• DocumentCode
    267166
  • Title

    Categorization of Standards, Guidelines and Tools for Secure System Design for Critical Infrastructure IT in the Cloud

  • Author

    Paudel, Sarita ; Tauber, Markus ; Wagner, Christian ; Hudic, Aleksandar ; Wee-Kong Ng

  • Author_Institution
    Austrian Inst. of Technol., Vienna, Austria
  • fYear
    2014
  • fDate
    15-18 Dec. 2014
  • Firstpage
    956
  • Lastpage
    963
  • Abstract
    With the increasing popularity of cloud computing, security in cloud-based applications is gaining awareness and is regarded as one of the most crucial factors for the long term success of such applications. Despite all benefits of cloud computing, its fate lies in its success in gaining trust from its users achieved by ensuring cloud services being built in a safe and secure manner. This work evaluates existing security standards and tools for creating Critical Infrastructure (CI) services in cloud environments -- often implemented as cyber physical systems (CPS). We also identify security issues from a literature review and from a show case analysis. Furthermore, we analyse and evaluate how mitigation options for identified open security issues for CI in the cloud point to individual aspects of standards and guidelines to support the creation of secure CPS/CI in the cloud. Additionally, we presented the results in a multidimensional taxonomy based on the mapping of the issues and the standards and tools. We show which areas require the attention as they are currently not covered completely by existing standards, guidelines and tools.
  • Keywords
    cloud computing; critical infrastructures; open systems; security of data; standards; trusted computing; CPS; cloud computing; cloud environments; cloud services; cloud-based applications; critical infrastructure IT; critical infrastructure services; cyberphysical systems; guideline categorization; multidimensional taxonomy; open security issues; secure system design; standard categorization; Cloud computing; Context; Guidelines; Security; Standards; Taxonomy; CPS; critical infrastructure; secure software development; security-engineering;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Computing Technology and Science (CloudCom), 2014 IEEE 6th International Conference on
  • Conference_Location
    Singapore
  • Type

    conf

  • DOI
    10.1109/CloudCom.2014.172
  • Filename
    7037790