Cloud Security Risk Management is a frequently discussed and analyzed topic that, in recent years, has captured the interest of many scholars and professionals. It reunites under a single category different remarkable elements: The technical and economic relevance of cloud systems, whose diffusion has been one of the most notable phenomena of the last decade; the growing concerns about information security, including privacy; the increasing relevance of risk analysis and management applied to information technology and systems as processes that encompass technical aspects as well as compliance, governance and business. However, Cloud Security Risk Management as a research field and a set of methodologies, analyses and techniques is still far to be a mature discipline. On the contrary, it is ridden with uncertainty derived from the still early stages of security risk analysis, especially applied to cloud systems, and the relatively poor experience in managing cloud risks. For these reasons there is still an on going debate about which risks should be considered cloud-specific and new, which established risk-mitigating solutions and standards could be applied to the cloud environment and so forth. In this chapter, we conduct a survey on the fundamental aspects of Cloud Security Risk Management, starting from the definition of risk and moving to analyze cloud-specific risks. With respect to risk management, we emphasize the contractual nature of cloud computing, thus focusing specifically on Service Level Agreements (SLAs), an issue that has been the subject of several relevant analyses and proposals in recent years.

Cloud security risk management / M. Cremonini - In: Cloud Computing Security : Foundations and Challenges / [a cura di] J.R. Vacca. - Prima edizione. - Stati Uniti : CRC Press, 2016 Sep. - ISBN 9781482260946. - pp. 87-101 [10.1201/9781315372112-9]

Cloud security risk management

M. Cremonini
2016

Abstract

Cloud Security Risk Management is a frequently discussed and analyzed topic that, in recent years, has captured the interest of many scholars and professionals. It reunites under a single category different remarkable elements: The technical and economic relevance of cloud systems, whose diffusion has been one of the most notable phenomena of the last decade; the growing concerns about information security, including privacy; the increasing relevance of risk analysis and management applied to information technology and systems as processes that encompass technical aspects as well as compliance, governance and business. However, Cloud Security Risk Management as a research field and a set of methodologies, analyses and techniques is still far to be a mature discipline. On the contrary, it is ridden with uncertainty derived from the still early stages of security risk analysis, especially applied to cloud systems, and the relatively poor experience in managing cloud risks. For these reasons there is still an on going debate about which risks should be considered cloud-specific and new, which established risk-mitigating solutions and standards could be applied to the cloud environment and so forth. In this chapter, we conduct a survey on the fundamental aspects of Cloud Security Risk Management, starting from the definition of risk and moving to analyze cloud-specific risks. With respect to risk management, we emphasize the contractual nature of cloud computing, thus focusing specifically on Service Level Agreements (SLAs), an issue that has been the subject of several relevant analyses and proposals in recent years.
Cloud computing; risk managenent; service level agreement
Settore INF/01 - Informatica
Settore ING-INF/05 - Sistemi di Elaborazione delle Informazioni
set-2016
Book Part (author)
File in questo prodotto:
File Dimensione Formato  
Chapter 10.pdf

accesso riservato

Descrizione: Capitolo
Tipologia: Pre-print (manoscritto inviato all'editore)
Dimensione 251.08 kB
Formato Adobe PDF
251.08 kB Adobe PDF   Visualizza/Apri   Richiedi una copia
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/2434/451996
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? 0
social impact