Software-as-a-Service Security Challenges and Best Practices: A Multivocal Literature Review

被引:4
作者
Humayun, Mamoona [1 ]
Niazi, Mahmood [2 ,3 ]
Almufareh, Maram Fahhad [1 ]
Jhanjhi, N. Z. [4 ]
Mahmood, Sajjad [2 ,3 ]
Alshayeb, Mohammad [2 ,3 ]
机构
[1] Jouf Univ, Dept Informat Syst, Coll Comp & Informat Sci, Sakakah 72311, Saudi Arabia
[2] King Fahd Univ Petr & Minerals, Dept Informat & Comp Sci, Dhahran 31261, Saudi Arabia
[3] King Fahd Univ Petr & Minerals, Interdisciplinary Res Ctr Intelligent Secure Syst, Dhahran 31261, Saudi Arabia
[4] Taylors Univ, Sch Comp Sci & Engn SCE, Subang Jaya 47500, Malaysia
来源
APPLIED SCIENCES-BASEL | 2022年 / 12卷 / 08期
关键词
cloud computing; software-as-a-service (SaaS); multi-vocal literature review (MVLR); security;
D O I
10.3390/app12083953
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Cloud computing (CC) is the delivery of computing services on demand and is charged using a "pay per you use" policy. Of the multiple services offered by CC, SaaS is the most popular and widely adapted service platform and is used by billions of organizations due to its wide range of benefits. However, security is a key challenge and obstacle in cloud adoption and therefore needs to be addressed. Researchers and practitioners (R&P) have discussed various security challenges for SaaS along with possible solutions. However, no research study exists that systematically accumulates and analyzes the security challenges and solutions. To fill this gap and provide the state-of-the-art (SOTA) picture of SaaS security, this study provides a comprehensive multivocal literature review (MVLR), including SaaS security issues/challenges and best practices for mitigating these security issues. We identified SaaS security issues/challenges and best practices from the formal literature (FL) as well as the grey literature (GL) to evaluate whether R&P is on the same page or if controversies exist. A total of 93 primary studies were identified, of which 58 are from the FL and 35 belong to the GL. The studies are from the last ten years, from 2010 to 2021. The selected studies were evaluated and analyzed to identify the key security issues faced by SaaS computing and to be aware of the best practices suggested by R&P to improve SaaS security. This MVLR will assist SaaS users to identify the many areas in which additional research and development in SaaS security is required. According to our study findings, data breaches/leakage, identity and access management, governance and regulatory compliance/SLA compliance, and malicious insiders are the key security challenges with the maximum frequency of occurrence in both FL and GL. On the other hand, R&P agree that up-to-date security controls/standards, the use of strong encryption techniques, regulatory compliance/SLA compliance, and multifactor authentication are the most important solutions.
引用
收藏
页数:29
相关论文
共 37 条
  • [2] [Anonymous], 2020, TOP 5 ADV SOFTW SERV
  • [3] [Anonymous], 2018, THE EC TIME
  • [4] A Novel Approach to Address Interoperability Concern in Cloud Computing
    Arunkumar, G.
    Venkataraman, Neelanarayanan
    [J]. BIG DATA, CLOUD AND COMPUTING CHALLENGES, 2015, 50 : 554 - 559
  • [5] Cloud computing services adoption among higher education faculties: development of a standardized questionnaire
    Asadi, Zoleixa
    Abdekhoda, Mohammadhiwa
    Nadrian, Haidar
    [J]. EDUCATION AND INFORMATION TECHNOLOGIES, 2020, 25 (01) : 175 - 191
  • [6] Bhatta N., 2021, ELECT J BUS ETHICS O, V26, P30
  • [7] Study on the security models and strategies of cloud computing
    Che, Jianhua
    Duan, Yamin
    Zhang, Tao
    Fan, Jie
    [J]. PEEA 2011, 2011, 23
  • [8] Analysis of performance measures in cloud-based ubiquitous SaaS CRM project systems
    Chen, You-Shyang
    Wu, Chienwen
    Chu, Heng-Hsing
    Lin, Chien-Ku
    Chuang, Huan-Ming
    [J]. JOURNAL OF SUPERCOMPUTING, 2018, 74 (03) : 1132 - 1156
  • [9] da Silva C.M.R., 2013, ARXIV13036782
  • [10] Felter B, DIFFERENT TYPES CLOU