Title :
Categorization of Standards, Guidelines and Tools for Secure System Design for Critical Infrastructure IT in the Cloud
Author :
Paudel, Sarita ; Tauber, Markus ; Wagner, Christian ; Hudic, Aleksandar ; Wee-Kong Ng
Author_Institution :
Austrian Inst. of Technol., Vienna, Austria
Abstract :
With the increasing popularity of cloud computing, security in cloud-based applications is gaining awareness and is regarded as one of the most crucial factors for the long term success of such applications. Despite all benefits of cloud computing, its fate lies in its success in gaining trust from its users achieved by ensuring cloud services being built in a safe and secure manner. This work evaluates existing security standards and tools for creating Critical Infrastructure (CI) services in cloud environments -- often implemented as cyber physical systems (CPS). We also identify security issues from a literature review and from a show case analysis. Furthermore, we analyse and evaluate how mitigation options for identified open security issues for CI in the cloud point to individual aspects of standards and guidelines to support the creation of secure CPS/CI in the cloud. Additionally, we presented the results in a multidimensional taxonomy based on the mapping of the issues and the standards and tools. We show which areas require the attention as they are currently not covered completely by existing standards, guidelines and tools.
Keywords :
cloud computing; critical infrastructures; open systems; security of data; standards; trusted computing; CPS; cloud computing; cloud environments; cloud services; cloud-based applications; critical infrastructure IT; critical infrastructure services; cyberphysical systems; guideline categorization; multidimensional taxonomy; open security issues; secure system design; standard categorization; Cloud computing; Context; Guidelines; Security; Standards; Taxonomy; CPS; critical infrastructure; secure software development; security-engineering;
Conference_Titel :
Cloud Computing Technology and Science (CloudCom), 2014 IEEE 6th International Conference on
Conference_Location :
Singapore
DOI :
10.1109/CloudCom.2014.172