Abstract

Cloud computing has been one of the major emerging technologies in recent years. However, for cloud computing, the risk assessment becomes more complex since there are several issues that likely emerged. In this paper, we survey the existing work on assessing security risks in cloud computing applications. Existing work does not address the dynamic nature of cloud applications and there is a need for methods that calculate the security risk factor dynamically. In this paper, we use the National Institute of Standards and Technology (NIST) Risk Management Framework and present a dynamic scenario-based methodology for risk assessment. The methodology is based using Bayesian networks to estimate the likelihood of cloud application security failure which enables us to compute the probability distribution of failures over variables of interest given the evidence. We illustrate the methodology using two case studies and highlight the significant risk factors. We also show the effect of using security controls in reducing the risk factors.

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.