Traceability for adaptive information security in the cloud
Date
2014Author
Nhlabatsi, ArmstrongThun, Thein
Khan, Niamul
Yu, Yijun
Bandara, Arosha
Khan, Khaled
Nuseibeh, Bashar
...show more authors ...show less authors
Metadata
Show full item recordAbstract
One of the key challenges in cloud computing is the security of the consumer data stored and processed by cloud machines. When the usage context of a cloud application changes, or when the context is unknown, there is a risk that security policies are violated. To minimize this risk, cloud applications need to be engineered to adapt their security policies to maintain satisfaction of security requirements despite changes in their usage context. We call such adaptation capability Adaptive Information Security. The paper argues that one of the prerequisites to adaptive information security is the use of traceability as a means to understanding the relationship between security requirements and security policies. Using an example, we motivate the need for improving traceability in the development of cloud applications.
Collections
- Computer Science & Engineering [2402 items ]