A Stakeholder-Oriented Assessment Index for Cloud Security Auditing

被引:4
|
作者
Rizvi, Syed [1 ]
Ryoo, Jungwoo [1 ]
Kissell, John [1 ]
Aiken, Bill [1 ]
机构
[1] Penn State Univ, Dept Informat Sci & Technol, Altoona, PA 16601 USA
关键词
Cloud security; data privacy; cloud auditing; security metrics;
D O I
10.1145/2701126.2701226
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cloud computing is an emerging computing model that provides numerous advantages to organizations (both service providers and customers) in terms of massive scalability, lower cost, and flexibility, to name a few. Despite these technical and economical advantages of cloud computing, many potential cloud consumers are still hesitant to adopt cloud computing due to security and privacy concerns. This paper describes some of the unique cloud computing security factors and subfactors that play a critical role in addressing cloud security and privacy concerns. To mitigate these concerns, we develop a security metric tool to provide information to cloud users about the security status of a given cloud vendor. The primary objective of the proposed metric is to produce a security index that describes the security level accomplished by an evaluated cloud computing vendor. The resultant security index will give confidence to different cloud stakeholders and is likely to help them in decision making, increase the predictability of the quality of service, and allow appropriate proactive planning if needed before migrating to the cloud. To show the practicality of the proposed metric, we provide two case studies based on the available security information about two well-known cloud service providers (CSP). The results of these case studies demonstrated the effectiveness of the security index in determining the overall security level of a CSP with respect to the security preferences of cloud users.
引用
收藏
页数:7
相关论文
共 50 条
  • [31] Sustainability assurance and assurance providers: Corporate governance determinants in stakeholder-oriented countries
    Martinez-Ferrero, Jennifer
    Garcia-Sanchez, Isabel-Maria
    JOURNAL OF MANAGEMENT & ORGANIZATION, 2017, 23 (05) : 647 - 670
  • [32] Social Capital and the Viability of Stakeholder-Oriented Firms: Evidence from Savings Banks*
    Ostergaard, Charlotte
    Schindele, Ibolya
    Vale, Bent
    REVIEW OF FINANCE, 2016, 20 (05) : 1673 - 1718
  • [33] Canadian banks and their responses to COVID-19 - stakeholder-oriented crisis management
    Ordonez-Ponce, Eduardo
    Dordi, Truzaar
    Talbot, David
    Weber, Olaf
    JOURNAL OF SUSTAINABLE FINANCE & INVESTMENT, 2024, 14 (02) : 388 - 409
  • [34] Mutual Auditing Framework for Service Level Security Auditing in Cloud
    Sasmal, Soumitra
    Pan, Indrajit
    2017 THIRD IEEE INTERNATIONAL CONFERENCE ON RESEARCH IN COMPUTATIONAL INTELLIGENCE AND COMMUNICATION NETWORKS (ICRCICN), 2017, : 297 - 302
  • [35] Agriculture market information e-service in bangladesh:: A stakeholder-oriented case analysis
    Islam, M. Sirajul
    Gronlund, Ake
    ELECTRONIC GOVERNMENT, PROCEEDINGS, 2007, 4656 : 167 - +
  • [36] Enterprise Meta Modeling Methods - Combining a Stakeholder-Oriented and a Causality-Based Approach
    Lagerstrom, Robert
    Saat, Jan
    Franke, Ulrik
    Aier, Stephan
    Ekstedt, Mathias
    ENTERPRISE, BUSINESS-PROCESS AND INFORMATION SYSTEMS MODELING, 2009, 29 : 381 - +
  • [37] A phase-wise development approach to business excellence: Towards an innovative, stakeholder-oriented assessment tool for organizational excellence and CSR
    Van Marrewijk M.
    Wuisman I.
    De Cleyn W.
    Timmers J.
    Panapanaan V.
    Linnanen L.
    Journal of Business Ethics, 2004, 55 (2) : 83 - 98
  • [38] Stakeholder-oriented multi-objective process optimization based on an improved genetic algorithm
    Su, Yang
    Jin, Saimeng
    Zhang, Xiangping
    Shen, Weifeng
    Eden, Mario R.
    Ren, Jingzheng
    COMPUTERS & CHEMICAL ENGINEERING, 2020, 132
  • [39] The Board Structure and Performance in IPO Firms: Evidence from Stakeholder-Oriented Corporate Governance
    Watanabel, Naoki
    Yamauchi, Shohei
    Sakawa, Hideaki
    SUSTAINABILITY, 2022, 14 (13)
  • [40] A phase-wise development approach to business excellence: Towards an innovative, stakeholder-oriented assessment tool for organizational excellence and CSR
    van Marrewijk, M
    Wuisman, I
    De Cleyn, W
    Timmers, J
    Panapanaan, V
    Linnanen, L
    JOURNAL OF BUSINESS ETHICS, 2004, 55 (02) : 83 - 98