Visible to the public Data Analysis of Cloud Security Alliance's Security, Trust & Assurance Registry

TitleData Analysis of Cloud Security Alliance's Security, Trust & Assurance Registry
Publication TypeConference Paper
Year of Publication2018
AuthorsSen, Amartya, Madria, Sanjay
Conference NameProceedings of the 19th International Conference on Distributed Computing and Networking
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-6372-3
Keywordscloud computing, composability, CSA STAR, Data Analyses, Human Behavior, information assurance, Metrics, policy-based governance, pubcrawl, Resiliency, risk assessment
AbstractThe security of clients' applications on the cloud platforms has been of great interest. Security concerns associated with cloud computing are improving in both the domains; security issues faced by cloud providers and security issues faced by clients. However, security concerns still remain in domains like cloud auditing and migrating application components to cloud to make the process more secure and cost-efficient. To an extent, this can be attributed to a lack of detailed information being publicly present about the cloud platforms and their security policies. A resolution in this regard can be found in Cloud Security Alliance's Security, Trust, and Assurance Registry (STAR) which documents the security controls provided by popular cloud computing offerings. In this paper, we perform some descriptive analysis on STAR data in an attempt to comprehend the information publicly presented by different cloud providers. It is to help clients in more effectively searching and analyzing the required security information they need for the decision making process for hosting their applications on cloud. Based on the analysis, we outline some augmentations that can be made to STAR as well as certain specific design improvements for a cloud migration risk assessment framework.
URLhttp://doi.acm.org/10.1145/3154273.3154343
DOI10.1145/3154273.3154343
Citation Keysen_data_2018