Traceability for Adaptive Information Security in the Cloud

Armstrong Nhlabatsi, Thein Thun, Niamul Khan, Yijun Yu, Arosha Bandara, Khaled Khan, Bashar Nuseibeh
2014 2014 IEEE 7th International Conference on Cloud Computing  
One of the key challenges in cloud computing is the security of the consumer data stored and processed by cloud machines. When the usage context of a cloud application changes, or when the context is unknown, there is a risk that security policies are violated. To minimize this risk, cloud applications need to be engineered to adapt their security policies to maintain satisfaction of security requirements despite changes in their usage context. We call such adaptation capability Adaptive
more » ... tion Security. The paper argues that one of the prerequisites to adaptive information security is the use of traceability as a means to understanding the relationship between security requirements and security policies. Using an example, we motivate the need for improving traceability in the development of cloud applications.
doi:10.1109/cloud.2014.141 dblp:conf/IEEEcloud/NhlabatsiTKYBKN14 fatcat:qz5pkf5nmzaa3ot7gsncynax3a