Security risk assessment framework for cloud computing environments

Cloud computing has become today's most common technology buzzword. Despite the promises of cloud computing to decrease computing implementation costs and deliver computing as a service, which allows clients to pay only for what they need and use, cloud computing also raises many security conce...

Full description

Saved in:
Bibliographic Details
Main Authors: Shanmugam, Bharanidharan, Narayana Samy, Ganthan, Idris, Norbik Bashah, Saif Qaid, Samer Hasan, Ahmad, Azuan
Format: Article
Published: John Wiley and Sons Inc. 2014
Subjects:
Online Access:http://eprints.utm.my/id/eprint/62535/
http://dx.doi.org/10.1002/sec.923
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Universiti Teknologi Malaysia
id my.utm.62535
record_format eprints
spelling my.utm.625352017-06-18T06:04:21Z http://eprints.utm.my/id/eprint/62535/ Security risk assessment framework for cloud computing environments Shanmugam, Bharanidharan Narayana Samy, Ganthan Idris, Norbik Bashah Saif Qaid, Samer Hasan Ahmad, Azuan QA75 Electronic computers. Computer science Cloud computing has become today's most common technology buzzword. Despite the promises of cloud computing to decrease computing implementation costs and deliver computing as a service, which allows clients to pay only for what they need and use, cloud computing also raises many security concerns. Most popular risk assessment standards, such as ISO27005, NIST SP800-30, and AS/NZS 4360, assume that an organization's assets are fully managed by the organization itself and that all security management processes are imposed by the organization. These assumptions, however, do not apply to cloud computing environments. Hence, this paper proposes a security risk assessment framework that can enable cloud service providers to assess security risks in the cloud computing environment and allow cloud clients to contribute in risk assessment. The proposed framework provides a more realistic and accurate risk assessment outcome by considering the cloud clients' evaluation of security risk factors and avoiding the complexity that can result from the involvement of clients in whole risk assessment process. John Wiley and Sons Inc. 2014 Article PeerReviewed Shanmugam, Bharanidharan and Narayana Samy, Ganthan and Idris, Norbik Bashah and Saif Qaid, Samer Hasan and Ahmad, Azuan (2014) Security risk assessment framework for cloud computing environments. Security and Communication Networks, 7 (11). p. 2124. ISSN 1939-0114 http://dx.doi.org/10.1002/sec.923 DOI:10.1002/sec.923
institution Universiti Teknologi Malaysia
building UTM Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Teknologi Malaysia
content_source UTM Institutional Repository
url_provider http://eprints.utm.my/
topic QA75 Electronic computers. Computer science
spellingShingle QA75 Electronic computers. Computer science
Shanmugam, Bharanidharan
Narayana Samy, Ganthan
Idris, Norbik Bashah
Saif Qaid, Samer Hasan
Ahmad, Azuan
Security risk assessment framework for cloud computing environments
description Cloud computing has become today's most common technology buzzword. Despite the promises of cloud computing to decrease computing implementation costs and deliver computing as a service, which allows clients to pay only for what they need and use, cloud computing also raises many security concerns. Most popular risk assessment standards, such as ISO27005, NIST SP800-30, and AS/NZS 4360, assume that an organization's assets are fully managed by the organization itself and that all security management processes are imposed by the organization. These assumptions, however, do not apply to cloud computing environments. Hence, this paper proposes a security risk assessment framework that can enable cloud service providers to assess security risks in the cloud computing environment and allow cloud clients to contribute in risk assessment. The proposed framework provides a more realistic and accurate risk assessment outcome by considering the cloud clients' evaluation of security risk factors and avoiding the complexity that can result from the involvement of clients in whole risk assessment process.
format Article
author Shanmugam, Bharanidharan
Narayana Samy, Ganthan
Idris, Norbik Bashah
Saif Qaid, Samer Hasan
Ahmad, Azuan
author_facet Shanmugam, Bharanidharan
Narayana Samy, Ganthan
Idris, Norbik Bashah
Saif Qaid, Samer Hasan
Ahmad, Azuan
author_sort Shanmugam, Bharanidharan
title Security risk assessment framework for cloud computing environments
title_short Security risk assessment framework for cloud computing environments
title_full Security risk assessment framework for cloud computing environments
title_fullStr Security risk assessment framework for cloud computing environments
title_full_unstemmed Security risk assessment framework for cloud computing environments
title_sort security risk assessment framework for cloud computing environments
publisher John Wiley and Sons Inc.
publishDate 2014
url http://eprints.utm.my/id/eprint/62535/
http://dx.doi.org/10.1002/sec.923
_version_ 1643655448197332992