Building a Security Aware Cloud by Extending Internal Control to Cloud
Building a Security Aware Cloud by Extending Internal Control to Cloud
复制标题
将内控延伸至云端,构建安全感知云
DOI:
10.1109/isads.2011.48
复制
发表时间:
2011
期刊:
影响因子:
--
通讯作者:
Tanimoto Shigeaki
中科院分区:
文献类型:
--
作者:
SATO Hiroyuki;Kanai Atsushi;Tanimoto Shigeaki
Faced with today's innovative blow-up of cloud technologies, we are forced to rebuild services in terms of cloud. In the rebuilding, considering a facet of cloud as social infrastructure, security is a critical problem. Most of insecurity against clouds can be summarized as insecurity of management, which is classified into the multiple stakeholder problem, and the open space security problem. As a solution to these problems, we extend ISMS internal control to cloud by implementing trust base of security on IAM and key management. Because ISMS internal control is a source of trust, its extension to cloud can be an essential solution of security. Moreover, by controlling levels of quality of service and security by contract, we can optimize cost on service and security delegated to a cloud.