Enhancing Cloud Security Standards


Cloud computing was introduced with the promise to dramatically reduce complexity for the user organizations. After approximately a decade, cloud computing services are now so complex with regard to assembly of functionality, provisioning and maintenance, that it is rather impossible to use them right now, on-demand without a significant amount of preparation. Nevertheless, several cloud computing standards could be understood in a way that cloud computing is a simple function that can instantly be used after ordering it through a self-service portal. A closer look, however, reveals that today’s cloud computing services can be complex. The complexity also concerns the IT security management – also for the user organization. Whereas in traditional outsourcing, the IT service provider took care about most essential security aspects, modern public cloud offerings leave many tasks to the user organizations. But there is more. Cloud services differ in their construction which may also affect the IT security and compliance risk profile.

Current cloud security standards (e.g. [1], [2] and [3]) do not provide user organizations with sufficient detail. This can be because authors did not see any possibility to do this. They focused on cloud services they considered being typical and added statements that further analysis is required when a specific cloud service is about to be contracted.

This document describes an alternative:

  1. Cloud security standards shall demand the Cloud Service Provider (CSP) to provide appropriate guidance for user organizations.
  2. This guidance shall characterize the cloud computing service, specifically the cloud’s Deployment Model (for whom and how the service provided) and the cloud’s Service Model (which party is responsible for what).
  3. In addition to the content of guidance, the cloud security standards shall also define its structure and the syntax and semantics of the sentences (called Patterns in the following) the guidance for user organizations consists of. This third condition ensures that user organization can compare the cloud computing services or, more precisely, their security and compliance risk profile and the division of labor throughout the service’s lifecycle.

The concept can be extended to and used in other areas than cloud security. According to this Zero Outage Industry Standard, security standards shall request that a user’s guide is provided which contains all necessary detail. Security standards shall also define content and structure of that user’s guide. Refer to below to read more about the reasons and the implementation of this concept.

This document is developed based on concepts described in [4] and using diagrams from [5]. In this document a simple model is used with two parties: the IT service provider or Cloud Service Provider (CSC) as the supplying party on the one hand and the user organization or Cloud Service Consumer (CSC) as the consuming party on the other hand. The model is extended when required.

