Journal article icon

Journal article

Cyber supply chain risks in cloud computing – bridging the risk assessment gap

Abstract:
Cloud computing represents a significant paradigm shift in the delivery of information technology (IT) services. The rapid growth of the cloud and the increasing security concerns associated with the delivery of cloud services has led many researchers to study cloud risks and risk assessments. Some of these studies highlight the inability of current risk assessments to cope with the dynamic nature of the cloud, a gap we believe is as a result of the lack of consideration for the inherent risk of the supply chain. This paper, therefore, describes the cloud supply chain and investigates the effect of supply chain transparency in conducting a comprehensive risk assessment. We conducted an industry survey to gauge stakeholder awareness of supply chain risks, seeking to find out the risk assessment methods commonly used, factors that hindered a comprehensive evaluation and how the current state-of-the-art can be improved. The analysis of the survey dataset showed the lack of flexibility of the popular qualitative assessment methods in coping with the risks associated with the dynamic supply chain of cloud services, typically made up of an average of eight suppliers. To address these gaps, we propose a Cloud Supply Chain Cyber Risk Assessment (CSCCRA) model, a quantitative risk assessment model which is supported by decision support analysis and supply chain mapping in the identification, analysis and evaluation of cloud risks.
Publication status:
Published
Peer review status:
Peer reviewed

Actions


Access Document


Files:

Authors


More by this author
Institution:
University of Oxford
Division:
MPLS
Department:
Computer Science
Role:
Author
More by this author
Institution:
University of Oxford
Division:
Social Sciences Division
Department:
Said Business School
Role:
Author
More by this author
Institution:
University of Oxford
Division:
MPLS Division
Department:
Computer Science
Role:
Author


More from this funder
Funding agency for:
Akinrolabu, O
Grant:
EP/K004778/1


Publisher:
RonPub
Journal:
Open Journal of Cloud Computing More from this journal
Volume:
5
Issue:
1
Pages:
1-19
Publication date:
2017-11-23
Acceptance date:
2017-11-09
ISSN:
2199-1987


Language:
English
Keywords:
Pubs id:
pubs:812139
UUID:
uuid:751fc4ce-1cfb-45f9-b442-d6c76f099076
Local pid:
pubs:812139
Source identifiers:
812139
Deposit date:
2017-12-20

Terms of use



Views and Downloads






If you are the owner of this record, you can report an update to it here: Report update to this record

TO TOP