Cloud Security Certifications: A Comparison to Improve Cloud Service Provider Security

被引:2
|
作者
Di Giulio, Carlo [1 ]
Sprabery, Read [1 ]
Kamhoua, Charles [2 ]
Kwiat, Kevin [2 ]
Campbell, Roy H. [1 ]
Bashir, Masooda N. [1 ]
机构
[1] Univ Illinois, Champaign, IL 61820 USA
[2] Air Force Res Lab, Wright Patterson AFB, OH USA
关键词
FedRAMP; ISO; Certification; Standard; Framework; Cloud; Privacy; Security;
D O I
10.1145/3018896.3025169
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The great diffusion of cloud computing applications and services in the last years has brought new threats to security of information. 1 IT Certification and authorization mechanisms try to provide assurance against those threats by leveraging high security standards and controls. Two examples of such certification based on IT security controls are ISO/IEC 27001 and FedRAMP. While these two certifications largely share their scope it is important to note that ISO is a standardization adopted worldwide since 2005 whereas FedRAMP was developed in 2012 specifically for US Government Cloud Service Providers. New frameworks, however, are not always more effective than earlier ones, especially in the fast-moving world of cloud computing where IT security standards need to be constantly updated. This study offers an overview of adequacy and completeness of ISO/IEC 27001 and FedRAMP, bringing to question the level of protection that they provide by comparing them to each other and evaluating both in terms of known threats to cloud computing. The study identifies weaknesses in the certification build process and highlights necessary improvements.
引用
收藏
页数:12
相关论文
共 50 条
  • [31] Security-as-a-Service in Multi-cloud and Federated Cloud Environments
    Pawar, Pramod S.
    Sajjad, Ali
    Dimitrakos, Theo
    Chadwick, David W.
    TRUST MANAGEMENT IX, 2015, 454 : 251 - 261
  • [32] Security of Visual Codes in Service Management in the Cloud
    Ogiela, Lidia
    Ogiela, Marek R.
    2017 2ND INTERNATIONAL CONFERENCE ON INTELLIGENT INFORMATICS AND BIOMEDICAL SCIENCES (ICIIBMS), 2017, : 165 - 168
  • [33] Adaptive Security for Cloud Data Warehouse as a Service
    Guermazi, Emna
    Ben Ayed, Mounir
    Ben-Abdallah, Hanene
    2015 IEEE/ACIS 14TH INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION SCIENCE (ICIS), 2015, : 647 - 650
  • [34] Editorial: Security of cloud service for the manufacturing industry
    Cheng, Xiaochun
    Liu, Zheli
    Ning, Yongsheng
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2022, 33 (04)
  • [35] Measuring Data Security for a Cloud Computing Service
    Shaikh, Rizwana A. R.
    Modak, Masooda M.
    2017 INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION, CONTROL AND AUTOMATION (ICCUBEA), 2017,
  • [36] Towards Security as a Service (SecaaS): on the modeling of Security Services for Cloud Computing
    Furfaro, Angelo
    Garro, Alfredo
    Tundis, Andrea
    2014 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2014,
  • [37] Leveraging countermeasures as a service for VoIP security in the cloud
    Dabbebi, Oussema
    Badonnel, Remi
    Festor, Olivier
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2014, 24 (01) : 70 - 84
  • [38] Security as a Service for Public Cloud Tenants(SaaS)
    Hawedi, Mohamed
    Talhi, Chamseddine
    Boucheneb, Hanifa
    9TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT 2018) / THE 8TH INTERNATIONAL CONFERENCE ON SUSTAINABLE ENERGY INFORMATION TECHNOLOGY (SEIT-2018) / AFFILIATED WORKSHOPS, 2018, 130 : 1025 - 1030
  • [39] Encryption as a Service for Data Healthcare Cloud Security
    El Bouchti, Abdelali
    Bahsani, Samir
    Nahhal, Tank
    2016 FIFTH INTERNATIONAL CONFERENCE ON FUTURE COMMUNICATION TECHNOLOGIES (FGCT), 2016, : 48 - 54
  • [40] Integrating Security Services in Cloud Service Stores
    Daniel, Joshua
    El-Moussa, Fadi
    Ducatel, Gery
    Pawar, Pramod
    Sajjad, Ali
    Rowlingson, Robert
    Dimitrakos, Theo
    TRUST MANAGEMENT IX, 2015, 454 : 226 - 239