Cyber risk assessment in cloud provider environments: Current models and future needs

Traditional frameworks for risk assessment do not work well for cloud computing. While recent work has often focussed on the risks faced by firms adopting or selecting cloud services, there has been little research on how cloud providers might assess their own services. In this paper, we use an in-d...

पूर्ण विवरण

ग्रंथसूची विवरण
मुख्य लेखकों: Akinrolabu, O, Nurse, J, Martin, A, New, S
स्वरूप: Journal article
भाषा:English
प्रकाशित: Elsevier 2019
_version_ 1826302157706493952
author Akinrolabu, O
Nurse, J
Martin, A
New, S
author_facet Akinrolabu, O
Nurse, J
Martin, A
New, S
author_sort Akinrolabu, O
collection OXFORD
description Traditional frameworks for risk assessment do not work well for cloud computing. While recent work has often focussed on the risks faced by firms adopting or selecting cloud services, there has been little research on how cloud providers might assess their own services. In this paper, we use an in-depth review of the extant literature to highlight the weaknesses of traditional risk assessment frameworks for this task. Using examples, we then describe a new risk assessment model (CSCCRA) and compare this against three established approaches. For each approach, we consider its goals, the risk assessment process, decisions, the scope of the assessment and the way in which risk is conceptualised. This evaluation points to the need for dynamic models specifically designed to evaluate cloud risk. Our suggestions for future research are aimed at improving the identification, assessment, and mitigation of inter-dependent cloud risks inherent in a defined supply chain.
first_indexed 2024-03-07T05:43:18Z
format Journal article
id oxford-uuid:e656a71c-596b-453c-a68b-b03ff3b5a2b8
institution University of Oxford
language English
last_indexed 2024-03-07T05:43:18Z
publishDate 2019
publisher Elsevier
record_format dspace
spelling oxford-uuid:e656a71c-596b-453c-a68b-b03ff3b5a2b82022-03-27T10:30:21ZCyber risk assessment in cloud provider environments: Current models and future needsJournal articlehttp://purl.org/coar/resource_type/c_dcae04bcuuid:e656a71c-596b-453c-a68b-b03ff3b5a2b8EnglishSymplectic Elements at OxfordElsevier2019Akinrolabu, ONurse, JMartin, ANew, STraditional frameworks for risk assessment do not work well for cloud computing. While recent work has often focussed on the risks faced by firms adopting or selecting cloud services, there has been little research on how cloud providers might assess their own services. In this paper, we use an in-depth review of the extant literature to highlight the weaknesses of traditional risk assessment frameworks for this task. Using examples, we then describe a new risk assessment model (CSCCRA) and compare this against three established approaches. For each approach, we consider its goals, the risk assessment process, decisions, the scope of the assessment and the way in which risk is conceptualised. This evaluation points to the need for dynamic models specifically designed to evaluate cloud risk. Our suggestions for future research are aimed at improving the identification, assessment, and mitigation of inter-dependent cloud risks inherent in a defined supply chain.
spellingShingle Akinrolabu, O
Nurse, J
Martin, A
New, S
Cyber risk assessment in cloud provider environments: Current models and future needs
title Cyber risk assessment in cloud provider environments: Current models and future needs
title_full Cyber risk assessment in cloud provider environments: Current models and future needs
title_fullStr Cyber risk assessment in cloud provider environments: Current models and future needs
title_full_unstemmed Cyber risk assessment in cloud provider environments: Current models and future needs
title_short Cyber risk assessment in cloud provider environments: Current models and future needs
title_sort cyber risk assessment in cloud provider environments current models and future needs
work_keys_str_mv AT akinrolabuo cyberriskassessmentincloudproviderenvironmentscurrentmodelsandfutureneeds
AT nursej cyberriskassessmentincloudproviderenvironmentscurrentmodelsandfutureneeds
AT martina cyberriskassessmentincloudproviderenvironmentscurrentmodelsandfutureneeds
AT news cyberriskassessmentincloudproviderenvironmentscurrentmodelsandfutureneeds