DocumentCode :
1711415
Title :
A Semantic Approach to Cloud Security and Compliance
Author :
Hendre, Amit ; Joshi, Karuna Pande
Author_Institution :
CSEE Dept., Univ. of Maryland Baltimore County, Baltimore, MD, USA
fYear :
2015
Firstpage :
1081
Lastpage :
1084
Abstract :
Cloud services are becoming an essential part of many organizations. Cloud providers have to adhere to security and privacy policies to ensure their users´ data remains confidential and secure. Though there are some ongoing efforts on developing cloud security standards, most cloud providers are implementing a mish-mash of security and privacy controls. This has led to confusion among cloud consumers as to what security measures they should expect from the cloud services, and whether these measures would comply with their security and compliance requirements. We have conducted a comprehensive study to review the potential threats faced by cloud consumers and have determined the compliance models and security controls that should be in place to manage the risk. Based on this study, we have developed an ontology describing the cloud security controls, threats and compliances. We have also developed an application that classifies the security threats faced by cloud users and automatically determines the high level security and compliance policy controls that have to be activated for each threat. The application also displays existing cloud providers that support these security policies. Cloud consumers can use our system to formulate their security policies and find compliant providers even if they are not familiar with the underlying technology.
Keywords :
cloud computing; ontologies (artificial intelligence); security of data; cloud consumers; cloud security standards; compliance policy controls; compliance requirements; high level security; ontology; security threats; semantic approach; Cloud computing; ISO Standards; NIST; Ontologies; Security; Cloud computing; Cloud security models; Security compliance models; cloud security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cloud Computing (CLOUD), 2015 IEEE 8th International Conference on
Conference_Location :
New York City, NY
Print_ISBN :
978-1-4673-7286-2
Type :
conf
DOI :
10.1109/CLOUD.2015.157
Filename :
7214167
Link To Document :
بازگشت