Risk Assessment for Cloud-Based IT Systems

Author(s):  
Yuyu Chou ◽  
Jan Oetting

The use of Cloud Computing services is an attractive option to improve IT systems to achieve rapidly and elastically provisioned capability, and also to offer economic benefits. However, companies see security as a major concern in migrating to the Cloud. To bring clarity in Cloud security, this paper presents a systematic approach to manage the risks and analyzes the full range of risk in Cloud Computing solutions. Furthermore, as a study case, Google App Engine Platform is assessed based on ISO/IEC 27002 and OWASP Top 10 Risk List in this paper. Knowing the risks of Cloud solutions, companies can execute well-informed decisions on going into the Cloud and build their Cloud solutions in a secure way, relying on a robust e-trust relationship.

Author(s):  
Yuyu Chou ◽  
Jan Oetting

The use of Cloud Computing services is an attractive option to improve IT systems to achieve rapidly and elastically provisioned capability, and also to offer economic benefits. However, companies see security as a major concern in migrating to the Cloud. To bring clarity in Cloud security, this paper presents a systematic approach to manage the risks and analyzes the full range of risk in Cloud Computing solutions. Furthermore, as a study case, Google App Engine Platform is assessed based on ISO/IEC 27002 and OWASP Top 10 Risk List in this paper. Knowing the risks of Cloud solutions, companies can execute well-informed decisions on going into the Cloud and build their Cloud solutions in a secure way, relying on a robust e-trust relationship.


2012 ◽  
pp. 272-285
Author(s):  
Yuyu Chou ◽  
Jan Oetting

The use of Cloud Computing services is an attractive option to improve IT systems to achieve rapidly and elastically provisioned capability, and also to offer economic benefits. However, companies see security as a major concern in migrating to the Cloud. To bring clarity in Cloud security, this paper presents a systematic approach to manage the risks and analyzes the full range of risk in Cloud Computing solutions. Furthermore, as a study case, Google App Engine Platform is assessed based on ISO/IEC 27002 and OWASP Top 10 Risk List in this paper. Knowing the risks of Cloud solutions, companies can execute well-informed decisions on going into the Cloud and build their Cloud solutions in a secure way, relying on a robust e-trust relationship.


2014 ◽  
Vol 3 (2) ◽  
pp. 63-68 ◽  
Author(s):  
Rian Rahmanda Putra ◽  
Wanda Kinasih ◽  
Dana Indra Sensuse

Cloud computing is an innovation that allows the use of IT as a utility based on-demand. Since cloud computing is a new technology, its led to a variety of risks that required an assessment model to assess the organization's readiness to adopt cloud computing. Moreover, by using cloud computing services means organizations or outsourcing involves a third party. Before adopting cloud computing technology, organizations need to consider some of the effects that arise as a result of cloud computing, namely in terms of costs, risks and benefits. To assist organizations to consider the migration of existing IT systems to the cloud, it can be used the cost approach valuation models and risk and benefit. This paper discusses two models of cost-based assessment of risk and benefit modeling and modeling that can be used as a tool to assist organizations in making decisions related to the migration of existing IT systems to the cloud. 


2014 ◽  
Vol 3 ◽  
pp. 94-112
Author(s):  
Angelė Pečeliūnaitė

The article analyses the possibility of how Cloud Computing can be used by libraries to organise activities online. In order to achieve a uniform understanding of the essence of technology SaaS, IaaS, and PaaS, the article discusses the Cloud Computing services, which can be used for the relocation of libraries to the Internet. The improvement of the general activity of libraries in the digital age, the analysis of the international experience in the libraries are examples. Also the article discusses the results of a survey of the Lithuanian scientific community that confirms that 90% of the scientific community is in the interest of getting full access to e-publications online. It is concluded that the decrease in funding for libraries, Cloud Computing can be an economically beneficial step, expanding the library services and improving their quality.


Author(s):  
Shengju Yang

In order to solve the trust problems between users and cloud computing service providers in cloud computing services, the existing trust evaluation technology and access control technology in the cloud computing service are analyzed. And the evaluation index of cloud computing is also analyzed. Users can calculate the relevant indicators of cloud computing service according to their own business goals, and choose the appropriate cloud computing services according to their own trust need. In addition, the reliability assessment method of users based on the service process is proposed. Cloud computing access control system can be used for user credibility evaluation, and it can handle user access requests according to user's creditability. In the study, a cloud computing service trust evaluation tool is designed, and the modeling and architecture designs of trust evaluation are also given. The effectiveness of the method is verified by experiments on cloud computing service evaluation methods.


2021 ◽  
Vol 10 (5/6) ◽  
pp. 533
Author(s):  
Moulhime El Bekkali ◽  
Benaissa Bernoussi ◽  
Mohammed Fattah ◽  
Said Mazer ◽  
Younes Balboul ◽  
...  

Sign in / Sign up

Export Citation Format

Share Document