Cyber Supply Chain Risks in Cloud Computing - Bridging the Risk Assessment Gap

نویسندگان

  • Olusola Akinrolabu
  • Steve New
  • Andrew Martin
چکیده

Cloud computing represents a significant paradigm shift in the delivery of information technology (IT) services. The rapid growth of the cloud and the increasing security concerns associated with the delivery of cloud services has led many researchers to study cloud risks and risk assessments. Some of these studies highlight the inability of current risk assessments to cope with the dynamic nature of the cloud, a gap we believe is as a result of the lack of consideration for the inherent risk of the supply chain. This paper, therefore, describes the cloud supply chain and investigates the effect of supply chain transparency in conducting a comprehensive risk assessment. We conducted an industry survey to gauge stakeholder awareness of supply chain risks, seeking to find out the risk assessment methods commonly used, factors that hindered a comprehensive evaluation and how the current state-of-the-art can be improved. The analysis of the survey dataset showed the lack of flexibility of the popular qualitative assessment methods in coping with the risks associated with the dynamic supply chain of cloud services, typically made up of an average of eight suppliers. To address these gaps, we propose a Cloud Supply Chain Cyber Risk Assessment (CSCCRA) model, a quantitative risk assessment model which is supported by decision support analysis and supply chain mapping in the identification, analysis and evaluation of cloud risks. TYPE OF PAPER AND

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Identifying Tools and Methods For Risk Identification and Assessment in Construction Supply Chain

The construction project is a business full of risk in every process due to its complexity, changes, and involvement from various stakeholders. One of the critical risks in the construction project is in the supply chain. Identifying and assessing the risk with the right tools and methods in that area will inevitably affect the success of the project. Unfortunately, the research for the tools a...

متن کامل

A risk model for cloud processes

Traditionally, risk assessment consists of evaluating the probability of "feared events", corresponding to known threats and attacks, as well as these events' severity, corresponding to their impact on one or more stakeholders. Assessing risks of cloud-based processes is particularly difficult due to lack of historical data on attacks, which has prevented frequency-based identification...

متن کامل

A Fuzzy AHP-TOPSIS Framework for the Risk Assessment of Green Supply Chain Implementation in the Textile Industry

In the emerging supply chain environment, green supply chain risk management plays a significant role than ever. Risk is an inherent uncertainty and has tendency to disrupt the typical green supply chain management (GSCM) operations and eventually reduce the success rate of industries. In order to mitigate the consequences, a fuzzy multi-criteria group decision making modeling (FMCGDM) which co...

متن کامل

Design of Multi-Objective Model for Disruption Risk Assessment of Supply Chain Using Combined Genetic Algorithm and Simulated Annealing

Due to the many risks involved in the supply chain, and the high costs associated with damage to the supply chain, risk identification and evaluation should be a top priority in risk management programs in organizations. Risk assessment and ratings determine the superiority of each risk based on the relevant indicators and thus provide an appropriate response to each risk. In this regard, this ...

متن کامل

Prioritization of Supply Chain Risks in Automotive Industry

Supply chains are constantly exposed to various risks. An incident or uncertain event, which has positive or negative effect on the objectives of a project, is called a risk. According to this identification, analysis and prioritization of risks may have a significant role in the success of the project. The purpose of risk management is to reduce the risks of non-achievement of these object...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • OJCC

دوره 5  شماره 

صفحات  -

تاریخ انتشار 2018