2013
DOI: 10.1007/978-3-642-38323-6_7
|View full text |Cite
|
Sign up to set email alerts
|

In Cloud We Trust: Risk-Assessment-as-a-Service

Abstract: Abstract. Cloud computing is an emerging paradigm that allows adoption of on-demand services in a cost-effective way. Migrating services to the Cloud also means been exposed to new threats and vulnerabilities, thus, resulting in a modified assessment of risk. Assessing risk in the Cloud remains an open research issue, as it requires a given level of trust of the Cloud service provider for providing assessment data and implementing controls. This paper surveys existing knowledge, regarding risk assessment for t… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
10
0

Year Published

2014
2014
2022
2022

Publication Types

Select...
5
3
1

Relationship

0
9

Authors

Journals

citations
Cited by 20 publications
(10 citation statements)
references
References 29 publications
0
10
0
Order By: Relevance
“…It hopes to achieve this by showing how a holistic quantitative risk assessment and decision analysis model provides a unique capability for capturing the dynamic behaviour of risks within a cloud supply chain and measuring the overall risk behaviour. While numerous scholars have openly questioned the subjectivity of expert's estimate in quantitative analysis [12,18], our implementation of CSCCRA aims to prove that despite the lack of historical data, cloud risk assessments can achieve increased objectivity through the use of controlled experimentation, clearly defined model, peer reviews and calibration of the expert judges [19,55].…”
Section: The Csccra Modelmentioning
confidence: 99%
See 1 more Smart Citation
“…It hopes to achieve this by showing how a holistic quantitative risk assessment and decision analysis model provides a unique capability for capturing the dynamic behaviour of risks within a cloud supply chain and measuring the overall risk behaviour. While numerous scholars have openly questioned the subjectivity of expert's estimate in quantitative analysis [12,18], our implementation of CSCCRA aims to prove that despite the lack of historical data, cloud risk assessments can achieve increased objectivity through the use of controlled experimentation, clearly defined model, peer reviews and calibration of the expert judges [19,55].…”
Section: The Csccra Modelmentioning
confidence: 99%
“…While some of these studies have concentrated on cloud adoption risk assessment, others have followed the traditional route to security risk assessment, adapting the traditional risk frameworks, for example, ISO/IEC 27005, ISO/IEC 31000 and NIST 800-30v1. Being predominantly qualitative or at best semi-quantitative, the prevalent use of these traditional methodologies in assessing cloud risks presents a wide range of limitations including the subjectivity of risk evaluation and the inability to cope with the dynamic cloud infrastructure [12,13].…”
Section: Introductionmentioning
confidence: 99%
“…Industrial Car Company uses this interface to manage and interact with cloud services. Table VIII illustrates unique vulnerabilities in the cloud respect to the cloud assets [9]. Each vulnerability is mapped to an asset.…”
Section: B Resultsmentioning
confidence: 99%
“…ISO 27005, ISO 31000 and NIST 800-30v1. Being predominantly qualitative or at best semi-quantitative, these exhibit serious limitations, including the subjectivity of risk evaluation and the inability to cope with the dynamic cloud infrastructure [18], [19]. We have argued elsewhere that the lack of CSP transparency is also perceived to be a contributing factor to the use of qualitative methods in assessing cloud risks [20].…”
Section: Background and Related Workmentioning
confidence: 99%