A Stakeholder-Oriented Assessment Index for Cloud Security Auditing

被引:4
|
作者
Rizvi, Syed [1 ]
Ryoo, Jungwoo [1 ]
Kissell, John [1 ]
Aiken, Bill [1 ]
机构
[1] Penn State Univ, Dept Informat Sci & Technol, Altoona, PA 16601 USA
关键词
Cloud security; data privacy; cloud auditing; security metrics;
D O I
10.1145/2701126.2701226
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cloud computing is an emerging computing model that provides numerous advantages to organizations (both service providers and customers) in terms of massive scalability, lower cost, and flexibility, to name a few. Despite these technical and economical advantages of cloud computing, many potential cloud consumers are still hesitant to adopt cloud computing due to security and privacy concerns. This paper describes some of the unique cloud computing security factors and subfactors that play a critical role in addressing cloud security and privacy concerns. To mitigate these concerns, we develop a security metric tool to provide information to cloud users about the security status of a given cloud vendor. The primary objective of the proposed metric is to produce a security index that describes the security level accomplished by an evaluated cloud computing vendor. The resultant security index will give confidence to different cloud stakeholders and is likely to help them in decision making, increase the predictability of the quality of service, and allow appropriate proactive planning if needed before migrating to the cloud. To show the practicality of the proposed metric, we provide two case studies based on the available security information about two well-known cloud service providers (CSP). The results of these case studies demonstrated the effectiveness of the security index in determining the overall security level of a CSP with respect to the security preferences of cloud users.
引用
收藏
页数:7
相关论文
共 50 条
  • [21] Stakeholder-oriented systematic design methodology for prognostic and health management system: Stakeholder expectation definition
    Li, Rui
    Verhagen, Wim J. C.
    Curran, Richard
    ADVANCED ENGINEERING INFORMATICS, 2020, 43
  • [22] How IT and social change facilitates public participation: A stakeholder-oriented approach
    Wagner, Sascha Alexander
    Vogt, Sebastian
    Kabst, Ruediger
    GOVERNMENT INFORMATION QUARTERLY, 2016, 33 (03) : 435 - 443
  • [23] Institutional Ownership and Firm Performance under Stakeholder-Oriented Corporate Governance
    Sakawa, Hideaki
    Watanabel, Naoki
    SUSTAINABILITY, 2020, 12 (03)
  • [24] A Stakeholder-oriented Framework to Consider the Plurality of Land Policy Integration in Sahel
    Papazian, Hermine
    Bousquet, Francois
    Antona, Martine
    d'Aquino, Patrick
    ECOLOGICAL ECONOMICS, 2017, 132 : 155 - 168
  • [25] A stakeholder-oriented innovative product conceptualization strategy based on fuzzy integrals
    Yan, Wei
    Chen, Chun-Hsien
    Chang, Daofang
    Chong, Yih Tng
    ADVANCED ENGINEERING INFORMATICS, 2009, 23 (02) : 201 - 209
  • [26] The ESSGG proposition for stakeholder-oriented urban management performance: a theoretical perspective
    Beck, Donizete
    REVISTA DE GESTAO AMBIENTAL E SUSTENTABILIDADE-GEAS, 2022, 12 (01):
  • [27] New Trends in French Corporate Governance: Towards a Stakeholder-oriented Approach?
    Magnier, Veronique
    EUROPEAN COMPANY LAW, 2012, 9 (05): : 245 - 249
  • [28] A security evaluation framework for cloud security auditing
    Rizvi, Syed
    Ryoo, Jungwoo
    Kissell, John
    Aiken, William
    Liu, Yuhong
    JOURNAL OF SUPERCOMPUTING, 2018, 74 (11): : 5774 - 5796
  • [29] A security evaluation framework for cloud security auditing
    Syed Rizvi
    Jungwoo Ryoo
    John Kissell
    William Aiken
    Yuhong Liu
    The Journal of Supercomputing, 2018, 74 : 5774 - 5796
  • [30] Hybrid modeling and simulation for trustworthy software process management: a stakeholder-oriented approach
    Bai, Xu
    Huang, LiGuo
    Zhang, He
    Koolmanojwong, Supannika
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2012, 24 (07) : 721 - 740