Journal article
Cyber supply chain risks in cloud computing – bridging the risk assessment gap
- Abstract:
- Cloud computing represents a significant paradigm shift in the delivery of information technology (IT) services. The rapid growth of the cloud and the increasing security concerns associated with the delivery of cloud services has led many researchers to study cloud risks and risk assessments. Some of these studies highlight the inability of current risk assessments to cope with the dynamic nature of the cloud, a gap we believe is as a result of the lack of consideration for the inherent risk of the supply chain. This paper, therefore, describes the cloud supply chain and investigates the effect of supply chain transparency in conducting a comprehensive risk assessment. We conducted an industry survey to gauge stakeholder awareness of supply chain risks, seeking to find out the risk assessment methods commonly used, factors that hindered a comprehensive evaluation and how the current state-of-the-art can be improved. The analysis of the survey dataset showed the lack of flexibility of the popular qualitative assessment methods in coping with the risks associated with the dynamic supply chain of cloud services, typically made up of an average of eight suppliers. To address these gaps, we propose a Cloud Supply Chain Cyber Risk Assessment (CSCCRA) model, a quantitative risk assessment model which is supported by decision support analysis and supply chain mapping in the identification, analysis and evaluation of cloud risks.
- Publication status:
- Published
- Peer review status:
- Peer reviewed
Actions
Authors
+ Engineering and Physical Sciences Research Council
More from this funder
- Funding agency for:
- Akinrolabu, O
- Grant:
- EP/K004778/1
- Publisher:
- RonPub
- Journal:
- Open Journal of Cloud Computing More from this journal
- Volume:
- 5
- Issue:
- 1
- Pages:
- 1-19
- Publication date:
- 2017-11-23
- Acceptance date:
- 2017-11-09
- ISSN:
-
2199-1987
- Language:
-
English
- Keywords:
- Pubs id:
-
pubs:812139
- UUID:
-
uuid:751fc4ce-1cfb-45f9-b442-d6c76f099076
- Local pid:
-
pubs:812139
- Source identifiers:
-
812139
- Deposit date:
-
2017-12-20
Terms of use
- Copyright holder:
- Akinrolabu et al
- Copyright date:
- 2017
- Notes:
-
Copyright © 2018 by the authors; licensee RonPub, Lubeck, Germany. This article is an open access article distributed under the terms and conditions of ¨
the Creative Commons Attribution license (http://creativecommons.org/licenses/by/4.0/).
- Licence:
- CC Attribution (CC BY)
If you are the owner of this record, you can report an update to it here: Report update to this record