z-logo
open-access-imgOpen Access
CLOUD SECURITY PRE-ASSESSMENT MODEL FOR CLOUD SERVICE PROVIDER BASED ON ISO/IEC 27017:2015 ADDITIONAL CONTROL
Author(s) -
Nur Ahada Kamaruddin,
Ibrahim Mohamed,
Ahmad Dahari Jarno,
Maslina Daud
Publication year - 2020
Publication title -
international journal of innovation and industrial revolution
Language(s) - English
Resource type - Journals
ISSN - 2637-0972
DOI - 10.35631/ijirev.25001
Subject(s) - cloud computing , computer security , computer science , cloud computing security , software deployment , service provider , transparency (behavior) , security controls , service (business) , control (management) , business , software engineering , marketing , artificial intelligence , operating system
Cloud computing technology has succeeded in attracting the interest of both academics and industries because of its ability to provide flexible, cost-effective, and adaptable services in IT solution deployment. The services offered to Cloud Service Subscriber (CSS) are based on the concept of on-demand self-service, scalability, and rapid elasticity, which allows fast deployment of IT solutions, whilst leads to possible misconfiguration, un-patched system, etc. which, allows security threats to compromise the cloud services operations. From the viewpoint of Cloud Service Provider (CSP), incidents such as data loss and information breach, will tarnish their reputations, whilst allow them to conserve the issues internally, in which there is no transparency between CSP and CSS. In the aspects of information security, CSP is encouraged to practice cybersecurity in their cloud services by adopting ISO/IEC27017:2015 inclusive of all additional security controls as mandatory requirements. This study was conducted to identify factors that are influencing the CSP readiness level in the cybersecurity implementation of their cloud services by leveraging the developed pre-assessment model to determine the level of cloud security readiness. Approached the study is based on the combination of qualitative and quantitative assessment method in validating the proposed model through interview and prototype testing. The findings of this study had shown that factors that influence the CSP level of cloud security readiness are based on these domains; technology, organisation, policy, stakeholders, culture, knowledge, and environment. The contribution of the study as a Pre-Assessment Model for CSP which is suitable to be used as a guideline to provide a safer cloud computing environment.

The content you want is available to Zendy users.

Already have an account? Click here to sign in.
Having issues? You can contact us here