:::

詳目顯示

回上一頁
題名:一個基於ISO 31010評估標準的雲端風險評估方法
書刊名:電腦稽核
作者:連志誠 引用關係陳怡安游宗憲
出版日期:2012
卷期:26
頁次:頁1-9
主題關鍵詞:雲端運算風險評估Cloud computingRisk assessmentWindows azureISO 31010
原始連結:連回原系統網址new window
相關次數:
  • 被引用次數被引用次數:期刊(0) 博士論文(0) 專書(0) 專書論文(0)
  • 排除自我引用排除自我引用:0
  • 共同引用共同引用:0
  • 點閱點閱:9
雲端運算時代來臨,企業紛紛走入雲端運算領域,將服務建置於雲端環境中,降低IT進入門檻,節省龐大的硬體設備費用。然而歐洲網路與資訊安全局(European Network and Information Security Agency, ENISA)針對企業對雲端觀點調查指出,安全成為許多企業的重要考量(Alessandro Perilli et.al.2010)。因此為了提升客戶對雲端供應商提供服務之信任,風險評估已成為採用雲端服務的重要程序之一。目前雲端服務風險評估的研究鮮少,無法顯示服務造成損失和評估標準。因此本研究以目前雲端供應商微軟的Windows Azure服務元件進行探討,基於ISO 31010定義風險評估之準則,提出雲端服務之風險評估方法,使用監控機制即時更新雲端環境之風險發生機率,並利用金額量化評估結果,顯示雲端服務對企業造成的損失,作為企業採用雲端服務之決策依據。
Enterprise could easily configure services from cloud computing with low upfront investments of hardware and equipment. Nevertheless, ENISA (European Network and Information Security Agency) researches on cloud services show that the security concern is the most important point for enterprise adoption of cloud services. To achieve this, risk assessment becomes a main of procedures to improve the trust of cloud services for users. In this paper, we propose an approach to assess the risk associated with applying a cloud service, exemplified by Windows Azure and based on principle of risk assessment from ISO 31010. Our approach could monitor the probability of risk of the related services, and present the quantitative risk in corresponding money loss, which then can be used to support decision making of adoption of the service.
期刊論文
1.Hwang, Kai、Li, Deyi(2010)。Trusted Cloud Computing with Secure Resources and Data Coloring。IEEE Internet Computing,14(5),14-22。  new window
2.Pallis, G.(2010)。Cloud computing: The new frontier of internet computing。IEEE Internet Computing,14(5),70-73。  new window
3.Garvey, Paul R.(2001)。Implementing a Risk Management Process for a Large Scale Information System Upgrade--A Case Study。INSIGHT,4。  new window
4.Pauley, W. A.(2010)。Cloud provider transparency: An empirical evaluation。SECURITY & PRIVACY,8(6),32-39。  new window
會議論文
1.Saripalli, K. P.、Mahasenan, N. M.、Cook, E. M.(2003)。Risk and hazard assessment for projects involving the geological sequestration of co2。Sixth International Greenhouse Gas Control Conference,285-289。  new window
2.Saripalli, Prasad、Walters, Ben(2010)。Quirc: A quantitative impact and risk assessment framework for cloud security。The 2010 IEEE 3rd international conference on cloud computing。Miami, Florida。280-288。  new window
3.Cha, Shi-Cho、Liu, Li-Ting、Yu, Bo-Chen(2009)。Process-oriented approach for validating asset value for evaluating information security risk。Computational Science and Engineering International Conference。  new window
4.Bleikertz, Soren(2010)。Security audits of multi-tier virtual infrastructures in public infrastructure clouds。Cloud computing security workshop。  new window
5.Mahmood, Zaigham(2011)。Data location and security issues in cloud computing。International Conference on Emerging Intelligent Data and Web Technologies。  new window
圖書
1.NIST(2009)。Recommended security controls for federal information systems and organizations。  new window
2.方國偉、趙立威(2011)。讓雲觸手可及--微軟雲端運算實踐指南。臺北:博碩文化股份有限公司。  延伸查詢new window
3.Perilli, Alessandro(2010)。ENSIA report on cloud computing security risk assessment。  new window
4.Agarwwal, Anurag(2008)。OWASP testing guide。  new window
5.Sosinsky, Barrie(2011)。Computing Bible。Wiley Publishing。  new window
6.Cloud Security Alliance(2009)。Security guidance for critical areas of focus in cloud computing。  new window
7.Li, Henry(2009)。Introduction to Windows Azure。Apress。  new window
8.Ahronovitz, Miha(2010)。Cloud computing use cases。  new window
9.Garvey, Paul R.(2009)。Analytical methods for risk management--A systems engineering perspective。CRC Press。  new window
10.Krishnan, Sriram(2010)。Programming Windows Azure。O'Reilly。  new window
11.Redkar, Tejaswi(2009)。Windows Azure Platform。Apress。  new window
其他
1.Gens, Frank(2009)。IDC cloud computing 2010-an idc update,http://www.idc.com/prodserv/idc_cloud.jsp。  new window
2.IEC & ISO(2009)。IEC/FDIS 31010-Risk management-Risk assessment techniques,http://www.previ.be/pdf/31010_FDIS.pdf。  new window
3.IEC & ISO(2008)。ISO/IEC 27005:2008,http://www.iso.org/iso/。  new window
 
 
 
 
第一頁 上一頁 下一頁 最後一頁 top
QR Code
QRCODE