ITALIAN CLOUD STRATEGY
3.3 Aspects of Resilience
Cloud infrastructures and services supporting PA applications and national essential entities must adopt
appropriate procedural and technical security measures, as well as redundancy and interoperability
operations. The application of layered security controls (e.g. pseudonymisation, encryption with onpremise key management) in compliance with the specific requirements of the data processed, as well
as service continuity and disaster recovery measures available throughout the entire national territory, will
increase the level of resilience against incidents such as cyber attacks and breakdowns.
In particular, although international practices and technical standards are widely applied by Cloud
service providers, given the criticality of the data and services involved, the Cloud migration strategy
requires a certification process of public Cloud providers and their services. The qualification must assess
not only the security dimension but also the architectural and organisational aspects which may have
negative impacts on the resilience, e.g. vendor lock-in situations. Another important direction, in line with
the recent initiatives and directives of the European Digital Agenda6, is the standardisation, harmonisation
and interoperability of Cloud services. Within this context, and with the aim of developing common
requirements for a European data infrastructure, the GAIA-X project7 was launched; since the project’s
inception Italy had an active involvement in its development. The project, designed for European based
companies, has the objective to build an open and resilient digital ecosystem through the federation of
cloud services. This ecosystem is built on common standards, ensures transparency and interoperability,
capable of connecting centralised and decentralised infrastructures, and transforming them into a
homogeneous system.
6
7
8
https://ec.europa.eu/info/strategy/priorities-2019-2024/europe-fit-digital-age_en
https://www.data-infrastructure.eu/