2019
DOI: 10.1007/978-3-030-11395-7_16
|View full text |Cite
|
Sign up to set email alerts
|

CSCCRA: A Novel Quantitative Risk Assessment Model for Cloud Service Providers

Abstract: Assessing and managing cloud risks can be a challenge, even for the cloud service providers (CSPs), due to the increased numbers of parties, devices and applications involved in cloud service delivery. The limited visibility of security controls down the supply chain, further exacerbates this risk assessment challenge. As such, we propose the Cloud Supply Chain Cyber Risk Assessment (CSCCRA) model, a quantitative risk assessment model which is supported by cloud supplier security assessment (CSSA) and cloud su… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
2

Citation Types

0
11
0

Year Published

2019
2019
2022
2022

Publication Types

Select...
4
1

Relationship

2
3

Authors

Journals

citations
Cited by 5 publications
(11 citation statements)
references
References 10 publications
0
11
0
Order By: Relevance
“…We developed the CSCCRA model [11] to address the gap in cloud supply chain transparency, particularly how the lack of visibility of supplier's security controls has contributed to the inadequate level of cloud risk assessment. It aims to present the CSP's cloud risk in a format that is consistent, repeatable, traceable and understandable, allowing for the proactive mitigation of cloud risks.…”
Section: A the Csccra Modelmentioning
confidence: 99%
See 2 more Smart Citations
“…We developed the CSCCRA model [11] to address the gap in cloud supply chain transparency, particularly how the lack of visibility of supplier's security controls has contributed to the inadequate level of cloud risk assessment. It aims to present the CSP's cloud risk in a format that is consistent, repeatable, traceable and understandable, allowing for the proactive mitigation of cloud risks.…”
Section: A the Csccra Modelmentioning
confidence: 99%
“…This approach requires us to analyse the interdependencies of a cloud service while making use of modelling and simulation techniques to draw the result of the assessment [24]. The CSCCRA model is made up of three components and builds on existing risk standards and guidance documents such as ISO 27005:2011, ISO 31000:2009, NIST 800-30v1 and FAIR risk assessment [11]. The components are:…”
Section: A the Csccra Modelmentioning
confidence: 99%
See 1 more Smart Citation
“…Our decision to address security risk assessment from a cloud provider perspective was influenced by the scarcity of studies in this area, and on the practical need for cloud providers to assess security risks to assure secure cloud delivery to customers. As such, we also describe our novel quantitative model for cloud providers: Cyber Supply Chain Cloud Risk Assessment (CSCCRA) [17]. Here we highlight its strengths, which include its systematic analysis of cloud risks, the visual representation of the cloud supply chain, and the assessment of the cybersecurity posture of cloud suppliers.…”
Section: Introductionmentioning
confidence: 99%
“…The contributions of this paper are the identification of gaps in cloud risk assessment, an analysis of current models, and a more detailed presentation of the proposed CSCCRA model we introduced in [17] which is meant to address some of the identified gaps. Furthermore, we present directions for future research by outlining areas where the theory and practice of cloud provisioning risk assessment can be improved including the application of dynamic modelling based on defined boundaries and the development of automated models for the proactive mitigation of cloud risks.…”
Section: Introductionmentioning
confidence: 99%