• DocumentCode
    3722157
  • Title

    A Novel Risk Identification Framework for Cloud Computing Security

  • Author

    Mackita Masky;Shin Soo Young;Tae-Young Choe

  • Author_Institution
    Dept. of IT Convergence Eng., Kumoh Nat. Inst. of Technol., Gumi, South Korea
  • fYear
    2015
  • Firstpage
    1
  • Lastpage
    4
  • Abstract
    This paper introduces the Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) Allegro methodology as a novel framework to identify risks for Cloud Computing. According to Cloud Security Alliance (CSA), before applying security controls in Cloud Computing, risks and threats must be effectively identified and assessed. OCTAVE Allegro approach being introduced is designed to allow broad assessment of Cloud Computing operational risk environment with the goal of producing more robust results without the need for extensive risk assessment knowledge. This approach differs from others by focusing primarily on information assets in the context of how they are used, where they are stored, transported, and processed, and how they are exposed to threats, vulnerabilities, and disruptions as a result.
  • Keywords
    "Cloud computing","Containers","Risk management","Servers","Context","Information security"
  • Publisher
    ieee
  • Conference_Titel
    Information Science and Security (ICISS), 2015 2nd International Conference on
  • Type

    conf

  • DOI
    10.1109/ICISSEC.2015.7370967
  • Filename
    7370967