ERMOCTAVE: A Risk Management Framework for IT Systems Which Adopt Cloud Computing

被引:6
|
作者
Mackita, Masky [1 ]
Shin, Soo-Young [2 ]
Choe, Tae-Young [3 ]
机构
[1] ING Bank, B-1040 Brussels, Belgium
[2] Kumoh Natl Inst Technol, Dept IT Convergence Engn, Gumi 39177, South Korea
[3] Kumoh Natl Inst Technol, Dept Comp Engn, Gumi 39177, South Korea
来源
FUTURE INTERNET | 2019年 / 11卷 / 09期
关键词
risk management; ERM; OCTAVE; cloud computing; Microsoft Azure;
D O I
10.3390/fi11090195
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Many companies are adapting cloud computing technology because moving to the cloud has an array of benefits. During decision-making, having processed for adopting cloud computing, the importance of risk management is progressively recognized. However, traditional risk management methods cannot be applied directly to cloud computing when data are transmitted and processed by external providers. When they are directly applied, risk management processes can fail by ignoring the distributed nature of cloud computing and leaving numerous risks unidentified. In order to fix this backdrop, this paper introduces a new risk management method, Enterprise Risk Management for Operationally Critical Threat, Asset, and Vulnerability Evaluation (ERMOCTAVE), which combines Enterprise Risk Management and Operationally Critical Threat, Asset, and Vulnerability Evaluation for mitigating risks that can arise with cloud computing. ERMOCTAVE is composed of two risk management methods by combining each component with another processes for comprehensive perception of risks. In order to explain ERMOCTAVE in detail, a case study scenario is presented where an Internet seller migrates some modules to Microsoft Azure cloud. The functionality comparison with ENISA and Microsoft cloud risk assessment shows that ERMOCTAVE has additional features, such as key objectives and strategies, critical assets, and risk measurement criteria.
引用
收藏
页数:21
相关论文
共 50 条
  • [1] A RISK MANAGEMENT FRAMEWORK FOR CLOUD COMPUTING
    Xie, Feng
    Peng, Yong
    Zhao, Wei
    Chen, Dongqing
    Wang, Xiaoran
    Huo, Xingmei
    2012 IEEE 2ND INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND INTELLIGENT SYSTEMS (CCIS) VOLS 1-3, 2012, : 476 - 480
  • [2] Adaptive Risk Management Framework for Cloud Computing
    Medhioub, Manel
    Hamdi, Mohamed
    Kim, Tai-Hoon
    2017 IEEE 31ST INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2017, : 1154 - 1161
  • [3] On Cloud Nine? An Integrative Risk Management Framework for Cloud Computing
    Troshani, Indrit
    Rampersad, Giselle
    Wickramasinghe, Nilmini
    24TH BLED ECONFERENCE: EFUTURE: CREATING SOLUTIONS FOR THE INDIVIDUAL, ORGANISATIONS AND SOCIETY, 2011, : 15 - +
  • [4] Risk Management Framework With COBIT 5 And Risk Management Framework for Cloud Computing Integration
    Khrisna, Akbar
    Harlili
    2014 INTERNATIONAL CONFERENCE OF ADVANCED INFORMATICS: CONCEPT, THEORY AND APPLICATION (ICAICTA), 2014, : 103 - 108
  • [5] A Risk Assessment Framework for Cloud Computing
    Djemame, Karim
    Armstrong, Django
    Guitart, Jordi
    Macias, Mario
    IEEE TRANSACTIONS ON CLOUD COMPUTING, 2016, 4 (03) : 265 - 278
  • [6] A New Conceptual Framework Modelling for Cloud Computing Risk Management in Banking Organizations
    Elzamly, Abdelrafe
    Hussin, Burairah
    Abu Naser, Samy
    Khanfar, Khalid
    Doheir, Mohamed
    Selamat, Ali
    Rashed, Abdullah
    INTERNATIONAL JOURNAL OF GRID AND DISTRIBUTED COMPUTING, 2016, 9 (09): : 137 - 154
  • [7] A Road Map to Risk Management Framework for Successful Implementation of Cloud Computing in Oman
    Al-Musawi, Fatma
    Al-Badi, Ali H.
    Ali, Saqib
    2015 INTERNATIONAL CONFERENCE ON INTELLIGENT NETWORKING AND COLLABORATIVE SYSTEMS IEEE INCOS 2015, 2015, : 417 - 422
  • [8] An enhanced data security and trust management enabled framework for cloud computing systems
    Cindhamani, J.
    Punya, Naguboynia
    Ealaruvi, Rasha
    Babu, L. D. Dhinesh
    2014 INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT, 2014,
  • [9] A Trust Management Framework for Cloud Computing Platforms
    Ruan, Yefeng
    Durresi, Arjan
    2017 IEEE 31ST INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2017, : 1146 - 1153
  • [10] A Framework for Trust Management in Cloud Computing Environment
    Mohammed, Alshaimaa M.
    Omara, Fatma A.
    PROCEEDINGS OF 2020 INTERNATIONAL CONFERENCE ON INNOVATIVE TRENDS IN COMMUNICATION AND COMPUTER ENGINEERING (ITCE), 2020, : 7 - 13