Information Security and Risk Management of Cloud Services: Guidelines and Recommendations for Organizations
Full text
Tommi Törmänen INFORMATION SECURITY AND RISK MANAGEMENT OF CLOUD SERVICES: GUIDELINES AND RECOMMENDATIONS FOR ORGANIZATIONS JYVÄSKYLÄN YLIOPISTO INFORMAATIOTEKNOLOGIAN TIEDEKUNTA 2024
ABSTRACT Törmänen, Tommi Information Security and Risk Management of Cloud Services: Guidelines and Recommendations for Organizations. Jyväskylä: University of Jyväskylä, 2024, 86 pp. Cyber Security, Master’s Thesis Supervisor(s): Viinikainen, Ari Cloud solutions have been the standard IT platform for over a decade and are increasingly adopted by organizations and consumers. Despite the strong trend of users and organizations moving to cloud solutions, cloud security remains a significant issue and a longstanding debate among both academics and practitioners, and many organizations are still hesitant to adopt cloud solutions due to security concerns. The objective for this thesis was to improve awareness among organizations regarding the security risks associated with cloud computing and the methods and tools available to mitigate these risks. The study aimed to answer one main research question: “What should organizations take into account regarding information security when deploying and managing cloud services?”, and one sub-research question: “What information security risks can the use of cloud services cause for organizations?”. The structure of the thesis encompasses a thorough literature review, followed by an empirical case study. The numerous challenges associated with cloud security highlight the critical need for organizations to implement robust security controls, conduct comprehensive risk assessments, and ensure continuous monitoring and development of their cloud environments. It is essential for organizations to remain adaptive and commit to continuous improvement to ensure that cloud security evolves alongside the cloud environment and the surrounding threat landscape. Organizations should adopt a comprehensive and multilayered approach to cloud security, adhering to the defense-in-depth principles. This includes ensuring that security is integrated into every layer of the cloud architecture by design. Keywords: cloud computing, cloud services, information security, risk management
TIIVISTELMÄ Törmänen, Tommi Pilvipalveluiden tietoturva ja riskienhallinta: Ohjeet ja suositukset organisaatioille Jyväskylä: Jyväskylän yliopisto, 2024, 86 s. Kyberturvallisuus, pro gradu -tutkielma Ohjaaja: Viinikainen, Ari Pilviratkaisut ovat olleet standardi IT-alusta yli vuosikymmenen ajan, ja organisaatiot sekä kuluttajat ottavat niitä käyttöön yhä enenevissä määrin. Huolimatta kuluttajien ja organisaatioiden vahvasta suuntauksesta siirtyä pilviratkaisuihin, pilven tietoturva on edelleen merkittävä ongelma ja pitkäaikainen keskustelunaihe sekä tutkijoiden että ammattilaisten keskuudessa. Monet organisaatiot epäröivät edelleen ottaa pilviratkaisuja käyttöön tietoturvaongelmien vuoksi. Tämän pro gradu -tutkielman tavoitteena oli lisätä organisaatioiden tietoisuutta pilvipalveluihin liittyvistä tietoturvariskeistä sekä käytettävissä olevista menetelmistä ja työkaluista näiden riskien hallitsemiseksi. Tutkimuksen tavoitteena oli vastata yhteen päätutkimuskysymykseen: "Mitä organisaatioiden tulisi ottaa huomioon tietoturvan osalta pilvipalveluiden käyttöönotossa ja hallinnassa?”, sekä yhteen apututkimuskysymykseen: "Mitä tietoturvariskejä pilvipalveluiden käyttö voi aiheuttaa organisaatioille?". Opinnäytetyön rakenne käsittää perusteellisen kirjallisuuskatsauksen, jota seuraa empiirinen tapaustutkimus. Pilven tietoturvaan liittyvät lukuisat haasteet korostavat organisaatioiden kriittistä tarvetta toteuttaa vaikuttavia tietoturvakontrolleja, suorittaa kattavia riskinarviointeja, ja varmistaa pilviympäristöjensä jatkuva valvonta sekä kehitystyö. Organisaatioiden on tärkeää pysyä mukautuvina ja sitoutua jatkuvaan parantamiseen varmistaakseen, että pilven tietoturva kehittyy pilviympäristön ja ympäröivän uhkaympäristön mukana. Organisaatioiden tulisi omaksua kattava ja monitasoinen lähestymistapa pilven tietoturvaan noudattaen syvyyssuuntaisen suojauksen periaatteita. Tähän sisältyy sen varmistaminen, että tietoturva on integroitu pilviarkkitehtuurin jokaiseen kerrokseen suunnitellusti. Asiasanat: pilvilaskenta, pilvipalvelut, tietoturvallisuus, riskienhallinta
FIGURES Figure 1 Attitude towards cloud services. ............................................................... 47 Figure 2 Ability to influence the security level of cloud services in use. ............ 51 TABLES Table 1 Used cloud service delivery models. .......................................................... 45 Table 2 Used cloud deployment models. ................................................................. 46 Table 3 Provided cloud service delivery models .................................................... 46 Table 4 Provided cloud deployment models. .......................................................... 46 Table 5 Importance of generally associated benefits with the adoption of cloud services compared to traditional information systems. ......................................... 48 Table 6 Benefits of cloud services in risk management and security. .................. 49 Table 7 Most important factors to ensure the level reliability and security of a CSP. ................................................................................................................................ 50 Table 8 How should risk management and security be taken into account in contracts with the CSPs. ............................................................................................. 50 Table 9 Significance of people related risks to cloud security. ............................. 52 Table 10 Significance of processes related risks to cloud security........................ 54 Table 11 Significance of technology related risks to cloud security. .................... 55 Table 12 Importance of people related security controls to cloud security. ....... 56 Table 13 Importance of processes related security controls to cloud security.... 57 Table 14 Importance of technology related security controls to cloud security. 60
TABLE OF CONTENT ABSTRACT ...................................................................................................................... 2 TIIVISTELMÄ ................................................................................................................. 3 FIGURES .......................................................................................................................... 4 TABLES ............................................................................................................................ 4 TABLE OF CONTENT ................................................................................................... 5 1 INTRODUCTION ................................................................................................. 7 2 CLOUD COMPUTING ....................................................................................... 10 2.1 Definition .................................................................................................... 11 2.2 Actors ........................................................................................................... 12 2.3 Service Delivery and Deployment Models ............................................ 12 2.4 Cloud Architecture .................................................................................... 15 2.5 Advantages ................................................................................................. 17 3 CLOUD SECURITY AND RISKS ...................................................................... 19 3.1 Confidentiality, Integrity, and Availability ........................................... 21 3.2 Cloud Security Management ................................................................... 23 3.3 Visibility and Transparency ..................................................................... 26 3.4 Multi-tenancy and Virtualization ............................................................ 28 3.5 Network Security & Cryptography......................................................... 29 3.6 Web Application & API Security ............................................................. 31 3.7 Identity Management and Access Control ............................................. 33 3.8 Human Factors ........................................................................................... 35 3.9 Incident Management and Forensics ...................................................... 37 4 RESEARCH METHODOLOGY ........................................................................ 39 4.1 Research Methods ...................................................................................... 40 4.2 Implementation and Data Collection ...................................................... 41 5 SURVEY RESULTS & ANALYSIS .................................................................... 45 5.1 Benefits of Cloud Services ........................................................................ 47 5.2 Choosing a Cloud Service Provider ........................................................ 49 5.3 Security of Cloud Services ........................................................................ 51 5.4 Cloud Security Risks ................................................................................. 52 5.5 Protection of Cloud Services .................................................................... 55 6 DISCUSSION ....................................................................................................... 61
7 CONCLUSION .................................................................................................... 65 REFERENCES ................................................................................................................ 67 APPENDIX 1: SURVEY TEMPLATE ......................................................................... 73
1 INTRODUCTION Most of us use cloud services on a daily basis without realizing it or giving it a second thought, such as services like Microsoft 365, Gmail, and iCloud (Chauhan & Shiaeles, 2023). Given that Amazon Web Services, Google Cloud, and Microsoft Azure are considered the most popular cloud service providers, it is likely more challenging to find an organization that does not utilize some of their services to some extinct than one that does (Qazi, 2023). Indeed, cloud solutions have been the standard IT platform for over a decade and are increasingly adopted by organizations and consumers, with more workloads continuously migrating from traditional storage to the cloud. (Gururaj et al., 2017: Mandal & Khan, 2021). Cloud computing fundamentally relies on virtualization and distributed computing technology, integrating IT resources such as computing power, storage, and networking into high-performance services that customers can access over networks, paying only for what they use on an on-demand basis (Khan & Al-Yasiri, 2016; Mandal & Khan, 2021; Xiaojun & Qiaoyan, 2010). The success of cloud computing is driven by a combination of market and technology factors (Coppolino et al., 2017; Rebollo et al., 2015). Organizations operate in a constantly evolving environment and must quickly adapt their IT operations to keep pace (Coppolino et al., 2017; Mandal & Khan, 2021). The number of services and applications being deployed and decommissioned is continuously rising, and the availability of cheaper processors, lower latency networks, and advancements in virtualization technologies are encouraging organizations to shift their operations from local IT platforms to distributed cloud environments (Coppolino et al., 2017; Rebollo et al., 2015). Especially for small and medium businesses, cloud solutions provide a cost-effective and low barrier access to industry best practice tools and resources fast, which would otherwise be out of their reach (Morsy et al., 2016: Subashini & Kavitha, 2010). In addition to cost-efficiency, cloud solutions offer organizations multiple other attractive benefits, such as operational efficiency and the ability to quickly acquire or dispose of resources like storage and
8 memory (Avram, 2014; Beckers et al., 2013; Chang et al., 2016; Mandal & Khan, 2021; Somorovsky et al., 2011). Despite the strong trend of users and organizations moving to cloud solutions, cloud security remains a significant issue and a longstanding debate among both academics and practitioners (Singh & Chatterjee, 2017; Subramanian & Tamilselvan, 2019; Xiaojun & Qiaoyan, 2010). Cloud security ranks among the top priorities for organizations because if the security level is inadequate, the cloud services and resources may not be reliable, compromising the security of data, applications, and infrastructure stored in the cloud (Alassafi et al., 2017; Chang et al., 2016; Chauhan & Shiaeles, 2023; Mandal & Khan, 2021). Simultaneously, academics consider cloud security an important research topic due to its complexity and significant impact on numerous stakeholders (Singh et al., 2016; Somorovsky et al., 2011). The appeal of cloud solutions as targets for criminals and other malicious groups is evident, given that organizations and consumers are increasingly migrating valuable data and services to the cloud (Mandal & Khan, 2021; Subashini & Kavitha, 2010).This is just one of the reasons for the phenomenon where despite the fact that cloud solutions have been widely in use for over a decade, many organizations are still hesitant to adopt cloud solutions due to security concerns (Arora et al., 2017; Beckers et al., 2013; Sun, 2018; Xiaojun & Qiaoyan, 2010; Zissis & Lekkas, 2012). In the midst of the flood of information and offers related to cloud security solutions, it can be difficult for organizations to understand what should be treated as essential, which information security controls should they focus on, and which guidelines or frameworks to rely on (Kalaiprasath et al., 2017). From an organizational perspective, the problem can be considered to be multidimensional, and among other things, it is concretized in the form of shortage of talent, lack of maturity, conflicting best practices and frameworks, and complex commercial structures of the service providers and suppliers (Gururaj et al., 2017; Zhu et al., 2012). The complexity is heightened because, despite cloud solutions sharing many fundamental components and technologies with traditional IT systems, traditional security mechanisms and controls may prove to be ineffective and inefficient with cloud environments (Khalil et al., 2014; Zissis & Lekkas, 2012). Coppolino et al. (2017) suggest that for cloud solutions to be considered a viable alternative, their security level should match or exceed that of traditional IT systems. Achieving this requires raising awareness about the security issues associated with cloud computing and the methods and tools available to mitigate these risks (Coppolino et al., 2017). This thesis aims to assist organizations on this objective by examining the security risks in cloud computing and identifying how and why these risks should be addressed when adopting or using cloud services.
9 The scope of the study is primarily limited to organizations operating in the private sector, although the findings can also be applicable to public sector organizations to a certain extent. Industry-specific regulations and mandatory standards are excluded from the scope of the study. When examining specific cloud platforms and their technical features, the scope is limited to the largest and most widely used platforms, namely Amazon Web Services, Google Cloud Platform, and Microsoft Azure (Wright et al., 2023). Since English is not the author's native language, the artificial intelligence (AI) based text editor ChatGPT was used to improve the readability of the thesis and to ensure grammatical correctness (OpenAI, 2024). However, ChatGPT or other AI-based tools were not used for any other purposes, such as serving as a scientific source or generating content from scratch. The use of ChatGPT during the thesis work was strictly limited to rephrasing sentences the author had first produced himself or written based on academic articles and other scientific sources. The sentences rephrased by ChatGPT were then carefully reviewed by the author to ensure that the content was not distorted, and they were factually correct. The rephrased sentences were mostly used as they were or modified by the author if deemed necessary. The structure of the thesis is organized as follows: the second and the third chapter form the literature review section of the thesis. The second chapter first introduces the definition of cloud computing and cloud services, describes the actors involved, and explores the service delivery and deployment models used in cloud computing. Towards the end of the second chapter, it identifies and explains the basic elements of cloud architecture, followed by a concise overview of the advantages organizations can gain through the adoption of cloud solutions. The third chapter describes the typical risks associated with cloud security from the organizations’ perspective and describes potential security measures than can be employed to mitigate these risks. The empirical section of the thesis begins from the fourth chapter, focusing on the research methods used in the study, their implementation, and the process of data collection using a survey. The fifth chapter presents the survey results and their analysis. Finally, the study's findings are discussed in the sixth chapter, followed by a conclusion of the thesis in the seventh chapter.
16 with each VM running its own operating system and applications, functioning independently of the other VMs (Amazon Web Services, 2024b; Broadcom, 2024b). VMs are stored to the host machine as image files, which can be easily moved to another device, copied or cloned (Singh & Chatterjee, 2017). VMs can be accessed with a software called a hypervisor, which enables one physical host computer to run multiple VMs by virtually allocating the underlying hardware resources to individual VMs as required and connecting multiple VMs with each other if needed (Amazon Web Services, 2024b; Broadcom, 2024a; Singh & Chatterjee, 2017). This can be used to facilitate multi-tenancy, which allows multiple customers or users from the same or different organizations to share resources and applications without visibility or access to each other’s data (Singh et al., 2016). Multi-tenant applications make it possible for each tenant to individually manage various features of the application, such as user interface and access control (Singh & Chatterjee, 2017). The PaaS model covers the platform layers, APIs, and service layers. PaaS layer is dependent on the virtualization of resources provided by the IaaS layer (Morsy et al., 2016). The increasing use of mobile devices and the popularity of APIs are one of the key reasons for the exponential growth of cloud computing services and more and more organizations migrating their data to the cloud (Qazi, 2023). An API serves as a software interface enabling digital devices, software applications, and data servers to communicate and interact with each other, and today the majority leading cloud platforms utilize APIs to manage all their user-related operations, such as identity management (Qazi, 2023). Cloud APIs enable the development of cloud infrastructure, software, services, and applications for many cloud platforms, and can be provided as an IaaS API to support the provision of computing and storage, SaaS API to connect to software or applications, or PaaS API to create applications and software. APIs rely on set protocols such as Simple object access control (SOAP) and representation state transfer (REST) which define how applications or databases can establish connections and communicate with each other. SOAP API protocol is more commonly used by security critical organizations as it is considered more secure than REST API protocol, which lacks the inherent security features and extensions found in SOAP, thus relying on the APIs themselves when it comes to security. GraphQL is a newer query language API standard introduced by Facebook that serves as an alternative to REST API and has some additional features compared REST, such as security measures, but is considered to be slow when executing large or complicated queries and prone to complex security implications. (Qazi, 2023) On the top of the layer stack, the SaaS model includes the applications and services provided to the end users. SaaS layer relies on the PaaS layer to host the services and IaaS layer to optimize resource utilization for multi-tenant delivery (Morsy et al., 2016). The application level is located at the topmost level, directly delivering the software to the users through an interface without the
17 need to install the software to client devices (Singh et al., 2016). The applications themselves are developed using the programming interfaces of the services located on the PaaS layer, which are accessible through the internet and often involve multiple intercommunicating cloud components (Jansen, 2011). An additional layer called the middleware layer resides between the application layer and the underlying platform, providing services from database servers to the software applications (Singh et al., 2016). Singh et al. (2016) characterize middleware as the glue software program that simplifies the implementation of communication for software developers within a cloud environment, and it is considered to be one of the standard technologies used to build cloud environments (Singh & Chatterjee, 2017). 2.5 Advantages Cloud computing can offer significant benefits for both individuals and organizations (Khalil et al., 2014). The growing complexity of managing software and IT infrastructure results in computing becoming increasingly more expensive for organizations, especially small and medium-sized ones (Esposito & Castiglione, 2016). Cloud solutions give organizations the opportunity to outsource their IT infrastructures to a CSP, by utilizing cost-effective, scalable, and location-independent platforms (Rizvi et al., 2017). This enables organizations to decrease their IT costs which is usually the main goal for organizations planning on migrating to the cloud, while it simultaneously eases the burden from managing and maintaining their own in-house IT infrastructure (Alassafi et al., 2017; Esposito & Castiglione, 2016; Rizvi et al., 2017). The basic business principle for cloud computing adheres to a simple pay-for-use pricing model, offering customers the ability to reduce their expenditure by provisioning a specific amount of resources, which are provided to the customer as on-demand service (Singh et al., 2016). This way cloud computing can also reduce the barrier to entry for smaller firms and presents a considerable opportunity for many developing countries that have lacked the resources and have not been fully able to participate in the IT revolution before (Avram, 2014). Avram (2014) emphasizes that cloud computing can also reduce IT barriers to innovation and enables the emergence of novel applications and services. Cloud solutions can provide nearly instant access to hardware resources with reduced capital investments, and this way also accelerating deployment and time to market for businesses (Avram, 2014; Esposito & Castiglione, 2016). Rapid elasticity is considered as one of the main characteristics of cloud computing (Mell & Grance, 2011), and it means that resources and services can be quickly scaled up and down for customers and users (Avram, 2014; Beckers et al., 2013). The cloud combines resources such as storage, processing, memory,
18 virtual machines, and network bandwidth into a unified pool, and can dynamically allocate and reallocate them according to the customers’ needs and use, while similarly optimizing utilization of existing resources of the CSP (Beckers et al., 2013; Esposito & Castiglione, 2016; Zissis & Lekkas, 2012). Cloud solutions usually feature advanced security technologies and controls that can be implemented throughout the cloud, mostly available as a result due to data centralization and universal architecture (Alassafi et al., 2017; Zissis & Lekkas, 2012). Together with the automation capabilities and CSPs typically more extensive security resources, this often results in more advanced security capabilities than could be achieved with traditional in-house IT structures and models, managed by a group of people with various other responsibilities (Butt et al., 2022; Khalil et al., 2014; Mandal & Khan, 2021; Zissis & Lekkas, 2012).
19 3 CLOUD SECURITY AND RISKS While there are numerous unique advantages to adopting cloud solutions, there are also unique challenges which cannot be ignored, with security being one of the key concerns (Avram, 2014; Coppolino et al., 2017; Esposito & Castiglione, 2016; Singh et al., 2016; Soms et al., 2022). Cloud security still poses a major concern for organizations, and many remain hesitant to adopt cloud solutions fearing that their sensitive information or critical services could be compromised (Morsy et al., 2016; Singh et al., 2016; Subramanian & Tamilselvan, 2019). This highlights the importance of cloud security and the necessity to enhance security in the cloud environment to speed up the adoption of cloud services and to address regulatory requirements (Esposito & Castiglione, 2016; Subashini & Kavitha, 2010; Subramanian & Tamilselvan, 2019). The amount of security attacks targeting cloud solutions continues to rise as the cloud has become an increasingly appealing target for attackers due to its high adoption rate and the valuable resources stored in and supported by the cloud (Mandal & Khan, 2021; Khalil et al., 2014; Singh et al., 2016). Especially the upper layers of the cloud, for which cloud customers are responsible, have become more susceptible to attacks, primarily due misconfigurations and human errors (Torkura et al., 2021). The potential of cloud computing has not gone unnoticed from the attackers either and the attackers are leveraging the cloud infrastructure as well to carry out attacks (Duncan, 2020; Singh & Chatterjee, 2017). Jansen (2011) equated data to the currency of 21st century and cloud environments to the banks where the currency is kept. Similarly to traditional banks became attractive targets for robbers, the cloud environments are also attractive to the modern-day cyber criminals and other threat agents. The attack vectors associated with cloud computing are similar to those threatening traditional network and computer security (Sun, 2018), and are mainly focusing either on network, hypervisor, or hardware layers (Coppolino et al., 2017). The attackers, also known as threat agents, may consist of internal users, external parties, and even the CSP itself can function as a threat agent (Coppolino et al., 2017; Singh & Chatterjee, 2017). External threat agents primarily execute attacks over networks, whereas internal threat agents, also
20 referred as malicious insiders, have the capability to launch attacks from within the cloud infrastructure, functioning as internal users or employees of the CSP, for example (Coppolino et al., 2017). In information security, it is crucial to understand the requirements and specific security needs in order to be able to design sufficient security solutions (Zissis & Lekkas, 2012). However, in the distributed environment of the cloud, with multiple users possessing diverse security requirements and needs, which the CSP is not always aware of, the cloud presents a unique security challenge and demands considerable expenses and resources from the CSPs (Almorsy et al., 2011; Arora et al., 2017; Morsy et al., 2016; Zissis & Lekkas, 2012). From the cloud customers perspective lack of visibility and transparency can also lead to security issues. Due to transparency issues in a multi-tenant environment, many CSPs do not permit customers to implement their own security monitoring or intrusion detection systems into the IaaS layer (Singh & Chatterjee, 2017). The complexity of the cloud infrastructure, comprised of technology, processes, personnel, and commercial constructs, generates a vast landscape of potential vulnerabilities and requires a holistic security strategy (Duncan, 2020; Gururaj et al., 2017; Singh & Chatterjee, 2017; Somorovsky et al., 2011). Each cloud computing service delivery model has different level of security requirements, and just as capabilities are inherited between them, so are the information security issues and risks (Morsy et al., 2016; Subashini & Kavitha, 2010). Past research has extensively researched and documented the risks and vulnerabilities related to cloud computing, and each CSP and customer must implement countermeasures and security controls to mitigate the risks according to their assessment (Gururaj et al., 2017; Singh & Chatterjee, 2017). The primary purpose of security controls is to maintain security in the cloud infrastructure (Soms et al., 2022). Organizations should first fully understand their users’ activities in the cloud and identify potential attack surfaces and weaknesses before assessing which native and third-party controls will be the most effective on preventing and responding to threats identified (Duncan, 2020; Singh & Chatterjee, 2017). Elasticity and multi-tenancy are one of the cloud’s key characteristics, but both have significant implications for the security of the cloud (Morsy et al., 2016; Singh et al., 2016; Subramanian & Tamilselvan, 2019). The cloud utilizes virtualization to achieve multi-tenancy, but VMs and hypervisors, like any other software, contain vulnerabilities posing a direct threat to the security and privacy of cloud services (Singh & Chatterjee, 2017). However, CSPs have enhanced the security of the IaaS layer over the years to that extent that attacks at this layer are now less common (Torkura et al., 2021). The nature of the cloud still inherently promotes information sharing, which in turn heightens the risk of unauthorized access to other users’ content and information (Subramanian & Tamilselvan, 2019).
21 Interoperability between cloud platforms also remains a challenge, as many CSPs have not yet developed seamless compatibility (Rizvi et al., 2017). This complicates data and application migration between different platforms and providers, heightening the risk of vendor lock-in for organizations (Rizvi et al., 2017; Singh & Chatterjee, 2017). Lack of interoperability can also prevent organizations from deploying different cloud platforms for different applications and tools, or result in organizations being unable to deploy for example their existing security and identity management policies and tools for applications running on different cloud platforms (Avram, 2014; Rizvi et al., 2017). Portability is another cloud specific issue worth to mention, and it refers to the ability to transfer data and applications among CSPs with as minimal integration challenges as possible (Rizvi et al., 2017). Organizations are increasingly dependent on cloud solutions for their daily operations, storing significant amounts of data in the cloud (Rizvi et al., 2017). There are number of reasons why the organizations might find themselves looking into migrating their data to another cloud platform, making portability a critical enabler for wide adoption of cloud computing, which organizations need to carefully consider when selecting a CSP (Avram, 2014; Rizvi et al., 2017). In addition to cloud specific threats, Butt et al. (2022) identifies traditional information and network related threats as major risks of cloud computing. Consequently, the security controls used to protect the cloud are somewhat similar to those used in traditional IT, but do not necessarily fully address the risks affiliated with cloud computing (Deyan & Hong, 2012; Khan & Al-Yasiri, 2016). The basic principles of information security also apply in cloud security, with the objective being to protect of the confidentiality, integrity, and availability of cloud assets (Butt et al., 2022; Chauhan & Shiaeles, 2023; Deyan & Hong, 2012; Rao & Selvamani, 2015; Singh & Chatterjee, 2017; Zissis & Lekkas, 2012). 3.1 Confidentiality, Integrity, and Availability In cloud computing it’s common for users of the cloud solutions to share and store their information on remote servers owned and operated by third parties and accessed via the internet or other networks. The material stored and shared in the cloud can be anything from sensitive personal identifying information (PII) to operation critical business information and governmental information. The risks naturally vary depending on the cloud customer and the information, but it is obvious that when individuals or organizations handle or store information in the cloud, concerns about confidentiality are usually present as well. (Rao & Selvamani, 2015; Subashini & Kavitha, 2010). Confidentiality means that the information assets can only be accessed by authorized parties or systems, often associated with authentication in the cloud context (Singh & Chatterjee, 2017; Zissis & Lekkas, 2012). The complex nature of
22 the cloud and various parties, devices, and applications being involved, leads to an increased amount of access points and an expanded attack surface, therefore also increasing the risk of the data being compromised (Singh & Chatterjee, 2017; Zissis & Lekkas, 2012). Software confidentiality is another term related to cloud security, indicating trust in specific applications or processes to manage and handle data securely (Zissis & Lekkas, 2012). For instance, the elasticity of cloud environments could potentially result to software confidentiality issues, as the scaling of a tenant’s resources may provide other tenants with the opportunity to utilize resources that were previously allocated to another tenant (Morsy et al., 2016). Integrity is considered as one of the key elements of information security, and insufficient integrity controls can lead to serious issues regardless of the system in question (Subashini & Kavitha, 2010; Zissis & Lekkas, 2012). Integrity refers to that information assets can only be modified by authorized parties, while data integrity aims to ensure the protection of data against unauthorized deletion, modification, or fabrication, which all can be done intentionally or by accident (Singh & Chatterjee, 2017; Zissis & Lekkas, 2012). Achieving data integrity is much easier in standalone systems having a single database, when comparing to a distributed systems with multiple databases such as the cloud environment (Subashini & Kavitha, 2010). Ensuring data integrity in a cloud setting requires preventing unauthorized access to data and managing transactions across multiple data sources in a fail-safe manner, as well as automated controls that check and verify that the integrity of data remains uncompromised (Butt et al., 2022; Subashini & Kavitha, 2010; Zissis & Lekkas, 2012). Availability means that the IT resources can be accessed and used by authorized entities, even in the case of possible security events and incidents such as errors or breaches, and the system will operate as needed when needed (Gururaj et al., 2017; Jansen, 2011; Singh & Chatterjee, 2017; Zissis & Lekkas, 2012). When people are talking about availability they usually refer primarily to software and data, but it applies to network and hardware infrastructure as well (Singh ym., 2016; Zissis & Lekkas, 2012). A single hardware failure could potentially affect the availability of the whole system (Singh & Chatterjee, 2017). CSPs need to ensure that cloud services are available 24/7 as the daily operations of many organizations depend on cloud services, thus making high availability level of the services crucial (Avram, 2014; Singh & Chatterjee, 2017; Subashini & Kavitha, 2010; Xiaojun & Qiaoyan, 2010; Zissis & Lekkas, 2012). This requires an infrastructure that supports load-balancing, resiliency to hardware and software failures, and also against malicious influencing such as denial of service attacks (Singh et al., 2016; Subashini & Kavitha, 2010). The risk of permanent or accidental loss of data stored in the cloud is known as the data loss threat, which is an important concern for cloud security (Butt et al., 2022; Chauhan & Shiaeles, 2023). Despite the numerous data
23 redundancy and backup systems offered by the cloud, there are still circumstances that can lead to data loss (Chauhan & Shiaeles, 2023). Examples of factors leading to data loss include intentional and unintentional data deletion or alteration without a backup of the original content, loss of encoding key for encrypted data, and hardware failure (Butt et al., 2022; Kalaiprasath et al., 2017; Singh & Chatterjee, 2017). Any unplanned incidents and emergencies need to be addressed with robust business continuity and disaster recovery plans to ensure that the data is not compromised, and possible downtime and disruptions to business remain as low as possible (Avram, 2014; Chauhan & Shiaeles, 2023; Singh & Chatterjee, 2017; Subashini & Kavitha, 2010; Zhu et al., 2012). Organizations should assess and take into consideration the reliability of the cloud services utilized when designing and implementing business continuity and disaster recovery plans (Jansen, 2011). For mission-critical operations and services dependent on cloud services, besides multi-location data replication processes organizations should consider alternative services, equipment, and locations as backup options in the event of prolonged or permanent outages (Chauhan & Shiaeles, 2023; Jansen, 2011; Singh et al., 2016). CSPs are usually responsible for taking regular backups of customer data to enable quick recovery in the event of disasters, but also to take care that the backup data is safeguarded at least with same level protection as the original data (Singh & Chatterjee, 2017; Singh et al., 2016; Subashini & Kavitha, 2010). 3.2 Cloud Security Management Cloud computing involves numerous stakeholders, a deep and complex dependency stack, and a high amount of security controls, making cloud security management a complicated task (Morsy et al., 2016). Security policies form the foundation of cloud security (Chang et al., 2016). They are aligned with the organization’s security goals and designed to mitigate risks (Chang et al., 2016; Torkura et al., 2021). Organizations should design their security policies and guidelines based on their risk analysis and use them as a standard when planning and implementing the required security controls (Singh & Chatterjee, 2017; Singh et al., 2016). The adoption of cloud solutions will most likely impact the organization’s IT team (Avram, 2014; Gururaj et al., 2017). The roles and responsibilities may evolve, and new skill sets are likely required to effectively maintain cloud controls and to mitigate cloud related IT risks (Avram, 2014). The IT team may also face unforeseen risks. For instance, developers working in the R&D teams might create new accounts or make changes that suit their needs without security or visibility to the IT team in mind (Soms et al., 2022). This presents a security challenge, as the IT team cannot safeguard things that they are unaware of (Soms et al., 2022). Indeed, shadow IT is another threat which needs to be taken into account, and it refers to the use of IT solutions and tools for
24 business purposes, that are not provided or approved by the organization’s IT department, and often without the IT department’s knowledge (Walterbusch et al., 2017). Shadow IT has been present since the dawn of information technology and emergence of cloud computing adds yet another dimension to its complexity (Walterbusch et al., 2017). The root cause for the emergence of shadow IT is the lack of adequate IT solutions that fulfill the needs of employees, also known as the IT gap (Walterbusch et al., 2017). Typically, employees may utilize cloud services alongside with shadow IT, resulting in a situation where there is no documentation of the cloud services used nor the outsourced data or processes (Walterbusch et al., 2017). The issue can be addressed either by improving the current official systems to bridge the IT gap, replacing the unauthorized cloud solutions with official corporate systems, integrating the unauthorized cloud solutions into the corporate IT governance, or by mitigating the risk through the implementation of adequate security controls and creating a safe environment (Walterbusch et al., 2017). Roles and responsibilities are another important topic for cloud security. Jansen (2011) states that while reduction of costs may be a primary motivation for many organizations to adopt cloud solutions, reducing responsibility for security should not be one. It is critical that organizations operating in the cloud recognize that responsibility for data integrity and protection cannot never be fully delegated, but cloud security is always a shared responsibility between the CSP and the cloud customer (Duncan, 2020; Soms ym., 2022). The security responsibilities can vary significantly between the CSP and the customer depending on the service model in question, and these responsibilities are not always clear to the cloud customers (Subashini & Kavitha, 2010; Torkura et al., 2021). Shared responsibility model is commonly used by CSPs to clearly define the responsibilities for security and compliance between the CSP and cloud customer (Duncan, 2020; Soms et al., 2022; Torkura et al., 2021). Depending on the CSP and the service provided, the model usually follows a principle that the cloud customer is responsible for the security in the cloud, while the CSP is responsible for the security of the cloud (Amazon Web Services, 2024a). • In the IaaS model, the CSP is usually responsible for the underlying infrastructure such as the datacenter, hardware, storage, and network. The customer is responsible for example the operating systems, network security, applications, access policies, identity and access management, endpoints, and information and data. (Amazon Web Services, 2024a; Google, 2024; Microsoft, 2024a; Sisodia & Khan, 2024; Zhu et al., 2012; Zissis & Lekkas, 2012) • In the PaaS model, the CSP is responsible for the same things as in IaaS, but usually also the operating systems and network management. Application layer processes and identity and access
25 management can be a shared responsibility depending on the CSP and the service provided. The customer is responsible for access policies, endpoints, as well as information and data. (Amazon Web Services, 2024a; Google, 2024; Microsoft, 2024a; Sisodia & Khan, 2024, Zhu et al., 2012) • In the SaaS, model the CSP is typically responsible for everything else but the access policies, endpoints, and information and data, which all fall under the customer’s responsibility. (Amazon Web Services, 2024a; Duncan, 2020; Google, 2024, Microsoft, 2024a; Sisodia & Khan, 2024; Zhu et al., 2012) To ensure effective security management throughout the information supply chain and service lifecycle and eliminating unrealistic expectations, it is critical for organizations and CSPs to agree and document the necessary security requirements and their implementation, and how the related roles and responsibilities are divided (Duncan, 2020; Khalil et al., 2014; Luna et al., 2015 Singh & Chatterjee, 2017). The basic principle should be that the organization is the one who defines the sufficient service level according to its security policies and current level of security (Duncan, 2020), but many times especially with the leading vendors this principle might turn out difficult to achieve (Singh & Chatterjee, 2017). The agreement for delivering cloud services during the entire lifecycle of the service is established between the CSP and the cloud customer through a Service Level Agreement (SLA) (Kandukuri et al., 2009; Morsy et al., 2016; Singh & Chatterjee, 2017). Both parties are required to adhere to the SLA, with penalties enforced for non-compliance (Morsy et al., 2016; Singh & Chatterjee, 2017). SLAs generally include terms and conditions and objectives related to performance, reliability, security, and agreed monitoring and auditing models (Morsy et al., 2016; Singh & Chatterjee, 2017). Typically, an SLA should cover at least the following areas (Kandukuri et al., 2009): • Services delivered • Performance management • Problem management • Roles and responsibilities • Legal & regulatory compliance • IPR • Security • Disaster recovery and business continuity • Termination Additionally, a more specific Security Service Level Agreement (SecSLA) can be drawn up, which is a documented high-level agreement between the CSP and the customer, which defines the needed security requirements, related roles and
32 Software Development Lifecycle (SDLC) processes should be followed when developing and implementing web applications (Morsy et al., 2016). Open Web Application Security Project (OWASP) maintains a list of the most critical identified threats to web applications called the “OWASP Top Ten” for organizations and software developers to utilize when assessing or developing the security of web applications (OWASP, 2024b). Application Programming Interfaces (APIs) serve as bridges between different software components, enabling communication and data sharing among them (Chauhan & Shiaeles, 2023). They are essential components of user access to information resources, serving as node points for communication and data processing (Qazi, 2023). Cloud APIs are a common and increasingly used method to access sensitive data and applications, located on the top layers of the cloud framework (Qazi, 2023; Singh & Chatterjee, 2017). However, API developers tend to often prioritize functionality and speed over security features, resulting in many APIs being inherently insecure (Qazi, 2023). This unfortunate combination makes APIs a tempting target for the attackers (Qazi, 2023). Qazi (2023) discovered that organizations tend to lack resources and training to educate user about APIs, with many also being unaware of the APIs they are using and instead relying on third-party providers to manage their API infrastructure. Such practice can lead to opaque API design and third-party providers mishandling their customers’ APIs (Qazi, 2023). The security of cloud APIs is a key component for the present web applications (Gururaj et al., 2017; Singh & Chatterjee, 2017; Qazi, 2023), and security vulnerabilities associated with APIs, such as lack of authentication and encryption, can lead to API attacks (Qazi, 2023). SQL Injection and Cross-site Scripting (XSS) are among the most common type of API injection attacks due to the extensive attack surface (Qazi, 2023). Sanitizing the data of API requests, validating input, using character escaping and filtering, and limiting response data can mitigate the risk of API injection attacks (Qazi, 2023). In Distributed Denial of Service (DDoS) attack, the attacker floods the server with network traffic to overwhelm API memory and restrict users from accessing online services and connected sites (Qazi, 2023). Man-in-the-middle (MITM) attacks are a common type of attack, wherein the attacker intercepts the traffic between a client and a server, enabling the attacker to tamper the communication or eavesdrop on confidential information (Qazi, 2023). MITM attack could for example be carried out by issuing an API request to an HTTP header between a session token (Qazi, 2023). Measures to mitigate DDoS attacks include limiting rate and payload size of incoming traffic, and encryption of the traffic is an effective way to mitigate MITM risks (Qazi, 2023). Securing APIs can be a difficult task, and many organizations still lack awareness of how to protect APIs from attacks, or even how many APIs they have (Qazi, 2023). The majority of APIs are deployed using API gateways, which among other functions serve the purpose of security gateways and are typically used especially for authentication and monitoring purposes (Red Hat,
33 2024). The basic principle of a security gateway is similar to firewalls, providing protection for the cloud environment, users, and applications from external malicious network traffic (Qazi, 2023). Robust authentication, authorization, and encryption controls are essential to ensure that only authorized entities can access to particular API functions and resources (Chauhan & Shiaeles, 2023; Kalaiprasath et al., 2017; Qazi, 2023). Indicators of suspicious activity such as potential breaches and unauthorized access attempts should be actively monitored through comprehensive monitoring and logging systems, which capture and analyze API activity (Chauhan & Shiaeles, 2023). Open Web OWASP maintains a list of the top 10 API security risks (OWASPa, 2024) and provides guidance on mitigating them, offering organizations a framework to address the most critical security issues associated with APIs (Qazi, 2023). 3.7 Identity Management and Access Control Information security and privacy are a growing concern for organizations, with unauthorized access to information resources in the cloud emerging as major issue (Jansen, 2011). Identity management (IDM) is an administrative process focusing on verifying the identities of users and cloud objects within a system and controlling access to the systems resources (Morsy et al., 2016; Singh & Chatterjee, 2017; Subashini & Kavitha, 2010; Sun, 2018). It forms the core for security of the systems and includes three main phases for the verification process which are identification, authentication, and authorization (Morsy et al., 2016; Sun, 2018). IDM and access control overlap with each other, but have distinct focuses, as IDM focuses more on authentication, while access control primarily addresses authorization (Sun, 2018). Cloud platforms should offer a robust and reliable native IDM system ensuring comprehensive coverage of all cloud resources and users, or alternatively support the effective implementation of external IDM systems (Morsy et al., 2016) Authentication can be defined as the process of verifying the identity of a system or an individual (Singh & Chatterjee, 2017; Zissis & Lekkas, 2012). It serves the purpose of preventing unauthorized access to information resources and can be carried out through various methods such as using passwords, tokens, certificates, or biometrics (Butt et al., 2022; Singh & Chatterjee, 2017; Xiaojun & Qiaoyan, 2010). Authorization again can be defined as the process of permitting or rejecting access to individuals or systems, after they have been authenticated (Singh & Chatterjee, 2017). Strong authentication is critical for cloud security, as weak or insufficient authentication methods can result in unauthorized access to the cloud resources (Singh et al., 2016; Zissis & Lekkas, 2012). Relying solely on traditional passwords for authentication presents vulnerabilities, as stolen passwords can quickly lead to breaches. Multifactor authentication has become a popular method to mitigate the risk by requiring one or more authentication factors beyond the password (Butt et al., 2022).
34 Another common authentication method in cloud environments is utilizing certificates, which requires a certification authority to validate entities involved in interactions, including servers, devices, and users (Zissis & Lekkas, 2012). This ensures that all physical and virtual entities are provided with the necessary strong credentials, establishing specific boundaries for the cloud’s security domain (Singh et al., 2016; Zissis & Lekkas, 2012). Most organizations utilize Lightweight Directory Access Protocol (LDAP) or Microsoft Active Directory (AD) servers to manage user credentials, authentication, and authorization (Singh & Chatterjee, 2017; Subashini & Kavitha, 2010), and the servers can be located either within or outside the cloud environment (Singh & Chatterjee, 2017). Managing multiple user credentials separately within a cloud environment can become overwhelming and risky, particularly when organizations use multiple cloud solutions (Jansen, 2011). Recognizing this challenge, CSPs often permit customers to integrate their LDAP or AD servers with the cloud service, streamlining credential management and enhancing security (Subashini & Kavitha, 2010). This usually involves adopting Single-Sign-On (SSO), enabling users to avoid repetitive authentication processes for each service by utilizing a single strong authentication method that grants them access to services across trusted parties (Singh & Chatterjee, 2017; Zissis & Lekkas, 2012). Utilizing certificates in combination with SSO and LDAP creates a strong authentication process for cloud environments without significantly hindering user mobility and flexibility (Zissis & Lekkas, 2012). In addition to authentication, effective identity management requires the ability to adjust user privileges and retain control over resource access (Jansen, 2011). Access control allows organizations to enforce specific restrictions for their data stored in the cloud (Butt et al., 2022). The basic principle of access control is that authorized users can access the data, while unauthorized users are restricted from altering or accessing data without permission (Butt et al., 2022). Organizations should design and enforce strict access control policies to determine who can access the data and how (Rao & Selvamani, 2015; Soms et al., 2022). CSPs in the other hand should be able to accommodate their customers’ access control policies, which in a multi-tenant environment demands flexibility from the cloud system (Singh et al., 2016; Subashini & Kavitha, 2010). Efficient access management capabilities are essential in the cloud, where data often needs to be accessed by multiple users with varying privileges that may require adjustments over time (Singh & Chatterjee, 2017; Xiaojun & Qiaoyan, 2010). Managing user credentials and privileges efficiently in the cloud can be a complex task, and failure to do so can result in loss of control (Singh & Chatterjee, 2017). One of the most significant security threats in cloud computing is the hijacking of accounts, services, and traffic (Alassafi et al., 2017; Chauhan & Shiaeles, 2023). Cloud account hijacking occurs when an attacker gains unauthorized access to
35 an individual’s or organization's cloud account, allowing the attacker to conduct malicious activities (Arora et al., 2017; Butt et al., 2022; Chauhan & Shiaeles, 2023). This form of identity theft involves the attacker taking control of the victim’s account, which may be further exploited to gain access to other accounts or areas in the cloud environment (Butt et al., 2022; Chauhan & Shiaeles, 2023; Coppolino et al., 2017). In the worst case-scenario, the attacker could gain access to administrative accounts, potentially leading to the loss of the entire service (Gururaj et al., 2017). The attacker could also capture the activities and sensitive transactions in the cloud environment and manipulate the data for example to return forged information to other users or direct them to malicious sites (Arora et al., 2017; Chauhan & Shiaeles, 2023; Singh & Chatterjee, 2017). Raising awareness of phishing and social engineering threats for the users of the cloud, implementing robust authentication mechanisms such as MFA, enforcing the use of strong passwords, and regularly updating them can mitigate the risk of account hijacking (Butt et al., 2022; Chauhan & Shiaeles, 2023; Kalaiprasath et al., 2017; Khan & Al-Yasiri, 2016). Strategies to mitigate the risk of service threats include regularly patching and updating cloud services to address known vulnerabilities, as well as applying robust network and application-level firewalls to prevent unauthorized access to services (Chauhan & Shiaeles, 2023). To mitigate traffic related risks, network communications can be encrypted by employing secure communication protocols such as HTTPS or TLS (Chauhan & Shiaeles, 2023). 3.8 Human Factors Singh et al. (2016) stated that humans are the root cause of all issues, but humans can also solve all issues. Employees might use cloud services every day without understanding how the system works or what kind of security precautions should be taken into account (Walterbusch et al., 2017). Cloud security awareness trainings and guidance materials can help to mitigate this risk and enhance the security culture of the organization (Alassafi et al., 2017; Walterbusch ym., 2017). Cloud computing also still suffers from the lack of skilled staff, and it is crucial for both the CSPs and organizations to support continuous education and training to develop expertise in cloud security (Soms et al., 2022). Social engineering refers to an attack that targets and exploits human vulnerabilities (Bullée et al., 2018; Wang et al., 2021), and it can be viewed as a manipulation technique that employs persuasion principles to trick the victim into complying with the attacker's request, causing the victim to fall for a malicious scam and allowing the attacker to bypass technical safeguards (Bullée et al., 2018; Gupta et al., 2017; Siddiqi et al., 2022; Sun, 2018; Wang et al., 2021). Social engineering based attacks have been a growing problem since the 1970s,
36 compromising both individuals and organizations (Gupta et al., 2016; Siddiqi et al., 2022; Wang et al., 2021). The goal of the attacks might be for example to obtain confidential data or gain unauthorized entry to physical locations such as data centers, breach computer systems and networks, or otherwise compromise the confidentiality, integrity, or availability of information and information systems such as cloud environments (Bullée et al., 2018; Siddiqi et al., 2022; Wang et al., 2021). Lastdrager (2014) conducted a comprehensive systematic review about the definition of phishing resulting in a consensual definition: “Phishing is a scalable act of deception whereby impersonation is used to obtain information from a target”. Phishing is categorized as a form of semantic attack and is typically classified into two main types: malware-based and social engineering based attacks (Arachchilage et al., 2016; Gupta et al., 2016). Phishing attacks are considered to be among the most effective online attack methods that rely on social engineering techniques to deceive victims into disclosing their personal or confidential information (Ebot, 2018; Gupta et al., 2016; Gupta et al., 2017; Khalil et al., 2014; Lance & Jevans, 2005, p. 33; Siddiqi et al., 2022). Despite technological advancements, social engineering-based attacks like phishing remain as a growing problem for cloud security as attackers exploit human vulnerabilities to bypass technical safeguards (Albladi & Weir, 2020; Gupta et al., 2016; Schaab et al., 2017; Siddiqi et al., 2022). Cyber security researchers and practitioners primarily suggest on two main approaches to mitigate the risk of social engineering based attacks like phishing: implementing technical safeguards and promoting security awareness (Bullée et al., 2018; Gupta et al., 2016; Wright & Marett, 2010). Technical safeguards typically include automation, such as anti-phishing filters and alerts, while enhancing security awareness involves educating users, which many studies have found to be effective (Sur, 2018; Wright & Marett, 2010). Malicious insider threats are another human based threat in cloud security, involving individuals who have authorized access to cloud resources but intentionally misuse their position for harmful purposes (Butt et al., 2022; Chauhan & Shiaeles, 2023; Singh & Chatterjee, 2017). Malicious insiders are considered as a major threat to cloud security, with the level of impact depending on their access rights and their ability to infiltrate organizations and their assets (Khalil et al., 2014; Rizvi et al., 2017; Soms et al., 2022). A significant portion of data breaches are caused by insiders, who are typically either CSPs or the cloud customer's current or former employees, contractors, partners, or service providers (Butt et al., 2022; Chauhan & Shiaeles, 2023; Singh & Chatterjee, 201; Soms et al., 2022). These individuals have been granted access to the cloud environment and may possess insider knowledge of its security arrangements (Butt et al., 2022; Chauhan & Shiaeles, 2023; Jansen, 2011; Singh & Chatterjee, 2017). To mitigate the risk of malicious insiders, organizations should implement strict access control measures, adhere to the principle of least privilege, and
37 establish robust IAM mechanisms and policies (Chauhan & Shiaeles, 2023). Robust monitoring and auditing systems can be utilized to track user activities and system events, as well as to report any detected anomalies (Chauhan & Shiaeles, 2023). Enforcing segregation of duties is crucial to ensure that individual employees do not hold disproportionate control or privileges over the cloud environment or critical processes (Chauhan & Shiaeles, 2023). Comprehensive screening processes are recommended during recruitment, especially for roles involving critical responsibilities or extensive administrative privileges (Gururaj et al., 2017). 3.9 Incident Management and Forensics Robust security incident management processes and controls are essential for effective threat detection and response (Duncan, 2020). Organizations should design and implement comprehensive incident management policies and procedures, leveraging monitoring and analytics throughout the cloud to identify threats, vulnerabilities, and configuration weaknesses (Duncan, 2020; Esposito & Castiglione, 2016). Due to the complexity of cloud environments and the massive amount of log data produced, real-time monitoring of threats and vulnerabilities become difficult if not impossible for humans to process by themselves, which is why automation is required to support the efficient threat detection and response processes (Khalil et al., 2014; Qazi, 2023). Intrusion Detection Systems (IDS) are applications or devices designed to monitor and analyze system activities and network traffic, identifying and reporting any detected anomalies and suspicious behavior (Butt et al., 2022; Khalil et al., 2014). However, studies show that traditional IDS are not optimal for cloud environments (Qazi, 2023). Security Information and Event Management (SIEM) systems are a more common security solution used within cloud environments, and it can be used to support the monitoring and analysis of real-time network events, issuing alerts based on learned patterns of normal and abnormal behavior within the network, and reacting to them based on set rules (Singh & Chatterjee, 2017). Most SIEM systems and some of the IDS leverage Machine Learning (ML), which is an extension of convolution neural networks (CNNs), enabling devices or systems to learn and make decisions by training them with relevant data (Qazi, 2023; Subramanian & Tamilselvan, 2019). This equips the system to handle diverse scenarios and make intelligent decisions (Subramanian & Tamilselvan, 2019). ML provides a fast and efficient way to analyze data, enabling detection of various threats and abnormal behavior more effectively than traditional security methods (Qazi, 2023). However, deploying ML based cloud security systems is a challenging and laborious task due to the substantial amount of training data required, and integrating new data forms requires intensive training efforts (Subramanian & Tamilselvan, 2019). Regular tuning of
38 the system is also essential to ensure its capability to detect new anomalies within the network and its boundaries (Subramanian & Tamilselvan, 2019). As cybercrime poses a major threat to organizations today, particularly as more and more of the business and daily operations are relying on network applications such as cloud applications and devices (Singh et al., 2016). Digital forensics is no longer a niche process solely for the use of the officials, but it plays a vital role in organizations across both public and private sectors to investigate cybercrime and computer-assisted crime (Singh et al., 2016). Different kind of digital forensic tools and techniques can be used to for collecting and examining digital evidence from disk images, logs, image files and snapshots, memory dumps, endpoint devices and such, and ensuring that the evidence remains forensically sound (Esposito & Castiglione, 2016; Singh & Chatterjee, 2017; Singh et al., 2016). Due to the complexity and dynamic nature of the cloud, applying digital forensic tools can be more challenging compared to traditional in-house IT environments, as the data is often moved between locations in the cloud rather than being stored in a static physical storage location (Singh & Chatterjee, 2017). To ensure the efficiency of cloud forensics, sufficient expertise and understanding of the domain is required from both the CSP and the cloud customer, depending on the deployment model and SLAs (Singh & Chatterjee, 2017).
39 4 RESEARCH METHODOLOGY In a university context, according to Myers (2020, p. 6) research can be defined as “an original investigation undertaken in order to contribute to knowledge and understanding in a particular field”. This research should generate new knowledge, ensuring that the related facts, their interpretations, or the theories used to explain them are novel in the particular field in question. To ensure that the research results are robust and novel, the findings must be subjected to scrutiny and formal evaluation by experts qualified in the field. This evaluation process, known as the peer review system, is present in all scientific disciplines and distinguishes science from other human endeavors, ensuring that the research must comply with certain standards before it can be published. Research is typically carried out by individuals who have specialized knowledge of the topics, theories, and methods to their field. This research can be empirical or conceptual in nature and in fields like computer science or information systems science, it may also involve the experimental design of new or enhanced materials, devices, products, or processes. Since the subject matter, theories, and methods used in a particular field can evolve over time, scholars typically demonstrate their understanding and familiarity with the latest knowledge by writing literature reviews that cover recent relevant research. (Myers, 2020, p. 6-7) In business and management, research focuses on topics pertinent to its own disciplines, such as management strategy, finance, human resources, logistics, information systems, marketing, and operational management. It often integrates research from other fields like statistics, psychology, and sociology. Balancing rigor and relevance is a persistent challenge for researchers in business and management. Business schools have faced criticism for prioritizing rigor at the expense of relevance in their research. Rigor in research is often defined as adherence to the standards of scientific research, including following the scientific research model, undergoing peer review, and being published in an academic journal. However, academic research business journals are often criticized for being too theoretical and not sufficiently
40 practical for business professionals. Then again, relevance in research is often characterized by having direct implications for business and management, with results that can be immediately applied or deployed by the business professionals. The downside of relevance in research is that it often comes with little theoretical contribution and is seen more similar to consulting, and therefore often fails to comply with the standards of scientific research. (Myers, 2020, p. 12-14) The following subchapters describe the research methodology used in the thesis, and the motivation for their selection. First, quantitative and qualitative research methods are introduced in general, followed by a description of the research methods chosen for the thesis. Finally, the implementation of the research and the data collection methods are introduced. 4.1 Research Methods Research methods are often classified as quantitative or qualitative. Quantitative methods, developed to study natural phenomena, include survey methods, laboratory experiments, formal methods, and numerical techniques such as mathematical modelling. One of the key characteristics of quantitative research include the use of statistical tools to analyze numerical data. Qualitative research methods were developed to study social and cultural phenomena and include approaches such as action research, case study research, and grounded theory. Data sources for qualitative research can include observations, interviews, questionnaires, documents and texts, as well as the researcher’s own impressions and reactions. Qualitative data primarily focuses on what people have said, helping us understand their motivations, actions, and the environments in which they work and live. (Myers, 2020, p. 8-9) Quantitative research is generally more suitable for large sample sizes and generalizing results to broader populations. It is ideal for situations where researchers aim to study a specific topic across numerous individuals or organizations to identify trends or patterns. In business and management, the primary limitation of quantitative research lies in its tendency to overlook a majority of the social and cultural factors within organizations. The context is often overshadowed by the emphasis on generalizing findings across a population. Qualitative research is better suited for studying social, cultural, and political characteristics of individuals and organizations, as well as in-depth exploration of specific subjects, making it ideal for cases where the topic is novel and has not been extensively researched before. However, a well-known challenge with qualitative research methods is the difficulty in generalizing findings to a larger population. (Myers, 2020, p.9-10)
41 Literature review is research method in which past research is studied and summarized to conduct a descriptive synthesis that can act as a base for future research findings (Mandal & Khan, 2021; Salminen, 2011). As a research method it can be considered as a mixed method since it can combine elements from both quantitative and qualitative research (Salminen, 2011). The emphasis placed on either approach depends on whether the literature review is conducted with a more descriptive and qualitative focus or a more statistical and quantitative orientation (Salminen, 2011). The literature review is typically situated in the introduction section of a study, making it commonly perceived as a supportive research method and technical phase aimed at presenting past research relevant to the study (Mandal & Khan, 2021; Salminen, 2011). Triangulation proves valuable when researchers aim to examine a topic from various perspectives, enhancing their comprehensive understanding of the subject. This can be accomplished by employing multiple research methods, using multiple techniques to collect data, or by integrating both qualitative and quantitative research methods within a single study. In qualitative research, triangulating data is often necessary. For example, this might involve cross-referencing data from interviews or surveys with information extracted from documents and texts, or with data collected through various research methods. (Myers, 2020, p. 10-11) In the realm of business and management research, qualitative methods are considered more apt for achieving both rigor and relevance as they facilitate the integration of scholarly insights with practical applications (Myers, 2020, p. 15). To conduct a successful qualitative study, researchers must actively engage with individuals in real-world organizations, recognizing the complexity inherent in organizational dynamics and addressing the often-unquantifiable issues at hand (Myers, 2020, p. 15). Therefore, qualitative research methods were deemed suitable and chosen for this thesis, with the research method being a qualitative case study. A literature review was used to create the knowledge base for the study, while empirical material was collected through a survey targeting experts in cloud services and information security. Triangulation was employed to form the study's findings, combining the results of the literature review and the survey. 4.2 Implementation and Data Collection The research method for the thesis is a qualitative case study, and the baseline of the study are organizations that use or produce cloud solutions. The aim of the study is to determine how and why organizations should address information security when adopting or using cloud services. One main research question was defined for the thesis, and one sub-research questions to support this, which the study aims to answer:
48 Not important at all Not very important Neutral Important Very important Unsure Cost-efficiency 0,0% 0,0% 7,7% 38,5% 53,8% 0,0% Rapid Deployment 0,0% 0,0% 15,4% 53,8% 30,8% 0,0% Scalability 0,0% 0,0% 0,0% 23,1% 76,9% 0,0% Data Shareability 0,0% 7,7% 30,8% 38,4% 23,1% 0,0% Accessibility of Services 0,0% 0,0% 7,7% 38,5% 53,8% 0,0% Interoperability of Systems 0,0% 0,0% 15,4% 30,8% 46,1% 7,7% Operational Reliability and Continuity 0,0% 0,0% 0,0% 15,4% 84,6% 0,0% Something else 0,0% 0,0% 0,0% 0,0% 0,0% 100,0% Total 0,0% 1,0% 9,6% 46,1% 46,1% 13,5% Table 5 Importance of generally associated benefits with the adoption of cloud services compared to traditional information systems. The respondents were also asked to briefly describe the most important benefits in terms of risk management and security that they believed could be achieved by adopting cloud services. A high level of availability and continuity of services was emphasized, particularly in terms of managing and protecting the physical infrastructure of the environment. The shared responsibility model was also regarded as a significant benefit of adopting cloud services, as it allows organizations to share security responsibilities with the cloud service provider (CSP). Additionally, many respondents highlighted the scalability of cloud services as an important advantage, as well as the extensive tools provided by CSPs to manage the security of the cloud environment. Responses The hyper scaler cloud providers are capable of offering so highly available infrastructure that the risk of hardware infrastructure failures are very low. The shared responsibility model of the cloud security is also a great way to improve the security when you don't have to worry about the data center and hardware related security threats. The physical protection of data is easily managed if you use well-known public cloud service providers. For example, it is easy to store backups in several geographical locations. Wellknown public cloud service providers also offer very stable platforms, making it easy to keep system availability at a very high level. Centralized risk and security management. Ease of managing access rights. For large trusted CSPs, security and risk management are offered as a standard service. Ready-to-use tools. Improving information security compared to on-premises solutions. By using public cloud providers, you get built in security for authentication and authorization. And the infrastructure is also managed by cloud service provider. It is also easier to get overview by using native cyber security tools provided by the cloud services provider. By using cloud provider, you also have automatically a very good inventory of
49 all your resources, which is important for security also. Compared to an on-premises service, using a cloud service is more cost-effective and continuity is better secured. Scalability is important vs. on-premises service where more capacity may be acquired at once, and some may remain completely unused. Secure by design (sometimes), operational reliability and observability. Local and possibly customer-administered servers can be get rid of, in which case the responsibility for maintaining operations, backups and general security rests with the supplier, who must be familiar with these at a completely different level than the company using the services. In risk management, the most important benefits are availability and scalability. In terms of security, cloud services offer solutions that are being designed and implemented by several experts. Flexibility/scalability, high-level if information security, ensuring continuity (backups, fast recovery, etc.) and ease of use. Table 6 Benefits of cloud services in risk management and security. 5.2 Choosing a Cloud Service Provider When asked about considerations for risk management and security when choosing a cloud service provider (CSP) and the most important factors for ensuring a CSP's reliability, many respondents emphasized the importance of certifications when assessing the reliability and security capabilities of a CSP. Especially ISO/IEC 27001 certification was highlighted by the respondents, when asked about security-related certificates or approvals required from CSPs by the respondents’ background organizations. The respondents also highlighted the importance of visibility and transparency, along with the comprehensiveness of the available documentation, which positively influenced the evaluation of a CSP's reliability. The availability of various tools to manage security was also deemed important. Additionally, well-known larger CSPs were initially perceived to be more reliable and a better option for risk management and security, as they are likely to have more resources and tools to manage cloud security effectively. However, many respondents emphasized that auditing the CSP and testing the offered cloud solution beforehand should always be conducted. Responses Rely on the bigger hyper scalers who have the resources to the mitigate the risk and security issues proactively and provide constantly new services for improving on those areas. Comprehensive documented risk analysis. It is worth finding out the available certifications. Comprehensive testing of the platform before taking it into use. Known service provider. Various certifications based on standards serve as a good proof of the reliability of the organization providing cloud services. In general, big global players are more reliable than small local ones. My personal view is that it would still be good to do an audit for a potential cloud service provider in addition to checking certifications.
50 Technical solution, service levels, competitive price level, technical expertise of the personnel. You should of course evaluate the provider and what if any certifications they have. Mostly for the physical and infrastructure. It is however a shared responsibility, and you will still have responsibility of the workloads in the cloud. You should therefore also evaluate what if any cyber security tools there are provided by the cloud service provider. Ensuring continuity of service, duplication of capacity. Provider certification, references. Alignment with best practices/industry standards. Data handling. Reporting in case of an incident. Compliance. Access management (authentication and access control). Reputation, level of documentation, transparency and information sharing, certifications. In my opinion, certificates are the most important factors when choosing providers. Large enough provider with good references and possibly previous cooperation. Google / Microsoft, for example are not likely to fall and you can always get either free/paid help from them if needed. Availability, location. Table 7 Most important factors to ensure the level reliability and security of a CSP. Many respondents highlighted the importance of SLAs when asked about incorporating risk management and security into contracts with CSPs, which supports the findings of previous studies. It was emphasized that agreeing on the preferred level of security and specific security requirements at the contract level with the CSP is essential, as well as clearly defining roles and responsibilities related to them. Additionally, data protection and privacy requirements were considered important factors to include in the contracts between the organization and the CSP. One respondent also emphasized the importance of avoiding vendor lock-in when finalizing a contract with the CSP, which has also been highlighted in previous research (Chauhan & Shiaeles, 2023; Rizvi et al., 2017; Singh & Chatterjee, 2017). Responses There should be a clear definition of the responsibilities as a part of the agreement. AWS has the good example within the shared responsibility model. You should pay special attention to data protection issues, e.g. because of GDPR. E.g. DPA and DPIA procedures. Easy to change service provider if desired. Continuity plans, recovery plans at a minimum The information security requirements for the service must be accurately described in the contract. The big cloud service providers will offer more terms of service than individual contracts, but there are service levels, and you should of course choose the service level and or extra services to fulfill your cyber security needs. SLA, security audits. Address data protection, privacy, and compliance requirements in the contract. The requirements include regular reporting, a clear delineation of responsibilities and obligations. A difficult question here, but certainly also for the party procuring the service if the company does not already have expertise related to the matter. SLAs with sanctions for contracts. Table 8 How should risk management and security be taken into account in contracts with the CSPs.
51 5.3 Security of Cloud Services 53% of respondents felt that the cloud services used in their background organization had a very good level of security, and 38% considered it to be on a good level. Only 8% felt that the security level was average, with none stating it was bad or very bad. This supports findings from previous research (Singh & Chatterjee, 2017; Torkura et al., 2021) that the increasing adoption of cloud solutions over the years has driven continuous advancements in cloud technology and security. Additionally, 54% of respondents agreed or completely agreed that they feel they can influence the security level of the cloud services used. However, 31% of respondents disagreed or completely disagreed that they had any influence on the security level of their organization's cloud services. This discrepancy could potentially be attributed to the varying roles and responsibilities of the respondents within their organizations. Users of information systems generally have less influence over the security of the system compared to those in administrative roles, for instance. Figure 2 Ability to influence the security level of cloud services in use. 62% of respondents indicated that their background organization has moved critical data or services to the cloud, while the remaining respondents stated that critical data or services had been partly moved to the cloud. Nearly half of the respondents (46%) were unsure if their background organization had chosen not to adopt certain cloud solutions or limit their use due to security concerns. Meanwhile, 8% of respondents answered that security concerns had not affected the adoption or usage of cloud solutions, and 46% stated that their background organization had either decided against adopting some cloud solutions or had limited their usage due to security concerns. Given that 91% of the respondents indicated the security level of the cloud solutions used in their organization is either good or very good, this finding prompts questions about why organizations continue to express hesitations about adopting or using cloud solutions due to security concerns. This could serve as an interesting topic for future research.
52 5.4 Cloud Security Risks 69% of the respondents stated that their background organization is either well aware (38%) or very well aware (31%) of security risks related to cloud solutions, while 31% answered their background organization to be moderately aware of the risks. None of the respondents rated their background organization to be either poorly or not very well aware of the cloud security risks. As cloud solutions have been widely adopted by organizations for over a decade, this result is unsurprising (Mandal & Khan, 2021). However, it underscores the need to improve awareness of security risks associated with cloud solutions, particularly given that the respondents predominantly worked in technology-oriented organizations. Regarding cloud security risks related to people, 62% of respondents perceived the lack of security awareness and training as a significant or critical risk. Opinions were divided on data leaks/data loss, with 46% viewing it as a critical risk and the rest considering it as more of a minor risk. Similarly, opinions on malicious insiders were split, with 46% seeing them as a significant or critical risk, while the rest considered them moderate or minor risks. The unauthorized abuse of cloud resources, such as crypto mining and executing DOS attacks, showed the most variation in respondents' perceptions of its risk level in terms of cloud security. Human errors were also mentioned as people-related risk for cloud security that should be taken into account. Based on the results, it can be concluded that security risks associated with people pose a significant threat to cloud security. Insignificant Minor Moderate Significant Critical Unsure Insider risks (malicious) 0,0% 30,7% 23,1% 30,8% 15,4% 0,0% Lack of security awareness or training 0,0% 15,4% 23,1% 38,4% 23,1% 0,0% Data leak/ Data loss 7,7% 38,5% 7,7% 0,0% 46,1% 0,0% Unauthorized cloud resource abuse (e.g. mining crypto, executing DOS attacks etc.) 0,0% 23,1% 30,7% 15,4% 23,1% 7,7% Something else, what? 0,0% 0,0% 33,4% 0,0% 33,3% 33,3% Total 0,0% 21,5% 23,6% 46,1% 8,2% 13,5% Table 9 Significance of people related risks to cloud security. Among cloud security risks related to processes, identity and access management (IAM) related risks were perceived as the most significant ones. 54% of respondents stated IAM risks to be either a significant or critical risk,
53 while 38% saw it as a moderate risk. None of the respondents classified IAM risks as a minor or insignificant risk for cloud security. Compliance risks (e.g., risks related to laws and regulations) and risks arising from inadequate contract models in terms of security were highlighted as significant or critical risks by over 40% of the respondents. Similarly, over 40% of respondents considered risks related to backup protection to be either significant or critical. Risk for the organization’s business models not supporting the usage of cloud solutions was perceived as moderate by 39% of the respondents, and risks related to data destruction and retention processes were also mostly deemed moderate (46%). While the roles and responsibilities regarding security were highlighted by the respondents earlier to be an important factor to take into account on a contract level with the CSPs, risks related to data ownership and responsibilities were considered to be significant or critical for cloud security only by 23% of the respondents, while 62% of respondents stated that the risk is only minor or moderate. Risks related to limited visibility of cloud solutions (e.g. location of data, security controls) were not seen as critical by none of the respondents, and 61% of respondents considered them to be either moderate or minor risks, and even insignificant (7%). This contrasts with previous research indicating that one of the primary challenges for cloud computing is the lack of visibility into how data is stored or secured (Carrera, 2022; Singh et al., 2016; Subashini & Kavitha, 2010). Overall, the significance of cloud security risks related to processes varied greatly depending on the specific process. With the exception of risks related to encryption key management, they were generally perceived as either significant, moderate, or even minor threats to cloud security. Insignificant Minor Moderate Significant Critical Unsure Organization's business models do not support cloud solutions 0,0% 15,4% 38,4% 15,4% 7,7% 23,1% Compliance risks (laws and regulations) 0,0% 30,7% 15,4% 30,8% 7,7% 15,4% Risks arising from inadequate contract models in terms of security 0,0% 30,8% 7,7% 38,4% 7,7% 15,4% Risks related to data ownership and responsibilities 0,0% 38,4% 23,1% 15,4% 7,7% 15,4% Risks related to limited visibility (location of data, security controls) 7,7% 23,1% 30,7% 30,8% 0,0% 7,7% Identity and access management risks (IAM) 0,0% 30,7% 38,5% 46,1% 7,7% 7,7%
54 Risks related to encryption key management 0,0% 38,5% 7,7% 23,1% 23,1% 15,4% Risks related to backup protection 0,0% 7,7% 15,4% 30,8% 15,4% 7,7% Risks related to data destruction and retention processes 0,0% 15,4% 46,1% 15,4% 7,7% 7,7% Something else, what? 0,0% 0,0% 0,0% 0,0% 0,0% 100,0% Total 0,8% 22,3% 22,3% 24,6% 8,5% 21,6% Table 10 Significance of processes related risks to cloud security. Cloud security risks related to technologies were mostly seen as either moderate or significant, though there was some variance in the responses. Denial of service attacks were clearly viewed as the most important technology-related risk for cloud security, with 31% of respondents considering it a critical risk and 39% a significant risk. Risks arising from vulnerabilities in shared technology, system architecture, and virtualization vulnerabilities were mostly seen as either significant or moderate by the respondents. Risks related to web application vulnerabilities and technical interfaces such as APIs were also deemed important. Web application vulnerabilities were considered a significant risk by 38% of respondents, while technical interface-related risks were deemed significant by only 15%, with 69% viewing them as a moderate risk. Surprisingly, despite availability being a fundamental aspect of information security, service availability issues were considered a minor risk by 39% of respondents, though 15% saw them as a critical risk and 38% as a moderate risk. Compatibility issues between cloud platforms emerged as the most ambiguous technology-related risk, with 31% of respondents unsure of its significance to cloud security. Supply chain risks were also mentioned to be noteworthy in terms of cloud security. Technology related security risks were mostly perceived as a significant or a moderate threat to cloud security, with some variance depending on the risk in question. Insignificant Minor Moderate Significant Critical Unsure Risks arising from vulnerabilities in shared technology 0,0% 23,1% 30,8% 38,4% 7,7% 7,7% Risks related to system architecture 0,0% 30,8% 23,1% 38,4% 7,7% 7,7% Risks related to virtualization vulnerabilities 7,7% 15,4% 23,1% 38,4% 15,4% 15,4% Risks related to web application vulnerabilities 0,0% 7,7% 53,8% 38,5% 0,0% 0,0%
55 Risks related to technical interfaces (e.g. API) 0,0% 15,4% 69,2% 15,4% 0,0% 0,0% Service availability issues 0,0% 38,4% 38,5% 0,0% 7,7% 7,7% Compatibility issues between cloud platforms 0,0% 30,7% 30,8% 7,7% 30,8% 30,8% Account, Service, and Traffic High- Jacking 0,0% 23,1% 23,1% 30,7% 15,4% 15,4% Denial of service attacks 0,0% 15,4% 7,7% 38,4% 7,7% 7,7% Something else, what? 0,0% 0,0% 50,0% 0,0% 0,0% 50,0% Total 0,8% 20,0% 35,0% 24,6% 5,4% 14,2% Table 11 Significance of technology related risks to cloud security. 5.5 Protection of Cloud Services Comprehensive security always comprises several factors, but the importance of specific security controls may be emphasized depending on the asset to be protected. Respondents were asked to assess the importance of various pre-listed security controls typically associated with cloud security. Given that the lack of security awareness and training was perceived as the most critical cloud security risk related to people, it was consequently seen as the most important people-related security control in terms of cloud security. 62% of respondents rated it as very important, while 38% rated it as important. Security management and clearly defined roles and responsibilities related to security were both perceived as equally important, with 46% of respondents rating each as very important and another 46% rating them as important. This finding once again contrasts with the previous survey results, where 62% of respondents considered risks related to data ownership and responsibilities to be minor or moderate for cloud security Trusting the CSP was deemed either very important (31%) or important (61%) by 92% of respondents, which supports the findings of previous research. Personnel security (e.g., screening) was perceived as the most neutral security control by 15% of respondents, but over 80% still rated it as either important (62%) or very important (23%). While 15% of respondents did not see ensuring non-disclosure obligations as very important, the majority (77%) rated it as either important (69%) or very important (8%). Ensuring and monitoring contractual obligations showed the most variation in responses; 16% did not see it as very important (8%) or rated it neutral (8%), whereas 69% rated it as important and 8% as very important. In general, people related security controls were seen as important for cloud security.
56 Not important at all Not very important Neutral Important Very important Unsure Security management 0,0% 0,0% 0,0% 46,1% 46,2% 7,7% Clearly defined roles and responsibilities related to security 0,0% 0,0% 0,0% 46,1% 46,2% 7,7% Trusting the CSP 0,0% 0,0% 7,7% 61,5% 30,8% 0,0% Ensuring and monitoring contractual obligations related to security 0,0% 7,7% 7,7% 61,5% 15,4% 7,7% Ensuring non-disclosure obligations 0,0% 15,4% 7,7% 69,2% 7,7% 0,0% Personnel security (e.g. screening) 0,0% 0,0% 15,4% 61,5% 23,1% 0,0% Security awareness and training 0,0% 0,0% 0,0% 38,5% 61,5% 0,0% Something else, what? 0,0% 0,0% 0,0% 0,0% 0,0% 100,0% Total 0,0% 2,9% 4,8% 48,1% 28,9% 15,4% Table 12 Importance of people related security controls to cloud security. Vulnerability management processes were deemed the most important cloud security control related to processes, with 46% of respondents stating it as very important and the remaining 54% as important. Maintaining monitoring, detection, and response capabilities was highlighted as very important by 54% of respondents and as important by 38%. Knowing the threat environment was perceived as important by 62% of respondents and very important by 38%. Incident management processes were found to be equally important and very important, each rated by 46% of respondents. Based on the survey results, it is evident that effective prevention, detection, response, and recovery procedures for various security incidents and events were generally emphasized as crucial by the respondents. Adhering to Secure Software Development (SSDLC) principles was perceived as very important by 46% of respondents, important by 38%, and neutral by 8%. Change management processes had the highest percentage of neutral responses at 23%, but nearly 70% still saw it as important (31%) or very important (38%). Preventive business continuity management measures were found to be either important (54%) or very important (38%), with 8% viewing it as neutral. Comprehensive and up-to-date information system descriptions had the highest percentage of respondents rating it as important (69%), while 15% saw it as very important and 8% as neutral. In general, processes related security controls were mostly seen as important or very important for cloud security.
57 Not important at all Not very important Neutral Important Very important Unsure Knowing the threat environment 0,0% 0,0% 0,0% 65,1% 38,5% 0,0% Adhering to Secure Software Development (SSDLC) principles 0,0% 0,0% 7,7% 38,5% 46,1% 7,7% Comprehensive and up-to-date information system descriptions 0,0% 0,0% 7,7% 69,2% 15,4% 7,7% Change management processes 0,0% 0,0% 23,1% 30,8% 38,4% 7,7% Maintaining monitoring, detection, and response capabilities 0,0% 0,0% 0,0% 38,5% 53,8% 7,7% Vulnerability management processes 0,0% 0,0% 0,0% 53,8% 46,2% 0,0% Incident management processes 0,0% 0,0% 0,0% 46,1% 46,2% 7,7% Preventive business continuity management measures 0,0% 0,0% 7,7% 53,8% 38,5% 0,0% Something else, what? 0,0% 0,0% 0,0% 0,0% 0,0% 100,0% Total 0,0% 0,0% 5,1% 43,6% 35,9% 15,4% Table 13 Importance of processes related security controls to cloud security. Cloud security controls related to technologies comprised the largest category of predefined security controls in the survey, demonstrating relatively significant variation in perceived importance among respondents. Encrypting network traffic outside the environment and identity and access management (IAM) emerged as the most critical controls, with 69% of respondents considering both to be very important and 23% viewing them as important. In contrast, encrypting network traffic within the environment was deemed very important by only 8% of respondents, important by 46%, and neutral or not very important by 23% (8% not very important). Malware protection was also found to be a top priority, with 69% rating it as very important. Similarly, encryption key management and backup protection were both viewed as very important by 61% of respondents. However, while 31% saw backup protection as important, only 23% rated
64 involves implementing robust security controls to ensure the environment is secure, private, and isolated (Subashini & Kavitha, 2010). While cloud computing shares foundational principles and components with traditional IT systems and addresses many vulnerabilities effectively, its dynamic nature can challenge the efficacy of traditional countermeasures (Zissis & Lekkas, 2012). The numerous challenges associated with cloud security underscore the critical need for organizations to implement robust security controls, conduct comprehensive risk assessments, and ensure continuous monitoring and development of their cloud environments (Chauhan & Shiaeles, 2023). Implementing security controls that support each other such as strict IAM policies and access control restrictions, encrypting sensitive data, conducting regular security assessments, and utilizing effective authentication controls like MFA can effectively address these concerns. Consequently, efficient security management is crucial for controlling and managing the various required security mechanisms, which should be dynamic and autonomous by nature, and consistently applied across the entire cloud environment and its supporting structures, particularly when developing or adopting new systems, processes, services, or applications (Duncan, 2020; Khalil et al., 2014; Morsy et al., 2016). The selection of security controls should be in balance with the risks involved, as implementing an excessive number or overly stringent controls can also prove to be ineffective and inefficient (Jansen, 2011). Since cloud environments are rarely static but rather constantly evolving with new technologies while new workloads and capabilities are added according with current needs, it is essential to remain adaptive and commit to continuous improvement to ensure that cloud security develops alongside with the cloud environment and the surrounding threat landscape (Duncan, 2020; Khalil et al., 2014; Morsy et al., 2016). Even if the cloud solution itself would stay the same, the threat landscape is still constantly changing (Duncan, 2020). Organizations should take a holistic and multilayered security approach for cloud security adhering to the defense in depth principles, ensuring that security is integrated into every layer of the cloud environment by design, meaning that security is rather built into the cloud architecture from the start than added later (Casola et al., 2016; Chang et al., 2016; Deyan & Hong, 2012; Duncan, 2020; Gururaj et al., 2017; Khalil et al., 2014).
65 7 CONCLUSION The objective for this thesis was to improve awareness among organizations regarding the security risks associated with cloud computing and the methods and tools available to mitigate these risks. This was achieved through by examining the security risks inherent in cloud computing and determining how and why organizations should address these risks when adopting or using cloud services. The study aimed to answer one main research question: “What should organizations take into account regarding information security when deploying and managing cloud services?”, and one sub-research question: “What information security risks can the use of cloud services cause for organizations?”. The structure of the thesis encompassed a thorough literature review covering chapters 2-3, followed by an empirical case study covering chapters 4-6. The theoretical foundation for the study was established through the literature review presented in chapters 2-3. The second chapter first introduced the definition of cloud computing and cloud services, described the actors involved, and explored the service delivery and deployment models used in cloud computing. Towards the end of the second chapter, the basic elements of cloud architecture were identified and explained, followed by a concise overview of the advantages organizations can gain through the adoption of cloud solutions. The third chapter described the typical risks associated with cloud security from the organizations’ perspective and the potential security measures than can be employed to mitigate these risks. The empirical section of the thesis was presented in chapters 4-6. The fourth chapter, focused on the research methods used in the study, their implementation, and the process of data collection while using a survey as a method. The fifth chapter presented the survey results and their analysis. The study's findings were discussed in the sixth chapter, finally followed by a conclusion of the thesis in this seventh chapter. Cloud computing presents numerous advantages for organizations, yet it also introduces various risks and vulnerabilities. Effectively safeguarding cloud environments requires organizations to comprehensively understand these risks and take appropriate measures to mitigate them. This involves gaining a
66 deep understanding of cloud-specific characteristics, architectural components specific to each cloud service and deployment model, and the specific roles of different entities in ensuring cloud security. Before adopting cloud solutions, organizations should conduct a thorough assessment of their existing processes and evaluate the associated risks and benefits. It's crucial to determine how adopting cloud solutions aligns with organizational objectives and the value it brings. Leveraging well-known security frameworks such as ISO/IEC 27001 can provide organizations with essential guidelines and controls to implement industry best practices for protecting cloud environments. These frameworks offer valuable insights and recommendations to enhance cloud security posture effectively. The numerous challenges associated with cloud security highlight the critical need for organizations to implement robust security controls, conduct comprehensive risk assessments, and ensure continuous monitoring and development of their cloud environments. It is essential for organizations to remain adaptive and commit to continuous improvement to ensure that cloud security evolves alongside the cloud environment and the surrounding threat landscape. Organizations should adopt a comprehensive and multilayered approach to cloud security, adhering to the defense-in-depth principles. This includes ensuring that security is integrated into every layer of the cloud architecture by design.
67 REFERENCES Alassafi, M.O., Alharthi, A., Walters, R.J. & Wills, G.B. (2017). A framework for critical security factors that influence the decision of cloud adoption by Saudi government agencies. Telematics and Informatics, 34, 996-1010. Albladi, S.M. & Weir, G.R.S. (2020). Predicting individuals’ vulnerability to social engineering in social networks. Cybersecurity, 3(7), 1-19. Almorsy, M., Grundy, J. & Ibrahim, A.S. (2011). Collaboration-Based Cloud Computing Security Management Framework. IEEE 4th International Conference on Cloud Computing (pp. 364-371). Washington, DC, USA. Amazon Web Services. (9.5.2024a). Shared Responsibility Model. https://aws.amazon.com/compliance/shared-responsibility-model/ Amazon Web Services. (7.5.2024b). What is a hypervisor?. https://aws.amazon.com/what-is/hypervisor/ Amazon Web Services. (11.5.2024c). What’s the Difference Between SSL and TLS?. https://aws.amazon.com/compare/the-difference-between-ssl-and-tls/ Arachchilage, N.A.G., Love, S. & Beznosov, K. (2016). Phishing threat avoidance behaviour: An empirical investigation. Computers in Human Behavior, 60, 185-197. Arora, A., Khanna, A., Anmol, R. & Agarwal, A. (2017). Cloud Security Ecosystem for Data Security and Privacy. 7th International Conference on Cloud Computing, Data Science & Engineering (pp. 288-292). Noida, India. Avram, M. G. (2014). Advantages and Challenges of Adopting Cloud Computing from an Enterprise Perspective. Procedia Technology, Vol. 12, 529-534. Beckers, K., Côté, I., Faßbender, S., Heisel, M. & Hofbauer, S. (2013). A pattern-based method for establishing a cloud-specific information security management system: Establishing information security management systems for clouds considering security, privacy, and legal compliance. Requirements Engineering for Security, Privacy & Services in Cloud Environments, 18, 343-395. Bohn, R.B., Messina, J., Liu, F., Tong, J. & Mao, J. (2011). NIST Cloud Computing Reference Architecture. 2011 IEEE World Congress on Services (pp. 594-596). Washington, DC, USA.
68 Broadcom. (7.5.2024a). What is a hypervisor?. https://www.vmware.com/topics/glossary/content/hypervisor.html Broadcom. (7.5.2024b). What is a virtual machine?. https://www.vmware.com/topics/glossary/content/virtualmachine.html Bullée, J-W.H., Montoya, L., Pieters, W., Junger, M. & Hartel, P. (2018). On the anatomy of social engineering attacks – A literature-based dissection of successful attacks. J Investig Psychol Offender Profil, 15, 20-45. Butt, U.A., Amin, R., Mehmood, M., Aldabbas, H., Alharbi, M.T. & Albaqami, N. (2022). Cloud Security Threats and Solution: A Survey. Wireless Personal Communications, 128, 387-413. Carrera, G. (2022). Building a comprehensive cloud security audit program. EDPACS, 66(1), 15-19. Casola, V., De Benedicts, A., Rak, M. & Rios, E. (2016). Security-by-design in clouds: a Security-SLA driven methodology to build secure cloud applications. Procedia Computer Science, 97, 53-62. Chang, V., Kuo, Y.-H. & Ramachandran, M. (2016). Cloud computing adoption framework: A security framework for business clouds. Future Generation Computer Systems, 57, 24-41. Chauhan, M. & Shiaeles, S. (2023). An Analysis of Cloud Security Frameworks, Problems and Proposed Solutions. Network, 3(3), 422–450. Coppolino, L., D’Antonio, S., Mazzeo, G., & Romano, L. (2017). Cloud security: Emerging threats and current solutions. Computers & Electrical Engineering, 59, 126-140. Deyan, C. & Hong, Z. (2012). Data Security and Privacy Protection Issues in Cloud Computing. International Conference on Computer Science and Electronics Engineering (pp. 647-651). Hangzhou, China. Di Giulio, C., Kamhoua, C., Campbell, R.H., Sprabery, R., Kwiat, K. & Bashir, M.N. (2017). Cloud Standards in Comparison: Are New Security Frameworks Improving Cloud Security. IEEE 10th International Conference on Cloud Computing (pp. 50-57). Honolulu, HI, USA. Duncan, R. (2020). A multi-cloud world requires a multi-cloud security approach. Computer Fraud & Security, 5, 11-12. Ebot, A.T (2018). Using stage theorizing to make anti-phishing recommendations more effective. Information & Computer Security, 26(4), 401-419.
69 Esposito, C. & Castiglione, A. (2016). Cloud Manufacturing: Security, Privacy, and Forensic Concerns. IEEE cloud computing, 3(4), 16–22. Google. (9.5.2024). Shared responsibilities and shared fate on Google Cloud. https://cloud.google.com/architecture/framework/security/sharedresponsibility-shared-fate Gupta, B.B., Tewari, A., Jain, A.K. & Agrawal, D.P. (2016). Fighting against phishing attacks: state of art and future challenges. Neural Comput & Applic, 28, 3629-3654. Gupta, B.B., Arachchilage, N.A.G., & Psannis, K.E. (2017). Defending against phishing attacks: taxonomy of methods, current issues and future directions. Telecommun Syst., 67, 247-267. Gururaj, R., Mohsin, I. & Farrukh, A. (2017). A Comprehensive Survey on Security in Cloud Computing. Procedia Computer Science, 110, 465-472. Jansen, W. A. (2011). Cloud Hooks: Security and Privacy Issues in Cloud Computing. Proceedings of the 44th Hawaii International Conference on System Sciences (pp. 1-10). Kauai, HI, USA. Kalaiprasath, R., Elankavi, R. & Udayakumar, R. (2017). Cloud Security and Compliance – A Semantic Approach in End to End Security. International Journal on Smart Sensing and Intelligent Systems Special Issue, 10(5), 482-494. Kandukuri, B.R., Paturi, V.R. & Rakshit, A. (2009). Cloud Security Issues. IEEE International Conference on Services Computing (pp. 517-520). Bangalore, India. Khalil, I.M., Khreishah, A. & Azeem, M. (2014). Cloud Computing Security: A Survey. Computers, 3, 1-35. Khan, N. & Al-Yasiri, A. (2016). Identifying Cloud Security Threats to Strengthen Cloud Computing Adoption Framework. Procedia Computer Science, 94, 485-490. Lance, J., & Jevans, D. (2005). Phishing Exposed. Elsevier Science & Technology Books. Lastdrager, E.E.H. (2014). Achieving a consensual definition of phishing based on a systematic review of the literature. Crime Science, 3(9), 1-10. Liu, F., Tong, J., Mao, J., Bohn, R., Messina, J., Badger, L. & Leaf, D. (2011). NIST Cloud Computing Reference Architechture. National Institute of Standards and Technology. https://www.nist.gov/publications/nist-cloud- computing-reference-architecture
70 Luna, J., Suri, N., Iorga, M. & Karmel, A. (2015). Leveraging the Potential of Cloud Security Service-Level Agreements through Standards. IEEE cloud computing, 2(3), 32-40. Mandal, S. & Khan, D.A. (2021). Comprehensive Survey of Security Issues & Framework in Data-Centric Cloud Applications. Journal of Engineering Science and Technology Review, 14(1), 1-24. Mell, P. & Grance, T. (2011). The NIST Definition of Cloud Computing. National Institute of Standards and Technology. https://csrc.nist.gov/pubs/sp/800/145/final Microsoft. (9.5.2024a). Shared responsibility in the cloud. https://learn.microsoft.com/enus/azure/security/fundamentals/shared-responsibility Microsoft. (7.5.2024b). Virtual Machines: virtual computers within computers. https://azure.microsoft.com/en-us/resources/cloud-computing- dictionary/what-is-a-virtual-machine Morsy, M., Grundy, J. & Müller, I. (2016). An Analysis of the Cloud Computing Security Problem. Ithaca, 1-6. Myers, M. (2020). Qualitative research in business & management (3rd edition). SAGE Publications Ltd. Naone, E. (2009). Conjuring Clouds: How engineers are making on-demand computing reality. MIT Technology Review. https://www.technologyreview.com/2009/06/23/212416/conjuringclouds/ OpenAI. (16.6.2024). ChatGPT. https://chatgpt.com/ OWASP. (12.5.2024a). OWASP Top 10 API Security Risks - 2023. https://owasp.org/API-Security/editions/2023/en/0x11-t10/ OWASP. (13.5.2024b). OWASP Top 10. https://owasp.org/www-project-top-ten/ Qazi, F.A. (2023). Application Programming Interface (API) Security in Cloud Applications. EAI endorsed transactions on cloud systems, 7(23), 1-14. Rao R.R. & Selvamani, K. (2015). Data Security Challenges and Its Solutions in Cloud Computing. Procedia Computer Science, 48, 204–209.
71 Rebollo, O., Mellado, D., Fernández-Medina, E. & Mouratidis, H. (2015). Empirical evaluation of a cloud computing information security governance framework. Information and Software Technology, 58, 44-57. Red Hat. (12.5.2024). What does an API gateway do?. https://www.redhat.com/en/topics/api/what-does-an-api-gateway-do Rizvi, S., Ryoo, J., Kissel, J., Aiken, W. & Liu, Y. (2017). A security evaluation framework for cloud security auditing. The Journal of Supercomputing, 74, 5774-5796. Salminen, S. (2011). Mikä kirjallisuuskatsaus? Johdatus kirjallisuuskatsauksen tyyppeihin ja hallintotieteellisiin sovelluksiin (Opetusjulkaisuja 62). Vaasan Yliopisto. http://www.uwasa.fi/materiaali/pdf/isbn_978-952-476-349- 3.pdf Schaab, P., Beckers, K. & Pape, S. (2017). Social engineering defence mechanisms and counteracting training strategies. Information & Computer Security, 25(2), 206-222. Siddiqi, M.A., Pak, W., & Siddiqi, M.A. (2022). A Study on the Psychology of Social Engineering-Based Cyberattacks and Existing Countermeasures. Appl. Sci., 12, 1-19. Singh, A. & Chatterjee, K. (2017). Cloud security issues and challenges: A survey. Journal of Network and Computer Applications, 79, 88–115. Singh, S., Jeong, Y.-S. & Park, J.H. (2016). A survey on cloud computing security: Issues, threats, and solutions. Journal of Network and Computer Applications, 75, 200-222. Sisodia, J. & Khan, M (2022). The Customer’s Responsibility in the Cloud: Shared Responsibility Model. ISACA. https://www.isaca.org/resources/news- and-trends/isaca-now-blog/2022/the-customers-responsibility-in-the- cloud-shared-responsibility-model Somorovsky, J., Heiderich, M., Jensen, M., Schwenk, J., Gruschka, N. & Lo lacono, L. (2011). All Your Clouds are Belong to us – Security Analysis of Cloud Management Interfaces. In Proceedings of the 3rd ACM workshop on Cloud computing security workshop, 11 (pp. 3-14). NY, USA. Soms, N., Oswalt, M.S. & Santhos, K.P. (2022). A case study on cloud security controls. International Journal of Health Sciences, 6(S1), 11374-11380. Stanoevska-Slabeva, K., Wozniak, T. & Ristol, S. (2010). Grid and Cloud Computing: A Business Perspective on Technology and Applications. Springer.
72 Subashini, S. & Kavitha, V. (2010). A survey on security issues in service delivery models of cloud computing. Journal of Network and Computer Applications, 34, 1–11. Subramanian, E.K. & Tamilselvan, L. (2019). A focus on future cloud: machine learning-based cloud security. Service Oriented Computing and Applications, 13, 237-249. Sun, X. (2018). Critical Security Issues in Cloud Computing: A Survey. IEEE 4th International Conference on Big Data Security on Cloud (pp. 216-221). Omaha, NE, USA. Sur, C. (2018). Ensemble one-vs-all learning technique with emphatic & rehearsal training for phishing email classification using psychology. Journal of Experimental & Theoretical Artificial Intelligence, 30(6), 733-762 Torkura, K.A., Sukmana, M.I.H., Cheng, F. & Meinel, C. (2021). Continuous auditing and threat detection in multi-cloud infrastructure. Computers & Security, 102, 102-124. Walterbusch, A., Fietz, A. & Teuteberg, F. (2017). Missing cloud security awareness: investigating risk exposure in shadow IT. Journal of Enterprise Information Management, 30(4), 644-665. Wang, Z., Zhu, H. & Sun, L. (2021). Social engineering in cybersecurity: Effect mechanisms, human vulnerabilities and attack methods. IEEE Access, 13, 11895-11910 Wright, D., Smith, D., Ji, K., Borrega, M.A., Galimberti, A. & Bauman, S. (2023). Magic Quadrant for Strategic Cloud Platform Services. Gartner, inc. https://www.gartner.com/doc/reprints?id=1-2ES4ML14&ct=230823 Wright, R.T. & Marett, K. (2010). The Influence of Experiential and Dispositional Factors in Phishing: An Empirical Investigation of the Deceived. Journal of Management Information Systems, 27(1), 273-303. Xiaojun, Y. & Qiaoyan, W. (2010). A View about Cloud Data Security from Data Life Cycle. International Conference on Computational Intelligence and Software Engineering (pp. 1–4). Wuhan, China. Zhu, Y., Liu, P. & Wang, J. (2012). Cloud security research in Cloud Computing. Applied Mechanics and Materials, 198-199, 415-419. Zissis, D. & Lekkas, L. (2012). Addressing cloud computing security issues. Future Generation Computer Systems, 28, 583–592.
73 APPENDIX 1: SURVEY TEMPLATE
80
81
82
83
84
85
86