Empirical evaluation of a cloud computing information security governance framework

被引:36
作者
Rebollo, Oscar [1 ]
Mellado, Daniel [2 ]
Fernandez-Medina, Eduardo [3 ]
Mouratidis, Haralambos [4 ]
机构
[1] Minist Labour & Social Secur, Social Secur IT Management, Madrid 28041, Spain
[2] Spanish Tax Agcy, Large Taxpayers Dept, IT Auditing Unit, Madrid 28045, Spain
[3] Univ Castilla La Mancha, Dept Informat Technol & Syst, GSyA Res Grp, E-13071 Ciudad Real, Spain
[4] Univ Brighton, Sch Comp Engn & Math, Secure & Dependable Software Syst Res Cluster, Brighton BN2 4GJ, E Sussex, England
关键词
Information security governance; Case study; Cloud computing; Security governance framework; Cloud lifecycle;
D O I
10.1016/j.infsof.2014.10.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Context: Cloud computing is a thriving paradigm that supports an efficient way to provide IT services by introducing on-demand services and flexible computing resources. However, significant adoption of cloud services is being hindered by security issues that are inherent to this new paradigm. In previous work, we have proposed ISGcloud, a security governance framework to tackle cloud security matters in a comprehensive manner whilst being aligned with an enterprise's strategy. Objective: Although a significant body of literature has started to build up related to security aspects of cloud computing, the literature fails to report on evidence and real applications of security governance frameworks designed for cloud computing environments. This paper introduces a detailed application of ISGCloud into a real life case study of a Spanish public organisation, which utilises a cloud storage service in a critical security deployment. Method: The empirical evaluation has followed a formal process, which includes the definition of research questions previously to the framework's application. We describe ISGcloud process and attempt to answer these questions gathering results through direct observation and from interviews with related personnel. Results: The novelty of the paper is twofold: on the one hand, it presents one of the first applications, in the literature, of a cloud security governance framework to a real-life case study along with an empirical evaluation of the framework that proves its validity; on the other hand, it demonstrates the usefulness of the framework and its impact to the organisation. Conclusion: As discussed on the paper, the application of ISGCloud has resulted in the organisation in question achieving its security governance objectives, minimising the security risks of its storage service and increasing security awareness among its users. (C) 2014 Elsevier B.V. All rights reserved.
引用
收藏
页码:44 / 57
页数:14
相关论文
共 42 条
[1]  
Abbadi I.M., 2012, INT J INF SECUR, P1
[2]  
[Anonymous], 2012, UNL POT CLOUD COMP E
[3]  
[Anonymous], SOC INF ESP 2011
[4]  
[Anonymous], 2008, 385002008 ISOIEC
[5]  
[Anonymous], 2011, 800145 SP NAT I STAN
[6]  
[Anonymous], 2009, SEC GUID CRIT AR FOC
[7]  
[Anonymous], 2005, ISO/IEC 27001:2005
[8]  
Avanade, 2011, 3 AV
[9]  
Bisong A., 2011, International Journal of Network Security and Its Application (IJNSA), V3, P30, DOI DOI 10.5121/IJNSA.2011.3103
[10]  
Bradshaw D., 2012, QUANTITATIVE ESTIMAT