Assessing the Security Posture of Cloud Service Providers

被引:0
|
作者
Rivera, Jorge [1 ]
Yu, Huiming [1 ]
Williams, Ken [1 ]
Zhan, Justin [1 ]
Yuan, Xiaohong [1 ]
机构
[1] North Carolina A&T State Univ, Dept Comp Sci, Greensboro, NC 27401 USA
关键词
cloud computing security; fuzzy Likert system; assessment;
D O I
暂无
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
Cloud computing offers on-demand scalable resources and IT-based solutions without the need to invest in new infrastructure or train new personnel. Despite its economic advantages, cloud computing has faced scrutiny regarding security risks involved with allowing sensitive data to be controlled and handled by third-party, off-site vendors. Many businesses with interest in using cloud services do not have a process to assess cloud providers security posture. To aid this issue, the Cloud Security Alliance (CSA) has developed the Consensus Assessments Initiative Questionnaire (CAIQ), which has quickly become an industry-accepted way to document security controls found within cloud services. The CSA CAIQ document provides prospective clients an in-depth look into the security controls of a given cloud service provider (CSP). The assessment process is very complicated because it requires clients to examine over 140 questions spanning over eleven security control categories in CAIQ, answer yes/no followed by explanatory comments related to the corresponding question. How cloud consumers can objectively use the CAIQ to assess CSP security levels becomes an important and urgent problem. A Fuzzy Likert System (FLS) was employed that uses fuzzy logic, Likert scales and decision making technologies to assess the Security Posture Score (SPS) for cloud service providers based on client evaluations of CSP feedback on the CAIQ document and client-defined weights signifying the relative importance of each CAIQ category. The FLS allows clients to numerically evaluate the CSA CAIQ and provides weights for each CAIQ category. Upon doing so, the FLS provides a score indicating the security posture of the given CSP. A one-tailed F-test is used to perform a statistical analysis comparing the standard deviation between 1000 random SPSs calculated with our FLS and a traditional weighted-average system. Experimental results indicate that the null hypothesis, which states that the two standard deviations are the same, can be rejected in favor of the alternate hypothesis, thus claiming that with 95% confidence there is a significant difference between scoring methods.
引用
收藏
页码:103 / 110
页数:8
相关论文
共 50 条
  • [21] Service providers: the gatekeepers of Internet security
    Newman S.
    2017, Elsevier Ltd (2017) : 5 - 7
  • [22] Assessing the Security of the Cloud Environment
    Al Awadhi, Eman
    Salah, Khaled
    Martin, Thomas
    2013 7TH IEEE GCC CONFERENCE AND EXHIBITION (GCC), 2013, : 251 - 256
  • [23] An Assessment of Security Requirements Compliance of Cloud Providers
    Bhensook, Nuntapun
    Senivongse, Twittie
    2012 IEEE 4TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2012,
  • [24] A methodology of Assessing Security Risk of Cloud Computing in User Perspective for Security-Service-Level Agreements
    Na, Sang-Ho
    Huh, Eui-Nam
    2014 FOURTH INTERNATIONAL CONFERENCE ON INNOVATIVE COMPUTING TECHNOLOGY (INTECH), 2014, : 87 - 92
  • [25] Areas of Focus for Cloud Security Providers Assessment
    Svata, Vlasta
    Zboril, Martin
    2020 10TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER INFORMATION TECHNOLOGIES (ACIT), 2020, : 806 - 810
  • [26] Assessing and Improving SLAs for IT Service Providers
    Abushaban, Rafat M.
    PROCEEDINGS OF THE 2013 PALESTINIAN INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY (PICICT), 2013, : 43 - 50
  • [27] Security Governance as a Service on the Cloud
    Bryce, Ciaran
    2018 IEEE/ACM INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING COMPANION (UCC COMPANION), 2018, : 30 - 35
  • [28] A Graph Neural Network-based Security Posture-aware Cloud Service Provider Selection for Multi-cloud
    Wijenayake, D. S.
    Henna, Shagufta
    Farrelly, William
    2023 31ST IRISH CONFERENCE ON ARTIFICIAL INTELLIGENCE AND COGNITIVE SCIENCE, AICS, 2023,
  • [29] Security governance as a service on the cloud
    Bryce, Ciaran
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2019, 8 (01):
  • [30] Security governance as a service on the cloud
    Ciarán Bryce
    Journal of Cloud Computing, 8