Cloud Security Certifications: A Comparison to Improve Cloud Service Provider Security

被引:2
|
作者
Di Giulio, Carlo [1 ]
Sprabery, Read [1 ]
Kamhoua, Charles [2 ]
Kwiat, Kevin [2 ]
Campbell, Roy H. [1 ]
Bashir, Masooda N. [1 ]
机构
[1] Univ Illinois, Champaign, IL 61820 USA
[2] Air Force Res Lab, Wright Patterson AFB, OH USA
关键词
FedRAMP; ISO; Certification; Standard; Framework; Cloud; Privacy; Security;
D O I
10.1145/3018896.3025169
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The great diffusion of cloud computing applications and services in the last years has brought new threats to security of information. 1 IT Certification and authorization mechanisms try to provide assurance against those threats by leveraging high security standards and controls. Two examples of such certification based on IT security controls are ISO/IEC 27001 and FedRAMP. While these two certifications largely share their scope it is important to note that ISO is a standardization adopted worldwide since 2005 whereas FedRAMP was developed in 2012 specifically for US Government Cloud Service Providers. New frameworks, however, are not always more effective than earlier ones, especially in the fast-moving world of cloud computing where IT security standards need to be constantly updated. This study offers an overview of adequacy and completeness of ISO/IEC 27001 and FedRAMP, bringing to question the level of protection that they provide by comparing them to each other and evaluating both in terms of known threats to cloud computing. The study identifies weaknesses in the certification build process and highlights necessary improvements.
引用
收藏
页数:12
相关论文
共 50 条
  • [1] Towards Automatic Comparison of Cloud Service Security Certifications
    Labaj, Martin
    Rastocny, Karol
    Chuda, Daniela
    THEORY AND PRACTICE OF COMPUTER SCIENCE, SOFSEM 2019, 2019, 11376 : 298 - 309
  • [2] An Initiation for Testing the Security of a Cloud Service Provider
    Ajay, D. M.
    Umamaheswari, E.
    PROCEEDINGS OF THE 3RD INTERNATIONAL SYMPOSIUM ON BIG DATA AND CLOUD COMPUTING CHALLENGES (ISBCC - 16'), 2016, 49 : 33 - 41
  • [3] Cloud Service Provider Security Readiness Model: The Malaysian Perspective
    Ahmad, Nur Ilyani
    Mohamed, Ibrahim
    Daud, Maslina
    Jarno, Ahmad Dahari
    Hamid, Norlaili Abdul
    PROCEEDING OF 2019 INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING AND INFORMATICS (ICEEI), 2019, : 75 - 80
  • [4] Measuring Security for Cloud Service Provider : A Third Party Approach
    Whaiduzzaman, Md
    Gani, Abdullah
    2013 INTERNATIONAL CONFERENCE ON ELECTRICAL INFORMATION AND COMMUNICATION TECHNOLOGY (EICT), 2013,
  • [5] Cloud Security: from Per-Provider to Per-Service Security SLAs
    De Benedictis, Alessandra
    Casola, Valentina
    Rakt, Massimiliano
    Villano, Umberto
    2016 8TH INTERNATIONAL CONFERENCE ON INTELLIGENT NETWORKING AND COLLABORATIVE SYSTEMS (INCOS), 2016, : 469 - 474
  • [6] IaaS Cloud Model Security Issues on Behalf Cloud Provider and User Security Behaviors
    Chawki, El Balmany
    Ahmed, Asimi
    Zakariae, Tbatou
    15TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2018) / THE 13TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC-2018) / AFFILIATED WORKSHOPS, 2018, 134 : 328 - 333
  • [7] Cloud Security Management Suite - Security as a Service
    Krishnan, Deepa
    Chatterjee, Madhumita
    PROCEEDINGS OF THE 2012 WORLD CONGRESS ON INFORMATION AND COMMUNICATION TECHNOLOGIES, 2012, : 431 - 436
  • [8] Classifying Cloud Provider Security Conformance to Cloud Controls Matrix
    Pumvarapruek, Nuttapong
    Senivongse, Twittie
    2014 11TH INTERNATIONAL JOINT CONFERENCE ON COMPUTER SCIENCE AND SOFTWARE ENGINEERING (JCSSE), 2014, : 268 - 273
  • [9] Cyber Security Risk Assessment Framework for Cloud Customer and Service Provider
    Kumari, N. Sujata
    Vurukonda, Naresh
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (12) : 683 - 697
  • [10] Security Governance as a Service on the Cloud
    Bryce, Ciaran
    2018 IEEE/ACM INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING COMPANION (UCC COMPANION), 2018, : 30 - 35