ISGcloud: a Security Governance Framework for Cloud Computing

被引:8
作者
Rebollo, Oscar [1 ]
Mellado, Daniel [2 ]
Fernandez-Medina, Eduardo [3 ]
机构
[1] Minist Labour & Immigrat, Social Secur IT Management, Madrid, Spain
[2] Spanish Tax Agcy, Large Taxpayers Dept, IT Auditing Unit, Madrid, Spain
[3] Univ Castilla La Mancha, Dept Informat Technol & Syst, GSyA Res Grp, E-13071 Ciudad Real, Spain
关键词
information security governance; secure cloud governance; cloud computing; security governance framework; cloud lifecycle; INTRUSION DETECTION; SYSTEM;
D O I
10.1093/comjnl/bxu141
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security risks to organizations' information assets are hindering the development of cloud computing services. A comprehensive security governance process is needed to foster the massive adoption of cloud services and to facilitate the deployment of a security culture within any company. In this paper, we present a framework focused on the security governance of the cloud computing environment (ISGcloud), which has been built upon standards. Its principal components are based on the ISO/IEC 38500 governance standard and on the ISO/IEC 27036 outsourcing security draft. We propose a systematic collection of activities and their related tasks which detail how security governance can be deployed during the entire cloud service lifecycle. Furthermore, the whole framework is formally modelled following the SPEM 2.0 specification that provides a standardized interface with which to automate and integrate our proposed process. The theoretical definition of our proposal is also accompanied by a practical example of its application, which provides specific details of ISGcloud framework's implementation.
引用
收藏
页码:2233 / 2254
页数:22
相关论文
共 50 条
[31]   Designing an efficient security framework for detecting intrusions in virtual network of cloud computing [J].
Patil, Rajendra ;
Dudeja, Harsha ;
Modi, Chirag .
COMPUTERS & SECURITY, 2019, 85 :402-422
[32]   An enhanced data security and trust management enabled framework for cloud computing systems [J].
Cindhamani, J. ;
Punya, Naguboynia ;
Ealaruvi, Rasha ;
Babu, L. D. Dhinesh .
2014 INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT, 2014,
[33]   Securing Cloud Computing Through IT Governance [J].
Faizi, Salman M. ;
Rahman, Shawon .
INFORMATION TECHNOLOGY IN INDUSTRY, 2019, 7 (01) :1-14
[34]   Agent Based Information Security Framework for Hybrid Cloud Computing [J].
Tariq, Muhammad Imran .
KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2019, 13 (01) :406-434
[35]   Security analysis and improvement of user authentication framework for cloud computing [J].
Chen, Nan ;
Jiang, Rui .
Journal of Networks, 2014, 9 (01) :198-203
[36]   Security and Privacy Issues in Cloud Computing [J].
Shaikh, Asma A. ;
Iyer, Kamatchi .
INTERNATIONAL CONFERENCE ON INTELLIGENT DATA COMMUNICATION TECHNOLOGIES AND INTERNET OF THINGS, ICICI 2018, 2019, 26 :1299-1306
[37]   On Cloud Computing Security [J].
Bai, Yun ;
Policarpio, Sean .
RECENT TRENDS IN WIRELESS AND MOBILE NETWORKS, 2011, 162 :388-396
[38]   Cloud Computing Security [J].
Carlin, Sean ;
Curran, Kevin .
INTERNATIONAL JOURNAL OF AMBIENT COMPUTING AND INTELLIGENCE, 2011, 3 (01) :14-19
[39]   Security in Cloud Computing [J].
Rishitha ;
Reshmi, T. R. .
PROCEEDINGS OF THE 2018 INTERNATIONAL CONFERENCE ON RECENT TRENDS IN ADVANCED COMPUTING (ICRTAC-CPS 2018), 2018, :14-20
[40]   Toward a unified framework for Cloud Computing governance: An approach for evaluating and integrating IT management and governance models [J].
Bounagui, Yassine ;
Mezrioui, Abdellatif ;
Hafiddi, Hatim .
COMPUTER STANDARDS & INTERFACES, 2019, 62 :98-118