A Framework for Cloud Security Risk Management Based on the Business Objectives of Organizations
Ahmed E. Youssef

TL;DR
This paper introduces a novel Cloud Security Risk Management Framework (CSRMF) that aligns cloud security risks with organizational business objectives, enabling better decision-making and risk mitigation in cloud adoption.
Contribution
The paper presents a new risk management framework driven by business objectives, addressing gaps in traditional models for cloud security risk assessment.
Findings
Framework helps organizations understand cloud security risks in relation to business goals.
Validation through a practical use-case scenario demonstrates its effectiveness.
Enables cost-value analysis for cloud adoption decisions.
Abstract
Security is considered one of the top ranked risks of Cloud Computing (CC) due to the outsourcing of sensitive data onto a third party. In addition, the complexity of the cloud model results in a large number of heterogeneous security controls that must be consistently managed. Hence, no matter how strongly the cloud model is secured, organizations continue suffering from lack of trust on CC and remain uncertain about its security risk consequences. Traditional risk management frameworks do not consider the impact of CC security risks on the business objectives of the organizations. In this paper, we propose a novel Cloud Security Risk Management Framework (CSRMF) that helps organizations adopting CC identify, analyze, evaluate, and mitigate security risks in their Cloud platforms. Unlike traditional risk management frameworks, CSRMF is driven by the business objectives of the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCloud Data Security Solutions · Cloud Computing and Resource Management · IoT and Edge/Fog Computing
