A framework to support selection of cloud providers based on security and privacy requirements

Haralambos Mouratidis, Shareeful Islam, Christos Kalloniatis, Stefanos Gritzalis
2013 Journal of Systems and Software  
Cloud Computing is an evolving paradigm that is radically changing the way humans store, share and access their digital files. Despite the many benefits, such as the introduction of a rapid elastic resource pool, and on-demand service, the paradigm also creates challenges for both users and providers. In particular, there are issues related to security and privacy, such as unauthorized access, loss of privacy, data replication and regulatory violation that require adequate attention.
more » ... s, and despite the recent research interest in developing software engineering techniques to support systems based on the cloud, the literature fails to provide a systematic and structured approach that enables software engineers to identify security and privacy requirements and select a suitable cloud service provider based on such requirements. This paper presents a novel framework that fills this gap. Our framework incorporates a modelling language and it provides a structured process that supports elicitation of security and privacy requirements and the selection of a cloud provider based on the satisfiability of the service provider to the relevant security and privacy requirements. To illustrate our work, we present results from a real case study.
doi:10.1016/j.jss.2013.03.011 fatcat:z6ekfy6jzjhoro6wj73fpp4uxa