01.12.2012 Views

Proceedings of the 11th European Conference on Information ...

Proceedings of the 11th European Conference on Information ...

Proceedings of the 11th European Conference on Information ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Cloud Computing and Security<br />

Abílio Cardoso 1 and Paulo Simões 2<br />

1 Portucalense University, Portugal<br />

2 CISUC-DEI, University <str<strong>on</strong>g>of</str<strong>on</strong>g> Coimbra, Portugal<br />

Abstract: There is always a str<strong>on</strong>g pressure <strong>on</strong> Informati<strong>on</strong> Technology (IT)<br />

to do more with fewer resources. Over <str<strong>on</strong>g>the</str<strong>on</strong>g> decades, this pressure to rati<strong>on</strong>alize<br />

IT costs spurred a number <str<strong>on</strong>g>of</str<strong>on</strong>g> paradigms, technologies and<br />

buzzwords. Some <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g>m failed to meet <str<strong>on</strong>g>the</str<strong>on</strong>g>ir promises, while o<str<strong>on</strong>g>the</str<strong>on</strong>g>rs became<br />

successfully embed in IT practices and infrastructures, providing<br />

sizeable benefits. The paradigm <str<strong>on</strong>g>of</str<strong>on</strong>g> cloud computing is currently riding this<br />

wave, promising to be <str<strong>on</strong>g>the</str<strong>on</strong>g> next great revoluti<strong>on</strong> in IT. Cloud computing<br />

appears to have <str<strong>on</strong>g>the</str<strong>on</strong>g> right technological and market ingredients to become<br />

widely successful. However, <str<strong>on</strong>g>the</str<strong>on</strong>g>re are some key areas where cloud computing<br />

is still underperforming – such as security. Availability, security, privacy<br />

and integrity <str<strong>on</strong>g>of</str<strong>on</strong>g> informati<strong>on</strong> are some <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> biggest c<strong>on</strong>cerns in <str<strong>on</strong>g>the</str<strong>on</strong>g> process<br />

<str<strong>on</strong>g>of</str<strong>on</strong>g> designing, implementing and running IT services based <strong>on</strong> cloud<br />

computing, due to technological and legal matters. There is already an extensive<br />

set <str<strong>on</strong>g>of</str<strong>on</strong>g> recommendati<strong>on</strong>s for IT management and IT governance in<br />

general – such as <str<strong>on</strong>g>the</str<strong>on</strong>g> popular Informati<strong>on</strong> Technology Infrastructure Library<br />

(ITIL) guidelines and C<strong>on</strong>trol Objectives for Informati<strong>on</strong> and related<br />

Technology (COBIT) recommendati<strong>on</strong>s. However, <str<strong>on</strong>g>the</str<strong>on</strong>g> field <str<strong>on</strong>g>of</str<strong>on</strong>g> cloud computing<br />

remains poorly covered. ITIL and o<str<strong>on</strong>g>the</str<strong>on</strong>g>r general sources can be sometimes<br />

translated to <str<strong>on</strong>g>the</str<strong>on</strong>g> c<strong>on</strong>text <str<strong>on</strong>g>of</str<strong>on</strong>g> cloud computing, but <str<strong>on</strong>g>the</str<strong>on</strong>g>re are many<br />

new challenges not addressed by those generic resources. Recognizing this<br />

state <str<strong>on</strong>g>of</str<strong>on</strong>g> affairs, a number <str<strong>on</strong>g>of</str<strong>on</strong>g> initiatives already started focusing <strong>on</strong> novel<br />

proposals specifically targeting cloud computing but, up to now, with no<br />

significant outcomes. In this paper, we discuss <str<strong>on</strong>g>the</str<strong>on</strong>g> security implicati<strong>on</strong>s<br />

involved in <str<strong>on</strong>g>the</str<strong>on</strong>g> migrati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> IT services to <str<strong>on</strong>g>the</str<strong>on</strong>g> cloud-computing model,<br />

proposing a set <str<strong>on</strong>g>of</str<strong>on</strong>g> rules and guidelines to be followed in <str<strong>on</strong>g>the</str<strong>on</strong>g> process <str<strong>on</strong>g>of</str<strong>on</strong>g><br />

migrating IT services to <str<strong>on</strong>g>the</str<strong>on</strong>g> cloud. This set <str<strong>on</strong>g>of</str<strong>on</strong>g> rules and guidelines largely<br />

builds <strong>on</strong> general ITIL recommendati<strong>on</strong>s, discussing how to extend/adapt<br />

<str<strong>on</strong>g>the</str<strong>on</strong>g>m to <str<strong>on</strong>g>the</str<strong>on</strong>g> field <str<strong>on</strong>g>of</str<strong>on</strong>g> cloud computing and identifying which a number <str<strong>on</strong>g>of</str<strong>on</strong>g><br />

novel areas not covered by current ITIL recommendati<strong>on</strong>s.<br />

Keywords: cloud computing, security, ITIL<br />

9

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!