A Stakeholder-Oriented Assessment Index for Cloud Security Auditing

被引:4
|
作者
Rizvi, Syed [1 ]
Ryoo, Jungwoo [1 ]
Kissell, John [1 ]
Aiken, Bill [1 ]
机构
[1] Penn State Univ, Dept Informat Sci & Technol, Altoona, PA 16601 USA
关键词
Cloud security; data privacy; cloud auditing; security metrics;
D O I
10.1145/2701126.2701226
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cloud computing is an emerging computing model that provides numerous advantages to organizations (both service providers and customers) in terms of massive scalability, lower cost, and flexibility, to name a few. Despite these technical and economical advantages of cloud computing, many potential cloud consumers are still hesitant to adopt cloud computing due to security and privacy concerns. This paper describes some of the unique cloud computing security factors and subfactors that play a critical role in addressing cloud security and privacy concerns. To mitigate these concerns, we develop a security metric tool to provide information to cloud users about the security status of a given cloud vendor. The primary objective of the proposed metric is to produce a security index that describes the security level accomplished by an evaluated cloud computing vendor. The resultant security index will give confidence to different cloud stakeholders and is likely to help them in decision making, increase the predictability of the quality of service, and allow appropriate proactive planning if needed before migrating to the cloud. To show the practicality of the proposed metric, we provide two case studies based on the available security information about two well-known cloud service providers (CSP). The results of these case studies demonstrated the effectiveness of the security index in determining the overall security level of a CSP with respect to the security preferences of cloud users.
引用
收藏
页数:7
相关论文
共 50 条
  • [41] Stakeholder-oriented brand management: A Venn-diagram approach to monitor brand associations
    Koll, Oliver
    von Wallpach, Sylvia
    Uzelac, Borislav
    EUROPEAN MANAGEMENT JOURNAL, 2023, 41 (03) : 437 - 444
  • [42] Cloud Security Auditing: Challenges and Emerging Approaches
    Ryoo, Jungwoo
    Rizvi, Syed
    Aiken, William
    Kissell, John
    IEEE SECURITY & PRIVACY, 2014, 12 (06) : 68 - 74
  • [43] On the security of auditing mechanisms for secure cloud storage
    Yu, Yong
    Niu, Lei
    Yang, Guomin
    Mu, Yi
    Susilo, Willy
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2014, 30 : 127 - 132
  • [44] A Value Based Approach to Organization Types: Towards a coherent set of stakeholder-oriented management tools
    Marcel van Marrewijk
    Journal of Business Ethics, 2004, 55 : 147 - 158
  • [45] A value based approach to organization types: Towards a coherent set of stakeholder-oriented management tools
    van Marrewijk, M
    JOURNAL OF BUSINESS ETHICS, 2004, 55 (02) : 147 - 158
  • [46] Building Security Assessment Index System on Cloud Computing Platform
    Wang Chen
    Lei Jing
    PROCEEDINGS OF THE 2016 5TH INTERNATIONAL CONFERENCE ON MEASUREMENT, INSTRUMENTATION AND AUTOMATION (ICMIA 2016), 2016, 138 : 303 - 306
  • [47] Non-Controlling Interests and Proxy of Real Activities Manipulation in Stakeholder-Oriented Corporate Governance
    Fujita, Kento
    Yamada, Akihiro
    JOURNAL OF ASIAN FINANCE ECONOMICS AND BUSINESS, 2022, 9 (10): : 105 - 113
  • [48] Impact of Parent Companies and Multiple Large Shareholders on Audit Fees in Stakeholder-Oriented Corporate Governance
    Yamada, Akihiro
    Fujita, Kento
    SUSTAINABILITY, 2022, 14 (09)
  • [49] Corporate responsibility for sustainable development: a review and conceptual comparison of market- and stakeholder-oriented strategies
    Heikkurinen, Pasi
    Bonnedahl, Karl Johan
    JOURNAL OF CLEANER PRODUCTION, 2013, 43 : 191 - 198
  • [50] Internationalization and the reliance of analyst forecasts in stakeholder-oriented corporate governance: Evidence from Japanese MNEs
    Sakawa, Hideaki
    Watanabel, Naoki
    Gu, Junjian
    PACIFIC-BASIN FINANCE JOURNAL, 2022, 73