Please use this identifier to cite or link to this item: http://hdl.handle.net/20.500.12188/20593
DC FieldValueLanguage
dc.contributor.authorKostoska, Magdalenaen_US
dc.contributor.authorGushev, Marjanen_US
dc.contributor.authorRistov, Sashkoen_US
dc.date.accessioned2022-07-06T12:04:05Z-
dc.date.available2022-07-06T12:04:05Z-
dc.date.issued2012-04-05-
dc.identifier.urihttp://hdl.handle.net/20.500.12188/20593-
dc.description.abstractCloud computing providers‘ and customers‘ services are not only exposed to existing security risks, but, due to multi-tenancy, outsourcing the application and data, and virtualization, they are exposed to the emergent, as well. Therefore, both the cloud providers and customers must establish information security system and trustworthiness each other, as well as end users. In this paper we analyze main international and industrial standards targeting information security and their conformity with cloud computing security challenges. We evaluate that almost all main cloud service providers (CSPs) are ISO 27001:2005 certified, at minimum. As a result, we propose an extension to the ISO 27001:2005 standard with new control objective about virtualization, to retain generic, regardless of company’s type, size and nature, that is, to be applicable for cloud systems, as well, where virtualization is its baseline. We also define a quantitative metric and evaluate the importance factor of ISO 27001:2005 control objectives if customer services are hosted on-premise or in cloud. The conclusion is that obtaining the ISO 27001:2005 certificate (or if already obtained) will further improve CSP and CC information security systems, and introduce mutual trust in cloud services but will not cover all relevant issues. In this paper we also continue our efforts in business continuity detriments cloud computing produces, and propose some solutions that mitigate the risks.en_US
dc.relation.ispartofarXiv preprint arXiv:1204.1140en_US
dc.subjectBusiness Information Security, Cloud Computing, Security Assessment, Security Standardsen_US
dc.titleCloud computing security in business information systemsen_US
dc.typeJournal Articleen_US
item.grantfulltextopen-
item.fulltextWith Fulltext-
crisitem.author.deptFaculty of Computer Science and Engineering-
crisitem.author.deptFaculty of Computer Science and Engineering-
crisitem.author.deptFaculty of Computer Science and Engineering-
Appears in Collections:Faculty of Computer Science and Engineering: Journal Articles
Files in This Item:
File Description SizeFormat 
1204.1140.pdf295.48 kBAdobe PDFView/Open
Show simple item record

Page view(s)

63
checked on May 22, 2024

Download(s)

16
checked on May 22, 2024

Google ScholarTM

Check


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.