2014 IEEE 6th International Conference on Cloud Computing Technology and Science 2014
DOI: 10.1109/cloudcom.2014.165
|View full text |Cite
|
Sign up to set email alerts
|

Reflecting on Whether Checklists Can Tick the Box for Cloud Security

Abstract: All Cloud computing standards are dependent upon checklist methodology to implement and then audit the alignment of a company or an operation with the standards that have been set. An investigation of the use of checklists in other academic areas has shown there to be significant weaknesses in the checklist solution to both implementation and audit; these weaknesses will only be exacerbated by the fast-changing and developing nature of clouds. We examine the problems that are inherent with using checklists and… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
11
0

Year Published

2015
2015
2023
2023

Publication Types

Select...
3
3
3

Relationship

3
6

Authors

Journals

citations
Cited by 15 publications
(11 citation statements)
references
References 48 publications
0
11
0
Order By: Relevance
“…We have argued that companies need to take account of these gaps in the standards when addressing issues of compliance. In (Duncan and Whittington, 2014), we have addressed the question of whether compliance with standards, assurance and audit can provide security, and in (Duncan and Whittington, 2015d), we have addressed one of the fundamental weaknesses of the standards compliance process.…”
Section: The Challengesmentioning
confidence: 99%
“…We have argued that companies need to take account of these gaps in the standards when addressing issues of compliance. In (Duncan and Whittington, 2014), we have addressed the question of whether compliance with standards, assurance and audit can provide security, and in (Duncan and Whittington, 2015d), we have addressed one of the fundamental weaknesses of the standards compliance process.…”
Section: The Challengesmentioning
confidence: 99%
“…However, cloud changes the rules of the game considerably; because there is often a poor understanding of the technical complexities of cloud, and often a complete lack of understanding that the cloud runs on someone else's hardware and often software too, resulting in a huge issue from lack of proper control. With cloud, the lack of proper and complete security standards [6] also presents a major issue, as does the method of implementing compliance with these standards [52].…”
Section: Current Solutionsmentioning
confidence: 99%
“…Concern, too, has been expressed [Walden, 2011], over issues involved in trying to obtain access to records held in foreign jurisdictions. Concern has also been expressed about the difficulties of cloud audit [Duncan and Whittington, 2015c] [Duncan and Whittington, 2016a], and in particular the mechanics of maintaining a proper audit trail [Duncan and Whittington, 2016b].…”
Section: Introductionmentioning
confidence: 99%