DocumentCode
1831749
Title
Pattern-Based Support for Context Establishment and Asset Identification of the ISO 27000 in the Field of Cloud Computing
Author
Beckers, Kristian ; Schmidt, Holger ; Küster, Jan-Christoph ; Fassbender, S.
Author_Institution
Dept. of Comput. & Appl. Cognitive Sci., Univ. Duisburg-Essen, Duisburg, Germany
fYear
2011
fDate
22-26 Aug. 2011
Firstpage
327
Lastpage
333
Abstract
The ISO 27000 is a well-established series of information security standards. The scope for applying these standards can be an organisation as a whole, single business processes or even an IT application or IT infrastructure. The context establishment and the asset identification are among the first steps to be performed. The quality of the results produced when performing these steps has a crucial influence on the subsequent steps such as identifying loss, vulnerabilities, possible attacks and defining countermeasures. Thus, a context analysis to gather all necessary information in the initial steps is important, but is not offered in the standard. In this paper, we focus on the scope of cloud computing systems and present a way to support the context establishment and the asset identification described in ISO 27005. A cloud system analysis pattern and different kinds of stakeholder templates serve to understand and describe a given cloud development problem, i.e. the envisaged IT systems and the relevant parts of the operational environment. We illustrate our support using an online banking cloud scenario.
Keywords
ISO standards; cloud computing; security of data; ISO 27000; IT application; IT infrastructure; asset identification; business process; cloud computing; context establishment; information security standard; online banking cloud scenario; pattern-based support; stakeholder templates; Cloud computing; Context; ISO standards; Information security; Risk management; cloud computing; requirements engineering; security standards;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security (ARES), 2011 Sixth International Conference on
Conference_Location
Vienna
Print_ISBN
978-1-4577-0979-1
Electronic_ISBN
978-0-7695-4485-4
Type
conf
DOI
10.1109/ARES.2011.55
Filename
6045958
Link To Document