Cyber Security in Cloud: Risk Assessment Models

06/19/2021
by   Carlos Bendicho, et al.
0

The present paper shows a proposal of the characteristics Cloud Risk Assessment Models should have and presents the review of the literature considering those characteristics in order to identify current gaps. This work shows a ranking of Cloud RA models and their degree of compliance with the theoretical reference Cloud Risk Assessment model. The review of literature shows that RA approaches leveraging CSA (Cloud Security Alliance) STAR Registry that have into account organizations security requirements present higher degree of compliance, but they still lack risk economic quantification. The myriad of conceptual models, methodologies and frameworks although based on current NIST SP 800:30, ISO 27001, ISO 27005, ISO 30001, ENISA standards could be enhanced by the use of techno-economic models like UTEM, created by the author, in order to conceive more simplified models for effective Risk Assessment and Mitigation closer to the theoretical reference model for Cloud Risk Assessment, available for all cloud models (IaaS, PaaS, SaaS) and easy to use for all stakeholders.

READ FULL TEXT
research
04/09/2021

Techno-Economic Assessment Models for 5G

This paper proposes the characteristics a techno-economic model for 5G s...
research
03/11/2019

Standardisation of cyber risk impact assessment for the Internet of Things (IoT)

In this research article, we explore the use of a design process for ada...
research
07/05/2023

Security Risk Analysis Methodologies for Automotive Systems

Nowadays, systematic security risk analysis plays a vital role in the au...
research
06/18/2021

A Survey on Human and Personality Vulnerability Assessment in Cyber-security: Challenges, Approaches, and Open Issues

These days, cyber-criminals target humans rather than machines since the...
research
07/07/2022

A Methodology to Support Automatic Cyber Risk Assessment Review

Cyber risk assessment is a fundamental activity for enhancing the protec...
research
07/20/2023

ESASCF: Expertise Extraction, Generalization and Reply Framework for an Optimized Automation of Network Security Compliance

The Cyber threats exposure has created worldwide pressure on organizatio...

Please sign up or login with your details

Forgot password? Click here to reset