Cloud Security Risk Management is a frequently discussed and analyzed topic that, in recent years, has captured the interest of many scholars and professionals. It reunites under a single category different remarkable elements: The technical and economic relevance of cloud systems, whose diffusion has been one of the most notable phenomena of the last decade; the growing concerns about information security, including privacy; the increasing relevance of risk analysis and management applied to information technology and systems as processes that encompass technical aspects as well as compliance, governance and business. However, Cloud Security Risk Management as a research field and a set of methodologies, analyses and techniques is still far to be a mature discipline. On the contrary, it is ridden with uncertainty derived from the still early stages of security risk analysis, especially applied to cloud systems, and the relatively poor experience in managing cloud risks. For these reasons there is still an on going debate about which risks should be considered cloud-specific and new, which established risk-mitigating solutions and standards could be applied to the cloud environment and so forth. In this chapter, we conduct a survey on the fundamental aspects of Cloud Security Risk Management, starting from the definition of risk and moving to analyze cloud-specific risks. With respect to risk management, we emphasize the contractual nature of cloud computing, thus focusing specifically on Service Level Agreements (SLAs), an issue that has been the subject of several relevant analyses and proposals in recent years.
Cloud security risk management / M. Cremonini - In: Cloud Computing Security : Foundations and Challenges / [a cura di] J.R. Vacca. - Prima edizione. - Stati Uniti : CRC Press, 2016 Sep. - ISBN 9781482260946. - pp. 87-101 [10.1201/9781315372112-9]
Cloud security risk management
M. Cremonini
2016
Abstract
Cloud Security Risk Management is a frequently discussed and analyzed topic that, in recent years, has captured the interest of many scholars and professionals. It reunites under a single category different remarkable elements: The technical and economic relevance of cloud systems, whose diffusion has been one of the most notable phenomena of the last decade; the growing concerns about information security, including privacy; the increasing relevance of risk analysis and management applied to information technology and systems as processes that encompass technical aspects as well as compliance, governance and business. However, Cloud Security Risk Management as a research field and a set of methodologies, analyses and techniques is still far to be a mature discipline. On the contrary, it is ridden with uncertainty derived from the still early stages of security risk analysis, especially applied to cloud systems, and the relatively poor experience in managing cloud risks. For these reasons there is still an on going debate about which risks should be considered cloud-specific and new, which established risk-mitigating solutions and standards could be applied to the cloud environment and so forth. In this chapter, we conduct a survey on the fundamental aspects of Cloud Security Risk Management, starting from the definition of risk and moving to analyze cloud-specific risks. With respect to risk management, we emphasize the contractual nature of cloud computing, thus focusing specifically on Service Level Agreements (SLAs), an issue that has been the subject of several relevant analyses and proposals in recent years.File | Dimensione | Formato | |
---|---|---|---|
Chapter 10.pdf
accesso riservato
Descrizione: Capitolo
Tipologia:
Pre-print (manoscritto inviato all'editore)
Dimensione
251.08 kB
Formato
Adobe PDF
|
251.08 kB | Adobe PDF | Visualizza/Apri Richiedi una copia |
Pubblicazioni consigliate
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.