作者
Jesus Luna, Neeraj Suri, Michaela Iorga, Anil Karmel
发表日期
2015/7/15
期刊
IEEE Cloud Computing
卷号
2
期号
3
页码范围
32-40
出版商
IEEE
简介
Despite the undisputed advantages of cloud computing, customers-in particular, small and medium enterprises (SMEs)-still need meaningful understanding of the security and risk-management changes that the cloud entails so they can assess whether this new computing paradigm meets their security requirements. This article presents a fresh view on this problem by surveying and analyzing, from the standardization and risk assessment perspective, the specification of security in cloud service-level agreements (secSLA) as a promising approach to empower customers in assessing and understanding cloud security. Apart from analyzing the proposed risk-based approach and surveying the relevant landscape, this article presents a real-world scenario to support the creation and adoption of secSLAs as enablers for negotiating, assessing, and monitoring the achieved security levels in cloud services.
引用总数
2015201620172018201920202021202220232024181411993511