Title of article :
Empirical evaluation of a cloud computing information security governance framework
Author/Authors :
Rebollo، نويسنده , , Oscar and Mellado، نويسنده , , Daniel and Fernلndez-Medina، نويسنده , , Eduardo and Mouratidis، نويسنده , , Haralambos، نويسنده ,
Issue Information :
ماهنامه با شماره پیاپی سال 2015
Pages :
14
From page :
44
To page :
57
Abstract :
AbstractContext computing is a thriving paradigm that supports an efficient way to provide IT services by introducing on-demand services and flexible computing resources. However, significant adoption of cloud services is being hindered by security issues that are inherent to this new paradigm. In previous work, we have proposed ISGcloud, a security governance framework to tackle cloud security matters in a comprehensive manner whilst being aligned with an enterprise’s strategy. ive gh a significant body of literature has started to build up related to security aspects of cloud computing, the literature fails to report on evidence and real applications of security governance frameworks designed for cloud computing environments. This paper introduces a detailed application of ISGCloud into a real life case study of a Spanish public organisation, which utilises a cloud storage service in a critical security deployment. pirical evaluation has followed a formal process, which includes the definition of research questions previously to the framework’s application. We describe ISGcloud process and attempt to answer these questions gathering results through direct observation and from interviews with related personnel. s velty of the paper is twofold: on the one hand, it presents one of the first applications, in the literature, of a cloud security governance framework to a real-life case study along with an empirical evaluation of the framework that proves its validity; on the other hand, it demonstrates the usefulness of the framework and its impact to the organisation. sion cussed on the paper, the application of ISGCloud has resulted in the organisation in question achieving its security governance objectives, minimising the security risks of its storage service and increasing security awareness among its users.
Keywords :
CLOUD COMPUTING , Security governance framework , Information security governance , CASE STUDY , Cloud lifecycle
Journal title :
Information and Software Technology
Serial Year :
2015
Journal title :
Information and Software Technology
Record number :
2375368
Link To Document :
بازگشت