Summary of the results
| Rationale |
|
| |
| |
| |
| Practice |
|
| |
| |
| |
| |
| |
| |
| |
| Impact |
|
| |
| |
| Lessons learned |
|
| |
| |
| |
| |
| |
|
| Rationale | Why? – goal To identify information assets and to determine, which information assets are affected by which cloud service Compliance with laws and regulations |
Avoid economic, reputation and legal consequences Cost/benefit analysis of countermeasures Serving as supportive material for other risk assessments (e.g. on-site) Check if SLA with the cloud provider is achieved To identify threats and vulnerabilities in the cloud Cloud ISRA framework/method maturity | |
When? – initiation Introduction of a new service Changes in the current services Interval varies between monthly to yearly and every three years | |
Each cycle typically lasts a couple of days to one week | |
| Practice | Who is involved? Employees working with a specific cloud service Information asset owners IT department Info security experts in the organization |
Cloud ISRA frameworks/methods No specific (e.g. a matrix with risk likelihood and consequences) ISO/IEC 27000 series Metodstöd (Swedish Civil Contingencies Agency) KLASSA information classification method created by the Swedish Association of Local Authorities and Regions Combined methods, e.g. ISO/IEC 27005 and Metodstöd In-house (derived from other non-cloud ISRA frameworks) Methods are either chosen based on the familiarity of those conducting ISRA with the method or inherited from before | |
Tracking information assets whether they reside on the servers inside the organization or the cloud | |
Trusting the cloud provider affects the scope of the assessment | |
Analyzing the technical architecture, if possible, however, there are limitations | |
Dealing with the entanglement of the root cause of the risks; whether the risks come from a process, routine and practice inside or if they are related to the cloud vulnerabilities | |
Increasing risk scope, and therefore, the risk should be viewed as widely as possible | |
Deciding which activities fall under the organization domain and which are cloud’s responsibilities Managing risks are a combination of technical and operational activities (e.g. raising employee awareness to report the risks and encryption of data stored on the cloud) | |
| Impact | The decision on whether to shut down a cloud service |
Cyber situational awareness Making business decisions and using the resources in an optimal way | |
Cloud ISRA makes the organizations better at specifying requirements during service level agreements | |
| Lessons learned | Overall security culture improved |
Learning ISRA frameworks/methods | |
Organizations learn that they cannot entirely depend on the cloud service provider but must become better at specifying requirements during negotiations | |
Aligning overall security and cloud strategies | |
Cloud ISRA method adjustments are made after each iteration based on the alignment of assessed risks and ISRA rationale | |
A good cloud ISRA practice is both top-down and bottom-up, meaning that top management should support cloud ISRA and employees should be involved | |
Coordination of information security risks collected from different units and to propagate risk awareness in the whole organization |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.