Security and Compliance Issues in Cloud-Based Deployments of Content and Workflow Management Systems

Main Article Content

Ravi Kiran Kanneganti

Abstract

The spread of cloud-based content and workflow management systems has increased boisterously within industries, and usage has subjected organizations to severe security and compliance threats. This paper discusses these risks based on a process of systematic analysis of literature on twenty peer-reviewed sources. We are able to categorize five types of threats, analyze five hypothetical compliance models and provide a quantitative security assurance model based on weighted scoring. Conclusions indicate that data breaches and identity management successes and failures occur in content and workflow environments and can explain about 50% of reported incidents of cloud security. The three frameworks of compliance vary in terms of coverage, ease of implementation and integration of workflow. The article suggests a layered security architecture and quantitative assurance metrics to enable decision clouds to select cloud services and design policies based on that selection. Companies with coordinated compliance strategies have significantly low numbers of violations, and improved overall security status.

Article Details

How to Cite
Kanneganti, R. K. (2024). Security and Compliance Issues in Cloud-Based Deployments of Content and Workflow Management Systems. The Eastasouth Journal of Information System and Computer Science, 2(01), 131–138. https://doi.org/10.58812/esiscs.v2i01.1122
Section
Articles

References

[1] M. Iorga and A. Karmel, “Managing risk in a cloud ecosystem,” IEEE Cloud Computing, vol. 2, no. 6, pp. 51–57, Nov. 2015, doi: 10.1109/mcc.2015.122. Available: https://doi.org/10.1109/mcc.2015.122

[2] D. Yimam and E. B. Fernandez, “A survey of compliance issues in cloud computing,” Journal of Internet Services and Applications, vol. 7, no. 1, May 2016, doi: 10.1186/s13174-016-0046-8. Available: https://doi.org/10.1186/s13174-016-0046-8

[3] J. Crampton, G. Gutin, D. Karapetyan, and R. Watrigant, “The bi-objective workflow satisfiability problem and workflow resiliency,” Journal of Computer Security, vol. 25, no. 1, pp. 83–115, Dec. 2016, doi: 10.3233/jcs-16849. Available: https://doi.org/10.3233/jcs-16849

[4] N. M. Gonzalez, T. C. M. De Brito Carvalho, and C. C. Miers, “Cloud resource management: towards efficient execution of large-scale scientific applications and workflows on complex infrastructures,” Journal of Cloud Computing Advances Systems and Applications, vol. 6, no. 1, Jun. 2017, doi: 10.1186/s13677-017-0081-4. Available: https://doi.org/10.1186/s13677-017-0081-4

[5] J.-M. Martinez-Caro, A.-J. Aledo-Hernandez, A. Guillen-Perez, R. Sanchez-Iborra, and M.-D. Cano, “A comparative study of Web content Management Systems,” Information, vol. 9, no. 2, p. 27, Jan. 2018, doi: 10.3390/info9020027. Available: https://doi.org/10.3390/info9020027

[6] K. Brandis, S. Dzombeta, R. Colomo-Palacios, and V. Stantchev, “Governance, risk, and compliance in cloud scenarios,” Applied Sciences, vol. 9, no. 2, p. 320, Jan. 2019, doi: 10.3390/app9020320. Available: https://doi.org/10.3390/app9020320

[7] C. Bryce, “Security governance as a service on the cloud,” Journal of Cloud Computing Advances Systems and Applications, vol. 8, no. 1, Dec. 2019, doi: 10.1186/s13677-019-0148-5. Available: https://doi.org/10.1186/s13677-019-0148-5

[8] D. Georgiou and C. Lambrinoudakis, “Compatibility of a Security Policy for a Cloud-Based Healthcare System with the EU General Data Protection Regulation (GDPR),” Information, vol. 11, no. 12, p. 586, Dec. 2020, doi: 10.3390/info11120586. Available: https://doi.org/10.3390/info11120586

[9] Z. Georgiopoulou, E.-L. Makri, and C. Lambrinoudakis, “GDPR compliance: proposed technical and organizational measures for cloud provider,” Information and Computer Security, vol. 28, no. 5, pp. 665–680, Jun. 2020, doi: 10.1108/ics-01-2020-0009. Available: https://doi.org/10.1108/ics-01-2020-0009

[10] R. El-Gazzar and K. Stendal, “Examining how GDPR challenges emerging technologies,” Journal of Information Policy, vol. 10, pp. 237–275, May 2020, doi: 10.5325/jinfopoli.10.2020.0237. Available: https://doi.org/10.5325/jinfopoli.10.2020.0237

[11] Y. Hu, H. Wang, and W. Ma, “Intelligent cloud workflow management and scheduling method for big data applications,” Journal of Cloud Computing Advances Systems and Applications, vol. 9, no. 1, Jul. 2020, doi: 10.1186/s13677-020-00177-8. Available: https://doi.org/10.1186/s13677-020-00177-8

[12] T. Abioye, O. Arogundade, S. Misra, K. Adesemowo, and R. Damaševičius, “Cloud-Based Business Process Security Risk Management: A Systematic Review, Taxonomy, and Future Directions,” Computers, vol. 10, no. 12, p. 160, Nov. 2021, doi: 10.3390/computers10120160. Available: https://doi.org/10.3390/computers10120160

[13] N. Soveizi, F. Turkmen, and D. Karastoyanova, “Security and privacy concerns in cloud-based scientific and business workflows: A systematic review,” Future Generation Computer Systems, vol. 148, pp. 184–200, May 2023, doi: 10.1016/j.future.2023.05.015. Available: https://doi.org/10.1016/j.future.2023.05.015

[14] H. T. El-Kassabi, M. A. Serhani, M. M. Masud, K. Shuaib, and K. Khalil, “Deep learning approach to security enforcement in cloud workflow orchestration,” Journal of Cloud Computing Advances Systems and Applications, vol. 12, no. 1, p. 10, Jan. 2023, doi: 10.1186/s13677-022-00387-2. Available: https://doi.org/10.1186/s13677-022-00387-2

[15] A. Issaoui, J. Örtensjö, and M. S. Islam, “Exploring the General Data Protection Regulation (GDPR) compliance in cloud services: insights from Swedish public organizations on privacy compliance,” Future Business Journal, vol. 9, no. 1, Dec. 2023, doi: 10.1186/s43093-023-00285-2. Available: https://doi.org/10.1186/s43093-023-00285-2

[16] A. Shukla, B. Katt, and M. M. Yamin, “A quantitative framework for security assurance evaluation and selection of cloud services: a case study,” International Journal of Information Security, vol. 22, no. 6, pp. 1621–1650, Jun. 2023, doi: 10.1007/s10207-023-00709-8. Available: https://doi.org/10.1007/s10207-023-00709-8

[17] L. R. P. Sahayaraj and S. Muthurajkumar, “Efficient classification and preservation of log integrity through propagated chain in cloud,” Journal of Intelligent & Fuzzy Systems, vol. 45, no. 3, pp. 4669–4687, Jul. 2023, doi: 10.3233/jifs-224585. Available: https://doi.org/10.3233/jifs-224585

[18] D. Chatziamanetoglou and K. Rantos, “Blockchain-Based Security Configuration Management for ICT systems,” Electronics, vol. 12, no. 8, p. 1879, Apr. 2023, doi: 10.3390/electronics12081879. Available: https://doi.org/10.3390/electronics12081879

[19] M. Chauhan and S. Shiaeles, “An analysis of cloud security frameworks, problems and proposed solutions,” Network, vol. 3, no. 3, pp. 422–450, Sep. 2023, doi: 10.3390/network3030018. Available: https://doi.org/10.3390/network3030018

[20] V. Jayasinghe, E. Erturk, and Z. Li, “Critical factors Influencing cloud security posture of Enterprises: An Empirical analysis,” Information Dynamics and Applications, vol. 2, no. 4, pp. 210–222, Dec. 2023, doi: 10.56578/ida020405. Available: http://dx.doi.org/10.56578/ida020405

[21] N. Fotiou, A. Machas, G. C. Polyzos, and G. Xylomenos, “Access control as a service for the Cloud,” Journal of Internet Services and Applications, vol. 6, no. 1, May 2015, doi: 10.1186/s13174-015-0026-4. Available: https://doi.org/10.1186/s13174-015-0026-4

[22] J. Singh, J. Powles, T. Pasquier, and J. Bacon, “Data flow management and compliance in cloud computing,” IEEE Cloud Computing, vol. 2, no. 4, pp. 24–32, Jul. 2015, doi: 10.1109/mcc.2015.69. Available: https://doi.org/10.1109/mcc.2015.69

[23] M. Ouedraogo, S. Mignon, H. Cholez, S. Furnell, and E. Dubois, “Security transparency: the next frontier for security research in the cloud,” Journal of Cloud Computing Advances Systems and Applications, vol. 4, no. 1, Jun. 2015, doi: 10.1186/s13677-015-0037-5. Available: https://doi.org/10.1186/s13677-015-0037-5

[24] J. Li, X. Chen, J. Li, C. Jia, J. Ma, and W. Lou, “New access control systems based on outsourced attribute-based encryption,” Journal of Computer Security, vol. 23, no. 6, pp. 659–683, Sep. 2015, doi: 10.3233/jcs-150533. Available: https://doi.org/10.3233/jcs-150533

[25] S. P. Kaluvuri, A. I. Egner, J. D. Hartog, and N. Zannone, “SAFAX – An Extensible Authorization Service for Cloud Environments,” Frontiers in ICT, vol. 2, May 2015, doi: 10.3389/fict.2015.00009. Available: https://doi.org/10.3389/fict.2015.00009