ERMOCTAVE: A Risk Management Framework for IT Systems Which Adopt Cloud Computing

被引:6
|
作者
Mackita, Masky [1 ]
Shin, Soo-Young [2 ]
Choe, Tae-Young [3 ]
机构
[1] ING Bank, B-1040 Brussels, Belgium
[2] Kumoh Natl Inst Technol, Dept IT Convergence Engn, Gumi 39177, South Korea
[3] Kumoh Natl Inst Technol, Dept Comp Engn, Gumi 39177, South Korea
来源
FUTURE INTERNET | 2019年 / 11卷 / 09期
关键词
risk management; ERM; OCTAVE; cloud computing; Microsoft Azure;
D O I
10.3390/fi11090195
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Many companies are adapting cloud computing technology because moving to the cloud has an array of benefits. During decision-making, having processed for adopting cloud computing, the importance of risk management is progressively recognized. However, traditional risk management methods cannot be applied directly to cloud computing when data are transmitted and processed by external providers. When they are directly applied, risk management processes can fail by ignoring the distributed nature of cloud computing and leaving numerous risks unidentified. In order to fix this backdrop, this paper introduces a new risk management method, Enterprise Risk Management for Operationally Critical Threat, Asset, and Vulnerability Evaluation (ERMOCTAVE), which combines Enterprise Risk Management and Operationally Critical Threat, Asset, and Vulnerability Evaluation for mitigating risks that can arise with cloud computing. ERMOCTAVE is composed of two risk management methods by combining each component with another processes for comprehensive perception of risks. In order to explain ERMOCTAVE in detail, a case study scenario is presented where an Internet seller migrates some modules to Microsoft Azure cloud. The functionality comparison with ENISA and Microsoft cloud risk assessment shows that ERMOCTAVE has additional features, such as key objectives and strategies, critical assets, and risk measurement criteria.
引用
收藏
页数:21
相关论文
共 50 条
  • [21] CLOUD COMPUTING FOR AIR TRAFFIC MANAGEMENT - FRAMEWORK ANALYSIS
    Ren, Tiling
    Beckmann, Benjamin
    Citriniti, Thomas
    Castillo-Effen, Mauricio
    2013 IEEE/AIAA 32ND DIGITAL AVIONICS SYSTEMS CONFERENCE (DASC), 2013,
  • [22] A novel Risk Identification Framework for Cloud Computing Security
    Masky, Mackita
    Young, Shin Soo
    Choe, Tae-Young
    2015 2ND INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND SECURITY (ICISS), 2015, : 61 - 64
  • [23] Cloud Computing Risk: A Decision-making Framework
    Macharia, Mary
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2023, 63 (02) : 421 - 435
  • [24] A Study of Risk Evaluation Framework for Cloud Computing System
    Lin, Fan
    Xiahou, Jianbin
    Zeng, Wenhua
    JOURNAL OF INTERNET TECHNOLOGY, 2015, 16 (07): : 1351 - 1366
  • [25] Enhanced Risk Minimization Framework for Cloud Computing Environment
    Razaque, Abdul
    Li, Yuxin
    Liu, Qianqian
    Khan, Meer Jaro
    Doulat, Ahmad
    Almiani, Muder
    Alflahat, Ahmad
    2018 IEEE/ACS 15TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2018,
  • [26] Security risk assessment framework for cloud computing environments
    Albakri, Sameer Hasan
    Shanmugam, Bharanidharan
    Samy, Ganthan Narayana
    Idris, Norbik Bashah
    Ahmed, Azuan
    SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (11) : 2114 - 2124
  • [27] The Risk Management Strategy of Applying Cloud Computing
    Fan, Chiang Ku
    Chen, Tien-Chun
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2012, 3 (09) : 18 - 27
  • [28] Risk management of land use on cloud computing
    Liang, D.-H. (survey.tw@msa.hinet.net), 1600, Advanced Institute of Convergence Information Technology (07):
  • [29] A Cloud Computing Framework for Smarter District Heating Systems
    Dalipi, Fisnik
    Yayilgan, Sule Yildirim
    Gebremedhin, Alemayehu
    IEEE 12TH INT CONF UBIQUITOUS INTELLIGENCE & COMP/IEEE 12TH INT CONF ADV & TRUSTED COMP/IEEE 15TH INT CONF SCALABLE COMP & COMMUN/IEEE INT CONF CLOUD & BIG DATA COMP/IEEE INT CONF INTERNET PEOPLE AND ASSOCIATED SYMPOSIA/WORKSHOPS, 2015, : 1413 - 1416
  • [30] An Extensible Performance Evaluation Framework for Cloud Computing Systems
    Xiao, Peng
    Lin, Hui
    INTERNATIONAL JOURNAL OF FUTURE GENERATION COMMUNICATION AND NETWORKING, 2013, 6 (04): : 1 - 11