A Framework for Cloud Security Risk Management Based on the Business Objectives of Organizations

01/13/2020
by   Ahmed E. Youssef, et al.
0

Security is considered one of the top ranked risks of Cloud Computing (CC) due to the outsourcing of sensitive data onto a third party. In addition, the complexity of the cloud model results in a large number of heterogeneous security controls that must be consistently managed. Hence, no matter how strongly the cloud model is secured, organizations continue suffering from lack of trust on CC and remain uncertain about its security risk consequences. Traditional risk management frameworks do not consider the impact of CC security risks on the business objectives of the organizations. In this paper, we propose a novel Cloud Security Risk Management Framework (CSRMF) that helps organizations adopting CC identify, analyze, evaluate, and mitigate security risks in their Cloud platforms. Unlike traditional risk management frameworks, CSRMF is driven by the business objectives of the organizations. It allows any organization adopting CC to be aware of cloud security risks and align their low-level management decisions according to high-level business objectives. In essence, it is designed to address impacts of cloud-specific security risks into business objectives in a given organization. Consequently, organizations are able to conduct a cost-value analysis regarding the adoption of CC technology and gain an adequate level of confidence in Cloud technology. On the other hand, Cloud Service Providers (CSP) are able to improve productivity and profitability by managing cloud-related risks. The proposed framework has been validated and evaluated through a use-case scenario.

READ FULL TEXT
research
08/12/2018

Cloud Security Architecture and Implementation - A practical approach

While cloud computing provides lower Infrastructure cost, higher agility...
research
02/22/2022

A Hybrid Cloud ERP Framework For Processing Purchasing Data

Cloud-based enterprise resource planning (cloud ERP) systems have existe...
research
12/09/2020

Risk Management Framework for Machine Learning Security

Adversarial attacks for machine learning models have become a highly stu...
research
04/24/2019

Risky Business: Assessing Security with External Measurements

Security practices in large organizations are notoriously difficult to a...
research
09/19/2021

A Framework for Institutional Risk Identification using Knowledge Graphs and Automated News Profiling

Organizations around the world face an array of risks impacting their op...
research
02/21/2022

Manage risks in complex engagements by leveraging organization-wide knowledge using Machine Learning

One of the ways for organizations to continuously get better at executin...
research
12/21/2021

Exploring Spreadsheet Use and Practices in a Technologically Constrained Setting

This paper explores the impacts of spreadsheets on business operations i...

Please sign up or login with your details

Forgot password? Click here to reset