The Science and Information (SAI) Organization publishes open-access peer-reviewed journals in computer science and artificial intelligence.

Contact Info
Website thesai.org
Follow Us
Contact Info
Follow Us
Research Article | Open Access |

A Framework for Cloud Security Risk Management based on the Business Objectives of Organizations

Author 1: Ahmed E Youssef
International Journal of Advanced Computer Science and Applications (IJACSA) · Vol. 10, No. 12 · Published 2019

DOI: https://doi.org/10.14569/IJACSA.2019.0101226

Abstract

Security is considered one of the top ranked risks of Cloud Computing (CC) due to the outsourcing of sensitive data onto a third party. In addition, the complexity of the cloud model results in a large number of heterogeneous security controls that must be consistently managed. Hence, no matter how strongly the cloud model is secured, organizations continue suffering from lack of trust on CC and remain uncertain about its security risk consequences. Traditional risk management frameworks do not consider the impact of CC security risks on the business objectives of the organizations. In this paper, we propose a novel Cloud Security Risk Management Framework (CSRMF) that helps organizations adopting CC identifies, analyze, evaluate, and mitigate security risks in their Cloud platforms. Unlike traditional risk management frameworks, CSRMF is driven by the business objectives of the organizations. It allows any organization adopting CC to be aware of cloud security risks and align their low-level management decisions according to high-level business objectives. In essence, it is designed to address impacts of cloud-specific security risks into business objectives in a given organization. Consequently, organizations are able to conduct a cost-value analysis regarding the adoption of CC technology and gain an adequate level of confidence in Cloud technology. On the other hand, Cloud Service Providers (CSP) is able to improve productivity and profitability by managing cloud-related risks. The proposed framework has been validated and evaluated through a use-case scenario.

Keywords

How to Cite this Article

Ahmed E Youssef. "A Framework for Cloud Security Risk Management based on the Business Objectives of Organizations". International Journal of Advanced Computer Science and Applications (IJACSA), Vol. 10, No. 12, 2019. https://doi.org/10.14569/IJACSA.2019.0101226

BibTeX

@article{Youssef2019,
  title     = {A Framework for Cloud Security Risk Management based on the Business Objectives of Organizations},
  journal   = {International Journal of Advanced Computer Science and Applications},
  volume    = {10},
  number    = {12},
  year      = {2019},
  publisher = {The Science and Information Organization},
  author    = {Ahmed E Youssef},
  doi       = {10.14569/IJACSA.2019.0101226},
  url       = {https://doi.org/10.14569/IJACSA.2019.0101226}
}

Open Access — licensed under a Creative Commons Attribution 4.0 International License. Unrestricted use, distribution, and reproduction in any medium, even commercially, as long as the original work is properly cited.