Table 2.

Summary of the results

Rationale
  • Why? – goal

    • To identify information assets and to determine, which information assets are affected by which cloud service

    • Compliance with laws and regulations

  • Avoid economic, reputation and legal consequences

    • Cost/benefit analysis of countermeasures

    • Serving as supportive material for other risk assessments (e.g. on-site)

    • Check if SLA with the cloud provider is achieved

    • To identify threats and vulnerabilities in the cloud

    • Cloud ISRA framework/method maturity

  • When? – initiation

    • Introduction of a new service

    • Changes in the current services

    • Interval varies between monthly to yearly and every three years

  • Each cycle typically lasts a couple of days to one week

Practice
  • Who is involved?

    • Employees working with a specific cloud service

    • Information asset owners

    • IT department

    • Info security experts in the organization

  • Cloud ISRA frameworks/methods

    • No specific (e.g. a matrix with risk likelihood and consequences)

    • ISO/IEC 27000 series

    • Metodstöd (Swedish Civil Contingencies Agency)

    • KLASSA information classification method created by the Swedish Association of Local Authorities and Regions

    • Combined methods, e.g. ISO/IEC 27005 and Metodstöd

    • In-house (derived from other non-cloud ISRA frameworks)

    • Methods are either chosen based on the familiarity of those conducting ISRA with the method or inherited from before

  • Tracking information assets whether they reside on the servers inside the organization or the cloud

  • Trusting the cloud provider affects the scope of the assessment

  • Analyzing the technical architecture, if possible, however, there are limitations

  • Dealing with the entanglement of the root cause of the risks; whether the risks come from a process, routine and practice inside or if they are related to the cloud vulnerabilities

 
  • Increasing risk scope, and therefore, the risk should be viewed as widely as possible

  • Deciding which activities fall under the organization domain and which are cloud’s responsibilities

    • Managing risks are a combination of technical and operational activities (e.g. raising employee awareness to report the risks and encryption of data stored on the cloud)

Impact
  • The decision on whether to shut down a cloud service

  • Cyber situational awareness

    • Making business decisions and using the resources in an optimal way

  • Cloud ISRA makes the organizations better at specifying requirements during service level agreements

Lessons learned
  • Overall security culture improved

  • Learning ISRA frameworks/methods

  • Organizations learn that they cannot entirely depend on the cloud service provider but must become better at specifying requirements during negotiations

  • Aligning overall security and cloud strategies

  • Cloud ISRA method adjustments are made after each iteration based on the alignment of assessed risks and ISRA rationale

  • A good cloud ISRA practice is both top-down and bottom-up, meaning that top management should support cloud ISRA and employees should be involved

  • Coordination of information security risks collected from different units and to propagate risk awareness in the whole organization

or Create an Account

Close subscription notice
Close access options