论文标题
基于组织的业务目标的云安全风险管理的框架
A Framework for Cloud Security Risk Management Based on the Business Objectives of Organizations
论文作者
论文摘要
由于将敏感数据外包给第三方,安全被认为是云计算(CC)排名最高的风险之一。此外,云模型的复杂性导致了许多必须始终管理的异质安全控制。因此,无论云模型的确保程度如何,组织都会继续遭受对CC缺乏信任的困扰,并且对其安全风险后果不确定。传统的风险管理框架不考虑CC安全风险对组织业务目标的影响。在本文中,我们提出了一个新颖的云安全风险管理框架(CSRMF),该框架可帮助组织在其云平台中采用CC识别,分析,评估和减轻安全风险。与传统的风险管理框架不同,CSRMF由组织的业务目标驱动。它允许任何采用CC的组织都知道云安全风险,并根据高级业务目标使其低级管理决策保持一致。从本质上讲,它旨在解决特定组织在给定组织中的业务目标的影响。因此,组织能够就采用CC技术的采用并获得对云技术的足够信心进行成本值分析。另一方面,云服务提供商(CSP)能够通过管理与云相关的风险来提高生产率和盈利能力。提出的框架已通过用例场景进行了验证和评估。
Security is considered one of the top ranked risks of Cloud Computing (CC) due to the outsourcing of sensitive data onto a third party. In addition, the complexity of the cloud model results in a large number of heterogeneous security controls that must be consistently managed. Hence, no matter how strongly the cloud model is secured, organizations continue suffering from lack of trust on CC and remain uncertain about its security risk consequences. Traditional risk management frameworks do not consider the impact of CC security risks on the business objectives of the organizations. In this paper, we propose a novel Cloud Security Risk Management Framework (CSRMF) that helps organizations adopting CC identify, analyze, evaluate, and mitigate security risks in their Cloud platforms. Unlike traditional risk management frameworks, CSRMF is driven by the business objectives of the organizations. It allows any organization adopting CC to be aware of cloud security risks and align their low-level management decisions according to high-level business objectives. In essence, it is designed to address impacts of cloud-specific security risks into business objectives in a given organization. Consequently, organizations are able to conduct a cost-value analysis regarding the adoption of CC technology and gain an adequate level of confidence in Cloud technology. On the other hand, Cloud Service Providers (CSP) are able to improve productivity and profitability by managing cloud-related risks. The proposed framework has been validated and evaluated through a use-case scenario.