<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>Iranian Society of Cryptology</PublisherName>
				<JournalTitle>The ISC International Journal of Information Security</JournalTitle>
				<Issn>2008-2045</Issn>
				<Volume>6</Volume>
				<Issue>2</Issue>
				<PubDate PubStatus="epublish">
					<Year>2014</Year>
					<Month>07</Month>
					<Day>01</Day>
				</PubDate>
			</Journal>
<ArticleTitle>A risk model for cloud processes</ArticleTitle>
<VernacularTitle></VernacularTitle>
			<FirstPage>99</FirstPage>
			<LastPage>123</LastPage>
			<ELocationID EIdType="pii">39155</ELocationID>
			
<ELocationID EIdType="doi">10.22042/isecure.2015.6.2.2</ELocationID>
			
			<Language>EN</Language>
<AuthorList>
<Author>
					<FirstName>E.</FirstName>
					<LastName>Damiani</LastName>
<Affiliation></Affiliation>

</Author>
<Author>
					<FirstName>S.</FirstName>
					<LastName>Cimato</LastName>
<Affiliation></Affiliation>

</Author>
<Author>
					<FirstName>G.</FirstName>
					<LastName>Gianini</LastName>
<Affiliation></Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2014</Year>
					<Month>10</Month>
					<Day>23</Day>
				</PubDate>
			</History>
		<Abstract>Traditionally, risk assessment consists of evaluating the probability of &quot;feared events&quot;, corresponding to known threats and attacks, as well as these events&#039; &lt;em&gt;severity&lt;/em&gt;, corresponding to their impact on one or more stakeholders. Assessing risks of cloud-based processes is particularly difficult due to lack of historical data on attacks, which has prevented frequency-based identification of &quot;typical&quot; threats and attack vectors. Also, the dynamic, multi-party nature of cloud-based processes makes severity assessment very dependent on the particular set of stakeholders involved in each process execution. In this paper, we tackle these problems by presenting a novel, &lt;em&gt;process-oriented&lt;/em&gt; quantitative risk assessment methodology aimed at disclosure risks on cloud computing platforms. Key advantages of our methodology include (i) a fully quantitative and iterative approach, which enables stakeholders to compare alternative versions of cloud-based processes (e.g., with and without security controls) (ii) non-frequency-based probability estimates, which allow analyzing threats for which a detailed history is not available (iii) support for quick visual comparisons of risk profiles of alternative processes even when impact cannot be exactly quantified.</Abstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">cloud computing</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Value of Information</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Risk Assessment</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Secure Computation</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.isecure-journal.com/article_39155_c4a55894b71e51a90b84a28c1b946d2b.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
