The Experts below are selected from a list of 33 Experts worldwide ranked by ideXlab platform
Twittie Senivongse - One of the best experts on this subject based on the ideXlab platform.
-
cloud service trustworthiness assessment based on cloud controls matrix
International Conference on Advanced Communication Technology, 2017Co-Authors: Jirayu Kanpariyasoontorn, Twittie SenivongseAbstract:cloud computing has been widely adopted by corporate and individual customers due to its resource-sharing model that allows on-demand access to scalable and high performance computing services. The growth of such services means there are a lot of service providers who can provide similar services, and hence quality attributes of the services become the criteria for cloud service selection. This paper focuses on cloud service trustworthiness that embraces both security and dependability attributes. A trustworthiness assessment method is proposed based on the CSA cloud controls matrix security guidelines that are mapped to NIST SP800-53 security and privacy recommendations and AICPA trust services principles and criteria in order to classify security and dependability characteristics of each control. Based on the mapping, the provision capabilities of a cloud service as listed in the CSA Consensus Assessments Initiative Questionnaire are assessed and the trustworthiness score of the service is calculated. The assessment method then can assist service consumers in determining and comparing trustworthiness of candidate cloud services as one factor to consider in the service selection process.
-
Storage and search tool for cloud provider security information in CSA STAR
2016 13th International Joint Conference on Computer Science and Software Engineering JCSSE 2016, 2016Co-Authors: Chosita Phattanateeradej, Twittie SenivongseAbstract:At present, cloud computing is becoming a major IT service model. As the number of cloud providers is growing, prospective cloud consumers face difficulties in choosing the right provider for their use. As security is among the most important factors for the consumers to decide whether or not to adopt cloud services, cloud providers have to assure prospective consumers that the provided service is secure and can be trusted. One way is to publish security information of the service on cloud Security Alliance's Security, Trust, & Assurance Registry (or CSA STAR) website. STAR offers three levels of providers' security information, i.e. self-assessment, 3rd-party-assessment-based certification, and continuous-monitoring-based certification. However, the STAR website does not provide a convenient and useful way for cloud consumers to find security information of the providers when they are selecting a cloud service. The consumers, for example, have to know provider names and cannot search for providers by certain security criteria. To address such limitations, this paper presents a development of a storage and search tool based on the security information published on the STAR website. The tool stores and synchronizes providers' security information with the CSA STAR website, and allows consumers to search by different security criteria based on CSA's cloud controls matrix (CCM) security guideline and its accompanying CAIQ security questionnaire. The tool can also compare and visualize providers' security information. Hence it makes the CSA STAR information more accessible and more useful to prospective consumers when selecting cloud services.
-
semantic search for cloud providers with security conformance to cloud controls matrix
Computer Science and Software Engineering, 2014Co-Authors: Jakarin Thaweejinda, Twittie SenivongseAbstract:Prospective cloud consumers consider several quality attributes of cloud providers when selecting a cloud service. Security is a major quality attribute that is often used to differentiate between service offers from different cloud providers. cloud Security Alliance has published the cloud controls matrix (CCM) which contains security best practices and principles which cloud providers should follow to provide secure cloud services. This paper presents a semantic search framework for discovering cloud services which conform to the security controls in the CCM. In this framework, a security ontology is constructed from the CCM, and based on this security ontology, provider profiles can be built. A provider profile which presents relevant evidence of conformance to CCM security controls is then searched and ranked against a cloud consumer's query. cloud consumers then can determine and compare the degree of conformance of the cloud services to the CCM. In an experiment, the semantic search gives the search results that should be more useful to the consumers than normal text search.
-
Classifying cloud provider security conformance to cloud controls matrix
2014 11th Int. Joint Conf. on Computer Science and Software Engineering: "Human Factors in Computer Science and Software Engineering" - e-Science and , 2014Co-Authors: Nuttapong Pumvarapruek, Twittie SenivongseAbstract:Security of cloud services is a major concern to cloud consumers when selecting cloud providers. Sufficient security information should be provided so that consumer trust in cloud services can be built, but in practice, security information is critical and may not be publicized. During the service selection process, cloud consumers therefore have to study published information on the cloud providers' Web sites or the cloud providers registry in order to assess how secure the services are. To assist cloud consumers in service selection, this paper presents an initial attempt to apply text classification to classify published information on the providers' Web pages to determine which security best practices and guidelines the providers have followed in providing their services. We take the security best practices and guidelines from the cloud controls matrix (CCM) and the accompanying Consensus Assessments Initiative Questionnaire (CAIQ), and compile a set of security concepts before using it as a basis for classifying the providers' Web pages. The classification result roughly signifies the security conformance level of the providers. We demonstrate this method and present an evaluation using the case of five public cloud providers. © 2014 IEEE.
-
cloudCom - An assessment of security requirements compliance of cloud providers
4th IEEE International Conference on Cloud Computing Technology and Science Proceedings, 2012Co-Authors: Nuntapun Bhensook, Twittie SenivongseAbstract:cloud provider assessment is important for cloud consumers to determine, when outsourcing computing work, which providers can serve their business and system requirements. This paper presents an initial attempt to assess security requirements compliance of cloud providers by following the Goal Question Metric approach and defining a weighted scoring model for the assessment. The security goals and questions that address the goals are taken from cloud Security Alliance's cloud controls matrix and Consensus Assessments Initiative Questionnaire. We then transform such questions into more detailed ones and define metrics that help provide quantitative answers to the transformed questions based on evidence of security compliance provided by the cloud providers. The scoring is weighted by quality of evidence, i.e. its compliance with the associated questions and its completeness. We propose a scoring system architecture which utilizes cloudAudit and assess Amazon Web Services as an example.
Mike Mariano - One of the best experts on this subject based on the ideXlab platform.
-
CSA cloud controls matrix | What It Is & Why It's Important | I.S. Partners
2019Co-Authors: Mike MarianoAbstract:During the operations of your business, one of the biggest decisions you have to make is selecting a reliable cloud provider. You want your customers, ...
-
csa cloud controls matrix what it is why it s important i s partners
2019Co-Authors: Mike MarianoAbstract:During the operations of your business, one of the biggest decisions you have to make is selecting a reliable cloud provider. You want your customers, ...
Massimo Ferrari - One of the best experts on this subject based on the ideXlab platform.
-
release cloud controls matrix 3 0
www.cloudcomputing.info, 2013Co-Authors: Massimo FerrariAbstract:The cloud Security Alliance (CSA) is a not-for-profit organization, born in 2008, with the aim to promote the use of best practices for providing security ...
Nuttapong Pumvarapruek - One of the best experts on this subject based on the ideXlab platform.
-
Classifying cloud provider security conformance to cloud controls matrix
2014 11th Int. Joint Conf. on Computer Science and Software Engineering: "Human Factors in Computer Science and Software Engineering" - e-Science and , 2014Co-Authors: Nuttapong Pumvarapruek, Twittie SenivongseAbstract:Security of cloud services is a major concern to cloud consumers when selecting cloud providers. Sufficient security information should be provided so that consumer trust in cloud services can be built, but in practice, security information is critical and may not be publicized. During the service selection process, cloud consumers therefore have to study published information on the cloud providers' Web sites or the cloud providers registry in order to assess how secure the services are. To assist cloud consumers in service selection, this paper presents an initial attempt to apply text classification to classify published information on the providers' Web pages to determine which security best practices and guidelines the providers have followed in providing their services. We take the security best practices and guidelines from the cloud controls matrix (CCM) and the accompanying Consensus Assessments Initiative Questionnaire (CAIQ), and compile a set of security concepts before using it as a basis for classifying the providers' Web pages. The classification result roughly signifies the security conformance level of the providers. We demonstrate this method and present an evaluation using the case of five public cloud providers. © 2014 IEEE.
Jakarin Thaweejinda - One of the best experts on this subject based on the ideXlab platform.
-
semantic search for cloud providers with security conformance to cloud controls matrix
Computer Science and Software Engineering, 2014Co-Authors: Jakarin Thaweejinda, Twittie SenivongseAbstract:Prospective cloud consumers consider several quality attributes of cloud providers when selecting a cloud service. Security is a major quality attribute that is often used to differentiate between service offers from different cloud providers. cloud Security Alliance has published the cloud controls matrix (CCM) which contains security best practices and principles which cloud providers should follow to provide secure cloud services. This paper presents a semantic search framework for discovering cloud services which conform to the security controls in the CCM. In this framework, a security ontology is constructed from the CCM, and based on this security ontology, provider profiles can be built. A provider profile which presents relevant evidence of conformance to CCM security controls is then searched and ranked against a cloud consumer's query. cloud consumers then can determine and compare the degree of conformance of the cloud services to the CCM. In an experiment, the semantic search gives the search results that should be more useful to the consumers than normal text search.