Software-as-a-Service Security Challenges and Best Practices: A Multivocal Literature Review

被引:4
|
作者
Humayun, Mamoona [1 ]
Niazi, Mahmood [2 ,3 ]
Almufareh, Maram Fahhad [1 ]
Jhanjhi, N. Z. [4 ]
Mahmood, Sajjad [2 ,3 ]
Alshayeb, Mohammad [2 ,3 ]
机构
[1] Jouf Univ, Dept Informat Syst, Coll Comp & Informat Sci, Sakakah 72311, Saudi Arabia
[2] King Fahd Univ Petr & Minerals, Dept Informat & Comp Sci, Dhahran 31261, Saudi Arabia
[3] King Fahd Univ Petr & Minerals, Interdisciplinary Res Ctr Intelligent Secure Syst, Dhahran 31261, Saudi Arabia
[4] Taylors Univ, Sch Comp Sci & Engn SCE, Subang Jaya 47500, Malaysia
来源
APPLIED SCIENCES-BASEL | 2022年 / 12卷 / 08期
关键词
cloud computing; software-as-a-service (SaaS); multi-vocal literature review (MVLR); security;
D O I
10.3390/app12083953
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Cloud computing (CC) is the delivery of computing services on demand and is charged using a "pay per you use" policy. Of the multiple services offered by CC, SaaS is the most popular and widely adapted service platform and is used by billions of organizations due to its wide range of benefits. However, security is a key challenge and obstacle in cloud adoption and therefore needs to be addressed. Researchers and practitioners (R&P) have discussed various security challenges for SaaS along with possible solutions. However, no research study exists that systematically accumulates and analyzes the security challenges and solutions. To fill this gap and provide the state-of-the-art (SOTA) picture of SaaS security, this study provides a comprehensive multivocal literature review (MVLR), including SaaS security issues/challenges and best practices for mitigating these security issues. We identified SaaS security issues/challenges and best practices from the formal literature (FL) as well as the grey literature (GL) to evaluate whether R&P is on the same page or if controversies exist. A total of 93 primary studies were identified, of which 58 are from the FL and 35 belong to the GL. The studies are from the last ten years, from 2010 to 2021. The selected studies were evaluated and analyzed to identify the key security issues faced by SaaS computing and to be aware of the best practices suggested by R&P to improve SaaS security. This MVLR will assist SaaS users to identify the many areas in which additional research and development in SaaS security is required. According to our study findings, data breaches/leakage, identity and access management, governance and regulatory compliance/SLA compliance, and malicious insiders are the key security challenges with the maximum frequency of occurrence in both FL and GL. On the other hand, R&P agree that up-to-date security controls/standards, the use of strong encryption techniques, regulatory compliance/SLA compliance, and multifactor authentication are the most important solutions.
引用
收藏
页数:29
相关论文
共 50 条
  • [21] Multivocal literature review on zero-trust security implementation
    Itodo, Cornelius
    Ozer, Murat
    COMPUTERS & SECURITY, 2024, 141
  • [22] Security in microservice-based systems: A Multivocal literature review
    Pereira-Vale, Anelis
    Fernandez, Eduardo B.
    Monge, Raul
    Astudillo, Hernan
    Marquez, Gaston
    COMPUTERS & SECURITY, 2021, 103
  • [23] Practices for Managing Machine Learning Products: A Multivocal Literature Review
    Alves, Isaque
    Leite, Leonardo A. F.
    Meirelles, Paulo
    Kon, Fabio
    Aguiar, Carla Silva Rocha
    IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2023, 71 : 7425 - 7455
  • [24] Security in microservice-based systems: A Multivocal literature review
    Pereira-Vale, Anelis
    Fernandez, Eduardo B.
    Monge, Raúl
    Astudillo, Hernán
    Márquez, Gastón
    Computers and Security, 2021, 103
  • [25] Rethinking the role of security in client satisfaction with Software-as-a-Service (SaaS) providers
    Goode, Sigi
    Lin, Chinho
    Tsai, Jacob C.
    Jiang, James J.
    DECISION SUPPORT SYSTEMS, 2015, 70 : 73 - 85
  • [26] Function-as-a-Service performance evaluation: A multivocal literature review
    Scheuner, Joel
    Leitner, Philipp
    JOURNAL OF SYSTEMS AND SOFTWARE, 2020, 170
  • [27] A Review of BYOD Security Challenges, Solutions and Policy Best Practices. A Review Paper
    Alotaibi, Bashayer
    Almagwashi, Haya
    2018 1ST INTERNATIONAL CONFERENCE ON COMPUTER APPLICATIONS & INFORMATION SECURITY (ICCAIS' 2018), 2018,
  • [28] MLOps best practices, challenges and maturity models: A systematic literature review
    Zarour, Mohammad
    Alzabut, Hamza
    Al-Sarayreh, Khalid T.
    INFORMATION AND SOFTWARE TECHNOLOGY, 2025, 183
  • [29] A multivocal literature review on serious games for software process standards education
    Calderon, Alejandro
    Ruiz, Mercedes
    O'Connor, Rory V.
    COMPUTER STANDARDS & INTERFACES, 2018, 57 : 36 - 48
  • [30] Challenges and Best Practices in Information Security Management
    McLaughlin, Mark-David
    Gogan, Janis
    MIS QUARTERLY EXECUTIVE, 2018, 17 (03) : 237 - 262