Software-as-a-Service Security Challenges and Best Practices: A Multivocal Literature Review

被引:4
|
作者
Humayun, Mamoona [1 ]
Niazi, Mahmood [2 ,3 ]
Almufareh, Maram Fahhad [1 ]
Jhanjhi, N. Z. [4 ]
Mahmood, Sajjad [2 ,3 ]
Alshayeb, Mohammad [2 ,3 ]
机构
[1] Jouf Univ, Dept Informat Syst, Coll Comp & Informat Sci, Sakakah 72311, Saudi Arabia
[2] King Fahd Univ Petr & Minerals, Dept Informat & Comp Sci, Dhahran 31261, Saudi Arabia
[3] King Fahd Univ Petr & Minerals, Interdisciplinary Res Ctr Intelligent Secure Syst, Dhahran 31261, Saudi Arabia
[4] Taylors Univ, Sch Comp Sci & Engn SCE, Subang Jaya 47500, Malaysia
来源
APPLIED SCIENCES-BASEL | 2022年 / 12卷 / 08期
关键词
cloud computing; software-as-a-service (SaaS); multi-vocal literature review (MVLR); security;
D O I
10.3390/app12083953
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Cloud computing (CC) is the delivery of computing services on demand and is charged using a "pay per you use" policy. Of the multiple services offered by CC, SaaS is the most popular and widely adapted service platform and is used by billions of organizations due to its wide range of benefits. However, security is a key challenge and obstacle in cloud adoption and therefore needs to be addressed. Researchers and practitioners (R&P) have discussed various security challenges for SaaS along with possible solutions. However, no research study exists that systematically accumulates and analyzes the security challenges and solutions. To fill this gap and provide the state-of-the-art (SOTA) picture of SaaS security, this study provides a comprehensive multivocal literature review (MVLR), including SaaS security issues/challenges and best practices for mitigating these security issues. We identified SaaS security issues/challenges and best practices from the formal literature (FL) as well as the grey literature (GL) to evaluate whether R&P is on the same page or if controversies exist. A total of 93 primary studies were identified, of which 58 are from the FL and 35 belong to the GL. The studies are from the last ten years, from 2010 to 2021. The selected studies were evaluated and analyzed to identify the key security issues faced by SaaS computing and to be aware of the best practices suggested by R&P to improve SaaS security. This MVLR will assist SaaS users to identify the many areas in which additional research and development in SaaS security is required. According to our study findings, data breaches/leakage, identity and access management, governance and regulatory compliance/SLA compliance, and malicious insiders are the key security challenges with the maximum frequency of occurrence in both FL and GL. On the other hand, R&P agree that up-to-date security controls/standards, the use of strong encryption techniques, regulatory compliance/SLA compliance, and multifactor authentication are the most important solutions.
引用
收藏
页数:29
相关论文
共 50 条
  • [1] Motivations, Challenges, Best Practices, and Benefits for Bots and Conversational Agents in Software Engineering: A Multivocal Literature Review
    Lambiase, Stefano
    Catolino, Gemma
    Palomba, Fabio
    Ferrucci, Filomena
    ACM COMPUTING SURVEYS, 2025, 57 (04)
  • [2] Software-as-a-service(SaaS): perspectives and challenges
    TSAI WeiTek
    BAI XiaoYing
    HUANG Yu
    ScienceChina(InformationSciences), 2014, 57 (05) : 5 - 19
  • [3] Software-as-a-service (SaaS): perspectives and challenges
    WeiTek Tsai
    XiaoYing Bai
    Yu Huang
    Science China Information Sciences, 2014, 57 : 1 - 15
  • [4] Software-as-a-service (SaaS): perspectives and challenges
    Tsai WeiTek
    Bai XiaoYing
    Huang Yu
    SCIENCE CHINA-INFORMATION SCIENCES, 2014, 57 (05) : 1 - 15
  • [5] Information Security Needs and Practices for Cloud Based Healthcare Software-As-A-Service Model
    Turner, P.
    Sleeman, W.
    Srinivasan, S.
    Bose, P.
    Ghosh, P.
    Palta, J.
    Kapoor, R.
    MEDICAL PHYSICS, 2022, 49 (06) : E676 - E677
  • [6] Quantum computing challenges and solutions in software industry-A multivocal literature review
    Salam, Masaud
    Ilyas, Muhammad
    IET QUANTUM COMMUNICATION, 2024, : 462 - 485
  • [7] Capabilities and Practices in DevOps: A Multivocal Literature Review
    Amaro, Ricardo
    Pereira, Ruben
    da Silva, Miguel Mira
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2023, 49 (02) : 883 - 901
  • [8] A Systematic Literature Review of Best Practices and Challenges in Follow-the-Sun Software Development
    Kroll, Josiane
    Hashmi, Sajid Ibrahim
    Richardson, Ita
    Audy, Jorge L. N.
    2013 IEEE 8TH INTERNATIONAL CONFERENCE ON GLOBAL SOFTWARE ENGINEERING WORKSHOPS (ICGSEW 2013), 2013, : 18 - 23
  • [9] An extensive multivocal literature review of blockchain technology: Evolution, challenges, platforms, security, and interoperability
    Monika, Rajesh
    Bhatia, Rajesh
    Kumar, Manish
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2024, 35 (11):
  • [10] A Multivocal Literature Review of Function-as-a-Service (FaaS) Infrastructures and Implications for Software Developers
    Grogan, Jake
    Muheady, Connor
    McDermott, James
    Urbanavicius, Martynas
    Yilmaz, Murat
    Abgaz, Yalemisew
    McCarren, Andrew
    MacMahon, Silvana Togneri
    Garousi, Vahid
    Elger, Peter
    Clarke, Paul
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT (EUROSPI 2020), 2020, 1251 : 58 - 75