首页 | 本学科首页   官方微博 | 高级检索  
     检索      


Assessing information security risks in the cloud: A case study of Australian local government authorities
Institution:2. KPMG, 1 South Sathorn Rd, Yannawa, Sathorn Bangkok 10120, Thailand;1. TC Beirne School of Law, The University of Queensland, Australia;2. Royal Holloway, University of London, UK;1. School of Management, Shandong University, Jinan, China;2. School of Management Science and Engineering, Shandong University of Finance and Economics, Jinan, China
Abstract:Cloud computing enables cost-effective and scalable growth of IT services that can enhance government services. Despite the Australian Federal Government's ‘cloud-first’ strategy and policies, and the Queensland State Government's ‘digital-first’ strategy, cloud services adoption at local government level has been limited—largely due to data security concerns. We reviewed the ISO 27002 Information Security standard with extant literature and found that operational security, individual awareness and compliance matters pose more significant government challenges than the often-highlighted technical and process-oriented cloud security requirements. This study identifies and explores the critical factors associated with information security requirements of cloud services within the Australian regional local government context. We conducted 21 field interviews with IT managers, and surveyed 480 IT staff from Australia's 47 regional local governments. We propose a conceptual cloud computing security requirements model with four components – data security; risk assessment; legal & compliance requirements; and business & technical requirements – in order to promote a balanced view on cloud security for governments. Using this model, governments can work together to demand uniform security requirements for adopting cloud services.
Keywords:
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号