From rationale to lessons learned in the cloud information security risk assessment: a study of organizations in Sweden

Author:

Faizi Ana,Padyab Ali,Naess Andreas

Abstract

Purpose This study aims to address the issue of practicing information security risk assessment (ISRA) on cloud solutions by studying municipalities and large organizations in Sweden. Design/methodology/approach Four large organizations and five municipalities that use cloud services and conduct ISRA to adhere to their information security risk management practices were studied. Data were gathered qualitatively to answer the study’s research question: How is ISRA practiced on the cloud? The Coat Hanger model was used as a theoretical lens to study and theorize the practices. Findings The results showed that the organizations aimed to follow the guidelines, in the form of frameworks or their own experience, to conduct ISRA; furthermore, the frameworks were altered to fit the organizations’ needs. The results further indicated that one of the main concerns with the cloud ISRA was the absence of a culture that integrates risk management. Finally, the findings also stressed the importance of a good understanding and a well-written legal contract between the cloud providers and the organizations using the cloud services. Originality/value As opposed to the previous research, which was more inclined to try out and evaluate various cloud ISRA, the study provides insights into the practice of cloud ISRA experienced by the organizations. This study represents the first attempt to investigate cloud ISRA that organizations practice in managing their information security.

Publisher

Emerald

Subject

Management of Technology and Innovation,Information Systems and Management,Computer Networks and Communications,Information Systems,Software,Management Information Systems

Reference56 articles.

1. CSCCRA: a novel quantitative risk assessment model for SaaS cloud service providers;Computers,2019

2. Security risk assessment framework for cloud computing environments;Security and Communication Networks,2014

3. Assessing information security risks in the cloud: a case study of Australian local government authorities;Government Information Quarterly,2020

4. A survey on security risk management frameworks in cloud computing;Computer Science and Information Technology (CS and IT),2016

5. An exploratory study of current information security training and awareness practices in organizations,2018

Cited by 8 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Security Risk Assessment on Cloud: A Systematic Mapping Study;Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering;2024-06-18

2. Adapting to Change: Software Project Management in the Era of Security in Cloud Computing;Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering;2024-06-18

3. Strategic Approaches in Network Communication and Information Security Risk Assessment;Information;2024-06-14

4. IoT’s Impact on Nigeria’s Construction Industry: Unveiling Benefits in the Era of the 4th Industrial Revolution(4IR);2024 International Conference on Science, Engineering and Business for Driving Sustainable Development Goals (SEB4SDG);2024-04-02

5. Enhancing Cybersecurity in Nigeria: A Proposed Risk Management Framework for Universities;2024 International Conference on Science, Engineering and Business for Driving Sustainable Development Goals (SEB4SDG);2024-04-02

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3