...
首页> 外文期刊>Computers >CSCCRA: A Novel Quantitative Risk Assessment Model for SaaS Cloud Service Providers
【24h】

CSCCRA: A Novel Quantitative Risk Assessment Model for SaaS Cloud Service Providers

机译:CSCCRA:SaaS云服务提供商的一种新型量化风险评估模型

获取原文
           

摘要

Security and privacy concerns represent a significant hindrance to the widespread adoption of cloud computing services. While cloud adoption mitigates some of the existing information technology (IT) risks, research shows that it introduces a new set of security risks linked to multi-tenancy, supply chain and system complexity. Assessing and managing cloud risks can be a challenge, even for cloud service providers (CSPs), due to the increased numbers of parties, devices and applications involved in cloud service delivery. The limited visibility of security controls down the supply chain, further exacerbates this risk assessment challenge. As such, we propose the Cloud Supply Chain Cyber Risk Assessment (CSCCRA) model, a quantitative risk assessment model which is supported by supplier security posture assessment and supply chain mapping. Using the CSCCRA model, we assess the risk of a SaaS application, mapping its supply chain, identifying weak links in the chain, evaluating its security risks and presenting the risk value in monetary terms (£), with this, promoting cost-effective risk mitigation and optimal risk prioritisation. We later apply the Core Unified Risk Framework (CURF) in comparing the CSCCRA model with already established methods, as part of evaluating its completeness.
机译:安全和隐私问题代表了广泛采用云计算服务的重要障碍。虽然云采用减轻了一些现有的信息技术(IT)风险,但研究表明它介绍了与多租户,供应链和系统复杂性相关的一套新的安全风险。由于云服务交付所涉及的派对,设备和应用程序增加,评估和管理云风险可能是挑战,即使是云服务提供商(CSP),云服务交付所涉及的各方,设备和应用程序增加。安全控制供应链的安全可见性有限,进一步加剧了这种风险评估挑战。因此,我们提出了云供应链网络风险评估(CSCCRA)模型,是由供应商安全姿势评估和供应链映射支持的定量风险评估模型。使用CSCCRA模型,评估SaaS应用程序的风险,绘制其供应链,识别链中的薄弱环节,评估其安全风险,并以货币术语(£)提出风险价值,促进具有成本效益的风险减缓和最佳风险优先级。我们稍后将核心统一风险框架(CURF)应用于将CSCCRA模型与已经建立的方法进行比较,作为评估其完整性的一部分。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号