Cloud Security Risk Management A Critical Review

被引:10
|
作者
Damenu, Temesgen Kitaw [1 ]
Balakrishna, Chitra [1 ]
机构
[1] Edge Hill Univ, Dept Comp, Ormskirk, England
关键词
cloud security risk management; cloud security risk assessment; security risk management; cloud security risk;
D O I
10.1109/NGMAST.2015.25
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing has created a remarkable paradigm shift in the IT industry and brought several advantages such as on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. These advantages enabled cloud to have significant impact on different sectors of smart cites. However, cloud adoption has increased the sophistication of the ever changing security risks which frustrate enterprises on expanding their on-premises infrastructure towards cloud horizons. These risks have the potential of being a major concern for smart cities due to the increasing impact of cloud on them. Managing these security risks requires adopting effective risk management method which involve both the cloud service provider and the customer. The risk management frameworks currently applied to manage enterprise IT risks do not readily fit the cloud environment and the dynamic nature of clouds, which are characterized by on demand self-service and rapid elasticity. Therefore, researchers have proposed different cloud security risk management methods and frameworks. This paper critically reviews these risk management methods and frameworks. In addition, it conducts critical analysis on two of them using qualitative content analysis technique, and evaluates their effectiveness for assessing and mitigating cloud security risks.
引用
收藏
页码:370 / 375
页数:6
相关论文
共 50 条
  • [1] SECURITY RISK MANAGEMENT - CLOUD ENVIRONMENT
    Zboril, Martin
    [J]. STRATEGIC MODELING IN MANAGEMENT, ECONOMY AND SOCIETY (IDIMT-2018), 2018, 47 : 367 - 374
  • [2] A Critical Review of Security Threats in Cloud Computing
    Irfan, Mahroosh
    Usman, Muhammad
    Zhuang, Yan
    Fong, Simon
    [J]. 2015 3RD INTERNATIONAL SYMPOSIUM ON COMPUTATIONAL AND BUSINESS INTELLIGENCE (ISCBI 2015), 2015, : 105 - 111
  • [3] Data Security Implementations in Cloud Computing: A Critical Review
    Firdhous, M. F. M.
    Hussien, Naseer Ali
    [J]. 2018 3RD INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY RESEARCH (ICITR), 2018,
  • [4] Integrating Security Risk Management into Business Process Management for the Cloud
    Goettelmann, Elio
    Mayer, Nicolas
    Godart, Claude
    [J]. 2014 IEEE 16TH CONFERENCE ON BUSINESS INFORMATICS (CBI), VOL 1, 2014, : 86 - 93
  • [5] A Method of the Cloud Computing Security Management Risk Assessment
    Wang, Hongbing
    Liu, Feng
    Liu, Heng
    [J]. ADVANCES IN COMPUTER SCIENCE AND ENGINEERING, 2012, 141 : 609 - +
  • [6] Cloud Security: Analysis and Risk Management of VM Images
    Bindra, Gundeep Singh
    Singh, Prashant Kumar
    Kandwal, Krishen Kant
    Khanna, Seema
    [J]. PROCEEDING OF THE IEEE INTERNATIONAL CONFERENCE ON INFORMATION AND AUTOMATION, 2012, : 646 - 651
  • [7] Data Security Challenges and Solutions in Cloud Computing: Critical Review
    Al-Otaibi, Shuruq Zayed
    [J]. COMMUNICATIONS IN MATHEMATICS AND APPLICATIONS, 2022, 13 (02): : 795 - 806
  • [8] A Review of Security Risk Assessment Methods in Cloud Computing
    Alturkistani, Fatimah M.
    Emam, Ahmed Z.
    [J]. NEW PERSPECTIVES IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 1, 2014, 275 : 443 - 453
  • [9] IT Security Risk Management: Perceived IT Security Risks in the Context of Cloud Computing.
    Vinaja, Roberto
    [J]. JOURNAL OF GLOBAL INFORMATION TECHNOLOGY MANAGEMENT, 2013, 16 (03) : 82 - 84
  • [10] SECURITY AND RISK MANAGEMENT WHEN USING CLOUD COMPUTING IT SERVICES
    Sepulveda O, Erick
    Salcedo, Octavio J.
    Gomez Vargas, Ernesto
    [J]. REDES DE INGENIERIA-ROMPIENDO LAS BARRERAS DEL CONOCIMIENTO, 2010, 1 (02): : 10 - 21