Novel risk assessment method to identify information security threats in cloud computing environment

Cloud computing model brought many technical and economicbenefits, however, there are many security issues. Most of the common tradi-tional information security risk assessment methods such as ISO27005, NISTSP800-30 and AS/NZS 4360 are notfit for the cloud computing environment.Therefore, this study...

Full description

Saved in:
Bibliographic Details
Main Authors: Samy, G. N., Hasan Albakri, S., Maarop, N., Magalingam, P., Wong, D. H. T., Shanmugam, B., Perumal, S.
Format: Conference or Workshop Item
Language:English
Published: 2019
Subjects:
Online Access:http://eprints.utm.my/id/eprint/91326/1/GanthanNarayanaSamy2019_NovelRiskAssessmentMethod.pdf
http://eprints.utm.my/id/eprint/91326/
http://www.dx.doi.org/10.1007/978-3-319-99007-1_53
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:Cloud computing model brought many technical and economicbenefits, however, there are many security issues. Most of the common tradi-tional information security risk assessment methods such as ISO27005, NISTSP800-30 and AS/NZS 4360 are notfit for the cloud computing environment.Therefore, this study applies medical research approach to assess the informa-tion security threats in the cloud computing environment. This study has beenconducted as a retrospective cohort study and the collected data has been ana-lyzed by using the survival analysis method. The study has been conducted onthe software as a service (SaaS) environment that has more than one thousandand seven hundred cloud customers. The survival analysis method is used tomeasure the significance of the risk factor level. The information security threatshave been categorized into twenty-two categories. This study has proven that themedical research approach can be used to assess the security risk assessment incloud computing environment to overcome the weaknesses that accompany theusage of the traditional information security risk assessment methods in cloudcomputing environment.