous step.
4) Assessing the implemented security controls: The
controls to be assessed and the objectives of the assessment
are defined by GC, Auckland and Swinburne and
documented in the tenant security assessment plan. The
execution of such plan, the assessment process, should be
conducted by a third party. Our framework helps in
assessing security controls status when using security
controls that integrate with our framework (the framework
can understand and read their log structure). The outcome of
the assessment phase is a security assessment report.
5) Service Authorization: Swinburne and Auckland give
their formal acceptance of the security plan, assessment
plan, and the assessment reports. This acceptance represents
the authorization decision to use Galactic by the CC.
6) Monitoring the effectiveness of the security controls:
The framework collects the defined security metrics as per
the assessment plan of each tenant and generates status
reports to the intended cloud stakeholders. A report shows
the metrics status and trends, as shown in Figure 7.