ISGcloud: a Security Governance Framework for Cloud Computing

被引:7
|
作者
Rebollo, Oscar [1 ]
Mellado, Daniel [2 ]
Fernandez-Medina, Eduardo [3 ]
机构
[1] Minist Labour & Immigrat, Social Secur IT Management, Madrid, Spain
[2] Spanish Tax Agcy, Large Taxpayers Dept, IT Auditing Unit, Madrid, Spain
[3] Univ Castilla La Mancha, Dept Informat Technol & Syst, GSyA Res Grp, E-13071 Ciudad Real, Spain
来源
COMPUTER JOURNAL | 2015年 / 58卷 / 10期
关键词
information security governance; secure cloud governance; cloud computing; security governance framework; cloud lifecycle; INTRUSION DETECTION; SYSTEM;
D O I
10.1093/comjnl/bxu141
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security risks to organizations' information assets are hindering the development of cloud computing services. A comprehensive security governance process is needed to foster the massive adoption of cloud services and to facilitate the deployment of a security culture within any company. In this paper, we present a framework focused on the security governance of the cloud computing environment (ISGcloud), which has been built upon standards. Its principal components are based on the ISO/IEC 38500 governance standard and on the ISO/IEC 27036 outsourcing security draft. We propose a systematic collection of activities and their related tasks which detail how security governance can be deployed during the entire cloud service lifecycle. Furthermore, the whole framework is formally modelled following the SPEM 2.0 specification that provides a standardized interface with which to automate and integrate our proposed process. The theoretical definition of our proposal is also accompanied by a practical example of its application, which provides specific details of ISGcloud framework's implementation.
引用
收藏
页码:2233 / 2254
页数:22
相关论文
共 50 条
  • [1] Introducing a Security Governance Framework for Cloud Computing
    Rebollo, Oscar
    Mellado, Daniel
    Fernandez-Medina, Eduardo
    WOSIS: PROCEEDINGS OF THE 10TH INTERNATIONAL WORKSHOP ON SECURITY IN INFORMATION SYSTEMS, 2013, : 24 - 33
  • [2] Empirical evaluation of a cloud computing information security governance framework
    Rebollo, Oscar
    Mellado, Daniel
    Fernandez-Medina, Eduardo
    Mouratidis, Haralambos
    INFORMATION AND SOFTWARE TECHNOLOGY, 2015, 58 : 44 - 57
  • [3] Mitigation for cloud computing security risks and governance
    Jabez, J.
    Narmadha, R.
    Porkodi, S.
    Devi, L.
    International Journal of Cloud Computing, 2022, 11 (5-6) : 560 - 567
  • [4] A Security Protection Framework for Cloud Computing
    Zhu, Wenzheng
    Lee, Changhoon
    JOURNAL OF INFORMATION PROCESSING SYSTEMS, 2016, 12 (03): : 538 - 547
  • [5] A Framework for Security Transparency in Cloud Computing
    Ismail, Umar Mukhtar
    Islam, Shareeful
    Ouedraogo, Moussa
    Weippl, Edgar
    FUTURE INTERNET, 2016, 8 (01)
  • [6] A Framework for Storage Security in Cloud Computing
    Chen, Guoyou
    Miao, Jiajia
    Xie, Feng
    Mao, Handong
    ADVANCES IN MECHATRONICS AND CONTROL ENGINEERING, PTS 1-3, 2013, 278-280 : 1767 - +
  • [7] A Framework for Improving Security in Cloud Computing
    Surbiryala, Jayachander
    Li, Chunlei
    Rong, Chunming
    2017 2ND IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND BIG DATA ANALYSIS (ICCCBDA 2017), 2017, : 260 - 264
  • [8] A Cloud Computing Security Framework Based on Cloud Security Trusted Authority
    Dawoud, Mohammed M.
    Ebrahim, Gamal A.
    Youssef, Sameh A.
    INTERNATIONAL CONFERENCE ON INFORMATICS AND SYSTEMS (INFOS 2016), 2016, : 133 - 138
  • [9] COBIT Evaluation as a Framework for Cloud Computing Governance
    Bounagui, Yassine
    Hafiddi, Hatim
    Mezrioui, Abdellatif
    INTERNATIONAL JOURNAL OF CLOUD APPLICATIONS AND COMPUTING, 2016, 6 (04) : 65 - 82
  • [10] New Governance Framework to Secure Cloud Computing
    Saidah, Ahmed Shaker
    Abdelbaki, Nashwa
    CLOUD COMPUTING AND SERVICES SCIENCES, CLOSER 2014, 2015, 512 : 187 - 199