Abstract:
Cloud provider assessment is important for cloud consumers to determine, when outsourcing computing work, which providers can serve their business and system requirements. Functional requirements described explicitly or as quantitative information, e.g. platform and computing capacity, are usually easier to determine, whereas non-functional requirements, e.g. security, have to be checked against descriptive information on providers Web sites and therefore they are more difficult for cross-provider comparison. This research follows the Goal Question Metric approach and presents a weighted scoring model for assessing security requirements compliance of cloud providers. The security goals and questions that address the goals are taken from Cloud Security Alliances Cloud Controls Matrix and Consensus Assessments Initiative Questionnaire. The questions are transformed into more detailed ones and metrics are defined to help provide quantitative answers to the transformed questions based on evidence of security compliance provided by the cloud providers. The scoring is weighted by the quality of the evidence with respect to their compliance with the associated metrics and their completeness. A scoring tool is also proposed to support the assessment.