透過您的圖書館登入
IP:3.135.206.125
  • 期刊

一個基於ISO 31010評估標準的雲端風險評估方法

摘要


雲端運算時代來臨,企業紛紛走入雲端運算領域,將服務建置於雲端環境中,降低IT進入門檻,節省龐大的硬體設備費用。然而歐洲網路與資訊安全局(European Network and Information Security Agency, ENISA)針對企業對雲端觀點調查指出,安全成為許多企業的重要考量(Alessandro Perilli et.al.2010)。因此為了提升客戶對雲端供應商提供服務之信任,風險評估已成為採用雲端服務的重要程序之一。目前雲端服務風險評估的研究鮮少,無法顯示服務造成損失和評估標準。因此本研究以目前雲端供應商微軟的Windows Azure服務元件進行探討,基於ISO 31010定義風險評估之準則,提出雲端服務之風險評估方法,使用監控機制即時更新雲端環境之風險發生機率,並利用金額量化評估結果,顯示雲端服務對企業造成的損失,作為企業採用雲端服務之決策依據。

並列摘要


Enterprise could easily configure services from cloud computing with low upfront investments of hardware and equipment. Nevertheless, ENISA (European Network and Information Security Agency) researches on cloud services show that the security concern is the most important point for enterprise adoption of cloud services. To achieve this, risk assessment becomes a main of procedures to improve the trust of cloud services for users. In this paper, we propose an approach to assess the risk associated with applying a cloud service, exemplified by Windows Azure and based on principle of risk assessment from ISO 31010. Our approach could monitor the probability of risk of the related services, and present the quantitative risk in corresponding money loss, which then can be used to support decision making of adoption of the service.

被引用紀錄


董仲瑋(2014)。以資服業經理人的角度探討雲端的資訊治理〔碩士論文,國立中正大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0033-2110201613571359

延伸閱讀