Centro de Documentação da PJ
Analítico de Periódico

CD 341
RIZVI, Zainab Batool, e outros
Analytical hierarchy process model for managing cloud security [Recurso eletrónico] / Zainab Batool Rizvi, Chaudry Bilal Ahmad Khan, Michael O’Sullivan
Information and Computer Security, Bingley, Vol. 32, n. 1 (2024), p. 93-111
Ficheiro de 764 KB em formato PDF.


SEGURANÇA INFORMÁTICA, INTERNET, BASE DE DADOS, PROCESSAMENTO DE DADOS

Purpose – This paper aims to explore key management actions for implementing security on the cloud, which is a critical issue as many organizations are moving business processes and data on it. The cloud is a flexible, low cost and highly available technology, but it comes with increased complexity in maintaining the cloud consumer’s security. In this research, a model was built to assist strategic decision-makers in choosing from a diverse range of actions that can be taken to manage cloud security. Design/methodology/approach – Published research from 2010 to 2022 was reviewed to identify alternatives to management actions pertaining to cloud security. Analytical hierarchical process (AHP) was applied to rate the most important action(s). For this, the alternatives, along with selection criteria, were summarized through thematic analysis. To gauge the relative importance of the alternatives, a questionnaire was distributed among cloud security practitioners to poll their opinion. AHP was then applied to the aggregated survey responses. Findings – It was found that the respondents gave the highest importance to aligning information security with business needs. Building a cloud-specific risk management framework was rated second, while the actions: enforce and monitor contractual obligations, and update organizational structure, were rated third and fourth, respectively. Research limitations/implications – The research takes a general view without catering to specialized industry-based scenarios. Originality/value – This paper highlights the role of management actions when implementing cloud security. It presents an AHP-based multi-criteria decision-making model that can be used by strategic decision-makers in selecting the optimum mode of action.