Abstract
Despite the attractive benefits of cloud-based business processes, security issues, cloud attacks, and privacy are some of the challenges that prevent many organizations from using this technology. This review seeks to know the level of integration of security risk management process at each phase of the Business Process Life Cycle (BPLC) for securing cloud-based business processes; usage of an existing risk analysis technique as the basis of risk assessment model, usage of security risk standard, and the classification of cloud security risks in a cloud-based business process. In light of these objectives, this study presented an exhaustive review of the current state-of-the-art methodology for managing cloud-based business process security risk. Eleven electronic databases (ACM, IEEE, Science Direct, Google Scholar, Springer, Wiley, Taylor and Francis, IEEE cloud computing Conference, ICSE conference, COMPSAC conference, ICCSA conference, Computer Standards and Interfaces Journal) were used for the selected publications. A total of 1243 articles were found. After using the selection criteria, 93 articles were selected, while 17 articles were found eligible for in-depth evaluation. For the results of the business process lifecycle evaluation, 17% of the approaches integrated security risk management into one of the phases of the business process, while others did not. For the influence of the results of the domain assessment of risk management, three key indicators (domain applicability, use of existing risk management techniques, and integration of risk standards) were used to substantiate our findings. The evaluation result of domain applicability showed that 53% of the approaches had been testing run in real-time, thereby making these works reusable. The result of the usage of existing risk analysis showed that 52.9% of the authors implemented their work using existing risk analysis techniques while 29.4% of the authors partially integrated security risk standards into their work. Based on these findings and results, security risk management, the usage of existing security risk management techniques, and security risk standards should be integrated with business process phases to protect against security issues in cloud services.
Subject
Computer Networks and Communications,Human-Computer Interaction
Reference122 articles.
1. Business Process Management: A Comprehensive Survey
2. How Work Gets Done: Business Process Management, Basics and Beyond;Mahal,2010
3. The Basics of Process Mapping;Damelio,2011
4. Business process performance measurement: a structured literature review of indicators, measures and metrics
5. Business Process Change: A Guide for Business Managers and BPM and Six Sigma Professionals;Harmon,2010
Cited by
8 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Enhanced threat intelligence framework for advanced cybersecurity resilience;Egyptian Informatics Journal;2024-09
2. Enabling security risk assessment and management for business process models;Journal of Information Security and Applications;2024-08
3. The Rise of Industry 6.0;Advances in Information Security, Privacy, and Ethics;2024-02-14
4. Managing Cloud Computing Assets for Scalability and Cost Efficiency;2023 10th IEEE Uttar Pradesh Section International Conference on Electrical, Electronics and Computer Engineering (UPCON);2023-12-01
5. A Resilience Engineering Approach for the Risk Assessment of IT Services;Applied Sciences;2023-10-10