
 
tasks related to the requirement of accountability. 
We have identified some specific techniques, 
namely: natural-language analysis of law, regulation 
and corporate guidelines on security and privacy of 
customer data in order to generate technically 
enforceable policies; use of sticky policies to 
achieve a strong binding between data and the 
stipulations that apply to the use and dissemination 
of that data; and active monitoring of a cloud 
provider's infrastructure to detect potential 
compliance problems. More in-depth analyses of 
ways to achieve accountability in the cloud are 
available in some of our previous work (see also 
(Casassa Mont et al., 2010); (Pearson, 2011); 
(Pearson et al., 2011) ; (Mowbray et al., 2010) ; (Ko 
et al., 2011a) ;(Ko et al., 2011b) ). 
Our main contribution in this paper has been to 
describe ongoing work on developing software tools 
for automated information extraction of cloud terms 
of service, and to identify classes of related software 
tools needed to achieve full accountability in cloud 
computing. There is clearly much work to be done to 
achieve this important goal for the sake of future 
cloud service users. 
REFERENCES 
Mell, P., Grance, T. The NIST Definition of Cloud 
Computing: Recommendations of the National 
Institute of Standards and Technology. NIST Special 
Publication, 2011, 800-145. 
Bradshaw, S., Millard, C., Walden, I. 2010. Contracts for 
Clouds: Comparison and Analysis of the Terms and 
Conditions of Cloud Computing Services. Queen 
Mary University of London, School of Law Legal 
Studies Research Paper No. 63/2010. 
Breaux, T. D., Gordon, D. G. 2011 Regulatory 
Requirements as Open Systems: Structures, Patterns 
and Metrics for the Design of Formal Requirements 
Specifications. Technical Report CMU-ISR-11-100, 
Institute for Software Research, Carnegie-Mellon 
University. 
Breaux, T. D., Vail, M.W., and Antón, A.I. 2006. Towards 
Regulatory Compliance: Extracting Rights and 
Obligations to Align Requirements with Regulations. 
In  Proceedings of 14th IEEE International 
Requirements Engineering Conference (RE’06), 2006. 
Cunningham, H., Maynard, D., Bontcheva, K.,  Tablan, 
V., Aswani, N., Roberts, I., Gorrell, G., Funk, A.,  
Roberts, A., Damljanovic, D., Heitz, T., Greenwood, 
M.A., Saggion, H., Petrak, J., Li, Y., Peters, W. 2011. 
Text Processing with GATE (Version 6). Department 
of Computer Science, University of Sheffield. 
Cranor, L., Langheinrich, M., Marchiori, M., Presler-
Marshall, M., Reagle, J. 2002. The Platform for 
Privacy Preferences 1.0 (P3P1.0) Specification. W3C 
Recommendation. 
May, M., Gunter, C., Lee, I., Zdancewic, S. 2009. Strong 
and Weak Policy Relations. In Proceedings of the 
2009 IEEE International Symposium on Policies for 
Distributed Systems and Networks (POLICY '09). 
IEEE Computer Society, Washington, DC, USA, pp. 
33-36, 2009.  
Papanikolaou, N., Creese, S., Goldsmith, M. Refinement 
checking for privacy policies. Science of Computer 
Programming. Article in Press, DOI:10.1016/ 
j.scico.2011.07.009. 
Casassa Mont, M., Pearson, S., Creese, S., Goldsmith, M., 
Papanikolaou, N. A Conceptual Model for Privacy 
Policies with Consent and Revocation Requirements. 
In Proceedings of PrimeLife/IFIP Summer School 
2010: Privacy and Identity Management for Life, 
Lecture Notes in Computer Science, Springer (2010). 
Pearson, S. Toward Accountability in the Cloud. View 
from the Cloud, IEEE Internet Computing, IEEE 
Computer Society, July/August issue, vol. 15, no. 4, 
2011. 
Pearson, S., Casassa Mont, M., Kounga, G. 2011. 
Enhancing Accountability in the Cloud via Sticky 
Policies. Secure and Trust Computing, Data 
Management and Applications, Communications in 
Computer and Information Science, vol. 187, Springer 
Verlag, Heidelberg, pp. 146-155. 
Mowbray, M., Pearson, S. and Shen, Y. 2010. Enhancing 
privacy in cloud computing via policy-based 
obfuscation. Journal of Supercomputing. DOI: 
10.1007/s11227-010-0425-z. 
Ko, R. K. L, Jagadpramana, P., Mowbray, M., Pearson, S., 
Kirchberg, M., Liang, Q., Lee, B.S. 2011a. 
TrustCloud: A Framework for Accountability and 
Trust in Cloud Computing, 2nd IEEE Cloud Forum for 
Practitioners (ICFP), IEEE Computer Society, 
Washington DC, USA. 
Ko, R.K.L., Lee, B. S., Pearson, S. 2011b. Towards 
achieving accountability, auditability and trust in 
cloud computing. A. Abraham et al. (Eds.), ACC 
2011, Part IV, CCIS 193, pp. 432–444, Springer-
Verlag, Heidelberg. 
AUTOMATINGCOMPLIANCEFORCLOUDCOMPUTINGSERVICES
637