DocumentCode
267166
Title
Categorization of Standards, Guidelines and Tools for Secure System Design for Critical Infrastructure IT in the Cloud
Author
Paudel, Sarita ; Tauber, Markus ; Wagner, Christian ; Hudic, Aleksandar ; Wee-Kong Ng
Author_Institution
Austrian Inst. of Technol., Vienna, Austria
fYear
2014
fDate
15-18 Dec. 2014
Firstpage
956
Lastpage
963
Abstract
With the increasing popularity of cloud computing, security in cloud-based applications is gaining awareness and is regarded as one of the most crucial factors for the long term success of such applications. Despite all benefits of cloud computing, its fate lies in its success in gaining trust from its users achieved by ensuring cloud services being built in a safe and secure manner. This work evaluates existing security standards and tools for creating Critical Infrastructure (CI) services in cloud environments -- often implemented as cyber physical systems (CPS). We also identify security issues from a literature review and from a show case analysis. Furthermore, we analyse and evaluate how mitigation options for identified open security issues for CI in the cloud point to individual aspects of standards and guidelines to support the creation of secure CPS/CI in the cloud. Additionally, we presented the results in a multidimensional taxonomy based on the mapping of the issues and the standards and tools. We show which areas require the attention as they are currently not covered completely by existing standards, guidelines and tools.
Keywords
cloud computing; critical infrastructures; open systems; security of data; standards; trusted computing; CPS; cloud computing; cloud environments; cloud services; cloud-based applications; critical infrastructure IT; critical infrastructure services; cyberphysical systems; guideline categorization; multidimensional taxonomy; open security issues; secure system design; standard categorization; Cloud computing; Context; Guidelines; Security; Standards; Taxonomy; CPS; critical infrastructure; secure software development; security-engineering;
fLanguage
English
Publisher
ieee
Conference_Titel
Cloud Computing Technology and Science (CloudCom), 2014 IEEE 6th International Conference on
Conference_Location
Singapore
Type
conf
DOI
10.1109/CloudCom.2014.172
Filename
7037790
Link To Document