Security governance as a service on the cloud

被引:3
|
作者
Bryce, Ciaran [1 ]
机构
[1] Univ Appl Sci & Arts Western Switzerland, Geneva Sch Business Adm HES SO, CH-1227 Geneva, Switzerland
关键词
Security; Security as a service; Compliance; Cloud; Process modeling; Burden of proofs;
D O I
10.1186/s13677-019-0148-5
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Small companies need help to detect and to respond to increasing security related threats. This paper presents a cloud service that automates processes that make checks for such threats, implement mitigating procedures, and generally instructs client companies on the steps to take. For instance, a process that automates the search for leaked credentials on the Dark Web will, in the event of a leak, trigger processes that instruct the client on how to change passwords and perhaps a micro-learning process on credential management. The security governance service runs on the cloud as it needs to be managed by a security expert and because it should run on an infrastructure separated from clients. It also runs as a cloud service for economy of scale: the processes it runs can service many clients simultaneously, since many threats are common to all. We also examine how the service may be used to prove to independent auditors (e.g., cyber-insurance agents) that a company is taking the necessary steps to implement its security obligations.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Security Governance as a Service on the Cloud
    Bryce, Ciaran
    2018 IEEE/ACM INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING COMPANION (UCC COMPANION), 2018, : 30 - 35
  • [2] Security governance as a service on the cloud
    Ciarán Bryce
    Journal of Cloud Computing, 8
  • [3] Data Governance Cloud Security Checklist at Infrastructure as a Service (IaaS)
    Abu Saed, Kamariah
    Aziz, Norshakirah
    Abdulkadir, Said Jadid
    Aziz, Izzatdin A.
    Hassan, Noor Hafizah
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2018, 9 (10) : 297 - 306
  • [4] Service brokering in cloud governance
    Munteanu, Victor Ion
    Mindruta, Cristina
    Fortis, Teodor-Florin
    14TH INTERNATIONAL SYMPOSIUM ON SYMBOLIC AND NUMERIC ALGORITHMS FOR SCIENTIFIC COMPUTING (SYNASC 2012), 2012, : 497 - 504
  • [5] The Evolution of Cloud Service Governance
    Linthicum, David S.
    IEEE CLOUD COMPUTING, 2015, 2 (06): : 86 - 89
  • [6] Moon Cloud: A Cloud Platform for ICT Security Governance
    Anisetti, Marco
    Ardagna, Claudio A.
    Gaudenzi, Filippo
    Diomede, Nicla
    Tufarolo, Patrizio
    Damiani, Ernesto
    2018 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2018,
  • [7] Cloud Security Management Suite - Security as a Service
    Krishnan, Deepa
    Chatterjee, Madhumita
    PROCEEDINGS OF THE 2012 WORLD CONGRESS ON INFORMATION AND COMMUNICATION TECHNOLOGIES, 2012, : 431 - 436
  • [8] Cloud Security Certifications: A Comparison to Improve Cloud Service Provider Security
    Di Giulio, Carlo
    Sprabery, Read
    Kamhoua, Charles
    Kwiat, Kevin
    Campbell, Roy H.
    Bashir, Masooda N.
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, DATA AND CLOUD COMPUTING (ICC 2017), 2017,
  • [9] ISGcloud: a Security Governance Framework for Cloud Computing
    Rebollo, Oscar
    Mellado, Daniel
    Fernandez-Medina, Eduardo
    COMPUTER JOURNAL, 2015, 58 (10): : 2233 - 2254
  • [10] Mitigation for cloud computing security risks and governance
    Jabez, J.
    Narmadha, R.
    Porkodi, S.
    Devi, L.
    International Journal of Cloud Computing, 2022, 11 (5-6) : 560 - 567